{"resultsPerPage":717,"startIndex":0,"totalResults":717,"format":"NVD_CVE","version":"2.0","timestamp":"2026-08-15T11:40:22.388","vulnerabilities":[{"cve":{"id":"CVE-2026-14229","sourceIdentifier":"contact@wpscan.com","published":"2026-08-15T06:16:49.917","lastModified":"2026-08-15T06:16:49.917","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"The ECS  WordPress plugin before 4.3.8 does not check the post status or any capability when rendering an Elementor document requested through one of its AJAX actions, allowing unauthenticated users to retrieve the rendered content of unpublished (private, draft, pending) documents by supplying their identifier."}],"affected":[{"source":"contact@wpscan.com","affectedData":[{"vendor":"Unknown","product":"ECS","defaultStatus":"unaffected","versions":[{"version":"0","lessThan":"4.3.8","versionType":"semver","status":"affected"}]}]}],"metrics":{},"references":[{"url":"https://wpscan.com/vulnerability/52b44fc8-90af-45e4-a745-37e6369d8b6b/","source":"contact@wpscan.com"}]}},{"cve":{"id":"CVE-2026-14230","sourceIdentifier":"contact@wpscan.com","published":"2026-08-15T06:16:55.960","lastModified":"2026-08-15T06:16:55.960","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"The ECS  WordPress plugin before 4.3.8 does not perform capability or object-ownership checks on its Dynamic Repeater AJAX handlers (gated only by a capability-agnostic nonce that any edit_posts user obtains from the Elementor editor), so a Contributor can write a data-source binding into any post — including admin-authored pages — whose attacker-controlled values are rendered into a widget's repeater output without sanitization, executing JavaScript in the session of any visitor or administrator who views the page."}],"affected":[{"source":"contact@wpscan.com","affectedData":[{"vendor":"Unknown","product":"ECS","defaultStatus":"unaffected","versions":[{"version":"0","lessThan":"4.3.8","versionType":"semver","status":"affected"}]}]}],"metrics":{},"references":[{"url":"https://wpscan.com/vulnerability/fded2f21-d104-4dcb-8fd1-29db9866cabc/","source":"contact@wpscan.com"}]}},{"cve":{"id":"CVE-2026-16007","sourceIdentifier":"ab69c47f-b95e-4bf2-b2d9-4b1fd1b24b4a","published":"2026-08-15T06:16:56.063","lastModified":"2026-08-15T06:16:56.063","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"AppFlowy's qcuiknote feature is affected by a SQL injection vulnerability. Authenticated users with access to the feature can inject arbitrary SQL to exfiltrate data in the underlying SQL database."}],"affected":[{"source":"ab69c47f-b95e-4bf2-b2d9-4b1fd1b24b4a","affectedData":[{"vendor":"AppFlowy-IO","product":"AppFlowy-Cloud","defaultStatus":"affected","versions":[{"version":"0","lessThanOrEqual":"*","versionType":"custom","status":"affected"}]}]}],"metrics":{"cvssMetricV40":[{"source":"ab69c47f-b95e-4bf2-b2d9-4b1fd1b24b4a","type":"Secondary","cvssData":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","baseScore":7.1,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"LOW","userInteraction":"NONE","vulnConfidentialityImpact":"HIGH","vulnIntegrityImpact":"LOW","vulnAvailabilityImpact":"NONE","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","subAvailabilityImpact":"NONE","exploitMaturity":"NOT_DEFINED","confidentialityRequirement":"NOT_DEFINED","integrityRequirement":"NOT_DEFINED","availabilityRequirement":"NOT_DEFINED","modifiedAttackVector":"NOT_DEFINED","modifiedAttackComplexity":"NOT_DEFINED","modifiedAttackRequirements":"NOT_DEFINED","modifiedPrivilegesRequired":"NOT_DEFINED","modifiedUserInteraction":"NOT_DEFINED","modifiedVulnConfidentialityImpact":"NOT_DEFINED","modifiedVulnIntegrityImpact":"NOT_DEFINED","modifiedVulnAvailabilityImpact":"NOT_DEFINED","modifiedSubConfidentialityImpact":"NOT_DEFINED","modifiedSubIntegrityImpact":"NOT_DEFINED","modifiedSubAvailabilityImpact":"NOT_DEFINED","Safety":"NOT_DEFINED","Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","valueDensity":"NOT_DEFINED","vulnerabilityResponseEffort":"NOT_DEFINED","providerUrgency":"NOT_DEFINED"}}]},"weaknesses":[{"source":"ab69c47f-b95e-4bf2-b2d9-4b1fd1b24b4a","type":"Secondary","description":[{"lang":"en","value":"CWE-89"}]}],"references":[{"url":"https://projectblack.io/blog/appflowy-authenticated-sql-injection/","source":"ab69c47f-b95e-4bf2-b2d9-4b1fd1b24b4a"}]}},{"cve":{"id":"CVE-2026-16541","sourceIdentifier":"contact@wpscan.com","published":"2026-08-15T06:17:08.280","lastModified":"2026-08-15T06:17:08.280","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"The Simply Schedule Appointments WordPress plugin before 1.6.12.17 does not restrict the user records returned by some of its REST endpoints to those the requester is entitled to see, allowing users with a low-privileged staff role to disclose the names and email addresses of arbitrary registered users."}],"affected":[{"source":"contact@wpscan.com","affectedData":[{"vendor":"Unknown","product":"Simply Schedule Appointments","defaultStatus":"unaffected","versions":[{"version":"0","lessThan":"1.6.12.17","versionType":"semver","status":"affected"}]}]}],"metrics":{},"references":[{"url":"https://wpscan.com/vulnerability/8172f778-5dc5-49e8-9967-81215ac187d7/","source":"contact@wpscan.com"}]}},{"cve":{"id":"CVE-2026-16611","sourceIdentifier":"contact@wpscan.com","published":"2026-08-15T06:17:08.380","lastModified":"2026-08-15T06:17:08.380","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"The Product Feed PRO for WooCommerce by AdTribes  WordPress plugin before 13.5.7 does not perform an authorization check on one of its REST read routes, allowing unauthenticated users to disclose a store's feed configuration (rules, filters and field mapping) and to enumerate the full product category taxonomy."}],"affected":[{"source":"contact@wpscan.com","affectedData":[{"vendor":"Unknown","product":"Product Feed PRO for WooCommerce by AdTribes","defaultStatus":"unaffected","versions":[{"version":"0","lessThan":"13.5.7","versionType":"semver","status":"affected"}]}]}],"metrics":{},"references":[{"url":"https://wpscan.com/vulnerability/87fe63af-5a43-4812-88ce-568b1cc1598f/","source":"contact@wpscan.com"}]}},{"cve":{"id":"CVE-2026-18216","sourceIdentifier":"contact@wpscan.com","published":"2026-08-15T06:17:08.487","lastModified":"2026-08-15T06:17:08.487","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"The Backup Migration WordPress plugin before 2.1.7 does not properly restrict a post-restore automatic login mechanism, allowing a user who administers one site of a multisite network to obtain a long-lived authenticated session as an administrator of another site in the same network, without credentials and bypassing two-factor authentication."}],"affected":[{"source":"contact@wpscan.com","affectedData":[{"vendor":"Unknown","product":"Backup Migration","defaultStatus":"unaffected","versions":[{"version":"0","lessThan":"2.1.7","versionType":"semver","status":"affected"}]}]}],"metrics":{},"references":[{"url":"https://wpscan.com/vulnerability/f12530c5-4069-42c2-9f1c-b00fc62aa387/","source":"contact@wpscan.com"}]}},{"cve":{"id":"CVE-2026-18807","sourceIdentifier":"contact@wpscan.com","published":"2026-08-15T06:17:17.050","lastModified":"2026-08-15T06:17:17.050","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"The ECS  WordPress plugin before 4.3.8 does not have capability or ownership checks on its dynamic repeater actions, relying only on a nonce available to any user who can open the page builder, allowing users with a contributor-level account or above to read, alter and delete the binding configuration of posts they do not own and to change the ECS  WordPress plugin before 4.3.8's site-wide presets."}],"affected":[{"source":"contact@wpscan.com","affectedData":[{"vendor":"Unknown","product":"ECS","defaultStatus":"unaffected","versions":[{"version":"0","lessThan":"4.3.8","versionType":"semver","status":"affected"}]}]}],"metrics":{},"references":[{"url":"https://wpscan.com/vulnerability/bf500bf2-1684-4ca1-a8ad-bcff9cbc127c/","source":"contact@wpscan.com"}]}},{"cve":{"id":"CVE-2026-68455","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:17:17.160","lastModified":"2026-08-15T06:17:17.160","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nliveupdate: validate session type before performing operation\n\nThe sessions ioctls are not applicable to all session types. PRESERVE_FD\nis only applicable to outgoing sessions. RETRIEVE_FD and FINISH are only\nvalid for incoming session. Calling a incoming ioctl on an outgoing\nsession is invalid and can cause file handlers to run into unexpected\nerrors.\n\nFor example, a user can create a (outgoing) session, preserve a memfd,\nand then immediately do a retrieve without doing a kexec in between.\nThis would result in memfd's retrieve handler to run. The handlers\nexpects to be called from a post-kexec context, and will try to do a\nkho_restore_vmalloc() or kho_restore_folio() to try and restore memory.\n\nKHO catches this (thanks to KHO_PAGE_MAGIC) and returns an error, but\nsince this is considered an internal error and KHO throws out a bunch of\nWARN()s.\n\nAssociate a type with each ioctl op and validate the type in\nluo_session_ioctl() before dispatching the ioctl handler to make sure\nthe op is being called for the right session type."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["kernel/liveupdate/luo_session.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"16cec0d265219f14a7fcebcc43aeb69205adba56","lessThan":"3dc8a46d08a8a060d4128e9f497060b8d03c1595","versionType":"git","status":"affected"},{"version":"16cec0d265219f14a7fcebcc43aeb69205adba56","lessThan":"507e3b479f9c6d85135eb5e1a77fb3fddb259ad8","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["kernel/liveupdate/luo_session.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.19","status":"affected"},{"version":"0","lessThan":"6.19","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/3dc8a46d08a8a060d4128e9f497060b8d03c1595","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/507e3b479f9c6d85135eb5e1a77fb3fddb259ad8","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-68456","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:17:32.713","lastModified":"2026-08-15T06:17:32.713","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nusb: atm: ueagle-atm: wait for pre-firmware load in .disconnect()\n\nueagle-atm uses the asynchronous request_firmware_nowait() in .probe(),\nbut does not wait for its completion, not even in .disconnect(); so, if the\ndevice is unplugged meanwhile, its teardown runs concurrently with that.\n\nEven though this inconsistency is worth addressing on its own, it has also\ntriggered several bug reports in syzbot over the years (some auto-closed)\nwhere the firmware sysfs fallback mechanism (CONFIG_FW_LOADER_USER_HELPER)\ncreates a firmware subdirectory in the device directory during its removal,\nwhich might hit unexpected conditions in kernfs, apparently, depending at\nwhich point the add and remove operations raced. (See links.)\n\nThe pattern is:\n\nusb ?-?: Direct firmware load for ueagle-atm/eagle?.fw failed with error -2\nusb ?-?: Falling back to sysfs fallback for: ueagle-atm/eagle?.fw\n<ERROR>\nCall trace:\n ...\n kernfs_create_dir_ns\n sysfs_create_dir_ns\n create_dir\n kobject_add_internal\n kobject_add_varg\n kobject_add\n class_dir_create_and_add\n get_device_parent\n device_add\n fw_load_sysfs_fallback\n fw_load_from_user_helper\n firmware_fallback_sysfs\n _request_firmware\n request_firmware_work_func\n ...\n\n(Some variations are observed, after fw_load_sysfs_fallback(), e.g., [1].)\n\nWhile the kernfs side is being looked at, the ueagle-atm side can be fixed\nby waiting for the pre-firmware load in the .disconnect() handler.\n\nThis change has a similar approach to previous work by Andrey Tsygunka [2]\n(wait_for_completion() in .disconnect()), but it is relatively different in\ndesign/implementation; using the Originally-by tag for credit assignment.\n\nThis has been tested with:\n- synthetic reproducer to check the error path;\n- USB gadget (virtual device) to check the firmware upload path;\n- QEMU device emulator to check the device ID re-enumeration path;\n(The latter two were written by Claude; no other code/text in this commit.)\n\nLinks (year first reported):\n 2025 https://syzbot.org/bug?extid=ce1e5a1b4e086b43e56d\n 2025 https://syzbot.org/bug?extid=9af8471255ac36e34fd4\n 2024 https://syzbot.org/bug?extid=306212936b13e520679d\n 2023 https://syzkaller.appspot.com/bug?extid=457452d30bcdda75ead2\n 2022 https://syzbot.org/bug?extid=782984d6f1701b526edb\n 2021 https://syzbot.org/bug?id=f3f221579f4ef7e9691281f3c6f56c05f83e8490\n 2021 https://syzbot.org/bug?id=84d86f0d71394829df6fc53daf6642c045983881\n 2021 https://syzbot.org/bug?id=3302dc1c0e2b9c94f2e8edb404eabc9267bc6f90\n\n[1] https://syzkaller.appspot.com/bug?extid=457452d30bcdda75ead2\n[2] https://lore.kernel.org/lkml/20250410093146.3776801-2-aitsygunka@yandex.ru/"}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/usb/atm/ueagle-atm.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"b72458a80c75cab832248f536412f386e20a93a0","lessThan":"d85f19aaef42a03e3e4765d659c761c8750a7f23","versionType":"git","status":"affected"},{"version":"b72458a80c75cab832248f536412f386e20a93a0","lessThan":"76861031b43a18065d13f9ffb8595d25c7576005","versionType":"git","status":"affected"},{"version":"b72458a80c75cab832248f536412f386e20a93a0","lessThan":"bbfedc84714064ea4845e6b76f96316eb5bb65d8","versionType":"git","status":"affected"},{"version":"b72458a80c75cab832248f536412f386e20a93a0","lessThan":"f2a6abc670104fc3e383ee3b1cf35c070485e3df","versionType":"git","status":"affected"},{"version":"b72458a80c75cab832248f536412f386e20a93a0","lessThan":"c581e30ae5b332d8acef64475a211b3f82099941","versionType":"git","status":"affected"},{"version":"b72458a80c75cab832248f536412f386e20a93a0","lessThan":"509b51327320bdeaef1969248177a446ded073ab","versionType":"git","status":"affected"},{"version":"b72458a80c75cab832248f536412f386e20a93a0","lessThan":"ddcdac47e1f2651c7be60e299f98faf981522797","versionType":"git","status":"affected"},{"version":"b72458a80c75cab832248f536412f386e20a93a0","lessThan":"e2674dfbed8a30d57e2bc872c4bfa6c3eec918bf","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/usb/atm/ueagle-atm.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"2.6.16","status":"affected"},{"version":"0","lessThan":"2.6.16","versionType":"semver","status":"unaffected"},{"version":"5.10.261","lessThanOrEqual":"5.10.*","versionType":"semver","status":"unaffected"},{"version":"5.15.212","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.178","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.97","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc3","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/509b51327320bdeaef1969248177a446ded073ab","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/76861031b43a18065d13f9ffb8595d25c7576005","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/bbfedc84714064ea4845e6b76f96316eb5bb65d8","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/c581e30ae5b332d8acef64475a211b3f82099941","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/d85f19aaef42a03e3e4765d659c761c8750a7f23","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/ddcdac47e1f2651c7be60e299f98faf981522797","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/e2674dfbed8a30d57e2bc872c4bfa6c3eec918bf","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/f2a6abc670104fc3e383ee3b1cf35c070485e3df","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-68457","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:17:48.460","lastModified":"2026-08-15T06:17:48.460","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nksmbd: use opener credentials for FSCTL mutations\n\nSET_SPARSE, SET_ZERO_DATA and SET_COMPRESSION operate on an open SMB\nhandle but call VFS xattr, fallocate or fileattr helpers with the current\nksmbd worker credentials. Those helpers can revalidate inode permissions,\nownership and LSM policy independently of the SMB handle access mask.\n\nRun each operation with the credentials captured in the target file when\nthe handle was opened. Keep credential handling local to these single-file\nFSCTLs rather than applying session credentials to the complete IOCTL\nhandler, which also contains handle-less and multi-handle operations."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["fs/smb/server/smb2pdu.c","fs/smb/server/vfs.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"a8c18434e1f0d9f7989170bdb0490c0160baf065","versionType":"git","status":"affected"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"1e112c47ec5dd1942e2d4ca6e8e9b712238e20c2","versionType":"git","status":"affected"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"fb1cae6302d58414ddf029e3f642711bd30243f7","versionType":"git","status":"affected"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"e205f3e7e8c31a47cd11efb6cf663a527177e432","versionType":"git","status":"affected"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"cfb2c6f71d61ed807c9d7a7af331d406f1f31877","versionType":"git","status":"affected"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"c6394bcaf254c5baf9aff43376020be5db6d3316","versionType":"git","status":"affected"},{"version":"0","lessThan":"6.1.178","versionType":"semver","status":"affected"},{"version":"0","lessThan":"6.6.145","versionType":"semver","status":"affected"},{"version":"0","lessThan":"6.12.97","versionType":"semver","status":"affected"},{"version":"0","lessThan":"6.18.40","versionType":"semver","status":"affected"},{"version":"0","lessThan":"7.1.5","versionType":"semver","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["fs/smb/server/smb2pdu.c","fs/smb/server/vfs.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.1.178","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.97","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/1e112c47ec5dd1942e2d4ca6e8e9b712238e20c2","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/a8c18434e1f0d9f7989170bdb0490c0160baf065","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/c6394bcaf254c5baf9aff43376020be5db6d3316","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/cfb2c6f71d61ed807c9d7a7af331d406f1f31877","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/e205f3e7e8c31a47cd11efb6cf663a527177e432","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/fb1cae6302d58414ddf029e3f642711bd30243f7","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-68458","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:18:15.350","lastModified":"2026-08-15T06:18:15.350","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nbinder: cache secctx size before release zeroes it\n\nbinder_transaction() bounds the scatter-gather buffer area with\nsg_buf_end_offset and subtracts the aligned LSM context size because\nthe secctx is written at the tail of that area.  The subtraction reads\nlsmctx.len, but that field has already been cleared by the time the\nline runs:\n\n    security_secid_to_secctx(secid, &lsmctx)   /* lsmctx.len set */\n    lsmctx_aligned_size = ALIGN(lsmctx.len, sizeof(u64))\n    extra_buffers_size += lsmctx_aligned_size\n    ...\n    security_release_secctx(&lsmctx)            /* memset zeroes len */\n    ...\n    sg_buf_end_offset = sg_buf_offset + extra_buffers_size\n                        - ALIGN(lsmctx.len, sizeof(u64)) /* ALIGN(0,8) */\n\nsecurity_release_secctx() does memset(cp, 0, sizeof(*cp)), so lsmctx.len\nreads back as 0 and the subtraction contributes nothing, leaving\nsg_buf_end_offset too large by the aligned secctx size on every\ntransaction to a txn_security_ctx node.\n\nEach BINDER_TYPE_PTR object then derives buf_left = sg_buf_end_offset -\nsg_buf_offset as the sole upper bound on its copy, so the inflated end\noffset lets the copy run into the bytes that already hold the secctx.\n\nThe aligned size must therefore be cached before release rather than\nre-read from the now-cleared field.  Fix by caching it in\nlsmctx_aligned_size at function scope when it is first computed and\nsubtracting lsmctx_aligned_size instead of re-reading lsmctx.len after\nrelease.  Reuse the same value for the earlier buf_offset computation."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/android/binder.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6fba89813ccf333d2bc4d5caea04cd5f3c39eb50","lessThan":"1228926e1e4d605cc74d9e675558982a6f2cf446","versionType":"git","status":"affected"},{"version":"6fba89813ccf333d2bc4d5caea04cd5f3c39eb50","lessThan":"4257f45ee1fddd0558e77b62af8bb63fd87b2162","versionType":"git","status":"affected"},{"version":"6fba89813ccf333d2bc4d5caea04cd5f3c39eb50","lessThan":"b34826e55aad3520ec813f1f367c11b24b29dc9f","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/android/binder.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.14","status":"affected"},{"version":"0","lessThan":"6.14","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc3","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/1228926e1e4d605cc74d9e675558982a6f2cf446","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/4257f45ee1fddd0558e77b62af8bb63fd87b2162","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/b34826e55aad3520ec813f1f367c11b24b29dc9f","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-68459","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:18:15.460","lastModified":"2026-08-15T06:18:15.460","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nf2fs: fix potential deadlock in gc_merge path of f2fs_balance_fs()\n\nWhen we mount device w/ gc_merge mount option, we may suffer below\npotential deadlock:\n\nKworker\t\t\t\t\tGC trehad\t\t\tTruncator\n- f2fs_write_cache_pages\n - f2fs_write_single_data_page\n  - f2fs_do_write_data_page\n   - folio_start_writeback  --- set writeback flag on folio\n   - f2fs_outplace_write_data\n   : cached folio in internal bio cache\n  - f2fs_balance_fs\n   - wake_up(gc_thread)\n   : wake up gc thread to run foreground GC\n   - finish_wait(fggc_wq)\n   : wait on the waitqueue --- wait on GC thread to finish the work\n\t\t\t\t\t\t\t\t\t- truncate_inode_pages_range\n\t\t\t\t\t\t\t\t\t - __filemap_get_folio(, FGP_LOCK)  --- lock folio\n\t\t\t\t\t\t\t\t\t - truncate_inode_partial_folio\n\t\t\t\t\t\t\t\t\t  - folio_wait_writeback            --- wait on writeback being cleared\n\t\t\t\t\t- do_garbage_collect\n\t\t\t\t\t - move_data_page\n\t\t\t\t\t  - f2fs_get_lock_data_folio\n\t\t\t\t\t   - lock on folio  --- blocked on folio's lock\n\nIn order to avoid such deadlock, let's call below functions to commit\ncached bios in GC_MERGE path of f2fs_balance_fs() as the same as we did\nin NOGC_MERGE path.\n- f2fs_submit_merged_write(sbi, DATA);\n- f2fs_submit_all_merged_ipu_writes(sbi);"}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["fs/f2fs/segment.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"351df4b201157351c7d26bf12c3eeb9dbce98854","lessThan":"8071500a8124e5a6d47d901a8d5ffd91743107a1","versionType":"git","status":"affected"},{"version":"351df4b201157351c7d26bf12c3eeb9dbce98854","lessThan":"eb02f218aacb36365e0ca2339cbae81fb05d31a5","versionType":"git","status":"affected"},{"version":"351df4b201157351c7d26bf12c3eeb9dbce98854","lessThan":"1436031b33fa23ab1ce7df5bc5500093413e8acf","versionType":"git","status":"affected"},{"version":"351df4b201157351c7d26bf12c3eeb9dbce98854","lessThan":"b885c7783c19c36c7bf899492a0bffcd68afa8c7","versionType":"git","status":"affected"},{"version":"351df4b201157351c7d26bf12c3eeb9dbce98854","lessThan":"89479a27fa4e1e11f378b3724944eabceb84f114","versionType":"git","status":"affected"},{"version":"351df4b201157351c7d26bf12c3eeb9dbce98854","lessThan":"aa807064473abd6f2cafe419fb77ea402d3e3104","versionType":"git","status":"affected"},{"version":"351df4b201157351c7d26bf12c3eeb9dbce98854","lessThan":"8b4468ec023d0d1b4669dfb867588997cc03a06b","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["fs/f2fs/segment.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"3.8","status":"affected"},{"version":"0","lessThan":"3.8","versionType":"semver","status":"unaffected"},{"version":"5.15.212","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.178","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.96","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.39","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/1436031b33fa23ab1ce7df5bc5500093413e8acf","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/8071500a8124e5a6d47d901a8d5ffd91743107a1","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/89479a27fa4e1e11f378b3724944eabceb84f114","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/8b4468ec023d0d1b4669dfb867588997cc03a06b","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/aa807064473abd6f2cafe419fb77ea402d3e3104","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/b885c7783c19c36c7bf899492a0bffcd68afa8c7","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/eb02f218aacb36365e0ca2339cbae81fb05d31a5","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-68460","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:18:22.117","lastModified":"2026-08-15T06:18:22.117","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nf2fs: fix potential deadlock in f2fs_balance_fs()\n\nWhen the f2fs filesystem space is nearly exhausted, we encounter deadlock\nissues as below:\n\nINFO: task A:1890 blocked for more than 120 seconds.\n      Tainted: G           O       6.12.41-g3fe07ddf05ab #1\n\"echo 0 > /proc/sys/kernel/hung_task_timeout_secs\" disables this message.\ntask:A    state:D stack:0     pid:1890  tgid:1626  ppid:1153   flags:0x00000204\nCall trace:\n __switch_to+0xf4/0x158\n __schedule+0x27c/0x908\n schedule+0x3c/0x118\n io_schedule+0x44/0x68\n folio_wait_bit_common+0x174/0x370\n folio_wait_bit+0x20/0x38\n folio_wait_writeback+0x54/0xc8\n truncate_inode_partial_folio+0x70/0x1e0\n truncate_inode_pages_range+0x1b0/0x450\n truncate_pagecache+0x54/0x88\n f2fs_file_write_iter+0x3e8/0xb80\n do_iter_readv_writev+0xf0/0x1e0\n vfs_writev+0x138/0x2c8\n do_writev+0x88/0x130\n __arm64_sys_writev+0x28/0x40\n invoke_syscall+0x50/0x120\n el0_svc_common.constprop.0+0xc8/0xf0\n do_el0_svc+0x24/0x38\n el0_svc+0x30/0xf8\n el0t_64_sync_handler+0x120/0x130\n el0t_64_sync+0x190/0x198\n\nINFO: task kworker/u8:11:2680853 blocked for more than 120 seconds.\n      Tainted: G           O       6.12.41-g3fe07ddf05ab #1\n\"echo 0 > /proc/sys/kernel/hung_task_timeout_secs\" disables this message.\ntask:kworker/u8:11   state:D stack:0     pid:2680853 tgid:2680853 ppid:2      flags:0x00000208\nWorkqueue: writeback wb_workfn (flush-254:0)\nCall trace:\n __switch_to+0xf4/0x158\n __schedule+0x27c/0x908\n schedule+0x3c/0x118\n io_schedule+0x44/0x68\n folio_wait_bit_common+0x174/0x370\n __filemap_get_folio+0x214/0x348\n pagecache_get_page+0x20/0x70\n f2fs_get_read_data_page+0x150/0x3e8\n f2fs_get_lock_data_page+0x2c/0x160\n move_data_page+0x50/0x478\n do_garbage_collect+0xd38/0x1528\n f2fs_gc+0x240/0x7e0\n f2fs_balance_fs+0x1a0/0x208\n f2fs_write_single_data_page+0x6e4/0x730\n f2fs_write_cache_pages+0x378/0x9b0\n f2fs_write_data_pages+0x2e4/0x388\n do_writepages+0x8c/0x2c8\n __writeback_single_inode+0x4c/0x498\n writeback_sb_inodes+0x234/0x4a8\n __writeback_inodes_wb+0x58/0x118\n wb_writeback+0x2f8/0x3c0\n wb_workfn+0x2c4/0x508\n process_one_work+0x180/0x408\n worker_thread+0x258/0x368\n kthread+0x118/0x128\n ret_from_fork+0x10/0x200\n\nINFO: task kworker/u8:8:2641297 blocked for more than 120 seconds.\n      Tainted: G           O       6.12.41-g3fe07ddf05ab #1\n\"echo 0 > /proc/sys/kernel/hung_task_timeout_secs\" disables this message.\ntask:kworker/u8:8    state:D stack:0     pid:2641297 tgid:2641297 ppid:2      flags:0x00000208\nWorkqueue: writeback wb_workfn (flush-254:0)\nCall trace:\n __switch_to+0xf4/0x158\n __schedule+0x27c/0x908\n rt_mutex_schedule+0x30/0x60\n __rt_mutex_slowlock_locked.constprop.0+0x460/0x8a8\n rwbase_write_lock+0x24c/0x378\n down_write+0x1c/0x30\n f2fs_balance_fs+0x184/0x208\n f2fs_write_inode+0xf4/0x328\n __writeback_single_inode+0x370/0x498\n writeback_sb_inodes+0x234/0x4a8\n __writeback_inodes_wb+0x58/0x118\n wb_writeback+0x2f8/0x3c0\n wb_workfn+0x2c4/0x508\n process_one_work+0x180/0x408\n worker_thread+0x258/0x368\n kthread+0x118/0x128\n ret_from_fork+0x10/0x20\n\nINFO: task B:1902 blocked for more than 120 seconds.\n      Tainted: G           O       6.12.41-g3fe07ddf05ab #1\n\"echo 0 > /proc/sys/kernel/hung_task_timeout_secs\" disables this message.\ntask:B     state:D stack:0     pid:1902  tgid:1626  ppid:1153   flags:0x0000020c\nCall trace:\n __switch_to+0xf4/0x158\n __schedule+0x27c/0x908\n rt_mutex_schedule+0x30/0x60\n __rt_mutex_slowlock_locked.constprop.0+0x460/0x8a8\n rwbase_write_lock+0x24c/0x378\n down_write+0x1c/0x30\n f2fs_balance_fs+0x184/0x208\n f2fs_map_blocks+0x94c/0x1110\n f2fs_file_write_iter+0x228/0xb80\n do_iter_readv_writev+0xf0/0x1e0\n vfs_writev+0x138/0x2c8\n do_writev+0x88/0x130\n __arm64_sys_writev+0x28/0x40\n invoke_syscall+0x50/0x120\n el0_svc_common.constprop.0+0xc8/0xf0\n do_el0_svc+0x24/0x38\n el0_svc+0x30/0xf8\n el0t_64_sync_handler+0x120/0x130\n el0t_64_sync+0x190/0x198\n\nINFO: task sync:2769849 blocked for more than 120 seconds.\n      Tainted: G     \n---truncated---"}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["fs/f2fs/data.c","fs/f2fs/f2fs.h","fs/f2fs/segment.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"162d57d8eb8440ad2d90469bf2c116abb04a9d33","versionType":"git","status":"affected"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"f51db99287b5acf81513ece82a0c95eb5db008e3","versionType":"git","status":"affected"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"e273116fbb6dfd7f027c0623e7c5109241be1919","versionType":"git","status":"affected"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"345c1d1ff751104ebdc32c145be80de566c5150f","versionType":"git","status":"affected"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"44480f7e3f8369671452c0d262831c51aa5a9c20","versionType":"git","status":"affected"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"998536c96b6ad9d99cd85dea11452ab83dc7c88d","versionType":"git","status":"affected"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"cf8b5937b7b258927ccca267995e13e76a07b38e","versionType":"git","status":"affected"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"dd3114870771562036fdcf5abe813956f36d224d","versionType":"git","status":"affected"},{"version":"0","lessThan":"5.10.261","versionType":"semver","status":"affected"},{"version":"0","lessThan":"5.15.212","versionType":"semver","status":"affected"},{"version":"0","lessThan":"6.1.178","versionType":"semver","status":"affected"},{"version":"0","lessThan":"6.6.145","versionType":"semver","status":"affected"},{"version":"0","lessThan":"6.12.96","versionType":"semver","status":"affected"},{"version":"0","lessThan":"6.18.39","versionType":"semver","status":"affected"},{"version":"0","lessThan":"7.1.5","versionType":"semver","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["fs/f2fs/data.c","fs/f2fs/f2fs.h","fs/f2fs/segment.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"5.10.261","lessThanOrEqual":"5.10.*","versionType":"semver","status":"unaffected"},{"version":"5.15.212","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.178","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.96","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.39","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/162d57d8eb8440ad2d90469bf2c116abb04a9d33","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/345c1d1ff751104ebdc32c145be80de566c5150f","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/44480f7e3f8369671452c0d262831c51aa5a9c20","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/998536c96b6ad9d99cd85dea11452ab83dc7c88d","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/cf8b5937b7b258927ccca267995e13e76a07b38e","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/dd3114870771562036fdcf5abe813956f36d224d","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/e273116fbb6dfd7f027c0623e7c5109241be1919","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/f51db99287b5acf81513ece82a0c95eb5db008e3","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-68461","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:18:34.113","lastModified":"2026-08-15T06:18:34.113","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\ndevice property: initialize the remaining fields of fwnode_handle in fwnode_init()\n\nIf a firmware node is allocated on the stack (for instance: temporary\nsoftware node whose life-time we control) or on the heap - but using a\nnon-zeroing allocation function - and initialized using fwnode_init(),\nits secondary pointer will contain uninitialized memory which likely\nwill be neither NULL nor IS_ERR() and so may end up being dereferenced\n(for example: in dev_to_swnode()). Set fwnode->secondary to NULL on\ninitialization. While at it: initialize the remaining fields of struct\nfwnode_handle too just to be sure.\n\n[ Fix typo in commit message. - Danilo ]"}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["include/linux/fwnode.h"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"01bb86b380a306bd937c96da36f66429f3362137","lessThan":"0198d579948322cda5178b9672d448375a32f947","versionType":"git","status":"affected"},{"version":"01bb86b380a306bd937c96da36f66429f3362137","lessThan":"173b61c9276c7b3a5fbcc63ae7aafc897fee1e18","versionType":"git","status":"affected"},{"version":"01bb86b380a306bd937c96da36f66429f3362137","lessThan":"f0b4e1cc8ad76baf49d898727eb52e91a4ef0544","versionType":"git","status":"affected"},{"version":"01bb86b380a306bd937c96da36f66429f3362137","lessThan":"c8542b68ba6ef4f61072098893a3f5b71c569b6c","versionType":"git","status":"affected"},{"version":"01bb86b380a306bd937c96da36f66429f3362137","lessThan":"9c86a1f930bb2ddb85f867b4736716e82a4a4683","versionType":"git","status":"affected"},{"version":"01bb86b380a306bd937c96da36f66429f3362137","lessThan":"c81e2af41de6a159837c7129a4fc444ac6e48046","versionType":"git","status":"affected"},{"version":"01bb86b380a306bd937c96da36f66429f3362137","lessThan":"7eba000621fff223dd7bab484d48918c7c77a307","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["include/linux/fwnode.h"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"5.11","status":"affected"},{"version":"0","lessThan":"5.11","versionType":"semver","status":"unaffected"},{"version":"5.15.212","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.178","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.96","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.39","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/0198d579948322cda5178b9672d448375a32f947","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/173b61c9276c7b3a5fbcc63ae7aafc897fee1e18","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/7eba000621fff223dd7bab484d48918c7c77a307","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/9c86a1f930bb2ddb85f867b4736716e82a4a4683","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/c81e2af41de6a159837c7129a4fc444ac6e48046","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/c8542b68ba6ef4f61072098893a3f5b71c569b6c","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/f0b4e1cc8ad76baf49d898727eb52e91a4ef0544","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-68462","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:18:39.803","lastModified":"2026-08-15T06:18:39.803","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nbpf: Reject negative const offsets for buffer pointers\n\nThe verifier rejects variable offsets for PTR_TO_TP_BUFFER and PTR_TO_BUF\naccesses, but it currently accepts a constant negative offset produced by\npointer arithmetic.\n\nCommit 022ac0750883 (\"bpf: use reg->var_off instead of reg->off for\npointers\") moved constant pointer offsets from reg->off to reg->var_off.\nHowever, __check_buffer_access() continued to check only the instruction\noffset. An access with reg->var_off equal to -8 and an instruction offset\nof zero therefore passes verification.\n\nFor writable raw tracepoints, the access end is also calculated from the\nunsigned reg->var_off.value. An eight-byte access starting at -8 wraps\nthe calculated end to zero, allowing the program to load and attach\nwithout increasing max_tp_access.\n\nAfter ensuring that reg->var_off is constant, calculate the effective\naccess start using signed arithmetic and reject it when it is negative.\nUse the validated start to calculate the access end for both\nPTR_TO_TP_BUFFER and PTR_TO_BUF."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["kernel/bpf/verifier.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"022ac075088366b62e130da5e1b200bc93a47191","lessThan":"314bd592085c0720ef519f6edbc5f41440ff78d4","versionType":"git","status":"affected"},{"version":"022ac075088366b62e130da5e1b200bc93a47191","lessThan":"fd4cfa8c8f9a17cdec0539334d28754bc1d8a5d9","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["kernel/bpf/verifier.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"7.1","status":"affected"},{"version":"0","lessThan":"7.1","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc4","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/314bd592085c0720ef519f6edbc5f41440ff78d4","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/fd4cfa8c8f9a17cdec0539334d28754bc1d8a5d9","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-68463","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:18:39.910","lastModified":"2026-08-15T06:18:39.910","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nmmc: sdhci-esdhc-imx: use pm_runtime_resume_and_get() in suspend\n\nReplace pm_runtime_get_sync() with pm_runtime_resume_and_get() to\nsimplify error handling. pm_runtime_resume_and_get() automatically\ndrops the usage counter on failure, avoiding the need for a separate\npm_runtime_put_noidle() call. If it fails, the device is unclocked and\naccessing hardware registers would cause a kernel panic, so return the\nerror immediately."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/mmc/host/sdhci-esdhc-imx.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"676a83855614635af3bf31ad3f8fec4031f81354","lessThan":"5b8f11cbe8ad5726b2b63ff1574d5cffa4df18c2","versionType":"git","status":"affected"},{"version":"676a83855614635af3bf31ad3f8fec4031f81354","lessThan":"6355749aebf6c78081f7096a52edcd28d2aa0fab","versionType":"git","status":"affected"},{"version":"676a83855614635af3bf31ad3f8fec4031f81354","lessThan":"8da5930144712412d85e7f868693d96ec5c2018c","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/mmc/host/sdhci-esdhc-imx.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.16","status":"affected"},{"version":"0","lessThan":"6.16","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc4","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/5b8f11cbe8ad5726b2b63ff1574d5cffa4df18c2","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/6355749aebf6c78081f7096a52edcd28d2aa0fab","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/8da5930144712412d85e7f868693d96ec5c2018c","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-68464","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:19:25.430","lastModified":"2026-08-15T06:19:25.430","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nmmc: sdhci-esdhc-imx: disable irq during suspend to fix unhandled interrupt\n\nWhen using WIFI out-of-band wakeup, an \"irq xxx: nobody cared\" warning\noccurs. This happens because the usdhc interrupt is not disabled during\nsystem suspend when device_may_wakeup() returns false.\n\nThe sequence of events leading to this issue:\n1. System enters suspend without disabling usdhc interrupt\n(because device_may_wakeup() returns false for usdhc device)\n2. WIFI out-of-band wakeup triggers system resume via GPIO interrupt\n3. WIFI sends a Card interrupt before usdhc has fully resumed\n4. usdhc is still in runtime suspend state and cannot handle the\ninterrupt properly\n5. The unhandled interrupt triggers \"nobody cared\" warning\n\nFix this by unconditionally disabling the usdhc interrupt during suspend\nand re-enabling it during resume, regardless of the wakeup capability.\nThis ensures no interrupts are processed during the suspend/resume\ntransition."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/mmc/host/sdhci-esdhc-imx.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"676a83855614635af3bf31ad3f8fec4031f81354","lessThan":"4f96903e2fd228aa96013372402d650f6dbe5cb3","versionType":"git","status":"affected"},{"version":"676a83855614635af3bf31ad3f8fec4031f81354","lessThan":"9bf4ee05a1109d889de9151ee78bd80293923f70","versionType":"git","status":"affected"},{"version":"676a83855614635af3bf31ad3f8fec4031f81354","lessThan":"9d87eaf985cef9581b6ed99b461b38e8cd666480","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/mmc/host/sdhci-esdhc-imx.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.16","status":"affected"},{"version":"0","lessThan":"6.16","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc4","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/4f96903e2fd228aa96013372402d650f6dbe5cb3","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/9bf4ee05a1109d889de9151ee78bd80293923f70","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/9d87eaf985cef9581b6ed99b461b38e8cd666480","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-68465","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:19:34.433","lastModified":"2026-08-15T06:19:34.433","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nmmc: sdhci-esdhc-imx: fix esdhc_change_pinstate() to allow default state restore\n\nesdhc_change_pinstate() checks for pins_100mhz and pins_200mhz at the\ntop of the function and returns -EINVAL if either is not defined. This\nprevents the default case from ever being reached, which means devices\nwith a sleep pinctrl state but without high-speed pin states (100mhz/\n200mhz) can never restore their default pin configuration.\n\nMove the IS_ERR checks for pins_100mhz and pins_200mhz into their\nrespective switch cases."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/mmc/host/sdhci-esdhc-imx.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"676a83855614635af3bf31ad3f8fec4031f81354","lessThan":"aa276aa6cbfbc5622bf974cf9be1d579ce4a5fab","versionType":"git","status":"affected"},{"version":"676a83855614635af3bf31ad3f8fec4031f81354","lessThan":"bb72b2398c05fd0a4ebf13f49c7d599d7023d484","versionType":"git","status":"affected"},{"version":"676a83855614635af3bf31ad3f8fec4031f81354","lessThan":"5adc14cd4b905629d5b9163b3a416dcab24c7ce2","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/mmc/host/sdhci-esdhc-imx.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.16","status":"affected"},{"version":"0","lessThan":"6.16","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc4","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/5adc14cd4b905629d5b9163b3a416dcab24c7ce2","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/aa276aa6cbfbc5622bf974cf9be1d579ce4a5fab","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/bb72b2398c05fd0a4ebf13f49c7d599d7023d484","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-68466","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:19:34.530","lastModified":"2026-08-15T06:19:34.530","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nmtd: rawnand: lpc32xx_slc: fail DMA transfer on completion timeout\n\nlpc32xx_xmit_dma() waits for the DMA completion callback but ignores\nwait_for_completion_timeout(). A timed out DMA transfer is therefore\nunmapped and reported as successful to the NAND read/write path.\n\nReturn -ETIMEDOUT when the completion wait expires. Terminate the DMA\nchannel before unmapping the scatterlist so the timed out transfer cannot\ncontinue to access the buffer after the error is returned."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/mtd/nand/raw/lpc32xx_slc.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"2944a44da09e46b6db2fd2c3334f242b09e05c43","lessThan":"307e4f4c1d4e1575b3495ecc6e41aa2adc40f491","versionType":"git","status":"affected"},{"version":"2944a44da09e46b6db2fd2c3334f242b09e05c43","lessThan":"c367af37ce7238c96c6071337149099467160746","versionType":"git","status":"affected"},{"version":"2944a44da09e46b6db2fd2c3334f242b09e05c43","lessThan":"623c4d8e740debb4af28981e3d4e209f9d0260a4","versionType":"git","status":"affected"},{"version":"2944a44da09e46b6db2fd2c3334f242b09e05c43","lessThan":"bd4a622786f92e1f183f7557ab89dd32891cef60","versionType":"git","status":"affected"},{"version":"2944a44da09e46b6db2fd2c3334f242b09e05c43","lessThan":"8f5c3ee53a5dc1a0f7cfd780485f2c8b5d17f91d","versionType":"git","status":"affected"},{"version":"2944a44da09e46b6db2fd2c3334f242b09e05c43","lessThan":"cf7258f57d18026b8f77c0e80ff1805e9caf7250","versionType":"git","status":"affected"},{"version":"2944a44da09e46b6db2fd2c3334f242b09e05c43","lessThan":"cb2031f8b226efbd13735c07b075e5f14ec11f6d","versionType":"git","status":"affected"},{"version":"2944a44da09e46b6db2fd2c3334f242b09e05c43","lessThan":"17a8ce84964f243c8f89dc7353ac7e8d3137bc74","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/mtd/nand/raw/lpc32xx_slc.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"3.7","status":"affected"},{"version":"0","lessThan":"3.7","versionType":"semver","status":"unaffected"},{"version":"5.10.261","lessThanOrEqual":"5.10.*","versionType":"semver","status":"unaffected"},{"version":"5.15.212","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.178","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.97","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc4","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/17a8ce84964f243c8f89dc7353ac7e8d3137bc74","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/307e4f4c1d4e1575b3495ecc6e41aa2adc40f491","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/623c4d8e740debb4af28981e3d4e209f9d0260a4","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/8f5c3ee53a5dc1a0f7cfd780485f2c8b5d17f91d","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/bd4a622786f92e1f183f7557ab89dd32891cef60","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/c367af37ce7238c96c6071337149099467160746","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/cb2031f8b226efbd13735c07b075e5f14ec11f6d","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/cf7258f57d18026b8f77c0e80ff1805e9caf7250","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-68467","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:19:46.527","lastModified":"2026-08-15T06:19:46.527","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nmtd: mchp23k256: use SPI match data for chip caps\n\nThe driver stores chip capacity information in both the OF match table\nand the SPI id table. Probe currently uses of_device_get_match_data(),\nso a non-OF SPI modalias match falls back to mchp23k256_caps even when\nthe SPI id table selected a different part.\n\nUse spi_get_device_match_data() so SPI id-table driver_data is consumed\nwhen OF match data is absent. This keeps the existing default fallback\nwhile avoiding the wrong MTD geometry for id-table-only matches."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/mtd/devices/mchp23k256.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"4379075a870b8de43a9ecd5b46884953234fc669","lessThan":"2e179b028da9fd628a09286a2c9df4fa076b2cc9","versionType":"git","status":"affected"},{"version":"4379075a870b8de43a9ecd5b46884953234fc669","lessThan":"a0c38083623c8b210a5b87fd34bebd05aa935ae8","versionType":"git","status":"affected"},{"version":"4379075a870b8de43a9ecd5b46884953234fc669","lessThan":"7c0a3a73dccc9a3fc701f6be762449f18d0ca0fc","versionType":"git","status":"affected"},{"version":"4379075a870b8de43a9ecd5b46884953234fc669","lessThan":"dbe2254d1da99c986f9a3392471fc5eaa3229647","versionType":"git","status":"affected"},{"version":"4379075a870b8de43a9ecd5b46884953234fc669","lessThan":"04ebd3766861f219325852c9598e0f0281cb3636","versionType":"git","status":"affected"},{"version":"4379075a870b8de43a9ecd5b46884953234fc669","lessThan":"09e044192a42f716215fbd1a100ee87fa57426aa","versionType":"git","status":"affected"},{"version":"4379075a870b8de43a9ecd5b46884953234fc669","lessThan":"d322e40f4edf92bf0ca329e5aa4ae1c0316feb38","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/mtd/devices/mchp23k256.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"4.13","status":"affected"},{"version":"0","lessThan":"4.13","versionType":"semver","status":"unaffected"},{"version":"5.15.212","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.178","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.97","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc4","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/04ebd3766861f219325852c9598e0f0281cb3636","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/09e044192a42f716215fbd1a100ee87fa57426aa","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/2e179b028da9fd628a09286a2c9df4fa076b2cc9","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/7c0a3a73dccc9a3fc701f6be762449f18d0ca0fc","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/a0c38083623c8b210a5b87fd34bebd05aa935ae8","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/d322e40f4edf92bf0ca329e5aa4ae1c0316feb38","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/dbe2254d1da99c986f9a3392471fc5eaa3229647","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-68468","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:19:57.520","lastModified":"2026-08-15T06:19:57.520","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nmtd: virt-concat: free duplicate generated name\n\nEvery MTD registration runs mtd_virt_concat_create_join().  Once a\nvirtual concat has already been registered, the function builds the same\nname again and takes the equal-name branch.  That branch skips to the\nnext item without freeing the newly allocated string.\n\nFree the temporary name before continuing."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/mtd/mtd_virt_concat.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"43db6366fc2de02050e66389f5628d3fdc9af10a","lessThan":"0e65079d28e5c461b6813ea5821be4dfff24ff63","versionType":"git","status":"affected"},{"version":"43db6366fc2de02050e66389f5628d3fdc9af10a","lessThan":"caa0ecbeff4f7fbf70f22bd8ca598918bffb1b78","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/mtd/mtd_virt_concat.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"7.1","status":"affected"},{"version":"0","lessThan":"7.1","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc4","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/0e65079d28e5c461b6813ea5821be4dfff24ff63","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/caa0ecbeff4f7fbf70f22bd8ca598918bffb1b78","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-68469","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:19:57.620","lastModified":"2026-08-15T06:19:57.620","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: mwifiex: fix permanently busy scans after multiple roam iterations\n\nIn order for the firmware to sleep, the driver has to confirm a\npreviously received sleep request. The normal sequence of evets goes\nlike this:\nEVENT_SLEEP -> adapter->ps_state = PS_STATE_PRE_SLEEP -> sleep-confirm\n-> SLEEP -> EVENT_AWAKE -> AWAKE.\nBefore sending the sleep-confirm command, the driver must make sure\nthere are no commands either running or waiting to be completed.\n\nmwifiex_ret_802_11_associate() unconditionally sets\nps_state = PS_STATE_AWAKE when it processes the association command\nresponse, outside of the normal powersave management flow. If\nEVENT_SLEEP arrives while the association command is in flight,\nps_state is PRE_SLEEP when the association command response is parsed,\nand the forced AWAKE overwrites it. The deferred sleep-confirm is\nnever sent.\n\nA subsequent scan_start command is correctly acknowledged, but the\nfirmware doesn't generate scan_result events. The scan request never\nfinishes, and additional requests from userspace fail with -EBUSY.\n\nAfter testing on both IW412 and W8997, I could only trigger the bug on\nthe IW412 and observed the firmwares behave differently. On the IW412\nthe firmware still sends EVENT_SLEEP while the authentication /\nassociation process is ongoing. A W8997 under the same\nconditions seems to suppress power-save for the duration of the\nassociation, so PRE_SLEEP never coincided with the association response\neven after extended periods of testing using the loops\ndescribed below (>12hours).\n\nOn the IW412, the delay between commands that triggers an EVENT_SLEEP\nwas empirically determined to be ~20ms. This delay can naturally occur\nwhen the driver is outputting debugging information\n(debug_mask = 0x00000037), in which situation the busy scans issue is\nrepeatable while running \"test 1)\" as described below. If the delay\nbetween commands is less than ~20ms, the firmware stays awake and\nthe issue was not reproducible running the same test.\n\nThe host_mlme=false path also behaves differently. In this case, the\nentire authentication / association transaction is executed by one\ncommand (HostCmd_CMD_802_11_ASSOCIATE), and the firmware doesn't emit\nEVENT_SLEEP while the command is running.\n\nRemove the assignment so the ps_state is only manipulated in the paths\nthat are related to powersave event handling and on the main workqueue\nfor correct sleep confirmation.\n\nThe following loop tests were performed (with debugging output enabled):\n1) force roaming between two AP's, one 5GHz and one 2.4GHz, same\nSSID. Use wpa_cli to trigger the roaming behavior, sleep 2s\nbetween iterations.\n2) force a disconnection to AP 1 and a connection to AP 2, test\nscan. Use wpa_cli to trigger the connection changes, sleep 2s\nbetween iterations.\n\nEach test ran in each device for at least 3 hours."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/net/wireless/marvell/mwifiex/join.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"5e6e3a92b9a4c9416b17f468fa5c7fa2233b8b4e","lessThan":"2ed36b2586f16c480ed58de303af704c2235e16d","versionType":"git","status":"affected"},{"version":"5e6e3a92b9a4c9416b17f468fa5c7fa2233b8b4e","lessThan":"5796eabe435d83544b6fe39851ce47ca68fdb778","versionType":"git","status":"affected"},{"version":"5e6e3a92b9a4c9416b17f468fa5c7fa2233b8b4e","lessThan":"31a2c409f8f58d20f0f6391c151421155768ed77","versionType":"git","status":"affected"},{"version":"5e6e3a92b9a4c9416b17f468fa5c7fa2233b8b4e","lessThan":"deb5f0ae384f1cf41fccaf6375266db2f2911b2b","versionType":"git","status":"affected"},{"version":"5e6e3a92b9a4c9416b17f468fa5c7fa2233b8b4e","lessThan":"1bc55db2d34756bd53e4460dbb699619ee13cd7f","versionType":"git","status":"affected"},{"version":"5e6e3a92b9a4c9416b17f468fa5c7fa2233b8b4e","lessThan":"a59cfa165aee3e29d06145041c0ebe46a51de604","versionType":"git","status":"affected"},{"version":"5e6e3a92b9a4c9416b17f468fa5c7fa2233b8b4e","lessThan":"6126e12bf8c87badeab41a164c9689ac88e5c160","versionType":"git","status":"affected"},{"version":"5e6e3a92b9a4c9416b17f468fa5c7fa2233b8b4e","lessThan":"d78a407bad6f500884a8606aea1a5a9207be4030","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/net/wireless/marvell/mwifiex/join.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"3.0","status":"affected"},{"version":"0","lessThan":"3.0","versionType":"semver","status":"unaffected"},{"version":"5.10.261","lessThanOrEqual":"5.10.*","versionType":"semver","status":"unaffected"},{"version":"5.15.212","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.178","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.97","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc4","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/1bc55db2d34756bd53e4460dbb699619ee13cd7f","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/2ed36b2586f16c480ed58de303af704c2235e16d","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/31a2c409f8f58d20f0f6391c151421155768ed77","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/5796eabe435d83544b6fe39851ce47ca68fdb778","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/6126e12bf8c87badeab41a164c9689ac88e5c160","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/a59cfa165aee3e29d06145041c0ebe46a51de604","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/d78a407bad6f500884a8606aea1a5a9207be4030","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/deb5f0ae384f1cf41fccaf6375266db2f2911b2b","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-68470","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:19:57.767","lastModified":"2026-08-15T06:19:57.767","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: mac80211: validate extension-frame layout before RX\n\nExtension frames only have the extension header at the regular 802.11\nheader offset. The generic RX path can still reach helpers and interface\ndispatch code that read regular header address fields before unsupported\nextension subtypes are dropped.\n\nmac80211 currently only handles S1G beacon extension frames. Drop other\nextension subtypes before they can reach regular-header RX processing.\nFor S1G beacons, linearize the SKB with the management-frame path and\nrequire the fixed S1G beacon header, including optional fixed fields\nindicated by frame control, before generic RX dispatch.\n\nRoute S1G beacons through the station/default-link RX path without\nregular-header station lookup. Avoid regular-header address reads in the\nmac80211 RX paths that process S1G extension beacons, including\naccept-frame, duplicate-detection, address-copy, and MLO\naddress-translation paths.\n\nAlso make ieee80211_get_bssid() length-safe before returning the S1G\nsource-address pointer."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["net/mac80211/rx.c","net/mac80211/util.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"09a740ce352e1a1d16b9984115514ba9a4f4704b","lessThan":"625fc704b19cb48d7d269ad54ffffb4d3bf9c7ed","versionType":"git","status":"affected"},{"version":"09a740ce352e1a1d16b9984115514ba9a4f4704b","lessThan":"57d503ce32eccfa7650065ca4c560f7e29a2e676","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["net/mac80211/rx.c","net/mac80211/util.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"5.10","status":"affected"},{"version":"0","lessThan":"5.10","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc4","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/57d503ce32eccfa7650065ca4c560f7e29a2e676","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/625fc704b19cb48d7d269ad54ffffb4d3bf9c7ed","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-68471","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:20:05.433","lastModified":"2026-08-15T06:20:05.433","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: ieee80211: validate MLE common info length\n\nieee80211_mle_common_size() uses the first common-info octet as the\ncommon information length for all known MLE types. However,\nieee80211_mle_size_ok() only validates that octet for Basic, Probe\nRequest, and TDLS MLEs.\n\nReconfiguration MLEs also skipped the length octet when calculating the\nminimum common size, and Priority Access MLEs skipped validation of the\nadvertised common information length.\n\nAccount for the Reconfiguration common-info length octet and validate\nthe advertised common information length for all known MLE types. Keep\nunknown-type handling unchanged.\n\n[remove now misleading comment]"}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["include/linux/ieee80211-eht.h"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"0f48b8b88aa9ed7b65d7cb55dbc57ec914ddada1","lessThan":"90576bd6921a91eb038bffbb4b9467c2dc26aa1d","versionType":"git","status":"affected"},{"version":"0f48b8b88aa9ed7b65d7cb55dbc57ec914ddada1","lessThan":"2b1589fd9a076727a73bfb39e96622a76415ad32","versionType":"git","status":"affected"},{"version":"0f48b8b88aa9ed7b65d7cb55dbc57ec914ddada1","lessThan":"293baeae9b2434a3e432629d7720b5603db2d77e","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["include/linux/ieee80211-eht.h"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.0","status":"affected"},{"version":"0","lessThan":"6.0","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc4","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/293baeae9b2434a3e432629d7720b5603db2d77e","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/2b1589fd9a076727a73bfb39e96622a76415ad32","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/90576bd6921a91eb038bffbb4b9467c2dc26aa1d","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-68472","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:20:05.570","lastModified":"2026-08-15T06:20:05.570","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: cfg80211: validate EHT MLE before MLD ID read\n\ncfg80211_gen_new_ie() copies ML probe response elements from\nthe parent frame when the parent EHT multi-link element has an\nMLD ID matching the nontransmitted BSSID index.\n\nThe code only checked that the extension element had more than\none byte before calling ieee80211_mle_get_mld_id(). That helper\nassumes a BASIC MLE with enough common info and documents that\ncallers must first use ieee80211_mle_type_ok().\n\nAttack chain:\nmalicious AP sends a short EHT MLE in an MBSSID beacon.\ncfg80211_inform_bss_frame_data() stores the copied IE buffer.\ncfg80211_parse_mbssid_data() builds the nontransmitted BSS IE.\ncfg80211_gen_new_ie() sees the EHT MLE in the parent frame.\nieee80211_mle_get_mld_id() then reads past the IE boundary.\n\nValidate the MLE type and size before reading the MLD ID. This\nmatches the contract required by the MLE helper and rejects the\nshort element before any internal MLE fields are accessed."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["net/wireless/scan.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"61dcfa8c2a8f6c53ce77b2c832b82990754b2aa9","lessThan":"584657c5fc58d7a840623a2fa06331c9661dd0f1","versionType":"git","status":"affected"},{"version":"61dcfa8c2a8f6c53ce77b2c832b82990754b2aa9","lessThan":"3b0505e43da8fb5b2a7994c3c3604e5a74692154","versionType":"git","status":"affected"},{"version":"61dcfa8c2a8f6c53ce77b2c832b82990754b2aa9","lessThan":"74e27cd1d98b546fdb276008a83708d062339661","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["net/wireless/scan.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.14","status":"affected"},{"version":"0","lessThan":"6.14","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc4","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/3b0505e43da8fb5b2a7994c3c3604e5a74692154","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/584657c5fc58d7a840623a2fa06331c9661dd0f1","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/74e27cd1d98b546fdb276008a83708d062339661","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-68473","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:20:29.240","lastModified":"2026-08-15T06:20:29.240","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\npowerpc/uaccess: correct check for CONFIG_PPC_E500 in mask_user_address()\n\nmask_user_address() incorrectly checks for CONFIG_E500 instead of\nCONFIG_PPC_E500, causing mask_user_address_isel() to not be used on\nE500 hardware. Fix the check to use the correct name."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["arch/powerpc/include/asm/uaccess.h"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"861574d51bbd7a06dbf07f658a9a8def012c2f74","lessThan":"d5c234774a82f27b594f70c15fc45ce3648e4295","versionType":"git","status":"affected"},{"version":"861574d51bbd7a06dbf07f658a9a8def012c2f74","lessThan":"d610d3ab18197d87618da11ec5fe8b3cebf32208","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["arch/powerpc/include/asm/uaccess.h"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"7.0","status":"affected"},{"version":"0","lessThan":"7.0","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc4","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/d5c234774a82f27b594f70c15fc45ce3648e4295","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/d610d3ab18197d87618da11ec5fe8b3cebf32208","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-68474","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:20:34.937","lastModified":"2026-08-15T06:20:34.937","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\npowerpc/spufs: fix out-of-bounds access in spufs_mem_mmap_access()\n\nspufs_mem_mmap_access() computes the local store offset as\naddress - vma->vm_start, but bounds-checks it against vma->vm_end\ninstead of the local store size. On 64-bit, offset is always well\nbelow vma->vm_end, so the clamp never fires and len stays unbounded\nagainst the LS_SIZE buffer returned by ctx->ops->get_ls().\n\nReject offsets at or beyond LS_SIZE and clamp len to the remaining\nspace, mirroring the guard already used by spufs_mem_mmap_fault() and\nspufs_ps_fault()."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["arch/powerpc/platforms/cell/spufs/file.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"a352894d07059649398c4769dc8b645e1a1dad88","lessThan":"aa7aa8ba40c089762d821e3987aaae19e1f5705c","versionType":"git","status":"affected"},{"version":"a352894d07059649398c4769dc8b645e1a1dad88","lessThan":"d479a7711f8ff127946467b910d947bd971b94ed","versionType":"git","status":"affected"},{"version":"a352894d07059649398c4769dc8b645e1a1dad88","lessThan":"9d3569bfdceda69d5ffd5148901e57b69954d9ef","versionType":"git","status":"affected"},{"version":"a352894d07059649398c4769dc8b645e1a1dad88","lessThan":"d97a8f3668949a8a9d1f6202f8c53446f2d89aa7","versionType":"git","status":"affected"},{"version":"a352894d07059649398c4769dc8b645e1a1dad88","lessThan":"913feef74354c653f10ecd4631df7618a95c49c2","versionType":"git","status":"affected"},{"version":"a352894d07059649398c4769dc8b645e1a1dad88","lessThan":"3c1e92f75e11a11492b8cb901fceeb9f16ae6415","versionType":"git","status":"affected"},{"version":"a352894d07059649398c4769dc8b645e1a1dad88","lessThan":"4efa313b15925bdd864784865d6585174979294b","versionType":"git","status":"affected"},{"version":"a352894d07059649398c4769dc8b645e1a1dad88","lessThan":"47b87f469a35b5ffc81c16eee6b13a9b6c8d55c6","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["arch/powerpc/platforms/cell/spufs/file.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"2.6.27","status":"affected"},{"version":"0","lessThan":"2.6.27","versionType":"semver","status":"unaffected"},{"version":"5.10.261","lessThanOrEqual":"5.10.*","versionType":"semver","status":"unaffected"},{"version":"5.15.212","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.178","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.97","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc4","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/3c1e92f75e11a11492b8cb901fceeb9f16ae6415","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/47b87f469a35b5ffc81c16eee6b13a9b6c8d55c6","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/4efa313b15925bdd864784865d6585174979294b","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/913feef74354c653f10ecd4631df7618a95c49c2","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/9d3569bfdceda69d5ffd5148901e57b69954d9ef","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/aa7aa8ba40c089762d821e3987aaae19e1f5705c","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/d479a7711f8ff127946467b910d947bd971b94ed","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/d97a8f3668949a8a9d1f6202f8c53446f2d89aa7","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-68475","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:20:35.067","lastModified":"2026-08-15T06:20:35.067","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nreset: sunxi: fix memory region leak on ioremap failure\n\nIn sunxi_reset_init(), when ioremap() fails, the memory region obtained\nvia request_mem_region() is not released, leading to a resource leak.\n\nAdd an err_mem_region label to properly release the memory region before\nfreeing the data structure."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/reset/reset-sunxi.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"8f1ae77f466660b6da2455cccecc07ae631fa66d","lessThan":"23af4ea217800a20c405d72e82b11e24e27721f3","versionType":"git","status":"affected"},{"version":"8f1ae77f466660b6da2455cccecc07ae631fa66d","lessThan":"ec836995c00a1968e403ef6beb53a73a9b0f318c","versionType":"git","status":"affected"},{"version":"8f1ae77f466660b6da2455cccecc07ae631fa66d","lessThan":"b4d7333849839ff42e1bc802d5b5f63d71c65add","versionType":"git","status":"affected"},{"version":"8f1ae77f466660b6da2455cccecc07ae631fa66d","lessThan":"6dc0c8cd9c8a84808c6df760024d2604bc6d31fe","versionType":"git","status":"affected"},{"version":"8f1ae77f466660b6da2455cccecc07ae631fa66d","lessThan":"01e43f4e7d12dae6fa82ae1b2e91c9ce07e06cd8","versionType":"git","status":"affected"},{"version":"8f1ae77f466660b6da2455cccecc07ae631fa66d","lessThan":"82753ac86cb3d641b8634a61335fd0f04a61cc1a","versionType":"git","status":"affected"},{"version":"8f1ae77f466660b6da2455cccecc07ae631fa66d","lessThan":"d826d3e04c5bd9d284ba29f330246a317a8a7023","versionType":"git","status":"affected"},{"version":"8f1ae77f466660b6da2455cccecc07ae631fa66d","lessThan":"1a8c89f8c112c75e84ff9a140f969e372aed0c9a","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/reset/reset-sunxi.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"3.14","status":"affected"},{"version":"0","lessThan":"3.14","versionType":"semver","status":"unaffected"},{"version":"5.10.261","lessThanOrEqual":"5.10.*","versionType":"semver","status":"unaffected"},{"version":"5.15.212","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.178","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.97","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc4","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/01e43f4e7d12dae6fa82ae1b2e91c9ce07e06cd8","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/1a8c89f8c112c75e84ff9a140f969e372aed0c9a","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/23af4ea217800a20c405d72e82b11e24e27721f3","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/6dc0c8cd9c8a84808c6df760024d2604bc6d31fe","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/82753ac86cb3d641b8634a61335fd0f04a61cc1a","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/b4d7333849839ff42e1bc802d5b5f63d71c65add","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/d826d3e04c5bd9d284ba29f330246a317a8a7023","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/ec836995c00a1968e403ef6beb53a73a9b0f318c","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-68476","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:20:41.387","lastModified":"2026-08-15T06:20:41.387","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nipvs: reload ip header after head reallocation\n\n__ip_vs_get_out_rt() calls skb_ensure_writable() which may\nreallocate skb->head."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["net/netfilter/ipvs/ip_vs_xmit.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"8d8e20e2d7bba8c50e64e0eca1cb83956f468e49","lessThan":"ac6ac3d35bfc0ade9d17d354c84e503a946ebdab","versionType":"git","status":"affected"},{"version":"8d8e20e2d7bba8c50e64e0eca1cb83956f468e49","lessThan":"e51687fc56c2e39ea6e9532925f1aabd4d529f61","versionType":"git","status":"affected"},{"version":"8d8e20e2d7bba8c50e64e0eca1cb83956f468e49","lessThan":"3fb7edd2018bb1ad0a68157383d9b9dac33dd645","versionType":"git","status":"affected"},{"version":"8d8e20e2d7bba8c50e64e0eca1cb83956f468e49","lessThan":"ad1e14710b360bda087ebf9fb82460eb5ef775de","versionType":"git","status":"affected"},{"version":"8d8e20e2d7bba8c50e64e0eca1cb83956f468e49","lessThan":"a2f57827bf7c695b8c72dc4511cae8e86582369d","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["net/netfilter/ipvs/ip_vs_xmit.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"4.10","status":"affected"},{"version":"0","lessThan":"4.10","versionType":"semver","status":"unaffected"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.97","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc4","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/3fb7edd2018bb1ad0a68157383d9b9dac33dd645","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/a2f57827bf7c695b8c72dc4511cae8e86582369d","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/ac6ac3d35bfc0ade9d17d354c84e503a946ebdab","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/ad1e14710b360bda087ebf9fb82460eb5ef775de","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/e51687fc56c2e39ea6e9532925f1aabd4d529f61","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-68477","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:20:47.440","lastModified":"2026-08-15T06:20:47.440","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nipvs: fix more places with wrong ipv6 transport offsets\n\nSashiko reports for more incorrect IPv6 transport offsets.\n\nThe app code for TCP was assuming IPv4 network header\neven after the ipvsh argument was provided. This can\ncause problems with apps over IPv6. As for the only\nofficial app in the kernel tree (FTP) this problem is\nharmless because we use Netfilter to mangle the FTP\nports and we do not adjust the TCP seq numbers.\n\nAlso, provide correct offset of the ICMPV6 header in\nip_vs_out_icmp_v6() for correct checksum checks when\nthe IPv6 packet has extension headers."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["net/netfilter/ipvs/ip_vs_app.c","net/netfilter/ipvs/ip_vs_core.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"2a3b791e6e1169f374224d164738e9f7be703d77","lessThan":"613ce63711b8d431bba90781f133c39a21684f87","versionType":"git","status":"affected"},{"version":"2a3b791e6e1169f374224d164738e9f7be703d77","lessThan":"95d4511d81b2b37e5d2bdde5d912e48243eae517","versionType":"git","status":"affected"},{"version":"2a3b791e6e1169f374224d164738e9f7be703d77","lessThan":"3a9dc9b55b53d94613a587604b77d3b20024090c","versionType":"git","status":"affected"},{"version":"2a3b791e6e1169f374224d164738e9f7be703d77","lessThan":"a3f0d5b605cd5da5c95279969fb8cea4e55cee5b","versionType":"git","status":"affected"},{"version":"2a3b791e6e1169f374224d164738e9f7be703d77","lessThan":"7350eb7ead172ae8024897d4b0f2e15c5318279c","versionType":"git","status":"affected"},{"version":"2a3b791e6e1169f374224d164738e9f7be703d77","lessThan":"d4ec18f48ce78a3bf7c999ac908691007375fe99","versionType":"git","status":"affected"},{"version":"2a3b791e6e1169f374224d164738e9f7be703d77","lessThan":"905d7a363ade96a19f214815361e11981142c547","versionType":"git","status":"affected"},{"version":"2a3b791e6e1169f374224d164738e9f7be703d77","lessThan":"b3fe4cbd583895987935a9bdad01c8f9d3a02310","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["net/netfilter/ipvs/ip_vs_app.c","net/netfilter/ipvs/ip_vs_core.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"2.6.28","status":"affected"},{"version":"0","lessThan":"2.6.28","versionType":"semver","status":"unaffected"},{"version":"5.10.261","lessThanOrEqual":"5.10.*","versionType":"semver","status":"unaffected"},{"version":"5.15.212","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.178","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.97","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc4","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/3a9dc9b55b53d94613a587604b77d3b20024090c","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/613ce63711b8d431bba90781f133c39a21684f87","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/7350eb7ead172ae8024897d4b0f2e15c5318279c","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/905d7a363ade96a19f214815361e11981142c547","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/95d4511d81b2b37e5d2bdde5d912e48243eae517","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/a3f0d5b605cd5da5c95279969fb8cea4e55cee5b","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/b3fe4cbd583895987935a9bdad01c8f9d3a02310","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/d4ec18f48ce78a3bf7c999ac908691007375fe99","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-68478","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:20:47.573","lastModified":"2026-08-15T06:20:47.573","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nmemstick: ms_block: reject a card that reports too many blocks\n\nmsb_ftl_initialize() computes the zone count from the card block count\nwith no bound:\n\n\tmsb->zone_count = msb->block_count / MS_BLOCKS_IN_ZONE;\n\t...\n\tfor (i = 0; i < msb->zone_count; i++)\n\t\tmsb->free_block_count[i] = MS_BLOCKS_IN_ZONE;\n\nmsb->block_count is a card value. msb_read_boot_blocks() reads\nnumber_of_blocks from the card boot page and byte swaps it.\nfree_block_count is a fixed int[MS_MAX_ZONES]. MS_MAX_ZONES is 16, so the\nvalid indices are 0 to 15. The init loop above indexes it by zone_count.\nmsb_mark_block_used() and msb_mark_block_unused() index it by\npba / MS_BLOCKS_IN_ZONE, for pba up to block_count - 1. A card may report\nup to 65535 blocks. A block_count above 8192 (MS_MAX_ZONES *\nMS_BLOCKS_IN_ZONE) lets the pba index reach 16. That writes past\nfree_block_count[] and corrupts struct msb_data. A larger count runs the\ninit loop past the end too.\n\nA real Memory Stick has at most 16 zones. So it has at most 8192 blocks.\nmsb_ftl_initialize() now rejects a card that reports more than\nMS_MAX_ZONES * MS_BLOCKS_IN_ZONE blocks."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/memstick/core/ms_block.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"0ab30494bc4f3bc1ea4659b7c5d97c5218554a63","lessThan":"a4b9961efe8640f50800811b4a2b2046b3dc2ccc","versionType":"git","status":"affected"},{"version":"0ab30494bc4f3bc1ea4659b7c5d97c5218554a63","lessThan":"8937b11f1c3896e066c3fb07387ba17bc8c50b8a","versionType":"git","status":"affected"},{"version":"0ab30494bc4f3bc1ea4659b7c5d97c5218554a63","lessThan":"f1c675ecf6e5ad02722f0019f729d8bb588d502e","versionType":"git","status":"affected"},{"version":"0ab30494bc4f3bc1ea4659b7c5d97c5218554a63","lessThan":"d5db3439ee8d1c165a09a47e984c4ba508c130df","versionType":"git","status":"affected"},{"version":"0ab30494bc4f3bc1ea4659b7c5d97c5218554a63","lessThan":"b86666ac4009a252501cc17242582a7ec9ed976e","versionType":"git","status":"affected"},{"version":"0ab30494bc4f3bc1ea4659b7c5d97c5218554a63","lessThan":"39151f0708c84221e94cdd6aa070aba5d7cb1c01","versionType":"git","status":"affected"},{"version":"0ab30494bc4f3bc1ea4659b7c5d97c5218554a63","lessThan":"47f0c7d856c67c9935546d2644f18c0d0131b449","versionType":"git","status":"affected"},{"version":"0ab30494bc4f3bc1ea4659b7c5d97c5218554a63","lessThan":"718178f524b98bc920d74bc771aed823c8b81425","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/memstick/core/ms_block.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"3.12","status":"affected"},{"version":"0","lessThan":"3.12","versionType":"semver","status":"unaffected"},{"version":"5.10.261","lessThanOrEqual":"5.10.*","versionType":"semver","status":"unaffected"},{"version":"5.15.212","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.178","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.97","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc4","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/39151f0708c84221e94cdd6aa070aba5d7cb1c01","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/47f0c7d856c67c9935546d2644f18c0d0131b449","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/718178f524b98bc920d74bc771aed823c8b81425","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/8937b11f1c3896e066c3fb07387ba17bc8c50b8a","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/a4b9961efe8640f50800811b4a2b2046b3dc2ccc","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/b86666ac4009a252501cc17242582a7ec9ed976e","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/d5db3439ee8d1c165a09a47e984c4ba508c130df","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/f1c675ecf6e5ad02722f0019f729d8bb588d502e","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-68479","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:20:51.380","lastModified":"2026-08-15T06:20:51.380","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nBluetooth: btrtl: validate firmware patch bounds\n\nrtlbt_parse_firmware() copies patch_length - 4 bytes before appending the\nfirmware version. A malformed firmware patch shorter than the version field\ncan make this subtraction underflow and turn the copy into an oversized\nread and write during Bluetooth setup.\n\nThe existing patch_offset + patch_length check can also wrap on 32-bit\narchitectures. Validate the patch length and range without arithmetic\noverflow before allocating or copying the patch."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/bluetooth/btrtl.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"db33c77dddc2ed2cff3061d0b096a9f5ab0c3647","lessThan":"39e01b4addfbbe177567d6ed1dfb81f9cccb19e6","versionType":"git","status":"affected"},{"version":"db33c77dddc2ed2cff3061d0b096a9f5ab0c3647","lessThan":"bda3c598ade6ea03884074b91e31608326684921","versionType":"git","status":"affected"},{"version":"db33c77dddc2ed2cff3061d0b096a9f5ab0c3647","lessThan":"a4cb830e0b55ac76c849fd7840afb251f4c028fa","versionType":"git","status":"affected"},{"version":"db33c77dddc2ed2cff3061d0b096a9f5ab0c3647","lessThan":"68c5a2a19987c035eb129e627e579adafb04f637","versionType":"git","status":"affected"},{"version":"db33c77dddc2ed2cff3061d0b096a9f5ab0c3647","lessThan":"83534891c058ed71e251135072640911670869aa","versionType":"git","status":"affected"},{"version":"db33c77dddc2ed2cff3061d0b096a9f5ab0c3647","lessThan":"6744ab60dfac55d1df5733960aad5be300984301","versionType":"git","status":"affected"},{"version":"db33c77dddc2ed2cff3061d0b096a9f5ab0c3647","lessThan":"f1ca750c0510bdbb504bf084d2f196ef2af92ea6","versionType":"git","status":"affected"},{"version":"db33c77dddc2ed2cff3061d0b096a9f5ab0c3647","lessThan":"609c5b04a28dc1b0f3af6a7bc93055135b2d2059","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/bluetooth/btrtl.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"4.2","status":"affected"},{"version":"0","lessThan":"4.2","versionType":"semver","status":"unaffected"},{"version":"5.10.261","lessThanOrEqual":"5.10.*","versionType":"semver","status":"unaffected"},{"version":"5.15.212","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.178","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.97","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc4","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/39e01b4addfbbe177567d6ed1dfb81f9cccb19e6","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/609c5b04a28dc1b0f3af6a7bc93055135b2d2059","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/6744ab60dfac55d1df5733960aad5be300984301","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/68c5a2a19987c035eb129e627e579adafb04f637","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/83534891c058ed71e251135072640911670869aa","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/a4cb830e0b55ac76c849fd7840afb251f4c028fa","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/bda3c598ade6ea03884074b91e31608326684921","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/f1ca750c0510bdbb504bf084d2f196ef2af92ea6","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-72003","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:20:53.557","lastModified":"2026-08-15T06:20:53.557","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: brcmfmac: cyw: fix heap overflow on a short auth frame\n\nbrcmf_notify_auth_frame_rx() takes the frame length from the firmware\nevent and copies the frame body with the management header offset\nsubtracted:\n\n\tu32 mgmt_frame_len = e->datalen - sizeof(struct brcmf_rx_mgmt_data);\n\t...\n\tmemcpy(&mgmt_frame->u, frame,\n\t       mgmt_frame_len - offsetof(struct ieee80211_mgmt, u));\n\nThe only length check is e->datalen >= sizeof(*rxframe), so mgmt_frame_len\ncan be anything from 0 up. offsetof(struct ieee80211_mgmt, u) is 24. When\nmgmt_frame_len is below that, the subtraction wraps as an unsigned value to\na huge length. The memcpy then runs far past the kzalloc'd buffer. A\nmalicious or malfunctioning AP can make the frame short during the\nexternal SAE auth exchange, so this is a remotely triggered heap overflow.\n\nReject frames shorter than the management header offset before the copy."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/net/wireless/broadcom/brcm80211/brcmfmac/cyw/core.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"66f909308a7c05082919ff214a0bbe2a76aa0283","lessThan":"55b26abb1fa1ec406b3ad11b43c49c7624257565","versionType":"git","status":"affected"},{"version":"66f909308a7c05082919ff214a0bbe2a76aa0283","lessThan":"185bb156c427d0f865d344a6d0eaa02c6d05cc57","versionType":"git","status":"affected"},{"version":"66f909308a7c05082919ff214a0bbe2a76aa0283","lessThan":"240c8d2c717b3f8153e7e877b22a82518d78dbdc","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/net/wireless/broadcom/brcm80211/brcmfmac/cyw/core.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.16","status":"affected"},{"version":"0","lessThan":"6.16","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc4","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/185bb156c427d0f865d344a6d0eaa02c6d05cc57","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/240c8d2c717b3f8153e7e877b22a82518d78dbdc","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/55b26abb1fa1ec406b3ad11b43c49c7624257565","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-72004","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:20:58.987","lastModified":"2026-08-15T06:20:58.987","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: mac80211: fix memory leak in ieee80211_register_hw()\n\nIf kmemdup() fails while copying supported band structures, the error\npath jumps to fail_rate. This skips rate_control_deinitialize() and\nleaks the initialized local->rate_ctrl.\n\nFix this by adding a fail_band label that shares the rate-control cleanup\npath before falling through to the remaining teardown.\n\nThe bug was first flagged by an experimental analysis tool we are\ndeveloping for kernel memory-management bugs while analyzing\nv6.13-rc1. The tool is still under development and is not yet publicly\navailable. Manual inspection confirms that the bug is still present in\nv7.1-rc7.\n\nAn x86_64 allyesconfig build showed no new warnings. As we do not have a\nsuitable mac80211 device/driver combination to test with, no runtime\ntesting was able to be performed."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["net/mac80211/main.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"09b4a4faf9d037990ac4f8110dd944b27b42d5df","lessThan":"f01eec75fd372961550b928902f3a2c11fca1daf","versionType":"git","status":"affected"},{"version":"09b4a4faf9d037990ac4f8110dd944b27b42d5df","lessThan":"3d8b9b290421c3cd505fcd2f551f143f8142786a","versionType":"git","status":"affected"},{"version":"09b4a4faf9d037990ac4f8110dd944b27b42d5df","lessThan":"08b71bd92317f99642b842cfc0d30200868162fc","versionType":"git","status":"affected"},{"version":"09b4a4faf9d037990ac4f8110dd944b27b42d5df","lessThan":"a02b52fe54f7b5107aefa1ce28c2f69749c57616","versionType":"git","status":"affected"},{"version":"09b4a4faf9d037990ac4f8110dd944b27b42d5df","lessThan":"45e9ac538cdff7bce656d731114a64eda85af0d7","versionType":"git","status":"affected"},{"version":"09b4a4faf9d037990ac4f8110dd944b27b42d5df","lessThan":"bdc0b8bfdc142439d6708b072e8159eb515ee7b0","versionType":"git","status":"affected"},{"version":"09b4a4faf9d037990ac4f8110dd944b27b42d5df","lessThan":"a7584f261e64fe14e45bdf70f343e16c1ee3a037","versionType":"git","status":"affected"},{"version":"09b4a4faf9d037990ac4f8110dd944b27b42d5df","lessThan":"95fc02722edde02946d0d475221f2b2054d3d8ba","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["net/mac80211/main.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"4.20","status":"affected"},{"version":"0","lessThan":"4.20","versionType":"semver","status":"unaffected"},{"version":"5.10.261","lessThanOrEqual":"5.10.*","versionType":"semver","status":"unaffected"},{"version":"5.15.212","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.178","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.97","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc4","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/08b71bd92317f99642b842cfc0d30200868162fc","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/3d8b9b290421c3cd505fcd2f551f143f8142786a","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/45e9ac538cdff7bce656d731114a64eda85af0d7","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/95fc02722edde02946d0d475221f2b2054d3d8ba","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/a02b52fe54f7b5107aefa1ce28c2f69749c57616","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/a7584f261e64fe14e45bdf70f343e16c1ee3a037","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/bdc0b8bfdc142439d6708b072e8159eb515ee7b0","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/f01eec75fd372961550b928902f3a2c11fca1daf","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-72005","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:20:59.113","lastModified":"2026-08-15T06:20:59.113","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: rt2x00: avoid full teardown before work setup in probe\n\nrt2x00lib_probe_dev() uses the full rt2x00lib_remove_dev() teardown for\nall probe failures. However, drv_data allocation and workqueue allocation\ncan fail before intf_work, autowakeup_work and sleep_work have been\ninitialized.\n\nDo not enter the full remove path until the probe has reached the point\nwhere those work items are set up. Return directly for drv_data allocation\nfailure, and use a small early cleanup path for workqueue allocation\nfailure.\n\nThis issue was found by our static analysis tool and then confirmed by\nmanual review of rt2x00lib_probe_dev() and rt2x00lib_remove_dev(). The\nearly probe exits should not call a common teardown path that assumes the\nlater work setup has already completed.\n\nA QEMU PoC forced alloc_ordered_workqueue() to fail before the work\ninitializers are reached. The resulting fail path entered\nrt2x00lib_remove_dev(), and DEBUG_OBJECTS reported invalid work drains with\nrt2x00lib_probe_dev() and rt2x00lib_remove_dev() in the stack."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/net/wireless/ralink/rt2x00/rt2x00dev.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"0439f5367c8d8bb2ebaca8d7329f51f3148b2fb2","lessThan":"8b58d1f1356df6a7d2de3f55bb665b18b04ffda0","versionType":"git","status":"affected"},{"version":"0439f5367c8d8bb2ebaca8d7329f51f3148b2fb2","lessThan":"59afe6148927395cf86f9429900e029a48b1d42b","versionType":"git","status":"affected"},{"version":"0439f5367c8d8bb2ebaca8d7329f51f3148b2fb2","lessThan":"3c0427d719bddb33caf18ff4ffb77cb47de7eb00","versionType":"git","status":"affected"},{"version":"0439f5367c8d8bb2ebaca8d7329f51f3148b2fb2","lessThan":"eb7474d0253bb2de4793e1d3ce833e8564bbe732","versionType":"git","status":"affected"},{"version":"0439f5367c8d8bb2ebaca8d7329f51f3148b2fb2","lessThan":"66bd9b1a72de7c2f5141b02d796048aafaed8a49","versionType":"git","status":"affected"},{"version":"0439f5367c8d8bb2ebaca8d7329f51f3148b2fb2","lessThan":"816559409e340acaa5c9d868291dab30d8c80263","versionType":"git","status":"affected"},{"version":"0439f5367c8d8bb2ebaca8d7329f51f3148b2fb2","lessThan":"56994852d704535ea354a4627ca667b1b4fa0deb","versionType":"git","status":"affected"},{"version":"0439f5367c8d8bb2ebaca8d7329f51f3148b2fb2","lessThan":"536fb3d739d75a03cb318c0c6fe799425cfea501","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/net/wireless/ralink/rt2x00/rt2x00dev.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"2.6.39","status":"affected"},{"version":"0","lessThan":"2.6.39","versionType":"semver","status":"unaffected"},{"version":"5.10.261","lessThanOrEqual":"5.10.*","versionType":"semver","status":"unaffected"},{"version":"5.15.212","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.178","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.97","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc4","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/3c0427d719bddb33caf18ff4ffb77cb47de7eb00","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/536fb3d739d75a03cb318c0c6fe799425cfea501","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/56994852d704535ea354a4627ca667b1b4fa0deb","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/59afe6148927395cf86f9429900e029a48b1d42b","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/66bd9b1a72de7c2f5141b02d796048aafaed8a49","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/816559409e340acaa5c9d868291dab30d8c80263","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/8b58d1f1356df6a7d2de3f55bb665b18b04ffda0","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/eb7474d0253bb2de4793e1d3ce833e8564bbe732","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-72006","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:20:59.250","lastModified":"2026-08-15T06:20:59.250","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nnet/mlx5: free mlx5_st_idx_data on final dealloc\n\nWorkloads that repeatedly allocate and release mkeys carrying TPH\nsteering-tag hints (e.g. churning RDMA MRs) leak one\nstruct mlx5_st_idx_data per cycle; kmemleak flags it as unreferenced\nand the kmalloc slab grows over time.\n\nWhen the last reference to an ST table entry is dropped,\nmlx5_st_dealloc_index() removed the entry from idx_xa but the backing\nmlx5_st_idx_data allocation was never freed.\n\nFree idx_data after the xa_erase() so the lifetime of the bookkeeping\nstruct matches the lifetime of the ST entry it tracks."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/net/ethernet/mellanox/mlx5/core/lib/st.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"888a7776f4fb04c19bec70c737c61c2f383c6b1e","lessThan":"262da8b6ea03d01ee7ed01ad309e4c89941f6b14","versionType":"git","status":"affected"},{"version":"888a7776f4fb04c19bec70c737c61c2f383c6b1e","lessThan":"6eb4cf2fa8997f62c11e0006dc010a1fd89c5a75","versionType":"git","status":"affected"},{"version":"888a7776f4fb04c19bec70c737c61c2f383c6b1e","lessThan":"df6134b527a88b3e65ba6ae5073664af091d5fd2","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/net/ethernet/mellanox/mlx5/core/lib/st.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.17","status":"affected"},{"version":"0","lessThan":"6.17","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc4","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/262da8b6ea03d01ee7ed01ad309e4c89941f6b14","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/6eb4cf2fa8997f62c11e0006dc010a1fd89c5a75","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/df6134b527a88b3e65ba6ae5073664af091d5fd2","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-72007","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:20:59.350","lastModified":"2026-08-15T06:20:59.350","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\npmdomain: imx: Fix i.MX8MP VC8000E power up sequence\n\nPer errata[1]:\nERR050531: VPU_NOC power down handshake may hang during VC8000E/VPUMIX\npower up/down cycling.\nDescription: VC8000E reset de-assertion edge and AXI clock may have a\ntiming issue.\nWorkaround: Set bit2 (vc8000e_clk_en) of BLK_CLK_EN_CSR to 0 to gate off\nboth AXI clock and VC8000E clock sent to VC8000E and AXI clock sent to\nVPU_NOC m_v_2 interface during VC8000E power up(VC8000E reset is\nde-asserted by HW)\n\nAdd a bool variable is_errata_err050531 in\n'struct imx8m_blk_ctrl_domain_data' to represent whether the workaround\nis needed. If is_errata_err050531 is true, first clear the clk before\npowering up gpc, then enable the clk after powering up gpc.\n\n[1] https://www.nxp.com/webapp/Download?colCode=IMX8MP_1P33A"}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/pmdomain/imx/imx8m-blk-ctrl.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"a1a5f15f7f6cb5c291f072af843305638c935be6","lessThan":"87af3ebc112fb3f06753794390daf0f665f151b4","versionType":"git","status":"affected"},{"version":"a1a5f15f7f6cb5c291f072af843305638c935be6","lessThan":"c498928f85651b56a4041ea165a22037eae69580","versionType":"git","status":"affected"},{"version":"a1a5f15f7f6cb5c291f072af843305638c935be6","lessThan":"4ff3960f3527189bc115a927ed3561c758f562f1","versionType":"git","status":"affected"},{"version":"a1a5f15f7f6cb5c291f072af843305638c935be6","lessThan":"4907f4c2d98b97e640191af5bcf2814ee1034b76","versionType":"git","status":"affected"},{"version":"a1a5f15f7f6cb5c291f072af843305638c935be6","lessThan":"25e252bcf1593b420b12a7231d9dd64b885a2ae2","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/pmdomain/imx/imx8m-blk-ctrl.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.1","status":"affected"},{"version":"0","lessThan":"6.1","versionType":"semver","status":"unaffected"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.97","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc4","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/25e252bcf1593b420b12a7231d9dd64b885a2ae2","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/4907f4c2d98b97e640191af5bcf2814ee1034b76","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/4ff3960f3527189bc115a927ed3561c758f562f1","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/87af3ebc112fb3f06753794390daf0f665f151b4","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/c498928f85651b56a4041ea165a22037eae69580","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-72008","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:20:59.473","lastModified":"2026-08-15T06:20:59.473","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\npmdomain: mediatek: Fix possible nullptr KP in HWV cleanup/on-check\n\nShould probe fail for HW_VOTER type power domains, this driver was\nunconditionally trying to perform cleanup for DIRECT_CTL domains,\nbut only after checking if the target domain is powered on... with\nthe DIRECT_CTL scpsys_domain_is_on() code again.\n\nAnd there's more: the scpsys_domain_is_on() function is also being\nunconditionally used in the probe path, for any power domain that\nhas flag MTK_SCPD_KEEP_DEFAULT_OFF!\n\nThis bug was never experienced by anyone because the HWV domains\nnever failed probe, and because none of those is declared with the\naforementioned flag - but it's still something critical.\n\nIn order to fix this, add a check for MTCMOS Type and, based on\nthat, call the correct functions for an \"is on\" check, and also\ndo the same for the cleanup path, calling the correct functions\nfor the \"power off\" action.\n\nFor the latter, since there's a call to pm_genpd_remove() right\nbefore calling power_off, be cautious and add a variation of the\npower off functions (with a _internal suffix) for those to get a\npointer to scpsys_domain instead of one to generic_pm_domain as,\neven if that's still working, this is way too much fragile and\nwould break at some point."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/pmdomain/mediatek/mtk-pm-domains.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"88914db077b6c2920b29a3ec76109a2fd3cf8d38","lessThan":"36c2d7728540252474752172027f0113028ab00c","versionType":"git","status":"affected"},{"version":"88914db077b6c2920b29a3ec76109a2fd3cf8d38","lessThan":"a4876f11aa1d076802676e23f8af500706e780e3","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/pmdomain/mediatek/mtk-pm-domains.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.19","status":"affected"},{"version":"0","lessThan":"6.19","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc4","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/36c2d7728540252474752172027f0113028ab00c","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/a4876f11aa1d076802676e23f8af500706e780e3","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-72009","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:20:59.570","lastModified":"2026-08-15T06:20:59.570","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\npmdomain: imx93-blk-ctrl: Extract PHY as shared domain for DSI/CSI\n\nThe MIPI DSI and CSI domains share control bits for clock and reset, which\ncan lead to incorrect behavior if one domain disables the shared resource\nwhile the other is still active.\n\nTo fix the issue, introduce a shared MIPI PHY power domain to own the\ncommon resources and make DSI and CSI its subdomains. This ensures the\nshared bits are properly managed and not disabled while still in use."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/pmdomain/imx/imx93-blk-ctrl.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"e9aa77d413c903ba4cf7da3fe0b419cae5b97a81","lessThan":"4fd5b33faf092ef2d09f730a7d9e49f9e976ac67","versionType":"git","status":"affected"},{"version":"e9aa77d413c903ba4cf7da3fe0b419cae5b97a81","lessThan":"4ba6d7166750d0b810c6cfc0b1df7585f513b48c","versionType":"git","status":"affected"},{"version":"e9aa77d413c903ba4cf7da3fe0b419cae5b97a81","lessThan":"99611233f8cda833169fa6487d5dacdf189e5cb0","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/pmdomain/imx/imx93-blk-ctrl.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.1","status":"affected"},{"version":"0","lessThan":"6.1","versionType":"semver","status":"unaffected"},{"version":"6.18.42","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc4","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/4ba6d7166750d0b810c6cfc0b1df7585f513b48c","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/4fd5b33faf092ef2d09f730a7d9e49f9e976ac67","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/99611233f8cda833169fa6487d5dacdf189e5cb0","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-72010","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:20:59.670","lastModified":"2026-08-15T06:20:59.670","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\ncgroup/cpuset: rebind mm mempolicy to effective_mems, not mems_allowed\n\nCreating a child cpuset where cpuset.mems is never set leads to a div/0\nwhen a VMA mempolicy with MPOL_F_RELATIVE_NODES rebinds in response to a\nCPU hotplug event.\n\nReproduction steps:\n 1) Create a cgroup w/ cpuset controls (do not set cpuset.mems)\n 2) Move the task into the child cpuset\n 3) Create a VMA mempolicy for that task with MPOL_F_RELATIVE_NODES\n 4) unplug and hotplug a cpu\n      echo 0 > /sys/devices/system/cpu/cpu1/online\n      echo 1 > /sys/devices/system/cpu/cpu1/online\n 5) mempolicy rebind does a div/0 in mpol_relative_nodemask on the\n    call to __nodes_fold()\n\nThe cpuset code passes (cs->mems_allowed) which is not guaranteed to have\nnodes to the rebind routine.  Use cs->effective_mems instead, which is\nguaranteed to have a non-empty nodemask once we reach that code path.\n\n[ david: add a comment, slightly rephrase description ]"}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["kernel/cgroup/cpuset.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"ae1c802382f7af60aa54879fb4f5920a9df1ff48","lessThan":"b7adeba2a21c98c7b20f18e27e3ead86bdb5e08d","versionType":"git","status":"affected"},{"version":"ae1c802382f7af60aa54879fb4f5920a9df1ff48","lessThan":"fcc8c310539c3cc523419113b227161a96b50550","versionType":"git","status":"affected"},{"version":"ae1c802382f7af60aa54879fb4f5920a9df1ff48","lessThan":"4b06449384b9ee5b3372bab60601ba5cd4162086","versionType":"git","status":"affected"},{"version":"ae1c802382f7af60aa54879fb4f5920a9df1ff48","lessThan":"02f67c4f88be8e3dbd91951d13cdcc5bcc82e9c7","versionType":"git","status":"affected"},{"version":"ae1c802382f7af60aa54879fb4f5920a9df1ff48","lessThan":"fc680afc510157f6b137956011c09abc23eb0842","versionType":"git","status":"affected"},{"version":"ae1c802382f7af60aa54879fb4f5920a9df1ff48","lessThan":"c844b7d9a9586de15dd28c06da5cc7f6ab28787d","versionType":"git","status":"affected"},{"version":"ae1c802382f7af60aa54879fb4f5920a9df1ff48","lessThan":"c17f06d8a085d6be58b544a440ce243f5e441a60","versionType":"git","status":"affected"},{"version":"ae1c802382f7af60aa54879fb4f5920a9df1ff48","lessThan":"b983c56426383e4a06fa5970c4e33cee879b1482","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["kernel/cgroup/cpuset.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"3.17","status":"affected"},{"version":"0","lessThan":"3.17","versionType":"semver","status":"unaffected"},{"version":"5.10.261","lessThanOrEqual":"5.10.*","versionType":"semver","status":"unaffected"},{"version":"5.15.212","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.178","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.97","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc4","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/02f67c4f88be8e3dbd91951d13cdcc5bcc82e9c7","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/4b06449384b9ee5b3372bab60601ba5cd4162086","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/b7adeba2a21c98c7b20f18e27e3ead86bdb5e08d","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/b983c56426383e4a06fa5970c4e33cee879b1482","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/c17f06d8a085d6be58b544a440ce243f5e441a60","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/c844b7d9a9586de15dd28c06da5cc7f6ab28787d","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/fc680afc510157f6b137956011c09abc23eb0842","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/fcc8c310539c3cc523419113b227161a96b50550","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-72011","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:20:59.800","lastModified":"2026-08-15T06:20:59.800","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\ns390/diag: Add missing array_index_nospec() call to memtop_get_page_count()\n\n'level' is user space controlled and used to read from an array. Add the\nmissing array_index_nospec() call to prevent speculative execution."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["arch/s390/kernel/diag/diag310.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"0d30871739ab433e114b0058f08b6b1c7b816f7e","lessThan":"c6b4d454865a81ceea1422243aaaedc363b6f713","versionType":"git","status":"affected"},{"version":"0d30871739ab433e114b0058f08b6b1c7b816f7e","lessThan":"83fe36f81200b7a85f8efe0a68a4e58be84d5f64","versionType":"git","status":"affected"},{"version":"0d30871739ab433e114b0058f08b6b1c7b816f7e","lessThan":"b7577fe4c47a31ca7c99714c53244a44af03cdfe","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["arch/s390/kernel/diag/diag310.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.14","status":"affected"},{"version":"0","lessThan":"6.14","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc3","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/83fe36f81200b7a85f8efe0a68a4e58be84d5f64","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/b7577fe4c47a31ca7c99714c53244a44af03cdfe","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/c6b4d454865a81ceea1422243aaaedc363b6f713","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-72012","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:20:59.907","lastModified":"2026-08-15T06:20:59.907","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\ntracing/osnoise: Call synchronize_rcu() when unregistering\n\nThis ensures that any RCU readers traversing the instance list\nhave finished, before releasing the reference on the tracer that\nthe instance points to."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["kernel/trace/trace_osnoise.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"a6ed2aee54644cfa2d04ca86308767f5c3a087e8","lessThan":"3c693635bb7b3a9b6645831a84fed2af46cdf249","versionType":"git","status":"affected"},{"version":"a6ed2aee54644cfa2d04ca86308767f5c3a087e8","lessThan":"38366140dc8ee3568c7f0191d517e117963bd580","versionType":"git","status":"affected"},{"version":"a6ed2aee54644cfa2d04ca86308767f5c3a087e8","lessThan":"fad36954b29592ce463254179c3043697678481f","versionType":"git","status":"affected"},{"version":"a6ed2aee54644cfa2d04ca86308767f5c3a087e8","lessThan":"dd0160a0842337f12e7694d68b184050afc6d3a4","versionType":"git","status":"affected"},{"version":"a6ed2aee54644cfa2d04ca86308767f5c3a087e8","lessThan":"fe58f457ad8d0a2bef4e053cfecca4b5cd266b1a","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["kernel/trace/trace_osnoise.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"5.17","status":"affected"},{"version":"0","lessThan":"5.17","versionType":"semver","status":"unaffected"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.97","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc3","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/38366140dc8ee3568c7f0191d517e117963bd580","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/3c693635bb7b3a9b6645831a84fed2af46cdf249","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/dd0160a0842337f12e7694d68b184050afc6d3a4","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/fad36954b29592ce463254179c3043697678481f","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/fe58f457ad8d0a2bef4e053cfecca4b5cd266b1a","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-72013","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:21:00.033","lastModified":"2026-08-15T06:21:00.033","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nriscv: Prevent NULL pointer dereference in machine_kexec_prepare()\n\nA NULL pointer dereference issue is noticed in riscv's\nmachine_kexec_prepare(), where image->segment[i].buf might be NULL and\ncopied unchecked.\n\nThe NULL buf comes from ima_add_kexec_buffer(), where kbuf is added by\nkexec_add_buffer(), but kbuf.buffer is NULL, then it is copied without\na check in machine_kexec_prepare():\n\n  kexec_file_load\n    -> kimage_file_alloc_init()\n       -> kimage_file_prepare_segments()\n          -> ima_add_kexec_buffer()\n             -> kexec_add_buffer()\n    -> machine_kexec_prepare()\n       -> memcpy()\n\nAddress this by adding a check before the data copy attempt."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["arch/riscv/kernel/machine_kexec.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"4211742f0f9e083188f4f0ada00d6eeeef31b7c7","lessThan":"606cc45e871e34b80a2f63874f069387a5b44176","versionType":"git","status":"affected"},{"version":"b7fb4d78a6ade6026d9e5cf438c2a46ab962e032","lessThan":"c462e15497dc40abe369b3be7a2c91ac5d1be6f9","versionType":"git","status":"affected"},{"version":"b7fb4d78a6ade6026d9e5cf438c2a46ab962e032","lessThan":"b5f92cc4e24a298bf390b0b189a4b888c0900161","versionType":"git","status":"affected"},{"version":"b7fb4d78a6ade6026d9e5cf438c2a46ab962e032","lessThan":"6ad6954492697681ebcfc1beb0eb384406cd4b65","versionType":"git","status":"affected"},{"version":"b7fb4d78a6ade6026d9e5cf438c2a46ab962e032","lessThan":"eadd0c2c76aee6a738f17f251434c77db3c606c8","versionType":"git","status":"affected"},{"version":"b7fb4d78a6ade6026d9e5cf438c2a46ab962e032","lessThan":"d5b2752a17efc165793ae38f2c24b5ed9c04ffde","versionType":"git","status":"affected"},{"version":"b7fb4d78a6ade6026d9e5cf438c2a46ab962e032","lessThan":"81bbcff0c053c4f5c711c31a9b72fc492bd96c3f","versionType":"git","status":"affected"},{"version":"3ca8a07f141fd8eec347a82bdfa4b94164f2bb97","versionType":"git","status":"affected"},{"version":"3ba83e46b591381e718007f55c9f831fd0cd7ee8","versionType":"git","status":"affected"},{"version":"5.15.47","lessThan":"5.15.212","versionType":"semver","status":"affected"},{"version":"5.17.15","lessThan":"5.18","versionType":"semver","status":"affected"},{"version":"5.18.4","lessThan":"5.19","versionType":"semver","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["arch/riscv/kernel/machine_kexec.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"5.19","status":"affected"},{"version":"0","lessThan":"5.19","versionType":"semver","status":"unaffected"},{"version":"5.15.212","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.178","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.97","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc3","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/606cc45e871e34b80a2f63874f069387a5b44176","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/6ad6954492697681ebcfc1beb0eb384406cd4b65","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/81bbcff0c053c4f5c711c31a9b72fc492bd96c3f","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/b5f92cc4e24a298bf390b0b189a4b888c0900161","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/c462e15497dc40abe369b3be7a2c91ac5d1be6f9","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/d5b2752a17efc165793ae38f2c24b5ed9c04ffde","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/eadd0c2c76aee6a738f17f251434c77db3c606c8","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-72014","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:21:00.173","lastModified":"2026-08-15T06:21:00.173","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\ndrbd: reject data replies with an out-of-range payload size\n\nrecv_dless_read() receives a P_DATA_REPLY from a peer into the bio of an\noutstanding read request. The peer-supplied payload length reaches it as\nthe signed int data_size, and two peer-controlled inputs can make it\nnegative. With a negotiated data-integrity-alg the digest length is\nsubtracted first, so a reply whose payload is smaller than the digest\nunderflows data_size. With no integrity algorithm (the default) data_size\nis assigned from the unsigned h95/h100 wire length and drbdd() never\nbounds it for a payload-carrying command, so a length above INT_MAX casts\nit negative; this path needs no non-default feature. The bio receive loop\nthen computes expect = min_t(int, data_size, bv_len), which is negative,\nand drbd_recv_all_warn(mapped, expect) receives with a size_t of SIZE_MAX\ninto the first mapped page.\n\nThe sibling receive path read_in_block() is not affected: it uses an\nunsigned size and rejects it against DRBD_MAX_BIO_SIZE before receiving.\nReject a data reply whose size is negative after the optional digest\nsubtraction, covering both triggers.\n\nImpact: a malicious or man-in-the-middle DRBD peer copies attacker-chosen\nbytes past a bio page in the receiver, corrupting kernel memory. A node\nthat reads from its peer (a diskless node, or read-balancing to the peer)\nis exposed in the default configuration; data-integrity-alg is not\nrequired."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/block/drbd/drbd_receiver.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"b411b3637fa71fce9cf2acf0639009500f5892fe","lessThan":"bca33f5442c3094511719d9db792ce3165d87e76","versionType":"git","status":"affected"},{"version":"b411b3637fa71fce9cf2acf0639009500f5892fe","lessThan":"741a682535deffe9ab7e5c89caf83571efbc9dd9","versionType":"git","status":"affected"},{"version":"b411b3637fa71fce9cf2acf0639009500f5892fe","lessThan":"f14e87d7b166490bceb9603b39310e51595d05b9","versionType":"git","status":"affected"},{"version":"b411b3637fa71fce9cf2acf0639009500f5892fe","lessThan":"f16866c62656865854106b79bcf6e4ca97a51a92","versionType":"git","status":"affected"},{"version":"b411b3637fa71fce9cf2acf0639009500f5892fe","lessThan":"5f59a8142000f0b8f75c432209ead73c424a745d","versionType":"git","status":"affected"},{"version":"b411b3637fa71fce9cf2acf0639009500f5892fe","lessThan":"38cc4867540ae8beedfe41a1a1a6ed37052c77d6","versionType":"git","status":"affected"},{"version":"b411b3637fa71fce9cf2acf0639009500f5892fe","lessThan":"648d4317326e6aa3f8c05cbf0fd14cc2eba6ca99","versionType":"git","status":"affected"},{"version":"b411b3637fa71fce9cf2acf0639009500f5892fe","lessThan":"bd910a7660d280595ef94cb6d193951d855d330f","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/block/drbd/drbd_receiver.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"2.6.33","status":"affected"},{"version":"0","lessThan":"2.6.33","versionType":"semver","status":"unaffected"},{"version":"5.10.261","lessThanOrEqual":"5.10.*","versionType":"semver","status":"unaffected"},{"version":"5.15.212","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.178","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.97","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc3","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/38cc4867540ae8beedfe41a1a1a6ed37052c77d6","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/5f59a8142000f0b8f75c432209ead73c424a745d","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/648d4317326e6aa3f8c05cbf0fd14cc2eba6ca99","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/741a682535deffe9ab7e5c89caf83571efbc9dd9","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/bca33f5442c3094511719d9db792ce3165d87e76","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/bd910a7660d280595ef94cb6d193951d855d330f","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/f14e87d7b166490bceb9603b39310e51595d05b9","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/f16866c62656865854106b79bcf6e4ca97a51a92","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-72015","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:21:00.307","lastModified":"2026-08-15T06:21:00.307","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nfs/resctrl: Fix double-add of pseudo-locked region's RMID to free list\n\nA pseudo-locked group's RMID is freed when it is created. On unmount\nrmdir_all_sub() unconditionally frees all RMID of all groups, resulting\nin a double-free of the pseudo-locked group's RMID. The consequence of this\nis that the original free results in the pseudo-locked group's RMID being\nadded to the rmid_free_lru linked list and the second free then attempts\nto add the same RMID entry to the rmid_free_lru again.\n\nDo not double-free a pseudo-locked group's RMID."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["fs/resctrl/rdtgroup.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"e0bdfe8e36f3fbbdc91e70bf927f743ca23917b0","lessThan":"9168176894332312c12ef052e784735dbf4ffe3f","versionType":"git","status":"affected"},{"version":"e0bdfe8e36f3fbbdc91e70bf927f743ca23917b0","lessThan":"b2fe9e140aa94b2816aab7ebc692b543e418f5e3","versionType":"git","status":"affected"},{"version":"e0bdfe8e36f3fbbdc91e70bf927f743ca23917b0","lessThan":"52007bfdce5310e8c8a29849bfbfb188a1e50ca0","versionType":"git","status":"affected"},{"version":"e0bdfe8e36f3fbbdc91e70bf927f743ca23917b0","lessThan":"f7628eea9212e185a09df3aea603ca8580b8678d","versionType":"git","status":"affected"},{"version":"e0bdfe8e36f3fbbdc91e70bf927f743ca23917b0","lessThan":"b9f089723aee892efc77c349ae47a6b452b293c4","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["fs/resctrl/rdtgroup.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"4.19","status":"affected"},{"version":"0","lessThan":"4.19","versionType":"semver","status":"unaffected"},{"version":"6.6.148","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.101","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc3","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/52007bfdce5310e8c8a29849bfbfb188a1e50ca0","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/9168176894332312c12ef052e784735dbf4ffe3f","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/b2fe9e140aa94b2816aab7ebc692b543e418f5e3","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/b9f089723aee892efc77c349ae47a6b452b293c4","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/f7628eea9212e185a09df3aea603ca8580b8678d","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-72016","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:21:00.433","lastModified":"2026-08-15T06:21:00.433","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\ncpu/hotplug: Fix NULL kobject warning in cpuhp_smt_enable()\n\nOn arm64, when booting with `maxcpus` greater than the number of present\nCPUs (e.g., QEMU -smp cpus=4,maxcpus=8), some CPUs are marked as 'present'\nbut have not yet been registered via register_cpu(). Consequently,\nthe per-cpu device objects for these CPUs are not yet initialized.\n\nIn cpuhp_smt_enable(), the code iterates over all present CPUs. Calling\n_cpu_up() for these unregistered CPUs eventually leads to\nsysfs_create_group() being called with a NULL kobject (or a kobject\nwithout a directory), triggering the following warning in\nfs/sysfs/group.c:\n\n  WARNING: fs/sysfs/group.c:137 at internal_create_group+0x41c/0x4bc, CPU#2: sh/181\n  [...]\n  Call trace:\n    internal_create_group+0x41c/0x4bc (P)\n    sysfs_create_group+0x18/0x24\n    topology_add_dev+0x1c/0x28\n    cpuhp_invoke_callback+0x104/0x20c\n    __cpuhp_invoke_callback_range+0x94/0x11c\n    _cpu_up+0x200/0x37c\n\nWhen booting with ACPI, arm64 smp_prepare_cpus() currently sets all\nenumerated CPUs as \"present\" regardless of their status in the MADT. This\ncauses issues with SMT hotplug control. For instance, with QEMU's\n\"-smp 4,maxcpus=8\" configuration, the MADT GICC entries are populated as\nfollows:\n\n1. The first four CPUs: `Enabled` set but `Online Capable` not set.\n\n2. The remaining four CPUs: `Online Capable` set but `Enabled` not set\n   to support potential hot-plugging.\n\nFix this by:\n\n1. When booting with ACPI, checking the ACPI_MADT_ENABLED flag in the GICC\n   entry before calling set_cpu_present() during SMP initialization.\n\n2. Properly managing the present mask in acpi_map_cpu() and\n   acpi_unmap_cpu() to support actual CPU hotplug events, This aligns with\n   other architectures like x86 and LoongArch.\n\n3. Update the arm64 CPU hotplug documentation to no longer state that all\n   online-capable vCPUs are marked as present by the kernel at boot time.\n\nThis ensures that only physically available or explicitly enabled CPUs\nare in the present mask, keeping the SMT control logic consistent with\nthe actual hardware state."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["Documentation/arch/arm64/cpu-hotplug.rst","arch/arm64/kernel/acpi.c","arch/arm64/kernel/smp.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"eed4583bcf9a60f8d6dd3a3c7c94dea28134b1eb","lessThan":"ccdf1770a4ba27e31599d24ad970d77a371c7912","versionType":"git","status":"affected"},{"version":"eed4583bcf9a60f8d6dd3a3c7c94dea28134b1eb","lessThan":"901a489d89ee9c854624c8444090e38e70aed234","versionType":"git","status":"affected"},{"version":"eed4583bcf9a60f8d6dd3a3c7c94dea28134b1eb","lessThan":"f9a82544c7174851f5c7524622f5966dcafd3a47","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["Documentation/arch/arm64/cpu-hotplug.rst","arch/arm64/kernel/acpi.c","arch/arm64/kernel/smp.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.15","status":"affected"},{"version":"0","lessThan":"6.15","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc3","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/901a489d89ee9c854624c8444090e38e70aed234","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/ccdf1770a4ba27e31599d24ad970d77a371c7912","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/f9a82544c7174851f5c7524622f5966dcafd3a47","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-72017","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:21:00.550","lastModified":"2026-08-15T06:21:00.550","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nnet: macb: drop in-flight Tx SKBs on close\n\nThe MACB driver has since forever leaked the outgoing SKBs that\nhave not yet been marked as completed. They live in queue->tx_skb\nwhich gets freed without remorse nor checking.\n\nmacb_free_consistent() gets called in a few codepaths, but only close will\ntrigger the added expressions. In macb_open() and macb_alloc_consistent()\nfailure cases, queues' tx_skb just got allocated and are empty."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/net/ethernet/cadence/macb_main.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"89e5785fc8a6b9eafd37f2318a9a76d479c796be","lessThan":"6124bd785073659c99385094657b77382ebce11b","versionType":"git","status":"affected"},{"version":"89e5785fc8a6b9eafd37f2318a9a76d479c796be","lessThan":"2143fdc0ce27adbb1caaa1a97e0bfb9f3750aef4","versionType":"git","status":"affected"},{"version":"89e5785fc8a6b9eafd37f2318a9a76d479c796be","lessThan":"26b131b2d5b55a81ef6182769d28105a870c0eb2","versionType":"git","status":"affected"},{"version":"89e5785fc8a6b9eafd37f2318a9a76d479c796be","lessThan":"109241d9880488aafd8e104832b4d4859ad57244","versionType":"git","status":"affected"},{"version":"89e5785fc8a6b9eafd37f2318a9a76d479c796be","lessThan":"27f575836cfebbf872dec020428742b10650a955","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/net/ethernet/cadence/macb_main.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"2.6.20","status":"affected"},{"version":"0","lessThan":"2.6.20","versionType":"semver","status":"unaffected"},{"version":"6.6.148","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.101","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc3","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/109241d9880488aafd8e104832b4d4859ad57244","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/2143fdc0ce27adbb1caaa1a97e0bfb9f3750aef4","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/26b131b2d5b55a81ef6182769d28105a870c0eb2","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/27f575836cfebbf872dec020428742b10650a955","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/6124bd785073659c99385094657b77382ebce11b","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-72018","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:21:00.670","lastModified":"2026-08-15T06:21:00.670","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\ndibs: loopback: validate offset and size in move_data()\n\nThe loopback move_data() performs a memcpy into the registered DMB\nwithout checking whether offset + size exceeds the DMB length.  Unlike\nreal ISM hardware, which enforces memory region bounds natively, the\nsoftware loopback has no such protection.\n\nA peer-supplied out-of-bounds offset or oversized write would result in\nan OOB write past the allocated kernel buffer.  Add an explicit bounds\ncheck before the memcpy to reject such requests with -EINVAL."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/dibs/dibs_loopback.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"f7a22071dbf316c982fb44308874bd7ad9ac2091","lessThan":"ee188a6b264b71315a67f1b9470faad308b730d2","versionType":"git","status":"affected"},{"version":"f7a22071dbf316c982fb44308874bd7ad9ac2091","lessThan":"b2f426a9a22886071966432ede8fceafffe12b8c","versionType":"git","status":"affected"},{"version":"f7a22071dbf316c982fb44308874bd7ad9ac2091","lessThan":"94fe0ab01b480b52bd8f977edbd845ef375d69fd","versionType":"git","status":"affected"},{"version":"f7a22071dbf316c982fb44308874bd7ad9ac2091","lessThan":"78237e3c0720fcc6eb9b87e90fd70f63eeca886f","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/dibs/dibs_loopback.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.10","status":"affected"},{"version":"0","lessThan":"6.10","versionType":"semver","status":"unaffected"},{"version":"6.12.97","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc3","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/78237e3c0720fcc6eb9b87e90fd70f63eeca886f","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/94fe0ab01b480b52bd8f977edbd845ef375d69fd","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/b2f426a9a22886071966432ede8fceafffe12b8c","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/ee188a6b264b71315a67f1b9470faad308b730d2","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-72019","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:21:00.790","lastModified":"2026-08-15T06:21:00.790","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nmacsec: don't read an unset MAC header in macsec_encrypt()\n\nmacsec_encrypt() reads the Ethernet header via eth_hdr(skb)\n(skb->head + skb->mac_header) to memmove() the 12 source/destination MAC\nbytes forward and make room for the SecTAG.\n\nOn the AF_PACKET SOCK_RAW + PACKET_QDISC_BYPASS transmit path the skb\nreaches the macsec ndo_start_xmit() with the MAC header unset, so\neth_hdr(skb) resolves to skb->head + (u16)~0 and the read is out of\nbounds: a 12-byte heap over-read that is also emitted on the wire as the\nframe's outer source/destination MAC. KASAN reports a slab-out-of-bounds\nread in macsec_start_xmit() on 6.0; on current mainline a CONFIG_DEBUG_NET\nbuild flags it as an unset mac header in skb_mac_header().\n\nOn the TX path the L2 header is at skb->data, so use skb_eth_hdr(), added\nby commit 96cc4b69581d (\"macvlan: do not assume mac_header is set in\nmacvlan_broadcast()\") for exactly this purpose."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/net/macsec.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"c09440f7dcb304002dfced8c0fea289eb25f2da0","lessThan":"dc9ffa1905e72f026d080880a2e4cfc42aa91000","versionType":"git","status":"affected"},{"version":"c09440f7dcb304002dfced8c0fea289eb25f2da0","lessThan":"f21fa533a3ed15ada74106aac4b9ddd078fc6b7a","versionType":"git","status":"affected"},{"version":"c09440f7dcb304002dfced8c0fea289eb25f2da0","lessThan":"e17a42199824973cd8212e95b21ffadf4114a21b","versionType":"git","status":"affected"},{"version":"c09440f7dcb304002dfced8c0fea289eb25f2da0","lessThan":"2cf10d042562283ff4ae97c02d0993d4f1b5ea29","versionType":"git","status":"affected"},{"version":"c09440f7dcb304002dfced8c0fea289eb25f2da0","lessThan":"c39087ad0b97fc11a3b058dfc8db9fd370762cb9","versionType":"git","status":"affected"},{"version":"c09440f7dcb304002dfced8c0fea289eb25f2da0","lessThan":"f5089008f90c0a7c5520dff3934e0af00adf322d","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/net/macsec.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"4.6","status":"affected"},{"version":"0","lessThan":"4.6","versionType":"semver","status":"unaffected"},{"version":"6.1.178","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.97","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc3","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/2cf10d042562283ff4ae97c02d0993d4f1b5ea29","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/c39087ad0b97fc11a3b058dfc8db9fd370762cb9","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/dc9ffa1905e72f026d080880a2e4cfc42aa91000","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/e17a42199824973cd8212e95b21ffadf4114a21b","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/f21fa533a3ed15ada74106aac4b9ddd078fc6b7a","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/f5089008f90c0a7c5520dff3934e0af00adf322d","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-72020","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:21:00.920","lastModified":"2026-08-15T06:21:00.920","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nipvs: reset full ip_vs_seq structs in ip_vs_conn_new\n\nCommit 9a05475cebdd (\"ipvs: avoid kmem_cache_zalloc in\nip_vs_conn_new\") changed ip_vs_conn_new() to allocate an ip_vs_conn\nobject with kmem_cache_alloc().  The function then initializes many\nfields explicitly, but only resets in_seq.delta and out_seq.delta in the\ntwo struct ip_vs_seq members.\n\nThat leaves init_seq and previous_delta uninitialized.  This is normally\nharmless while the corresponding IP_VS_CONN_F_IN_SEQ or\nIP_VS_CONN_F_OUT_SEQ flag is clear.  For connections learned from a sync\nmessage, however, ip_vs_proc_conn() preserves those flags from\nIP_VS_CONN_F_BACKUP_MASK and passes opt=NULL when the message omits\nIPVS_OPT_SEQ_DATA.  In that case the new connection can be hashed with\nSEQ flags set but with the rest of in_seq/out_seq still containing stale\nslab data.\n\nWhen a packet for such a connection is later handled by an IPVS\napplication helper, vs_fix_seq() and vs_fix_ack_seq() use\nprevious_delta and init_seq to rewrite TCP sequence numbers.  A malformed\nsync message can therefore make forwarded packets carry stale slab bytes\nin their TCP seq/ack numbers, and can also corrupt the forwarded TCP\nflow.\n\nReset both struct ip_vs_seq members completely before publishing the\nconnection.  This matches the existing \"reset struct ip_vs_seq\" comment\nand keeps the sequence-adjustment gates inactive unless valid sequence\ndata is installed later."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["net/netfilter/ipvs/ip_vs_conn.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"9a05475cebdd6341884b5901e53870be26e65158","lessThan":"3bf9a260188b2a5449cbddc032a749ab433fe328","versionType":"git","status":"affected"},{"version":"9a05475cebdd6341884b5901e53870be26e65158","lessThan":"6378c5cb360eb1750f88839d7c3613ea92ac1816","versionType":"git","status":"affected"},{"version":"9a05475cebdd6341884b5901e53870be26e65158","lessThan":"32c299e28b8eea6cbbd23b97dc61401e9ef9c445","versionType":"git","status":"affected"},{"version":"9a05475cebdd6341884b5901e53870be26e65158","lessThan":"9e36602cbec552286f7e691cfd366525c565ee74","versionType":"git","status":"affected"},{"version":"9a05475cebdd6341884b5901e53870be26e65158","lessThan":"d0eed7177e822cab83141e5c44b2aa345c7fd379","versionType":"git","status":"affected"},{"version":"9a05475cebdd6341884b5901e53870be26e65158","lessThan":"83fb4c2c5344f02eac929f66de3c9d1adfcde04c","versionType":"git","status":"affected"},{"version":"9a05475cebdd6341884b5901e53870be26e65158","lessThan":"6335ab62d5fc9ed875279238233fba3462c168f5","versionType":"git","status":"affected"},{"version":"9a05475cebdd6341884b5901e53870be26e65158","lessThan":"2975324d164c552b028632f107b567302863b7f6","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["net/netfilter/ipvs/ip_vs_conn.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"3.10","status":"affected"},{"version":"0","lessThan":"3.10","versionType":"semver","status":"unaffected"},{"version":"5.10.261","lessThanOrEqual":"5.10.*","versionType":"semver","status":"unaffected"},{"version":"5.15.212","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.178","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.97","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc3","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/2975324d164c552b028632f107b567302863b7f6","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/32c299e28b8eea6cbbd23b97dc61401e9ef9c445","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/3bf9a260188b2a5449cbddc032a749ab433fe328","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/6335ab62d5fc9ed875279238233fba3462c168f5","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/6378c5cb360eb1750f88839d7c3613ea92ac1816","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/83fb4c2c5344f02eac929f66de3c9d1adfcde04c","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/9e36602cbec552286f7e691cfd366525c565ee74","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/d0eed7177e822cab83141e5c44b2aa345c7fd379","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-72021","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:21:01.053","lastModified":"2026-08-15T06:21:01.053","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nipvs: use parsed transport offset in SCTP state lookup\n\nset_sctp_state() reads the SCTP chunk header again in order to drive the\nIPVS SCTP state table. For IPv6 it computes the offset with\nsizeof(struct ipv6hdr), while the surrounding IPVS code uses iph.len from\nip_vs_fill_iph_skb(), where ipv6_find_hdr() has already skipped\nextension headers and found the real transport header.\n\nThis makes the state machine read from the wrong offset for IPv6 SCTP\npackets that carry extension headers. For example, an INIT packet with an\n8-byte destination options header can be scheduled correctly by\nsctp_conn_schedule(), but set_sctp_state() reads the first byte of the\nSCTP verification tag as a DATA chunk type. The connection then moves\nfrom NONE to ESTABLISHED instead of INIT1, gets the longer established\ntimeout, and updates the active/inactive destination counters\nincorrectly. This happens even though the SCTP handshake has not\ncompleted.\n\nUse the parsed transport offset passed down from ip_vs_set_state() for\nthe SCTP chunk-header lookup. For IPv4 and IPv6 packets without\nextension headers this preserves the existing offset."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["net/netfilter/ipvs/ip_vs_proto_sctp.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"2906f66a5682e5670a5eefe991843689b8d8563f","lessThan":"d2b8b1557ec07ea1bb5dddbceaf4dfe63d388e27","versionType":"git","status":"affected"},{"version":"2906f66a5682e5670a5eefe991843689b8d8563f","lessThan":"9f94573ab962a9e81954b755da016fa3cd2f5039","versionType":"git","status":"affected"},{"version":"2906f66a5682e5670a5eefe991843689b8d8563f","lessThan":"290e9e8389b556efc603522e28bd1543846aa336","versionType":"git","status":"affected"},{"version":"2906f66a5682e5670a5eefe991843689b8d8563f","lessThan":"9cb5ac594ca76d3a71803b23b74c835b0721e628","versionType":"git","status":"affected"},{"version":"2906f66a5682e5670a5eefe991843689b8d8563f","lessThan":"a4a2d2e483d79cc2ad3a170674cf159644acf22b","versionType":"git","status":"affected"},{"version":"2906f66a5682e5670a5eefe991843689b8d8563f","lessThan":"247d055504dcc852e539b9f7f30d19f9741474bf","versionType":"git","status":"affected"},{"version":"2906f66a5682e5670a5eefe991843689b8d8563f","lessThan":"e5d0bb8871668f20de8f3c94b5ae3f372346bc6e","versionType":"git","status":"affected"},{"version":"2906f66a5682e5670a5eefe991843689b8d8563f","lessThan":"2f75c0faa3361b28e36cc0512b3299e163e25789","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["net/netfilter/ipvs/ip_vs_proto_sctp.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"2.6.34","status":"affected"},{"version":"0","lessThan":"2.6.34","versionType":"semver","status":"unaffected"},{"version":"5.10.261","lessThanOrEqual":"5.10.*","versionType":"semver","status":"unaffected"},{"version":"5.15.212","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.178","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.97","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc3","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/247d055504dcc852e539b9f7f30d19f9741474bf","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/290e9e8389b556efc603522e28bd1543846aa336","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/2f75c0faa3361b28e36cc0512b3299e163e25789","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/9cb5ac594ca76d3a71803b23b74c835b0721e628","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/9f94573ab962a9e81954b755da016fa3cd2f5039","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/a4a2d2e483d79cc2ad3a170674cf159644acf22b","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/d2b8b1557ec07ea1bb5dddbceaf4dfe63d388e27","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/e5d0bb8871668f20de8f3c94b5ae3f372346bc6e","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-72022","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:21:01.193","lastModified":"2026-08-15T06:21:01.193","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nllc: fix SAP refcount leak in llc_ui_autobind()\n\nllc_ui_autobind() opens a SAP after choosing a dynamic LSAP.\nllc_sap_open() returns a reference owned by the caller, and\nllc_sap_add_socket() takes a second reference for the socket's\nmembership in the SAP hash tables.\n\nllc_ui_bind() drops the caller's reference after adding the socket,\nbut llc_ui_autobind() keeps it. When the socket is closed,\nllc_sap_remove_socket() releases only the socket reference, leaving\nthe SAP on llc_sap_list with sk_count == 0.\n\nThis is user-visible because repeated autobind and close cycles can consume\nall dynamic SAP values and make later autobinds fail with -EUSERS.\n\nDrop the caller's reference after a successful autobind, matching\nllc_ui_bind()'s ownership model."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["net/llc/af_llc.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"79dc4b508e3f2649390a1f745f7657813e5938ec","versionType":"git","status":"affected"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"a2f9fa31ae021ef1fdcaf3ab17bd49f9223dd6a4","versionType":"git","status":"affected"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"b589a965184dde49c43b8caf5bcc65715a7b4ef2","versionType":"git","status":"affected"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"c7881b6088276601beaccb7440b8d56eab0d65ae","versionType":"git","status":"affected"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"b2fc9955ddc7c4ca03be44b995193bd6486c62e1","versionType":"git","status":"affected"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"61a7ff4a62003b55a15022567486741b3bd83914","versionType":"git","status":"affected"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"21a537606fe35be2b85971a5fd35c0023b6ef98f","versionType":"git","status":"affected"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"660667cd406648bbaffbd5c0d897c2263a852f11","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["net/llc/af_llc.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"2.6.12","status":"affected"},{"version":"0","lessThan":"2.6.12","versionType":"semver","status":"unaffected"},{"version":"5.10.261","lessThanOrEqual":"5.10.*","versionType":"semver","status":"unaffected"},{"version":"5.15.212","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.178","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.97","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc3","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/21a537606fe35be2b85971a5fd35c0023b6ef98f","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/61a7ff4a62003b55a15022567486741b3bd83914","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/660667cd406648bbaffbd5c0d897c2263a852f11","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/79dc4b508e3f2649390a1f745f7657813e5938ec","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/a2f9fa31ae021ef1fdcaf3ab17bd49f9223dd6a4","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/b2fc9955ddc7c4ca03be44b995193bd6486c62e1","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/b589a965184dde49c43b8caf5bcc65715a7b4ef2","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/c7881b6088276601beaccb7440b8d56eab0d65ae","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-72023","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:21:01.323","lastModified":"2026-08-15T06:21:01.323","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nocteontx2-pf: fix SQB pointer leak on init failure\n\notx2_init_hw_resources() initializes SQ aura and pool resources before\nseveral later setup steps. On failure, err_free_sq_ptrs only frees SQB\npages, leaving the per-SQ sqb_ptrs arrays behind.\n\nUse otx2_free_sq_res() for the SQ unwind path and let it free sqb_ptrs\neven when sq->sqe has not been allocated yet.\n\nThe bug was first flagged by an experimental analysis tool we are\ndeveloping for kernel memory-management bugs while analyzing\nv6.13-rc1. The tool is still under development and is not yet publicly\navailable. Manual inspection confirms that the bug is still\npresent in v7.1.1.\n\nAn x86_64 allyesconfig build showed no new warnings. As we do not have an\nOcteonTX2 PF device and the corresponding AF mailbox setup to test with,\nno runtime testing was able to be performed."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/net/ethernet/marvell/octeontx2/nic/otx2_pf.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"caa2da34fd25a37e9fd43343b6966fb9d730a6d5","lessThan":"148d7ec0a3a98839c320e6cdd112e2e88bfb091b","versionType":"git","status":"affected"},{"version":"caa2da34fd25a37e9fd43343b6966fb9d730a6d5","lessThan":"5e023fe2569e630ba23b5558ebe4bf4837af4d16","versionType":"git","status":"affected"},{"version":"caa2da34fd25a37e9fd43343b6966fb9d730a6d5","lessThan":"5df30f05db96552903680a17f858d250dfd9e86e","versionType":"git","status":"affected"},{"version":"caa2da34fd25a37e9fd43343b6966fb9d730a6d5","lessThan":"23d917acd9c9a9fd999688ec3fdde7aa58ab8a14","versionType":"git","status":"affected"},{"version":"caa2da34fd25a37e9fd43343b6966fb9d730a6d5","lessThan":"62e7df6d042aeebd5efb581074e28865c04477be","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/net/ethernet/marvell/octeontx2/nic/otx2_pf.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"5.6","status":"affected"},{"version":"0","lessThan":"5.6","versionType":"semver","status":"unaffected"},{"version":"6.6.148","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.101","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc3","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/148d7ec0a3a98839c320e6cdd112e2e88bfb091b","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/23d917acd9c9a9fd999688ec3fdde7aa58ab8a14","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/5df30f05db96552903680a17f858d250dfd9e86e","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/5e023fe2569e630ba23b5558ebe4bf4837af4d16","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/62e7df6d042aeebd5efb581074e28865c04477be","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-72024","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:21:01.440","lastModified":"2026-08-15T06:21:01.440","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nmac802154: remove interfaces with RCU list deletion\n\nQueue wake, stop, and disable paths walk local->interfaces under RCU.\nThe bulk hardware teardown path removes entries with list_del(), so an\nasynchronous transmit completion can follow a poisoned list node in\nieee802154_wake_queue().\n\nUse list_del_rcu() as in the single-interface removal path. The following\nunregister_netdevice() waits for in-flight RCU readers before freeing the\nnetdevice, so no separate grace-period wait is needed."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["net/mac802154/iface.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"592dfbfc72f5352437c883aa11ab579d10cdb595","lessThan":"72ac5af9ad09662bd0ea91cb8845d490c8ef9c01","versionType":"git","status":"affected"},{"version":"592dfbfc72f5352437c883aa11ab579d10cdb595","lessThan":"2039f27b1a0c997137a5de7f8a3cee0e80fbf952","versionType":"git","status":"affected"},{"version":"592dfbfc72f5352437c883aa11ab579d10cdb595","lessThan":"4bf231f459b542414629b64f63d5cad6701bd07c","versionType":"git","status":"affected"},{"version":"592dfbfc72f5352437c883aa11ab579d10cdb595","lessThan":"b91e5248dd7af09b500879a46d22a36b60db3a57","versionType":"git","status":"affected"},{"version":"592dfbfc72f5352437c883aa11ab579d10cdb595","lessThan":"c7c031b75218b3ba3014a0f6b9849888994528d6","versionType":"git","status":"affected"},{"version":"592dfbfc72f5352437c883aa11ab579d10cdb595","lessThan":"77caf2d6eba7cb94a7ecd7b369a5974fd7d7c054","versionType":"git","status":"affected"},{"version":"592dfbfc72f5352437c883aa11ab579d10cdb595","lessThan":"d8b5b66388a51febe4b8505b0ecd9da15b4ba639","versionType":"git","status":"affected"},{"version":"592dfbfc72f5352437c883aa11ab579d10cdb595","lessThan":"539dfcf69105d8d3d4d677b71de6e5ede2e6dfa0","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["net/mac802154/iface.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"3.19","status":"affected"},{"version":"0","lessThan":"3.19","versionType":"semver","status":"unaffected"},{"version":"5.10.261","lessThanOrEqual":"5.10.*","versionType":"semver","status":"unaffected"},{"version":"5.15.212","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.178","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.97","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc3","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/2039f27b1a0c997137a5de7f8a3cee0e80fbf952","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/4bf231f459b542414629b64f63d5cad6701bd07c","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/539dfcf69105d8d3d4d677b71de6e5ede2e6dfa0","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/72ac5af9ad09662bd0ea91cb8845d490c8ef9c01","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/77caf2d6eba7cb94a7ecd7b369a5974fd7d7c054","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/b91e5248dd7af09b500879a46d22a36b60db3a57","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/c7c031b75218b3ba3014a0f6b9849888994528d6","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/d8b5b66388a51febe4b8505b0ecd9da15b4ba639","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-72025","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:21:01.580","lastModified":"2026-08-15T06:21:01.580","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\ns390/monwriter: Reject buffer reuse with different data length\n\nWhen data buffers are reused, e.g. for interval sample records, the\nfirst record determines the data length, and the size of the buffer for\nuser copy. Current monwriter code does not check if the data length was\nchanged for subsequent records, which also would never happen for valid\nuser programs.\n\nHowever, a malicious user could change the data length, resulting in out\nof bounds user copy to the kernel buffer, and memory corruption. By\ndefault, the monwriter misc device is created with root-only permissions,\nso practical impact is typically low.\n\nFix this by checking for changed data length and rejecting such records."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/s390/char/monwriter.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"096dff1247037d329c04b3a5be0ecdfb1c5c7ac6","versionType":"git","status":"affected"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"d39cf4a6d721b1ae21eb53bbf3e8cd984253d7ab","versionType":"git","status":"affected"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"759d91378203ea35fa9bca6726dcf0010de081fb","versionType":"git","status":"affected"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"036bc5661060702e798d215e81bb46da530965b3","versionType":"git","status":"affected"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"01f3ce411711c2c919598ea25320a5a48f71edbc","versionType":"git","status":"affected"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"f0745496f7c171271cafd9457df3b914a483ddeb","versionType":"git","status":"affected"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"ae5347f3db1782c6118f6cc0d9fd8b1d43397db3","versionType":"git","status":"affected"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"2995ccec260caa9e85b3301a4aba1e66ed80ad74","versionType":"git","status":"affected"},{"version":"0","lessThan":"5.10.261","versionType":"semver","status":"affected"},{"version":"0","lessThan":"5.15.212","versionType":"semver","status":"affected"},{"version":"0","lessThan":"6.1.178","versionType":"semver","status":"affected"},{"version":"0","lessThan":"6.6.145","versionType":"semver","status":"affected"},{"version":"0","lessThan":"6.12.97","versionType":"semver","status":"affected"},{"version":"0","lessThan":"6.18.40","versionType":"semver","status":"affected"},{"version":"0","lessThan":"7.1.5","versionType":"semver","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/s390/char/monwriter.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"5.10.261","lessThanOrEqual":"5.10.*","versionType":"semver","status":"unaffected"},{"version":"5.15.212","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.178","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.97","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc2","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/01f3ce411711c2c919598ea25320a5a48f71edbc","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/036bc5661060702e798d215e81bb46da530965b3","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/096dff1247037d329c04b3a5be0ecdfb1c5c7ac6","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/2995ccec260caa9e85b3301a4aba1e66ed80ad74","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/759d91378203ea35fa9bca6726dcf0010de081fb","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/ae5347f3db1782c6118f6cc0d9fd8b1d43397db3","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/d39cf4a6d721b1ae21eb53bbf3e8cd984253d7ab","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/f0745496f7c171271cafd9457df3b914a483ddeb","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-72026","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:21:01.730","lastModified":"2026-08-15T06:21:01.730","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nirqchip/irq-riscv-imsic-early: Fix fwnode leak on state setup failure\n\nimsic_early_acpi_init() allocates a firmware node before setting up the\nIMSIC state. If imsic_setup_state() fails, the function returns without\nfreeing the allocated fwnode.\n\nFree the fwnode and clear the global pointer on this error path, matching\nthe cleanup already done when imsic_early_probe() fails.\n\n[ tglx: Use a common cleanup path instead of copying code around ]"}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/irqchip/irq-riscv-imsic-early.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"fbe826b1c10699a70b81a441fe47b817d1019f37","lessThan":"a27f17bad38c5fea3c73281517869af0089a0451","versionType":"git","status":"affected"},{"version":"fbe826b1c10699a70b81a441fe47b817d1019f37","lessThan":"a5a367756926de1c21a013ea5ed7fc2219f4cb4f","versionType":"git","status":"affected"},{"version":"fbe826b1c10699a70b81a441fe47b817d1019f37","lessThan":"b321a046d7717225c07ba3f4b7b0a4758c2f9d58","versionType":"git","status":"affected"},{"version":"fbe826b1c10699a70b81a441fe47b817d1019f37","lessThan":"1358126fbed104e5657955d3ba029b283687ba02","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/irqchip/irq-riscv-imsic-early.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.12","status":"affected"},{"version":"0","lessThan":"6.12","versionType":"semver","status":"unaffected"},{"version":"6.12.97","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc2","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/1358126fbed104e5657955d3ba029b283687ba02","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/a27f17bad38c5fea3c73281517869af0089a0451","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/a5a367756926de1c21a013ea5ed7fc2219f4cb4f","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/b321a046d7717225c07ba3f4b7b0a4758c2f9d58","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-72027","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:21:01.843","lastModified":"2026-08-15T06:21:01.843","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nmm/compaction: handle free_pages_prepare() properly in compaction_free()\n\nfree_pages_prepare() can fail but compaction_free() does not handle the\nfailure case.  Failed pages should not be added back to cc->freepages for\nfuture use, since they can be either PageHWPoison or free_page_is_bad()\nand might cause data corruption."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["mm/compaction.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"733aea0b3a7bba0451dfc19322665de13a5b7af4","lessThan":"de8577db09039d4950239b01446ab5ead9028ab4","versionType":"git","status":"affected"},{"version":"733aea0b3a7bba0451dfc19322665de13a5b7af4","lessThan":"018d7ad26cb8bdfe9842f2ca68a42b0bfdcc82fe","versionType":"git","status":"affected"},{"version":"733aea0b3a7bba0451dfc19322665de13a5b7af4","lessThan":"23afc3786acf359c135093893fb43a436768c832","versionType":"git","status":"affected"},{"version":"733aea0b3a7bba0451dfc19322665de13a5b7af4","lessThan":"7da7d599b8a83271c464adfd5ef160202b470570","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["mm/compaction.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.9","status":"affected"},{"version":"0","lessThan":"6.9","versionType":"semver","status":"unaffected"},{"version":"6.12.97","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc3","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/018d7ad26cb8bdfe9842f2ca68a42b0bfdcc82fe","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/23afc3786acf359c135093893fb43a436768c832","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/7da7d599b8a83271c464adfd5ef160202b470570","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/de8577db09039d4950239b01446ab5ead9028ab4","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-72028","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:21:01.953","lastModified":"2026-08-15T06:21:01.953","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nriscv: probes: save original sp in rethook trampoline\n\nReading a word from the stack in a kretprobe crashes a risc-v kernel.\n\n$ cd /sys/kernel/tracing/\n$ echo 'r n_tty_write $stack0' > dynamic_events\n$ echo 1 > events/kprobes/enable\nUnable to handle kernel paging request at virtual address 0000000200000128\n...\n[<ffffffff80016d16>] regs_get_kernel_stack_nth+0x26/0x38\n[<ffffffff80177196>] process_fetch_insn+0x3ee/0x760\n[<ffffffff80177836>] kretprobe_trace_func+0x116/0x1f0\n[<ffffffff8017795a>] kretprobe_dispatcher+0x4a/0x58\n[<ffffffff8013572e>] kretprobe_rethook_handler+0x5e/0x90\n[<ffffffff80180838>] rethook_trampoline_handler+0x70/0x108\n[<ffffffff8001ba32>] arch_rethook_trampoline_callback+0x12/0x1c\n[<ffffffff8001ba84>] arch_rethook_trampoline+0x48/0x94\n[<ffffffff8067872a>] tty_write+0x1a/0x30\n\nIn regs_get_kernel_stack_nth, regs->sp contains an arbitrary value.\n\narch_rethook_trampoline saves the registers from the probed function in a\nstruct pt_regs. sp is not saved. Instead, sp is decremented for\narch_rethook_trampoline's local stack.\n\nFix this crash and save the original sp along with the other registers.\nUse a0 as a temporary register, it is overwritten anyway.\n\n[pjw@kernel.org: added Fixes tag; cc'ed stable]"}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["arch/riscv/kernel/probes/rethook_trampoline.S"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"c22b0bcb1dd024cb9caad9230e3a387d8b061df5","lessThan":"5da5cf48a432e30ded8d58087854e5383a36eff1","versionType":"git","status":"affected"},{"version":"c22b0bcb1dd024cb9caad9230e3a387d8b061df5","lessThan":"c386e1c591d72eab58ee2e69105c8cbc70928857","versionType":"git","status":"affected"},{"version":"c22b0bcb1dd024cb9caad9230e3a387d8b061df5","lessThan":"2faf0198168d2017cb528a79f76c560fda3b6e94","versionType":"git","status":"affected"},{"version":"c22b0bcb1dd024cb9caad9230e3a387d8b061df5","lessThan":"91b4d76dd07f1a1f20f73dfebb42ba04ac911a56","versionType":"git","status":"affected"},{"version":"c22b0bcb1dd024cb9caad9230e3a387d8b061df5","lessThan":"bc7b086a45521a986a49045907f017e3e46c763e","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["arch/riscv/kernel/probes/rethook_trampoline.S"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"5.12","status":"affected"},{"version":"0","lessThan":"5.12","versionType":"semver","status":"unaffected"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.97","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc2","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/2faf0198168d2017cb528a79f76c560fda3b6e94","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/5da5cf48a432e30ded8d58087854e5383a36eff1","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/91b4d76dd07f1a1f20f73dfebb42ba04ac911a56","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/bc7b086a45521a986a49045907f017e3e46c763e","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/c386e1c591d72eab58ee2e69105c8cbc70928857","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-72029","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:21:02.083","lastModified":"2026-08-15T06:21:02.083","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nnet: wwan: iosm: bound device offsets in the MUX downlink decoder\n\nmux_dl_adb_decode() walks a chain of aggregated datagram tables using\noffsets and lengths taken from the modem. first_table_index,\nnext_table_index, table_length, datagram_index and datagram_length are\nall device supplied le values. Only first_table_index was checked, and\nonly for being non zero. The decoder then formed adth = block +\nadth_index and read the table header and the datagram entries with no\nbound against the received skb. A modem that reports an index or a\nlength past the downlink buffer makes the decoder read out of bounds.\n\nThe buffer is IPC_MEM_MAX_DL_MUX_LITE_BUF_SIZE and skb->len is at most\nthat, so skb->len is the real limit, but none of these in band offsets\nwere checked against it.\n\nThe table chain is also followed with no forward progress check. The loop\ntakes the next table from adth->next_table_index and stops only when that\nreaches zero. A modem can stage two tables that point at each other, so\nthe loop never ends. It runs in softirq and clones the skb on every pass.\n\nValidate every device offset and length against skb->len before use.\nThe block header must fit. Each table header, on entry and after every\nnext_table_index, must lie inside the skb. The datagram table must fit.\nEach datagram index and length must stay inside the skb. The header\npadding must not exceed the datagram length so the receive length does\nnot wrap. Require each next_table_index to move forward so the chain\ncannot cycle.\n\nThis was reproduced under KASAN as a slab out of bounds read on a normal\ndownlink receive once the iosm net device is up."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/net/wwan/iosm/iosm_ipc_mux_codec.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"1f52d7b622854b8bd7a1be3de095ca2e1f77098e","lessThan":"155851e501d6c649cbcfcca6472dc26269b04b6b","versionType":"git","status":"affected"},{"version":"1f52d7b622854b8bd7a1be3de095ca2e1f77098e","lessThan":"2b822df8e498aa6ca828e16afd8ffec27f7e4c88","versionType":"git","status":"affected"},{"version":"1f52d7b622854b8bd7a1be3de095ca2e1f77098e","lessThan":"55cfea8e8d9117ad086d1e1a0ff87f306f8e3ad0","versionType":"git","status":"affected"},{"version":"1f52d7b622854b8bd7a1be3de095ca2e1f77098e","lessThan":"07f5eb6d268a37bd9e131079489655cd599182e0","versionType":"git","status":"affected"},{"version":"1f52d7b622854b8bd7a1be3de095ca2e1f77098e","lessThan":"77f0023f22f6a2616ae128e9c93961b24ae52611","versionType":"git","status":"affected"},{"version":"1f52d7b622854b8bd7a1be3de095ca2e1f77098e","lessThan":"526b8ef54668780c8f69e0211c342763d5dcbad1","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/net/wwan/iosm/iosm_ipc_mux_codec.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"5.18","status":"affected"},{"version":"0","lessThan":"5.18","versionType":"semver","status":"unaffected"},{"version":"6.1.178","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.97","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc2","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/07f5eb6d268a37bd9e131079489655cd599182e0","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/155851e501d6c649cbcfcca6472dc26269b04b6b","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/2b822df8e498aa6ca828e16afd8ffec27f7e4c88","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/526b8ef54668780c8f69e0211c342763d5dcbad1","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/55cfea8e8d9117ad086d1e1a0ff87f306f8e3ad0","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/77f0023f22f6a2616ae128e9c93961b24ae52611","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-72030","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:21:09.200","lastModified":"2026-08-15T06:21:09.200","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nata: libata-core: Reject an invalid concurrent positioning ranges count\n\nata_dev_config_cpr() takes the number of range descriptors from buf[0]\nof the concurrent positioning ranges log (up to 255), which the device\nreports independently of the log size in the GPL directory. The count is\nthen walked at a fixed 32-byte stride in two places with no bound: the\nlog read here, and the INQUIRY VPD page B9h emitter, which writes one\ndescriptor per range into the fixed 2048-byte ata_scsi_rbuf. A device\nreporting a count larger than its own log overflows the read buffer (up\nto 7704 bytes past a 512-byte slab), and a count above 62 overflows the\nresponse buffer on the emit side.\n\nBound the count once, on probe, against both the log the device returned\nand the number of descriptors the VPD B9h response buffer can hold\n(ATA_DEV_MAX_CPR, derived from the rbuf size). Reject an out-of-range\ncount with a warning; this keeps the emitter in bounds with no separate\nchange there."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/ata/libata-core.c","drivers/ata/libata-scsi.c","drivers/ata/libata.h"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"fe22e1c2f705676a705d821301fc52eecc2fe055","lessThan":"4cb4b4dd8853c4ab3057efe238b2c34277772176","versionType":"git","status":"affected"},{"version":"fe22e1c2f705676a705d821301fc52eecc2fe055","lessThan":"b1607f0ee5f5e53e0aa66f41794085b7cc98f5d1","versionType":"git","status":"affected"},{"version":"fe22e1c2f705676a705d821301fc52eecc2fe055","lessThan":"4c1e8ccd8655ee8cf1bcb1b7dfee72c9fa941fd4","versionType":"git","status":"affected"},{"version":"fe22e1c2f705676a705d821301fc52eecc2fe055","lessThan":"d43efd1b5d976203e6f1ef26f67e8b1a7bc2751b","versionType":"git","status":"affected"},{"version":"fe22e1c2f705676a705d821301fc52eecc2fe055","lessThan":"533a0b940f901c15e5cbbd4b5d66e871c209e8ce","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/ata/libata-core.c","drivers/ata/libata-scsi.c","drivers/ata/libata.h"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"5.16","status":"affected"},{"version":"0","lessThan":"5.16","versionType":"semver","status":"unaffected"},{"version":"6.6.148","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.101","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.42","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc2","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/4c1e8ccd8655ee8cf1bcb1b7dfee72c9fa941fd4","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/4cb4b4dd8853c4ab3057efe238b2c34277772176","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/533a0b940f901c15e5cbbd4b5d66e871c209e8ce","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/b1607f0ee5f5e53e0aa66f41794085b7cc98f5d1","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/d43efd1b5d976203e6f1ef26f67e8b1a7bc2751b","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-72031","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:21:12.030","lastModified":"2026-08-15T06:21:12.030","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nata: libata-core: Add NOLPM quirk for PNY CS900 1TB SSD\n\nThe PNY CS900 1TB SSD (Phison PS3111-S11, DRAM-less) drops off the bus\nafter entering Device-Initiated Slumber during idle. With the default\nmed_power_with_dipm policy the link goes down (SStatus 1 SControl 300)\nand does not recover, forcing the filesystem read-only. Forcing\nmax_performance keeps the link stable across prolonged idle.\n\nAdd a NOLPM quirk so link power management is disabled for this drive\nspecifically, leaving it intact for other devices on the host."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/ata/libata-core.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"299739909c486bcea7445f5c3b066fdbc0d2df96","versionType":"git","status":"affected"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"462775c620197adaabc983ce847e5b9878ff4cb0","versionType":"git","status":"affected"},{"version":"0","lessThan":"7.1.5","versionType":"semver","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/ata/libata-core.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc2","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/299739909c486bcea7445f5c3b066fdbc0d2df96","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/462775c620197adaabc983ce847e5b9878ff4cb0","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-72032","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:21:12.143","lastModified":"2026-08-15T06:21:12.143","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nnet/mlx5: HWS, fix matcher leak on resize target setup failure\n\nhws_bwc_matcher_move() allocates a replacement matcher before setting it\nas the resize target. If mlx5hws_matcher_resize_set_target() fails, the\nreplacement matcher is not attached anywhere and is leaked.\n\nFix the leak by destroying the replacement matcher before returning from\nthe resize-target failure path.\n\nThe bug was first flagged by an experimental analysis tool we are\ndeveloping for kernel memory-management bugs while analyzing\nv6.13-rc1. The tool is still under development and is not yet publicly\navailable. Manual inspection confirms that the bug is still\npresent in v7.1.1.\n\nAn x86_64 allyesconfig build showed no new warnings. As we do not have a\nmlx5 HWS-capable device to test with, no runtime testing was able to be\nperformed."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/net/ethernet/mellanox/mlx5/core/steering/hws/bwc.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"2111bb970c787b16b002dc726c1d296ce87a00fb","lessThan":"a751ccdc6ea9bde154f25a5ba66926f462f96c19","versionType":"git","status":"affected"},{"version":"2111bb970c787b16b002dc726c1d296ce87a00fb","lessThan":"1dce4f4bb3c1c02080b1a45bdd2abb2913a6642a","versionType":"git","status":"affected"},{"version":"2111bb970c787b16b002dc726c1d296ce87a00fb","lessThan":"ae0265f0a95aaacef59d560a3e1ea36db8be9a52","versionType":"git","status":"affected"},{"version":"2111bb970c787b16b002dc726c1d296ce87a00fb","lessThan":"bb09d0e64ecaa0aa0f7d1133a1696ed74dead295","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/net/ethernet/mellanox/mlx5/core/steering/hws/bwc.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.12","status":"affected"},{"version":"0","lessThan":"6.12","versionType":"semver","status":"unaffected"},{"version":"6.12.101","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc2","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/1dce4f4bb3c1c02080b1a45bdd2abb2913a6642a","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/a751ccdc6ea9bde154f25a5ba66926f462f96c19","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/ae0265f0a95aaacef59d560a3e1ea36db8be9a52","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/bb09d0e64ecaa0aa0f7d1133a1696ed74dead295","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-72033","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:21:12.247","lastModified":"2026-08-15T06:21:12.247","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\norangefs: keep the readdir entry size 64-bit in fill_from_part()\n\nfill_from_part() computes the size of a directory entry in size_t but\nstores it in a __u32. An entry length near U32_MAX wraps it to a small\nvalue, bypasses the bounds check, and is then used to index the entry,\nreading far past the directory part -- an out-of-bounds read that oopses\nthe kernel.\n\nCompute the size as a u64 so it cannot truncate; the bounds check then\nrejects the entry. The trailer is supplied by the userspace client."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["fs/orangefs/dir.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"480e3e532e31666a18520a7964bb4095d7a16b9a","lessThan":"1679780f482feeb82acb5995587d4fb1d1fe82fd","versionType":"git","status":"affected"},{"version":"480e3e532e31666a18520a7964bb4095d7a16b9a","lessThan":"a72bbb43689591c9d36e3bb45c2d4e688cf92682","versionType":"git","status":"affected"},{"version":"480e3e532e31666a18520a7964bb4095d7a16b9a","lessThan":"36723b28e3293047f087f4501f1ef4ead418dd84","versionType":"git","status":"affected"},{"version":"480e3e532e31666a18520a7964bb4095d7a16b9a","lessThan":"07c05601a9a8e5d4481b2a4a16dc0e3c5bc63ad9","versionType":"git","status":"affected"},{"version":"480e3e532e31666a18520a7964bb4095d7a16b9a","lessThan":"fdf06a1b66ff39664b01c6bb6a2aa98d81e8ebe1","versionType":"git","status":"affected"},{"version":"480e3e532e31666a18520a7964bb4095d7a16b9a","lessThan":"82fc886e244c76fadf05ef1958aaf8815478ccde","versionType":"git","status":"affected"},{"version":"480e3e532e31666a18520a7964bb4095d7a16b9a","lessThan":"e3d325c0bdb7bc5d1b4cc8d8441d79794cd03729","versionType":"git","status":"affected"},{"version":"480e3e532e31666a18520a7964bb4095d7a16b9a","lessThan":"18227a6bc98bd0ba96ed3ce9d5b28776a5a28dfc","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["fs/orangefs/dir.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"4.12","status":"affected"},{"version":"0","lessThan":"4.12","versionType":"semver","status":"unaffected"},{"version":"5.10.261","lessThanOrEqual":"5.10.*","versionType":"semver","status":"unaffected"},{"version":"5.15.212","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.178","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.97","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc2","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/07c05601a9a8e5d4481b2a4a16dc0e3c5bc63ad9","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/1679780f482feeb82acb5995587d4fb1d1fe82fd","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/18227a6bc98bd0ba96ed3ce9d5b28776a5a28dfc","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/36723b28e3293047f087f4501f1ef4ead418dd84","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/82fc886e244c76fadf05ef1958aaf8815478ccde","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/a72bbb43689591c9d36e3bb45c2d4e688cf92682","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/e3d325c0bdb7bc5d1b4cc8d8441d79794cd03729","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/fdf06a1b66ff39664b01c6bb6a2aa98d81e8ebe1","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-72034","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:21:12.383","lastModified":"2026-08-15T06:21:12.383","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nfhandle: reject detached mounts in capable_wrt_mount()\n\nThe recent fhandle RCU fix moved the mount namespace capability check\ninto capable_wrt_mount(), so a non-NULL mnt_namespace survives the\nns_capable() dereference. The helper still assumes the later\nREAD_ONCE(mount->mnt_ns) must be non-NULL because may_decode_fh()\nchecked is_mounted() first.\n\nThat assumption is not stable. A detached mount from\nopen_tree(..., OPEN_TREE_CLONE) can be dissolved on fput while\nopen_by_handle_at() is between those checks, and umount_tree() can\nclear mount->mnt_ns. If the helper observes NULL, it dereferences\nmnt_ns->user_ns and panics.\n\nReturn false when the RCU read observes a detached mount. This keeps\nthe relaxed permission path conservative: a mount no longer attached\nto a namespace cannot authorize open_by_handle_at() access."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["fs/fhandle.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"620c266f394932e5decc4b34683a75dfc59dc2f4","lessThan":"15104234c267ebe04b9f9a73e5c2179cc265ff60","versionType":"git","status":"affected"},{"version":"620c266f394932e5decc4b34683a75dfc59dc2f4","lessThan":"6c52226072a3c61337b1eec1799bb987748884fa","versionType":"git","status":"affected"},{"version":"620c266f394932e5decc4b34683a75dfc59dc2f4","lessThan":"6ee183d89261bf1d1cf9f06d80a40dab8f36ee55","versionType":"git","status":"affected"},{"version":"620c266f394932e5decc4b34683a75dfc59dc2f4","lessThan":"6c732471740bc2ac9b0946134f9f551dc75f4369","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["fs/fhandle.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.11","status":"affected"},{"version":"0","lessThan":"6.11","versionType":"semver","status":"unaffected"},{"version":"6.12.97","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc2","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/15104234c267ebe04b9f9a73e5c2179cc265ff60","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/6c52226072a3c61337b1eec1799bb987748884fa","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/6c732471740bc2ac9b0946134f9f551dc75f4369","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/6ee183d89261bf1d1cf9f06d80a40dab8f36ee55","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-72035","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:21:12.497","lastModified":"2026-08-15T06:21:12.497","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nnet/sched: sch_taprio: Replace direct dequeue call with peek and qdisc_dequeue_peeked\n\nWhen taprio's software path peeks a non-work-conserving child qdisc, the\nchild stashes the peeked skb in its gso_skb; taprio_dequeue_from_txq()\nthen takes the packet with a direct child ->dequeue() call, which ignores\nthat stash, orphans the peeked skb and desyncs the child's qlen/backlog.\nWith a qfq child this re-enters the child on an emptied list and\ndereferences NULL, panicking the kernel from softirq on ordinary egress.\n\nTake the packet through qdisc_dequeue_peeked(), as sch_red and sch_sfb\nnow do. The helper returns the child's stashed skb first and is a no-op\nwhen there is none, so a work-conserving child is unaffected and the\ngated path now consumes the skb whose length was charged to the budget."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["net/sched/sch_taprio.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"5a781ccbd19e4664babcbe4b4ead7aa2b9283d22","lessThan":"6ee5a7665a9080bcb05d703bf981a579436fd05e","versionType":"git","status":"affected"},{"version":"5a781ccbd19e4664babcbe4b4ead7aa2b9283d22","lessThan":"18d580cb00c55805633bae45e90cf22ed6b8e424","versionType":"git","status":"affected"},{"version":"5a781ccbd19e4664babcbe4b4ead7aa2b9283d22","lessThan":"e2b7ee61989f2d39df6c2cc06f9db1aea69bdb09","versionType":"git","status":"affected"},{"version":"5a781ccbd19e4664babcbe4b4ead7aa2b9283d22","lessThan":"2dcebbd1ad2e180fe7b98bf346ced69a872e11e6","versionType":"git","status":"affected"},{"version":"5a781ccbd19e4664babcbe4b4ead7aa2b9283d22","lessThan":"e056e1dfcddca877dd46d704e8ec9860cfc9ec44","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["net/sched/sch_taprio.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"4.20","status":"affected"},{"version":"0","lessThan":"4.20","versionType":"semver","status":"unaffected"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.97","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc2","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/18d580cb00c55805633bae45e90cf22ed6b8e424","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/2dcebbd1ad2e180fe7b98bf346ced69a872e11e6","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/6ee5a7665a9080bcb05d703bf981a579436fd05e","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/e056e1dfcddca877dd46d704e8ec9860cfc9ec44","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/e2b7ee61989f2d39df6c2cc06f9db1aea69bdb09","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-72036","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:21:12.613","lastModified":"2026-08-15T06:21:12.613","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nnet/sched: sch_multiq: Replace direct dequeue call with peek and qdisc_dequeue_peeked\n\nmultiq_dequeue() takes a packet from a band's child with a direct\n->dequeue() call after multiq_peek() peeked it. When the child is\nnon-work-conserving the peek stashes the skb in the child's gso_skb, so\nthe direct dequeue returns a different skb and orphans the stash,\ndesyncing the child's qlen/backlog. With a qfq child reached through a\npeeking parent (e.g. tbf) this re-enters the child on an emptied list and\ndereferences NULL, panicking the kernel from softirq on ordinary egress.\n\nTake the packet through qdisc_dequeue_peeked(), as sch_prio already does\nand as sch_red and sch_sfb were just fixed to do. The helper is a no-op\nwhen the child has no stash, so a work-conserving child is unaffected."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["net/sched/sch_multiq.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"77be155cba4e163e8bba9fd27222a8b6189ec4f7","lessThan":"3e5fd9d14f2d228e7260251f2e4a1d41ba8f705a","versionType":"git","status":"affected"},{"version":"77be155cba4e163e8bba9fd27222a8b6189ec4f7","lessThan":"eb1a9637f0bd84b5db8803af65dfb1f44785406f","versionType":"git","status":"affected"},{"version":"77be155cba4e163e8bba9fd27222a8b6189ec4f7","lessThan":"7a5a1582710981ef6637de9f074a60a5b1d63222","versionType":"git","status":"affected"},{"version":"77be155cba4e163e8bba9fd27222a8b6189ec4f7","lessThan":"86a61e46a1919e8abf4d227c204773dabb24068a","versionType":"git","status":"affected"},{"version":"77be155cba4e163e8bba9fd27222a8b6189ec4f7","lessThan":"1b9cc255e8089606b92b2adf504e334573682821","versionType":"git","status":"affected"},{"version":"77be155cba4e163e8bba9fd27222a8b6189ec4f7","lessThan":"5889064919a1e5c0a9469c54895000414fc46944","versionType":"git","status":"affected"},{"version":"77be155cba4e163e8bba9fd27222a8b6189ec4f7","lessThan":"fffeb2ab5eeb823d4c2330571a098f63237c9049","versionType":"git","status":"affected"},{"version":"77be155cba4e163e8bba9fd27222a8b6189ec4f7","lessThan":"54f6b0c843e228d499eb4b6bbb89df68cad9ad5d","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["net/sched/sch_multiq.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"2.6.29","status":"affected"},{"version":"0","lessThan":"2.6.29","versionType":"semver","status":"unaffected"},{"version":"5.10.261","lessThanOrEqual":"5.10.*","versionType":"semver","status":"unaffected"},{"version":"5.15.212","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.178","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.97","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc2","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/1b9cc255e8089606b92b2adf504e334573682821","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/3e5fd9d14f2d228e7260251f2e4a1d41ba8f705a","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/54f6b0c843e228d499eb4b6bbb89df68cad9ad5d","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/5889064919a1e5c0a9469c54895000414fc46944","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/7a5a1582710981ef6637de9f074a60a5b1d63222","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/86a61e46a1919e8abf4d227c204773dabb24068a","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/eb1a9637f0bd84b5db8803af65dfb1f44785406f","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/fffeb2ab5eeb823d4c2330571a098f63237c9049","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-72037","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:21:12.740","lastModified":"2026-08-15T06:21:12.740","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nnet: lan743x: Initialize eth_syslock spinlock before use\n\nlan743x_hardware_init() calls pci11x1x_strap_get_status() during the\nPCI11x1x probe sequence. That helper acquires the Ethernet subsystem\nhardware lock via lan743x_hs_syslock_acquire(), which relies on\nadapter->eth_syslock_spinlock to serialize access.\n\nThe spinlock is currently initialized only after the strap status is\nread. With CONFIG_DEBUG_SPINLOCK enabled, taking the zeroed initialized\nspinlock can trip the spinlock debug check.\n\nFix by initializing adapter->eth_syslock_spinlock before reading the\nstrap status so the probe path never attempts to lock an uninitialized\nspinlock."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/net/ethernet/microchip/lan743x_main.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"46b777ad9a8c269113634cee6a380bc4e53f3964","lessThan":"dfaefd9a7808736fcd2ed0de108f55c4badc15cc","versionType":"git","status":"affected"},{"version":"46b777ad9a8c269113634cee6a380bc4e53f3964","lessThan":"6523daa6852b1bfef32ec7a105b0217e8a115687","versionType":"git","status":"affected"},{"version":"46b777ad9a8c269113634cee6a380bc4e53f3964","lessThan":"b6a93a42e0e61f0ba0005a942ee3bffb16c0574e","versionType":"git","status":"affected"},{"version":"46b777ad9a8c269113634cee6a380bc4e53f3964","lessThan":"99a6f37b113c46815deb160c5012073563679ef4","versionType":"git","status":"affected"},{"version":"46b777ad9a8c269113634cee6a380bc4e53f3964","lessThan":"b99e890e6b32ffa11c145a16fefcf2c7137a9578","versionType":"git","status":"affected"},{"version":"46b777ad9a8c269113634cee6a380bc4e53f3964","lessThan":"39139b1c1c2b614096519b526112c726adb12ff0","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/net/ethernet/microchip/lan743x_main.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.0","status":"affected"},{"version":"0","lessThan":"6.0","versionType":"semver","status":"unaffected"},{"version":"6.1.178","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.97","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc2","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/39139b1c1c2b614096519b526112c726adb12ff0","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/6523daa6852b1bfef32ec7a105b0217e8a115687","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/99a6f37b113c46815deb160c5012073563679ef4","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/b6a93a42e0e61f0ba0005a942ee3bffb16c0574e","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/b99e890e6b32ffa11c145a16fefcf2c7137a9578","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/dfaefd9a7808736fcd2ed0de108f55c4badc15cc","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-72038","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:21:12.860","lastModified":"2026-08-15T06:21:12.860","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nnet: liquidio: fix BAR resource leak on PF number failure\n\nIf cn23xx_get_pf_num() fails, the function returns without\nunmapping either BAR. Unmap both BARs before returning from\nthe error path.\n\nFound by manual code review."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/net/ethernet/cavium/liquidio/cn23xx_pf_device.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"0c45d7fe12c7e1510bae9dfac189c8b927e4636b","lessThan":"75b924759de9427761115301308c137904aa3f99","versionType":"git","status":"affected"},{"version":"0c45d7fe12c7e1510bae9dfac189c8b927e4636b","lessThan":"4a45884566bab4122bbeb8fff7d2d6b5fdbded24","versionType":"git","status":"affected"},{"version":"0c45d7fe12c7e1510bae9dfac189c8b927e4636b","lessThan":"020e52aee732bb08e6b89dd02bbf88895a50fffd","versionType":"git","status":"affected"},{"version":"0c45d7fe12c7e1510bae9dfac189c8b927e4636b","lessThan":"b74f293e5f38052cfa14710abfacd6b6561cc2d6","versionType":"git","status":"affected"},{"version":"0c45d7fe12c7e1510bae9dfac189c8b927e4636b","lessThan":"a22103618ee5b6ee884c374351f65fcdff7248f0","versionType":"git","status":"affected"},{"version":"0c45d7fe12c7e1510bae9dfac189c8b927e4636b","lessThan":"715cce38424fb2488ef2c5e6e6ffbfe1b74a9e67","versionType":"git","status":"affected"},{"version":"0c45d7fe12c7e1510bae9dfac189c8b927e4636b","lessThan":"4140c516473a0e116ab3a73f9320c2aa5800210b","versionType":"git","status":"affected"},{"version":"0c45d7fe12c7e1510bae9dfac189c8b927e4636b","lessThan":"c63ee62a3c4ac1a1542f4c1a4b87e2f41df5a496","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/net/ethernet/cavium/liquidio/cn23xx_pf_device.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"4.14","status":"affected"},{"version":"0","lessThan":"4.14","versionType":"semver","status":"unaffected"},{"version":"5.10.261","lessThanOrEqual":"5.10.*","versionType":"semver","status":"unaffected"},{"version":"5.15.212","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.178","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.97","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc2","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/020e52aee732bb08e6b89dd02bbf88895a50fffd","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/4140c516473a0e116ab3a73f9320c2aa5800210b","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/4a45884566bab4122bbeb8fff7d2d6b5fdbded24","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/715cce38424fb2488ef2c5e6e6ffbfe1b74a9e67","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/75b924759de9427761115301308c137904aa3f99","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/a22103618ee5b6ee884c374351f65fcdff7248f0","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/b74f293e5f38052cfa14710abfacd6b6561cc2d6","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/c63ee62a3c4ac1a1542f4c1a4b87e2f41df5a496","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-72039","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:21:12.987","lastModified":"2026-08-15T06:21:12.987","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nbnx2x: fix potential memory leak in bnx2x_alloc_mem_bp()\n\nIf the allocation of fp[i].tpa_info fails, the error path will not free\nthe struct bnx2x_fastpath allocated earlier, as it is not linked to the\nbp structure yet. Fix that by linking it immediately after allocation."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/net/ethernet/broadcom/bnx2x/bnx2x_cmn.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"15192a8cf8a8d16e0ff38a144c8a4630c94f9fd6","lessThan":"58594ed2a2f859ffb93edbbfa4aabb7739bea383","versionType":"git","status":"affected"},{"version":"15192a8cf8a8d16e0ff38a144c8a4630c94f9fd6","lessThan":"c51b280b9cd3c9e97bf2cde33bb795c511f09669","versionType":"git","status":"affected"},{"version":"15192a8cf8a8d16e0ff38a144c8a4630c94f9fd6","lessThan":"6d46eaa1e4c078ad674908e24b86e431a7fd4b15","versionType":"git","status":"affected"},{"version":"15192a8cf8a8d16e0ff38a144c8a4630c94f9fd6","lessThan":"5576ee19a6a4aa111c61ce974e70bb79e7bb3952","versionType":"git","status":"affected"},{"version":"15192a8cf8a8d16e0ff38a144c8a4630c94f9fd6","lessThan":"7d8d454b5d24dbad346cd57ef315e7bf1ee8e856","versionType":"git","status":"affected"},{"version":"15192a8cf8a8d16e0ff38a144c8a4630c94f9fd6","lessThan":"6c98ccdb9a0967e04a7b1866eb0d97c0c8c0e403","versionType":"git","status":"affected"},{"version":"15192a8cf8a8d16e0ff38a144c8a4630c94f9fd6","lessThan":"356077547b1afa34a8ebae77176a577631a89041","versionType":"git","status":"affected"},{"version":"15192a8cf8a8d16e0ff38a144c8a4630c94f9fd6","lessThan":"a986fde914d88af47eb78fd29c5d1af7952c3500","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/net/ethernet/broadcom/bnx2x/bnx2x_cmn.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"3.6","status":"affected"},{"version":"0","lessThan":"3.6","versionType":"semver","status":"unaffected"},{"version":"5.10.261","lessThanOrEqual":"5.10.*","versionType":"semver","status":"unaffected"},{"version":"5.15.212","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.178","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.97","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/356077547b1afa34a8ebae77176a577631a89041","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/5576ee19a6a4aa111c61ce974e70bb79e7bb3952","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/58594ed2a2f859ffb93edbbfa4aabb7739bea383","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/6c98ccdb9a0967e04a7b1866eb0d97c0c8c0e403","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/6d46eaa1e4c078ad674908e24b86e431a7fd4b15","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/7d8d454b5d24dbad346cd57ef315e7bf1ee8e856","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/a986fde914d88af47eb78fd29c5d1af7952c3500","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/c51b280b9cd3c9e97bf2cde33bb795c511f09669","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-72040","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:21:13.123","lastModified":"2026-08-15T06:21:13.123","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nipmi: fix refcount leak in i_ipmi_request()\n\nWhen a caller provides a `supplied_recv` message to i_ipmi_request(),\nthe function increments the user's `nr_msgs` reference count. If an\nerror occurs later, the out_err cleanup path only frees the recv_msg\nif the function allocated it itself (i.e., !supplied_recv). In the\nsupplied_recv case the cleanup is skipped, leaving the reference count\nelevated. The caller ipmi_request_supply_msgs() does not release the\nsupplied_recv on error, so the reference is permanently leaked.\n\nFix this by explicitly reverting the reference count operations when a\nsupplied recv_msg with a valid user pointer is present in the error\npath: decrement nr_msgs and drop the user's kref."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/char/ipmi/ipmi_msghandler.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"348121b29594d42d1635648fd3ed31dfa25351d5","lessThan":"9409e18ffe7378d202efe1cf69989df9f67b0369","versionType":"git","status":"affected"},{"version":"53d6e403affbf6df2c859a0ea00ccfc1e72090ca","lessThan":"e2a3b77df6aef031455dd83ea8ed4344b7dca1f9","versionType":"git","status":"affected"},{"version":"b52da4054ee0bf9ecb44996f2c83236ff50b3812","lessThan":"f5c5065963024390ddad51bd455d1adc710de575","versionType":"git","status":"affected"},{"version":"b52da4054ee0bf9ecb44996f2c83236ff50b3812","lessThan":"0fd23994ec8c5436d9f0b50848deb87ed933e6b3","versionType":"git","status":"affected"},{"version":"b52da4054ee0bf9ecb44996f2c83236ff50b3812","lessThan":"a3f3859cecacb64f18fd446271ece9a3b3f2d4de","versionType":"git","status":"affected"},{"version":"f63723ca7d7623f9dae1990973cd158671f03c56","versionType":"git","status":"affected"},{"version":"0ed73be9a2547ffb9b5c1d879ad9bfab73d920b5","versionType":"git","status":"affected"},{"version":"6.6.113","lessThan":"6.6.148","versionType":"semver","status":"affected"},{"version":"6.12.54","lessThan":"6.12.101","versionType":"semver","status":"affected"},{"version":"6.1.157","lessThan":"6.2","versionType":"semver","status":"affected"},{"version":"6.17.4","lessThan":"6.18","versionType":"semver","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/char/ipmi/ipmi_msghandler.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.18","status":"affected"},{"version":"0","lessThan":"6.18","versionType":"semver","status":"unaffected"},{"version":"6.6.148","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.101","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/0fd23994ec8c5436d9f0b50848deb87ed933e6b3","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/9409e18ffe7378d202efe1cf69989df9f67b0369","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/a3f3859cecacb64f18fd446271ece9a3b3f2d4de","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/e2a3b77df6aef031455dd83ea8ed4344b7dca1f9","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/f5c5065963024390ddad51bd455d1adc710de575","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-72041","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:21:13.257","lastModified":"2026-08-15T06:21:13.257","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nespintcp: use sk_msg_free_partial to fix partial send\n\nsk_msg_free_partial() ensures consistency of the skmsg at every\niteration, without having to manually handle uncharges and offsets.\nThis simplifies the code, and fixes some bugs in skmsg accounting when\nwe don't send the full contents."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["net/xfrm/espintcp.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"e27cca96cd68fa2c6814c90f9a1cfd36bb68c593","lessThan":"54d73f18f8919735f4d04d6f43374f75756c0180","versionType":"git","status":"affected"},{"version":"e27cca96cd68fa2c6814c90f9a1cfd36bb68c593","lessThan":"14c0b42c8a2cd9b5361bbff45b52f69c62c6a286","versionType":"git","status":"affected"},{"version":"e27cca96cd68fa2c6814c90f9a1cfd36bb68c593","lessThan":"a66d45e0ce6d73cd79962d422388e61bfaf0cb50","versionType":"git","status":"affected"},{"version":"e27cca96cd68fa2c6814c90f9a1cfd36bb68c593","lessThan":"a338ce41bc933d8f74c39d9b3b6f1d8ca53d9714","versionType":"git","status":"affected"},{"version":"e27cca96cd68fa2c6814c90f9a1cfd36bb68c593","lessThan":"007800408002d871f5699bdb944f985896730b8f","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["net/xfrm/espintcp.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"5.6","status":"affected"},{"version":"0","lessThan":"5.6","versionType":"semver","status":"unaffected"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.97","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/007800408002d871f5699bdb944f985896730b8f","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/14c0b42c8a2cd9b5361bbff45b52f69c62c6a286","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/54d73f18f8919735f4d04d6f43374f75756c0180","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/a338ce41bc933d8f74c39d9b3b6f1d8ca53d9714","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/a66d45e0ce6d73cd79962d422388e61bfaf0cb50","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-72042","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:21:13.370","lastModified":"2026-08-15T06:21:13.370","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nipmi: Fix user refcount underflow in event delivery\n\nipmi_alloc_recv_msg(user) takes the temporary user reference owned by the\nreceive message, and ipmi_free_recv_msg() drops it again. If event delivery\nfails after allocating receive messages for earlier users,\nhandle_read_event_rsp() rolls those messages back with\nipmi_free_recv_msg().\n\nThat rollback path still drops user->refcount explicitly after freeing each\nmessage. The extra put can free a user that remains linked on intf->users,\nso later event delivery may dereference a freed user or trip refcount_t's\naddition-on-zero warning when ipmi_alloc_recv_msg() tries to acquire\nanother reference.\n\nRemove the stale explicit put and the now-dead user assignment. Keep the\nlist_del() and ipmi_free_recv_msg() calls; they are the required rollback\noperations."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/char/ipmi/ipmi_msghandler.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"b52da4054ee0bf9ecb44996f2c83236ff50b3812","lessThan":"ddbb6e3dc9bb4743de686aa1598c31e745cee76b","versionType":"git","status":"affected"},{"version":"b52da4054ee0bf9ecb44996f2c83236ff50b3812","lessThan":"7be349d4fcc5e065295b83418a22d27a68afbdb6","versionType":"git","status":"affected"},{"version":"b52da4054ee0bf9ecb44996f2c83236ff50b3812","lessThan":"6aa9e61c46465d231e9beddf56af7effd71be682","versionType":"git","status":"affected"},{"version":"f63723ca7d7623f9dae1990973cd158671f03c56","versionType":"git","status":"affected"},{"version":"348121b29594d42d1635648fd3ed31dfa25351d5","versionType":"git","status":"affected"},{"version":"53d6e403affbf6df2c859a0ea00ccfc1e72090ca","versionType":"git","status":"affected"},{"version":"0ed73be9a2547ffb9b5c1d879ad9bfab73d920b5","versionType":"git","status":"affected"},{"version":"6.1.157","lessThan":"6.2","versionType":"semver","status":"affected"},{"version":"6.6.113","lessThan":"6.7","versionType":"semver","status":"affected"},{"version":"6.12.54","lessThan":"6.13","versionType":"semver","status":"affected"},{"version":"6.17.4","lessThan":"6.18","versionType":"semver","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/char/ipmi/ipmi_msghandler.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.18","status":"affected"},{"version":"0","lessThan":"6.18","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/6aa9e61c46465d231e9beddf56af7effd71be682","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/7be349d4fcc5e065295b83418a22d27a68afbdb6","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/ddbb6e3dc9bb4743de686aa1598c31e745cee76b","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-72043","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:21:13.480","lastModified":"2026-08-15T06:21:13.480","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nLoongArch: Fix missing dirty page tracking in {pte,pmd}_wrprotect()\n\nWhen hardware page table walker (PTW) is enabled on LoongArch, the CPU\nmay set _PAGE_DIRTY directly in the page table entry during a write TLB\nmiss, without going through the software TLB store handler. The software\nTLB store handler (tlbex.S:254) sets both _PAGE_DIRTY and_PAGE_MODIFIED\ntogether:\n\n    ori t0, t0, (_PAGE_VALID | _PAGE_DIRTY | _PAGE_MODIFIED)\n\nSince hardware PTW only sets _PAGE_DIRTY, the software-only bit, i.e.\n_PAGE_MODIFIED is left unchanged. This creates a window where a PTE has\n_PAGE_DIRTY set (hardware knows the page is dirty) but _PAGE_MODIFIED\nclear (software is unaware).\n\nWhen fork()/clone() triggers copy-on-write, __copy_present_ptes() calls\npte_wrprotect(), which unconditionally clears both the _PAGE_WRITE and\n_PAGE_DIRTY bits:\n\n    pte_val(pte) &= ~(_PAGE_WRITE | _PAGE_DIRTY);\n\nSince _PAGE_MODIFIED was never set, the dirtiness information is lost\ncompletely. Subsequently, when memory pressure triggers page reclaim,\npage_mkclean() / try_to_unmap() sees the page as clean (i.e. pte_dirty()\nreturns false) and the page may be freed without writeback, causing data\ncorruption.\n\nFix this by propagating the _PAGE_DIRTY bit to the _PAGE_MODIFIED bit in\nboth pte_wrprotect() and pmd_wrprotect() before clearing writeable bits:\n\n    if (pte_val(pte) & _PAGE_DIRTY)\n        pte_val(pte) |= _PAGE_MODIFIED;\n\nThe pmd_wrprotect() fix handles the CONFIG_TRANSPARENT_HUGEPAGE case,\nwhere pmd entries need the same treatment.\n\nThis ensures the software dirty tracking bit (checked by pte_dirty() and\npmd_dirty(), which read both the _PAGE_DIRTY and _PAGE_MODIFIED bits) is\npreserved across fork COW write-protection.\n\nThe issue was found by the LTP madvise09 test case, which exercises page\nreclaim after \"madvise(MADV_FREE), write and fork\" operation sequence on\nprivate anonymous mappings."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["arch/loongarch/include/asm/pgtable.h"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"09cfefb7fa70c3af011b0db0a513fd80b2f18abc","lessThan":"76f88650763a35cbf1384c65d66d096fa31cc58d","versionType":"git","status":"affected"},{"version":"09cfefb7fa70c3af011b0db0a513fd80b2f18abc","lessThan":"e8a916579e427af32f2de8213dfa23c5df6e6664","versionType":"git","status":"affected"},{"version":"09cfefb7fa70c3af011b0db0a513fd80b2f18abc","lessThan":"39bb21a4bff0d70058bf752d7b5aa2e2ccc864a9","versionType":"git","status":"affected"},{"version":"09cfefb7fa70c3af011b0db0a513fd80b2f18abc","lessThan":"a65f49b6f7ece756394f8f0e85570020e7fd0e35","versionType":"git","status":"affected"},{"version":"09cfefb7fa70c3af011b0db0a513fd80b2f18abc","lessThan":"e483da960892c41fa7f0cf0d2fc2410d65a483d6","versionType":"git","status":"affected"},{"version":"09cfefb7fa70c3af011b0db0a513fd80b2f18abc","lessThan":"018e9828eb523c638fa3d9bdf0fd4956b74555b2","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["arch/loongarch/include/asm/pgtable.h"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"5.19","status":"affected"},{"version":"0","lessThan":"5.19","versionType":"semver","status":"unaffected"},{"version":"6.1.178","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.97","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/018e9828eb523c638fa3d9bdf0fd4956b74555b2","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/39bb21a4bff0d70058bf752d7b5aa2e2ccc864a9","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/76f88650763a35cbf1384c65d66d096fa31cc58d","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/a65f49b6f7ece756394f8f0e85570020e7fd0e35","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/e483da960892c41fa7f0cf0d2fc2410d65a483d6","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/e8a916579e427af32f2de8213dfa23c5df6e6664","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-72044","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:21:13.600","lastModified":"2026-08-15T06:21:13.600","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nksmbd: fix stack buffer overflow in multichannel session-key copy\n\nCommit 4b706360ffb7 (\"ksmbd: fix multichannel binding and enforce channel\nlimit\") moved the binding-path session key out of the session-wide\nsess->sess_key (CIFS_KEY_SIZE = 40) into a new per-channel buffer, and\nsized both that buffer and the on-stack copy used during binding with\nSMB2_NTLMV2_SESSKEY_SIZE (16):\n\n\tstruct channel {\n\t\tchar\tsess_key[SMB2_NTLMV2_SESSKEY_SIZE];\t/* 16 */\n\t\t...\n\t};\n\n\tntlm_authenticate() / krb5_authenticate():\n\t\tchar channel_key[SMB2_NTLMV2_SESSKEY_SIZE] = {};\t/* 16 */\n\t\tchar *auth_key = conn->binding ? channel_key : sess->sess_key;\n\nThe two writers that fill this destination still bound the copy length\nagainst CIFS_KEY_SIZE (40), not against the 16-byte buffer:\n\n\tksmbd_decode_ntlmssp_auth_blob() (NTLM key exchange):\n\t\tif (sess_key_len > CIFS_KEY_SIZE)\t/* 40 */\n\t\t\treturn -EINVAL;\n\t\tarc4_crypt(ctx_arc4, sess_key,\n\t\t\t   (char *)authblob + sess_key_off, sess_key_len);\n\n\tksmbd_krb5_authenticate():\n\t\tif (resp->session_key_len > sizeof(sess->sess_key))\t/* 40 */\n\t\t\t...\n\t\tmemcpy(sess_key, resp->payload, resp->session_key_len);\n\nOn a binding SESSION_SETUP, auth_key points at the 16-byte channel_key,\nso a client that supplies an NTLM EncryptedRandomSessionKey of up to 40\nbytes (with NTLMSSP_NEGOTIATE_KEY_EXCH), or a Kerberos ticket whose\nsession key is longer than 16 bytes (a normal AES256 key is 32), writes\npast the 16-byte stack buffer -- up to a 24-byte kernel stack overflow.\nKASAN reports it as a stack-out-of-bounds write in arc4_crypt() called\nfrom ksmbd_decode_ntlmssp_auth_blob().\n\nThe destinations must be able to hold the full session key the length\nchecks already permit. Size the per-channel key buffer and the two\non-stack channel_key buffers with CIFS_KEY_SIZE, matching sess->sess_key."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["fs/smb/server/mgmt/user_session.h","fs/smb/server/smb2pdu.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"a1f2ada2e4d33d316939dedefbfd2e7d94a0c61f","lessThan":"9a7f7b55d7d0fbc4662c981ee6c56e081fa66d58","versionType":"git","status":"affected"},{"version":"4b706360ffb7e459cb3d3edae30b06a584f6eddd","lessThan":"610346149d047a52a92c9a0eb329dd565b8f92c5","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["fs/smb/server/mgmt/user_session.h","fs/smb/server/smb2pdu.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"7.2-rc3","status":"affected"},{"version":"0","lessThan":"7.2-rc3","versionType":"semver","status":"unaffected"},{"version":"7.2-rc4","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/610346149d047a52a92c9a0eb329dd565b8f92c5","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/9a7f7b55d7d0fbc4662c981ee6c56e081fa66d58","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-72045","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:21:13.700","lastModified":"2026-08-15T06:21:13.700","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nocteontx2-af: cn10k: restrict VF LMTLINE sharing to its own PF\n\nrvu_mbox_handler_lmtst_tbl_setup() uses req->base_pcifunc as a direct\nindex into the LMT map table to read another function's LMTLINE\nphysical base address and copy it into the caller's own LMT map table\nentry. The mailbox dispatcher authenticates req->hdr.pcifunc from the\nIRQ source, but req->base_pcifunc is a separate payload field and is\nnot sanitized.\n\nReject the request with -EPERM when a VF caller's base_pcifunc is not a\nvalid function under its own PF. is_pf_func_valid() bounds the FUNC field\nto the PF's configured VF count, keeping the computed index inside the\ncaller's own slot block."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/net/ethernet/marvell/octeontx2/af/rvu_cn10k.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"893ae97214c385be02f8ec097298cc48c7f0d905","lessThan":"e9c5b03208507dd6d58b0c23a2c60b5c2f4c1b11","versionType":"git","status":"affected"},{"version":"893ae97214c385be02f8ec097298cc48c7f0d905","lessThan":"54535692bec9ef464adc714108eb19e49e38b5a2","versionType":"git","status":"affected"},{"version":"893ae97214c385be02f8ec097298cc48c7f0d905","lessThan":"c73b8795b45f4ad5a95120d2e9b435ea4616e08e","versionType":"git","status":"affected"},{"version":"893ae97214c385be02f8ec097298cc48c7f0d905","lessThan":"59da37fee81a8d76079313348ca13c5bc90dd6ae","versionType":"git","status":"affected"},{"version":"893ae97214c385be02f8ec097298cc48c7f0d905","lessThan":"8cdcf3d2caacdee7ddd363705fb4d93b0c1a0915","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/net/ethernet/marvell/octeontx2/af/rvu_cn10k.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"5.14","status":"affected"},{"version":"0","lessThan":"5.14","versionType":"semver","status":"unaffected"},{"version":"6.6.148","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.101","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.42","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/54535692bec9ef464adc714108eb19e49e38b5a2","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/59da37fee81a8d76079313348ca13c5bc90dd6ae","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/8cdcf3d2caacdee7ddd363705fb4d93b0c1a0915","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/c73b8795b45f4ad5a95120d2e9b435ea4616e08e","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/e9c5b03208507dd6d58b0c23a2c60b5c2f4c1b11","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-72046","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:21:13.810","lastModified":"2026-08-15T06:21:13.810","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\ngve: fix header buffer corruption with header-split and HW-GRO\n\nThe DQO RX datapath programs a per-buffer-queue-descriptor\nheader_buf_addr at post time and reads the split header back at\ncompletion time. Both the post and the read currently index the\nheader buffer by queue position rather than by the buffer's identity:\n\n  - post (gve_rx_post_buffers_dqo): header_buf_addr is computed from\n    bufq->tail\n  - read (gve_rx_dqo): the header is read from desc_idx (the completion\n    queue head index)\n\nThis relies on the buffer-queue index and the completion-queue index\nbeing equal for the start of every packet, i.e. on the device consuming\nposted buffers and returning completions in the exact same order. That\nassumption does not hold once HW-GRO is enabled with multiple\nflows: coalesced segments are accepted and completed in an order that\nmay differ from the order buffers were posted, and segments from\ndifferent flows may interleave.\n\nThat results in two problems:\n\n1. Wrong header slot on read. Because the read offset is derived from\n   the completion index (desc_idx) while the device wrote the header to\n   the address programmed for the buffer's buf_id, the driver can copy\n   a header belonging to a different packet. This shows up as\n   throughput drop (about 30% drop and large numbers of TCP\n   retransmissions) with header-split and HW-GRO both enabled and many\n   streams.\n\n2. Header buffer reused while still owned by the device. The driver\n   advances bufq->head by one per completion and re-posts buffers based\n   on that. Arrival of N RX completions only guarantees that at least N\n   RX buffer descriptors have been read by the device. It does not\n   guarantee that the device has relinquished the ownership of all the\n   buffers corresponding to those N descriptors. With out-of-order\n   completions (e.g. the completion for a packet copied into buffer N\n   arrives before the completion for a packet copied into buffer N-1),\n   the driver can re-post and overwrite a header buffer that the device\n   is still going to write into, corrupting the header of a packet\n   whose completion has not yet been processed.\n\nFix both issues by indexing the header buffer by buf_id on both the post\nand read paths. Reading from buf_id's slot is therefore always correct\nregardless of completion ordering (fixes problem 1).\n\nIndexing by buf_id also ties each header slot to the lifetime of its\nbuffer state. A buffer state is only returned to the free/recycle lists\nwhen its own completion (buf_id) is processed, so its header slot can\nonly be re-posted after the device is done with it. This makes header\nslot reuse safe under out-of-order completions (fixes problem 2).\n\nAllocate (gve_rx_alloc_hdr_bufs) and free (gve_rx_free_hdr_bufs) the\nheader buffers based on num_buf_states to match the buf_id indexing."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/net/ethernet/google/gve/gve_rx_dqo.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"5e37d8254e7f551dda62e7590e819d69c7491845","lessThan":"84d3753d4bf284ef770ead6dee2270aaabb3ef41","versionType":"git","status":"affected"},{"version":"5e37d8254e7f551dda62e7590e819d69c7491845","lessThan":"35267819b25074084130b6a7be18bbaf44d3ae74","versionType":"git","status":"affected"},{"version":"5e37d8254e7f551dda62e7590e819d69c7491845","lessThan":"9f8e7f59b0c2f466be74bd923726b0f5496c27ad","versionType":"git","status":"affected"},{"version":"5e37d8254e7f551dda62e7590e819d69c7491845","lessThan":"d676c9a73bdcd8237425dbb826f2bd1a25c36e40","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/net/ethernet/google/gve/gve_rx_dqo.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.9","status":"affected"},{"version":"0","lessThan":"6.9","versionType":"semver","status":"unaffected"},{"version":"6.12.101","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/35267819b25074084130b6a7be18bbaf44d3ae74","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/84d3753d4bf284ef770ead6dee2270aaabb3ef41","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/9f8e7f59b0c2f466be74bd923726b0f5496c27ad","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/d676c9a73bdcd8237425dbb826f2bd1a25c36e40","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-72047","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:21:13.933","lastModified":"2026-08-15T06:21:13.933","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nieee802154: ca8210: fix pointer truncation in kfifo on 64-bit\n\nca8210_test_int_driver_write() and ca8210_test_int_user_read() exchange\na kmalloc'd buffer pointer through a struct kfifo, but pass a literal\n'4' as the byte count to kfifo_in()/kfifo_out().\n\nThis is correct on 32-bit (pointer = 4 bytes), but on 64-bit only the\nlow 4 bytes of the 8-byte pointer are written into the FIFO. The reader\nthen reads back 4 bytes into an 8-byte local pointer variable, leaving\nthe upper 4 bytes uninitialized stack data. The first dereference of\nthe reconstructed pointer (fifo_buffer[1]) accesses an arbitrary kernel\naddress and generally results in an oops.\n\nUse sizeof(fifo_buffer) so the byte count matches pointer width on every\narchitecture.\n\nThe driver has no architecture restriction in Kconfig, so any 64-bit\nbuild with CONFIG_IEEE802154_CA8210_DEBUGFS=y is exposed. Issue has\nbeen latent since the driver was added in 2017 because it is most\ncommonly deployed on 32-bit MCUs.\n\nFound via a custom Coccinelle semantic patch hunting for short-byte\nkfifo I/O on byte-mode kfifos used to shuttle pointers."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/net/ieee802154/ca8210.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"ded845a781a578dfb0b5b2c138e5a067aa3b1242","lessThan":"2c1664ccfae653979b38788211240b5a1ee317ed","versionType":"git","status":"affected"},{"version":"ded845a781a578dfb0b5b2c138e5a067aa3b1242","lessThan":"093aacb0c56d5c693e3169a0224062e77c3fd0c0","versionType":"git","status":"affected"},{"version":"ded845a781a578dfb0b5b2c138e5a067aa3b1242","lessThan":"87dab14a4f68895d6f4d798e6ee3556cd64e8c72","versionType":"git","status":"affected"},{"version":"ded845a781a578dfb0b5b2c138e5a067aa3b1242","lessThan":"1fe2643d0b24ca3cdd61a31a45c2d3233dc6cbfe","versionType":"git","status":"affected"},{"version":"ded845a781a578dfb0b5b2c138e5a067aa3b1242","lessThan":"65dc342274a01616f5c17105f7360a3b4bfd7a3d","versionType":"git","status":"affected"},{"version":"ded845a781a578dfb0b5b2c138e5a067aa3b1242","lessThan":"2059c28bd725beded01277cdf1f67be33e714323","versionType":"git","status":"affected"},{"version":"ded845a781a578dfb0b5b2c138e5a067aa3b1242","lessThan":"d8ce67fa6a5e6929f5414e933ff9665176c2bce6","versionType":"git","status":"affected"},{"version":"ded845a781a578dfb0b5b2c138e5a067aa3b1242","lessThan":"6d7f7bcf225b2d566176bf6229dbd1252940cb3c","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/net/ieee802154/ca8210.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"4.12","status":"affected"},{"version":"0","lessThan":"4.12","versionType":"semver","status":"unaffected"},{"version":"5.10.261","lessThanOrEqual":"5.10.*","versionType":"semver","status":"unaffected"},{"version":"5.15.212","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.178","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.97","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/093aacb0c56d5c693e3169a0224062e77c3fd0c0","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/1fe2643d0b24ca3cdd61a31a45c2d3233dc6cbfe","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/2059c28bd725beded01277cdf1f67be33e714323","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/2c1664ccfae653979b38788211240b5a1ee317ed","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/65dc342274a01616f5c17105f7360a3b4bfd7a3d","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/6d7f7bcf225b2d566176bf6229dbd1252940cb3c","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/87dab14a4f68895d6f4d798e6ee3556cd64e8c72","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/d8ce67fa6a5e6929f5414e933ff9665176c2bce6","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-72048","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:21:14.050","lastModified":"2026-08-15T06:21:14.050","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nieee802154: ca8210: fix cas_ctl leak on spi_async failure\n\nca8210_spi_transfer() allocates cas_ctl with kzalloc_obj(GFP_ATOMIC)\nand relies entirely on the SPI completion callback\nca8210_spi_transfer_complete() to free it.\n\nThe spi_async() API only invokes the completion callback on successful\nsubmission.  On failure it returns a negative error code without ever\nqueuing the callback, which leaves cas_ctl and its embedded spi_message\nand spi_transfer orphaned.  Every kfree(cas_ctl) in the driver is\ninside the completion callback, so there is no other reclamation path.\n\nca8210_spi_transfer() is called from ca8210_spi_exchange(), the\ninterrupt handler ca8210_interrupt_handler(), and from the retry path\ninside the completion callback itself.  The exchange and interrupt\nhandler paths loop on -EBUSY, so under sustained SPI bus contention\nevery retry iteration leaks a fresh cas_ctl (~600 bytes per\noccurrence).\n\nFix it by freeing cas_ctl on the spi_async() error path.  While here,\ncorrect the misleading error string: the function calls spi_async(),\nnot spi_sync()."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/net/ieee802154/ca8210.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"ded845a781a578dfb0b5b2c138e5a067aa3b1242","lessThan":"460c5cd51e4d7d15b317f178f42cfcb666c0fe91","versionType":"git","status":"affected"},{"version":"ded845a781a578dfb0b5b2c138e5a067aa3b1242","lessThan":"b07aea90dbc6e188c74c100af64b77b9482ffc65","versionType":"git","status":"affected"},{"version":"ded845a781a578dfb0b5b2c138e5a067aa3b1242","lessThan":"fe90605b651573d30be8293ff5be40e3d7023117","versionType":"git","status":"affected"},{"version":"ded845a781a578dfb0b5b2c138e5a067aa3b1242","lessThan":"b9071dc7889bef42590e04fbf3e56cc65e1e5e6e","versionType":"git","status":"affected"},{"version":"ded845a781a578dfb0b5b2c138e5a067aa3b1242","lessThan":"d4a397fe803c2d157f6ebb068b802ef75fbf109e","versionType":"git","status":"affected"},{"version":"ded845a781a578dfb0b5b2c138e5a067aa3b1242","lessThan":"cb5cca1d2a908ddd5e357971de0f2009617b8d6a","versionType":"git","status":"affected"},{"version":"ded845a781a578dfb0b5b2c138e5a067aa3b1242","lessThan":"7e3630fbb6aabb844bbf35746dee0bf3894100c7","versionType":"git","status":"affected"},{"version":"ded845a781a578dfb0b5b2c138e5a067aa3b1242","lessThan":"e09390e439bd7cca30dd10893b1f64802961667a","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/net/ieee802154/ca8210.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"4.12","status":"affected"},{"version":"0","lessThan":"4.12","versionType":"semver","status":"unaffected"},{"version":"5.10.261","lessThanOrEqual":"5.10.*","versionType":"semver","status":"unaffected"},{"version":"5.15.212","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.178","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.97","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/460c5cd51e4d7d15b317f178f42cfcb666c0fe91","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/7e3630fbb6aabb844bbf35746dee0bf3894100c7","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/b07aea90dbc6e188c74c100af64b77b9482ffc65","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/b9071dc7889bef42590e04fbf3e56cc65e1e5e6e","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/cb5cca1d2a908ddd5e357971de0f2009617b8d6a","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/d4a397fe803c2d157f6ebb068b802ef75fbf109e","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/e09390e439bd7cca30dd10893b1f64802961667a","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/fe90605b651573d30be8293ff5be40e3d7023117","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-72049","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:21:14.190","lastModified":"2026-08-15T06:21:14.190","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nieee802154: admin-gate legacy LLSEC dump operations\n\nIn net/ieee802154/netlink.c, the legacy IEEE802154_NL family ops table\nbuilds the LLSEC dump entries (LLSEC_LIST_KEY, LLSEC_LIST_DEV,\nLLSEC_LIST_DEVKEY, LLSEC_LIST_SECLEVEL) with IEEE802154_DUMP() which\nsets no .flags, so generic netlink runs them ungated. The modern\nnl802154 family admin-gates the equivalent reads via\nNL802154_CMD_GET_SEC_KEY and friends with .flags = GENL_ADMIN_PERM.\n\nAny local uid that can open AF_NETLINK / NETLINK_GENERIC can resolve\nthe \"802.15.4 MAC\" family and dump LLSEC_LIST_KEY on any wpan netdev\nthat has an LLSEC key installed; the dump handler writes the raw\n16-byte AES-128 key bytes (IEEE802154_ATTR_LLSEC_KEY_BYTES, copied\nverbatim from struct ieee802154_llsec_key.key) into the reply.\nRecovering the AES key compromises 802.15.4 LLSEC link confidentiality\nand authenticity, since LLSEC uses CCM* and the same key authenticates\nand encrypts frames.\n\nImpact: any local uid with no capabilities can read the raw 16-byte\nAES-128 LLSEC key from the kernel keytable on any wpan netdev that has\nan administrator-installed LLSEC key, by issuing an LLSEC_LIST_KEY\ndump on the legacy IEEE802154_NL generic-netlink family.\n\nIntroduce IEEE802154_DUMP_PRIV() mirroring IEEE802154_DUMP() but\nsetting .flags = GENL_ADMIN_PERM, and use it for the four LLSEC dump\nentries. LIST_PHY and LIST_IFACE retain IEEE802154_DUMP() because the\nmodern nl802154 family exposes their equivalents to unprivileged\nreaders by design (NL802154_CMD_GET_WPAN_PHY and\nNL802154_CMD_GET_INTERFACE carry \"can be retrieved by unprivileged\nusers\" annotations)."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["net/ieee802154/ieee802154.h","net/ieee802154/netlink.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"3e9c156e2c210ab67b12b1b692983a6b97c19d3f","lessThan":"3465035ba18b1ed50f8d201897d14135d20532b0","versionType":"git","status":"affected"},{"version":"3e9c156e2c210ab67b12b1b692983a6b97c19d3f","lessThan":"dffe745760f38fac0b8288e0dc4759b23d9888ff","versionType":"git","status":"affected"},{"version":"3e9c156e2c210ab67b12b1b692983a6b97c19d3f","lessThan":"e84708ef7521f3bffc85a449954042018abbd60e","versionType":"git","status":"affected"},{"version":"3e9c156e2c210ab67b12b1b692983a6b97c19d3f","lessThan":"5abe94a205539d27945cda3ba43fdcfe295cf2c8","versionType":"git","status":"affected"},{"version":"3e9c156e2c210ab67b12b1b692983a6b97c19d3f","lessThan":"09fd25cd8cd80a6b3edef04e53a7324d06ac2180","versionType":"git","status":"affected"},{"version":"3e9c156e2c210ab67b12b1b692983a6b97c19d3f","lessThan":"1905ebabe638c946aced00c4bb664da26cac56d5","versionType":"git","status":"affected"},{"version":"3e9c156e2c210ab67b12b1b692983a6b97c19d3f","lessThan":"6383248058956f2a52d720b1e9f8921099cdae04","versionType":"git","status":"affected"},{"version":"3e9c156e2c210ab67b12b1b692983a6b97c19d3f","lessThan":"9c1e0b6d49471a712511d23fc9d06901561135e8","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["net/ieee802154/ieee802154.h","net/ieee802154/netlink.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"3.16","status":"affected"},{"version":"0","lessThan":"3.16","versionType":"semver","status":"unaffected"},{"version":"5.10.261","lessThanOrEqual":"5.10.*","versionType":"semver","status":"unaffected"},{"version":"5.15.212","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.178","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.97","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/09fd25cd8cd80a6b3edef04e53a7324d06ac2180","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/1905ebabe638c946aced00c4bb664da26cac56d5","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/3465035ba18b1ed50f8d201897d14135d20532b0","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/5abe94a205539d27945cda3ba43fdcfe295cf2c8","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/6383248058956f2a52d720b1e9f8921099cdae04","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/9c1e0b6d49471a712511d23fc9d06901561135e8","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/dffe745760f38fac0b8288e0dc4759b23d9888ff","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/e84708ef7521f3bffc85a449954042018abbd60e","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-72050","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:21:14.323","lastModified":"2026-08-15T06:21:14.323","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nocteontx2-af: Free BPID bitmap on setup failure\n\nnix_setup_bpids() allocates bp->bpids with rvu_alloc_bitmap(), which uses\na plain kcalloc(). If any of the following devm_kcalloc() allocations for\nthe BPID mapping arrays fails, the function returns without freeing the\nbitmap. Free the BPID bitmap before returning from those error paths."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/net/ethernet/marvell/octeontx2/af/rvu_nix.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"d6212d2e41a0cb1ff6b059db79c70752cdafc95e","lessThan":"7a939b683a74bd7d7ce4e3b7f696b491c8d71af4","versionType":"git","status":"affected"},{"version":"d6212d2e41a0cb1ff6b059db79c70752cdafc95e","lessThan":"19c148cb82d11bb7cc7d86038a94e608a297e63c","versionType":"git","status":"affected"},{"version":"d6212d2e41a0cb1ff6b059db79c70752cdafc95e","lessThan":"d0c880c9f4051100517040d065caff60e913b659","versionType":"git","status":"affected"},{"version":"d6212d2e41a0cb1ff6b059db79c70752cdafc95e","lessThan":"36323f54cd323122a1be89ab2c316a6e55a94e30","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/net/ethernet/marvell/octeontx2/af/rvu_nix.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.9","status":"affected"},{"version":"0","lessThan":"6.9","versionType":"semver","status":"unaffected"},{"version":"6.12.97","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/19c148cb82d11bb7cc7d86038a94e608a297e63c","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/36323f54cd323122a1be89ab2c316a6e55a94e30","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/7a939b683a74bd7d7ce4e3b7f696b491c8d71af4","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/d0c880c9f4051100517040d065caff60e913b659","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-72051","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:21:14.423","lastModified":"2026-08-15T06:21:14.423","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nnet: ip6_tunnel: require CAP_NET_ADMIN in the device netns for changelink\n\nip6_tnl_changelink() operates on at most two netns, dev_net(dev) and the\ntunnel link netns t->net. They differ once the device is created in or\nmoved to a netns other than the one the request runs in. The rtnl\nchangelink path checks CAP_NET_ADMIN only against dev_net(dev), so a\ncaller privileged there but not in t->net can rewrite a tunnel that\nlives in t->net.\n\nGate ip6_tnl_changelink() on rtnl_dev_link_net_capable() at its top,\nbefore any attribute is parsed."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["net/ipv6/ip6_tunnel.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"0bd8762824e73a3cce7b7560a97463301764b616","lessThan":"2636d061bc237a2446a146e42dcc6563acfa7432","versionType":"git","status":"affected"},{"version":"0bd8762824e73a3cce7b7560a97463301764b616","lessThan":"7f68f7928484f463a5bc0d50e6fdd8d16f55a5aa","versionType":"git","status":"affected"},{"version":"0bd8762824e73a3cce7b7560a97463301764b616","lessThan":"234cd54fc500f69db43e37de38603da617fbbeea","versionType":"git","status":"affected"},{"version":"0bd8762824e73a3cce7b7560a97463301764b616","lessThan":"d4bcc202a3530c856e1cb183384bc9cc8fddab22","versionType":"git","status":"affected"},{"version":"0bd8762824e73a3cce7b7560a97463301764b616","lessThan":"2496fa0b7d180b3ad356b514e7ff93bb14e6140a","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["net/ipv6/ip6_tunnel.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"3.12","status":"affected"},{"version":"0","lessThan":"3.12","versionType":"semver","status":"unaffected"},{"version":"6.6.148","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.101","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/234cd54fc500f69db43e37de38603da617fbbeea","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/2496fa0b7d180b3ad356b514e7ff93bb14e6140a","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/2636d061bc237a2446a146e42dcc6563acfa7432","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/7f68f7928484f463a5bc0d50e6fdd8d16f55a5aa","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/d4bcc202a3530c856e1cb183384bc9cc8fddab22","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-72052","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:21:14.523","lastModified":"2026-08-15T06:21:14.523","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nnet: ip6_gre: require CAP_NET_ADMIN in the device netns for changelink\n\nip6gre_changelink() and ip6erspan_changelink() operate on at most two\nnetns, dev_net(dev) and the tunnel link netns t->net. They differ once\nthe device is created in or moved to a netns other than the one the\nrequest runs in. The rtnl changelink path checks CAP_NET_ADMIN only\nagainst dev_net(dev), so a caller privileged there but not in t->net can\nrewrite a tunnel that lives in t->net.\n\nGate both ops on rtnl_dev_link_net_capable() at their top, before any\nattribute is parsed."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["net/ipv6/ip6_gre.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"690afc165bb314354667f67157c1a1aea7dc797a","lessThan":"129f8939e5af683cec3a1a5edcb40a64636ad81e","versionType":"git","status":"affected"},{"version":"690afc165bb314354667f67157c1a1aea7dc797a","lessThan":"e3724dedf57761c6de52f4d604ec74f66fd61611","versionType":"git","status":"affected"},{"version":"690afc165bb314354667f67157c1a1aea7dc797a","lessThan":"220162c9fedbe992da70d70f50a10da4f45f914c","versionType":"git","status":"affected"},{"version":"690afc165bb314354667f67157c1a1aea7dc797a","lessThan":"1d4d8ee002083ca4ead5353662bf8362428af57f","versionType":"git","status":"affected"},{"version":"690afc165bb314354667f67157c1a1aea7dc797a","lessThan":"0caa9f348f8b5356900de77b0bb89a697c4aff20","versionType":"git","status":"affected"},{"version":"690afc165bb314354667f67157c1a1aea7dc797a","lessThan":"03d8843b143ebbbfaf48511922abc6e886575a61","versionType":"git","status":"affected"},{"version":"690afc165bb314354667f67157c1a1aea7dc797a","lessThan":"c38c8b0db3c65b597e7ece317b6cb59de3d15e69","versionType":"git","status":"affected"},{"version":"690afc165bb314354667f67157c1a1aea7dc797a","lessThan":"f00a50876d2818bd6dc86fa98b3ef360884c53c8","versionType":"git","status":"affected"},{"version":"d0201d2405dac8d9b16773e97709925e397552d0","versionType":"git","status":"affected"},{"version":"7943bb0f06365cf5e32f3cf8a6b29eeae981fb8a","versionType":"git","status":"affected"},{"version":"4.19.100","lessThan":"4.20","versionType":"semver","status":"affected"},{"version":"5.4.16","lessThan":"5.5","versionType":"semver","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["net/ipv6/ip6_gre.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"5.5","status":"affected"},{"version":"0","lessThan":"5.5","versionType":"semver","status":"unaffected"},{"version":"5.10.261","lessThanOrEqual":"5.10.*","versionType":"semver","status":"unaffected"},{"version":"5.15.212","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.178","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.97","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/03d8843b143ebbbfaf48511922abc6e886575a61","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/0caa9f348f8b5356900de77b0bb89a697c4aff20","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/129f8939e5af683cec3a1a5edcb40a64636ad81e","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/1d4d8ee002083ca4ead5353662bf8362428af57f","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/220162c9fedbe992da70d70f50a10da4f45f914c","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/c38c8b0db3c65b597e7ece317b6cb59de3d15e69","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/e3724dedf57761c6de52f4d604ec74f66fd61611","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/f00a50876d2818bd6dc86fa98b3ef360884c53c8","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-72053","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:21:14.650","lastModified":"2026-08-15T06:21:14.650","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nnet: ipip: require CAP_NET_ADMIN in the device netns for changelink\n\nipip_changelink() operates on at most two netns, dev_net(dev) and the\ntunnel link netns t->net. They differ once the device is created in or\nmoved to a netns other than the one the request runs in. The rtnl\nchangelink path checks CAP_NET_ADMIN only against dev_net(dev), so a\ncaller privileged there but not in t->net can rewrite a tunnel that\nlives in t->net.\n\nGate ipip_changelink() on rtnl_dev_link_net_capable() at its top,\nbefore any attribute is parsed."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["net/ipv4/ipip.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6c742e714d8c282fd8f8b22d3e20b5141738c1ee","lessThan":"91571643e554ae89a91942380d5f5361fb7060a2","versionType":"git","status":"affected"},{"version":"6c742e714d8c282fd8f8b22d3e20b5141738c1ee","lessThan":"983cc4aa7e6f633b34c3ee743771252d7afa9a90","versionType":"git","status":"affected"},{"version":"6c742e714d8c282fd8f8b22d3e20b5141738c1ee","lessThan":"26544021d5c49cc6ae8a968ccb5033e6363854a4","versionType":"git","status":"affected"},{"version":"6c742e714d8c282fd8f8b22d3e20b5141738c1ee","lessThan":"68cadc3698c7de88966d306d12ec9c6217da228a","versionType":"git","status":"affected"},{"version":"6c742e714d8c282fd8f8b22d3e20b5141738c1ee","lessThan":"d49edcc65e0a37cc9b386a94415c5d6670ca8b71","versionType":"git","status":"affected"},{"version":"6c742e714d8c282fd8f8b22d3e20b5141738c1ee","lessThan":"8211a26324667980a463c069469a818e71207e02","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["net/ipv4/ipip.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"3.12","status":"affected"},{"version":"0","lessThan":"3.12","versionType":"semver","status":"unaffected"},{"version":"6.1.178","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.97","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/26544021d5c49cc6ae8a968ccb5033e6363854a4","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/68cadc3698c7de88966d306d12ec9c6217da228a","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/8211a26324667980a463c069469a818e71207e02","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/91571643e554ae89a91942380d5f5361fb7060a2","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/983cc4aa7e6f633b34c3ee743771252d7afa9a90","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/d49edcc65e0a37cc9b386a94415c5d6670ca8b71","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-72054","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:21:14.760","lastModified":"2026-08-15T06:21:14.760","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nnet: ip_vti: require CAP_NET_ADMIN in the device netns for changelink\n\nvti_changelink() operates on at most two netns, dev_net(dev) and the\ntunnel link netns t->net. They differ once the device is created in or\nmoved to a netns other than the one the request runs in. The rtnl\nchangelink path checks CAP_NET_ADMIN only against dev_net(dev), so a\ncaller privileged there but not in t->net can rewrite a tunnel that\nlives in t->net.\n\nGate vti_changelink() on rtnl_dev_link_net_capable() at its top,\nbefore any attribute is parsed."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["net/ipv4/ip_vti.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"895de9a3488abcdd186680f0af3cce7f2d4d4a6e","lessThan":"1caf737e625143c6f23c32d2b747b1a3e42e5699","versionType":"git","status":"affected"},{"version":"895de9a3488abcdd186680f0af3cce7f2d4d4a6e","lessThan":"32edf8aa297745226854eda2d96c0fac66c1bb15","versionType":"git","status":"affected"},{"version":"895de9a3488abcdd186680f0af3cce7f2d4d4a6e","lessThan":"973ead9e565423642e4533e1547b5d2c0476fb03","versionType":"git","status":"affected"},{"version":"895de9a3488abcdd186680f0af3cce7f2d4d4a6e","lessThan":"33fd93961557ec8e3e9958995b28684c5f949394","versionType":"git","status":"affected"},{"version":"895de9a3488abcdd186680f0af3cce7f2d4d4a6e","lessThan":"6d8bc0dc99472d62c57c2a3d436e6ab408592bda","versionType":"git","status":"affected"},{"version":"895de9a3488abcdd186680f0af3cce7f2d4d4a6e","lessThan":"9571af2eec8023af9a1671b7f2cd4ab400011724","versionType":"git","status":"affected"},{"version":"895de9a3488abcdd186680f0af3cce7f2d4d4a6e","lessThan":"88b33ee458a6ca5fbef6c53b9dba772da69dab68","versionType":"git","status":"affected"},{"version":"895de9a3488abcdd186680f0af3cce7f2d4d4a6e","lessThan":"95cceadbfd52d7239bd730afdda0655287d77425","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["net/ipv4/ip_vti.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"3.15","status":"affected"},{"version":"0","lessThan":"3.15","versionType":"semver","status":"unaffected"},{"version":"5.10.261","lessThanOrEqual":"5.10.*","versionType":"semver","status":"unaffected"},{"version":"5.15.212","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.178","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.97","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/1caf737e625143c6f23c32d2b747b1a3e42e5699","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/32edf8aa297745226854eda2d96c0fac66c1bb15","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/33fd93961557ec8e3e9958995b28684c5f949394","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/6d8bc0dc99472d62c57c2a3d436e6ab408592bda","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/88b33ee458a6ca5fbef6c53b9dba772da69dab68","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/9571af2eec8023af9a1671b7f2cd4ab400011724","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/95cceadbfd52d7239bd730afdda0655287d77425","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/973ead9e565423642e4533e1547b5d2c0476fb03","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-72055","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:21:14.890","lastModified":"2026-08-15T06:21:14.890","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nnet: ip6_vti: require CAP_NET_ADMIN in the device netns for changelink\n\nvti6_changelink() operates on at most two netns, dev_net(dev) and the\ntunnel link netns t->net. They differ once the device is created in or\nmoved to a netns other than the one the request runs in. The rtnl\nchangelink path checks CAP_NET_ADMIN only against dev_net(dev), so a\ncaller privileged there but not in t->net can rewrite a tunnel that\nlives in t->net.\n\nGate vti6_changelink() on rtnl_dev_link_net_capable() at its top,\nbefore any attribute is parsed."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["net/ipv6/ip6_vti.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"61220ab349485d911083d0b7990ccd3db6c63297","lessThan":"f5254e7766b4ac02b66b2ccef896cd278503cb11","versionType":"git","status":"affected"},{"version":"61220ab349485d911083d0b7990ccd3db6c63297","lessThan":"ef897249dc957089e6f7f11ceea699e093ad51bd","versionType":"git","status":"affected"},{"version":"61220ab349485d911083d0b7990ccd3db6c63297","lessThan":"f6e8b52a2cb3bbd72ddc2d44e474b907b9dcf5ba","versionType":"git","status":"affected"},{"version":"61220ab349485d911083d0b7990ccd3db6c63297","lessThan":"c64b9ae7eb97e81d54b792910a3aeafd92566c79","versionType":"git","status":"affected"},{"version":"61220ab349485d911083d0b7990ccd3db6c63297","lessThan":"b2b61c540571b3cc2f461e2a579ba2cc8c2a52cf","versionType":"git","status":"affected"},{"version":"61220ab349485d911083d0b7990ccd3db6c63297","lessThan":"0b2f9c908f930ec4be17d389723f9a202d6a883c","versionType":"git","status":"affected"},{"version":"61220ab349485d911083d0b7990ccd3db6c63297","lessThan":"f97e93ebf2f9b8ef3b87f7a9371255e84d151587","versionType":"git","status":"affected"},{"version":"61220ab349485d911083d0b7990ccd3db6c63297","lessThan":"e2ac3b242c37dff323a964962e43854f4b1a2b79","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["net/ipv6/ip6_vti.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"3.15","status":"affected"},{"version":"0","lessThan":"3.15","versionType":"semver","status":"unaffected"},{"version":"5.10.261","lessThanOrEqual":"5.10.*","versionType":"semver","status":"unaffected"},{"version":"5.15.212","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.178","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.97","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/0b2f9c908f930ec4be17d389723f9a202d6a883c","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/b2b61c540571b3cc2f461e2a579ba2cc8c2a52cf","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/c64b9ae7eb97e81d54b792910a3aeafd92566c79","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/e2ac3b242c37dff323a964962e43854f4b1a2b79","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/ef897249dc957089e6f7f11ceea699e093ad51bd","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/f5254e7766b4ac02b66b2ccef896cd278503cb11","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/f6e8b52a2cb3bbd72ddc2d44e474b907b9dcf5ba","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/f97e93ebf2f9b8ef3b87f7a9371255e84d151587","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-72056","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:21:15.010","lastModified":"2026-08-15T06:21:15.010","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nnet: ena: clean up XDP TX queues when regular TX setup fails\n\ncreate_queues_with_size_backoff() creates XDP TX queues before setting\nup the regular TX path. If the subsequent allocation or creation of\nregular TX queues fails, the error handling paths omit the teardown of the\nXDP TX queues, leading to a resource leak.\n\nFix this by explicitly destroying the XDP TX queue subset at the two\nmissing failure points.\n\nThe bug was first flagged by an experimental analysis tool we are\ndeveloping for kernel memory-management bugs while analyzing\nv6.13-rc1. The tool is still under development and is not yet publicly\navailable. Manual inspection confirms that the bug is still\npresent in v7.1-rc7.\n\nAn x86_64 allyesconfig build showed no new warnings. As we do not have\nan ENA device to test with, no runtime testing was able to be performed."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/net/ethernet/amazon/ena/ena_netdev.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"548c4940b9f1f527f81509468dd60b61418880b6","lessThan":"df65d9fea8437235e740552e542fb309765507db","versionType":"git","status":"affected"},{"version":"548c4940b9f1f527f81509468dd60b61418880b6","lessThan":"5daa63404b708fc74e94da8398affbb148d09044","versionType":"git","status":"affected"},{"version":"548c4940b9f1f527f81509468dd60b61418880b6","lessThan":"523caef03124ecc08ce62a78c617759c2d28cf1c","versionType":"git","status":"affected"},{"version":"548c4940b9f1f527f81509468dd60b61418880b6","lessThan":"f2ff634d95f8a6c885b9ce71a64067e255bcc34a","versionType":"git","status":"affected"},{"version":"548c4940b9f1f527f81509468dd60b61418880b6","lessThan":"6773d6d82bdabddab2b31605d6d7029c91dbd217","versionType":"git","status":"affected"},{"version":"548c4940b9f1f527f81509468dd60b61418880b6","lessThan":"6596baf8041100a9d1647beb5ea8ea4496ce058f","versionType":"git","status":"affected"},{"version":"548c4940b9f1f527f81509468dd60b61418880b6","lessThan":"11f68ebc6891d11de5f32b7dee918c5dc18b8de1","versionType":"git","status":"affected"},{"version":"548c4940b9f1f527f81509468dd60b61418880b6","lessThan":"1bd6676254b4ab6acd44b662b5e92822c036463a","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/net/ethernet/amazon/ena/ena_netdev.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"5.6","status":"affected"},{"version":"0","lessThan":"5.6","versionType":"semver","status":"unaffected"},{"version":"5.10.261","lessThanOrEqual":"5.10.*","versionType":"semver","status":"unaffected"},{"version":"5.15.212","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.178","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.97","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/11f68ebc6891d11de5f32b7dee918c5dc18b8de1","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/1bd6676254b4ab6acd44b662b5e92822c036463a","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/523caef03124ecc08ce62a78c617759c2d28cf1c","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/5daa63404b708fc74e94da8398affbb148d09044","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/6596baf8041100a9d1647beb5ea8ea4496ce058f","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/6773d6d82bdabddab2b31605d6d7029c91dbd217","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/df65d9fea8437235e740552e542fb309765507db","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/f2ff634d95f8a6c885b9ce71a64067e255bcc34a","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-72057","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:21:15.153","lastModified":"2026-08-15T06:21:15.153","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nnet/sched: act_ct: preserve tc_skb_cb across defragmentation\n\ntcf_ct_handle_fragments() calls nf_ct_handle_fragments() without saving\nand restoring skb->cb. The defrag helper clears IPCB/IP6CB, which aliases\nthe tc_skb_cb/qdisc_skb_cb control buffer. Fragmented traffic through\nact_ct therefore loses qdisc metadata such as pkt_segs and can trigger\nWARN_ON_ONCE() in qdisc_pkt_segs() when panic_on_warn is enabled.\n\nSave and restore the full tc_skb_cb around nf_ct_handle_fragments(),\nmatching the pattern used by ovs_ct_handle_fragments()."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["net/sched/act_ct.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"ec624fe740b416fb68d536b37fb8eef46f90b5c2","lessThan":"2400c4b05d58834b994500a9eec90a37db44187c","versionType":"git","status":"affected"},{"version":"ec624fe740b416fb68d536b37fb8eef46f90b5c2","lessThan":"5c3ae5f6c7c6de73ea9b6a75154fe4ed343e1bac","versionType":"git","status":"affected"},{"version":"ec624fe740b416fb68d536b37fb8eef46f90b5c2","lessThan":"b3d835407846134b0d54637c0281b39bebef831d","versionType":"git","status":"affected"},{"version":"ec624fe740b416fb68d536b37fb8eef46f90b5c2","lessThan":"f7f45ceb855d9ba1cba594fb3f383255f7013fad","versionType":"git","status":"affected"},{"version":"ec624fe740b416fb68d536b37fb8eef46f90b5c2","lessThan":"9092e15defbe6c7bc241c306093ca9d358a578e7","versionType":"git","status":"affected"},{"version":"0d76daf2013ce1da20eab5e26bd81d983e1c18fb","versionType":"git","status":"affected"},{"version":"5.15.13","lessThan":"5.16","versionType":"semver","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["net/sched/act_ct.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"5.16","status":"affected"},{"version":"0","lessThan":"5.16","versionType":"semver","status":"unaffected"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.97","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/2400c4b05d58834b994500a9eec90a37db44187c","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/5c3ae5f6c7c6de73ea9b6a75154fe4ed343e1bac","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/9092e15defbe6c7bc241c306093ca9d358a578e7","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/b3d835407846134b0d54637c0281b39bebef831d","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/f7f45ceb855d9ba1cba594fb3f383255f7013fad","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-72058","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:21:15.260","lastModified":"2026-08-15T06:21:15.260","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nnet: ixp4xx_hss: fix duplicate HDLC netdev allocation\n\nixp4xx_hss_probe() allocates two HDLC netdevs. The first one is stored\nin ndev, initialized, and registered with register_hdlc_device(). The\nsecond one is stored in port->netdev and later used by the remove path\nfor unregister_hdlc_device() and free_netdev().\n\nThis means that the registered netdev is not the same object that is\nunregistered and freed on remove. It also leaks the first allocation if\nthe second alloc_hdlcdev() call fails, and the first allocation is not\nchecked before ndev is used.\n\nOlder code allocated the HDLC netdev only once and stored the same object\nin both the local variable and port->netdev. The buggy conversion split\nthis into two alloc_hdlcdev() calls. A later rename changed the local\nvariable name to ndev, but the underlying mismatch remained.\n\nFix this by allocating the HDLC netdev only once and assigning the same\nobject to port->netdev."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/net/wan/ixp4xx_hss.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"99ebe65eb9c0ada015931d239d9f2d1dc8897fee","lessThan":"8f4c3c384092becbf4835a3f8ed8a3df1f544578","versionType":"git","status":"affected"},{"version":"99ebe65eb9c0ada015931d239d9f2d1dc8897fee","lessThan":"fd0b939ebd1eee29945a539c5ed65c35dddac8d6","versionType":"git","status":"affected"},{"version":"99ebe65eb9c0ada015931d239d9f2d1dc8897fee","lessThan":"ffba16e6f55948d94b7f16aa113d587c1c4c0643","versionType":"git","status":"affected"},{"version":"99ebe65eb9c0ada015931d239d9f2d1dc8897fee","lessThan":"3f85fcd520aa703824b1958f35169925ddae2558","versionType":"git","status":"affected"},{"version":"99ebe65eb9c0ada015931d239d9f2d1dc8897fee","lessThan":"91850f582783098415a334f8bd0a84c87ff15a8c","versionType":"git","status":"affected"},{"version":"99ebe65eb9c0ada015931d239d9f2d1dc8897fee","lessThan":"db818b0e8af7bac16860116a19c341a63d6677b4","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/net/wan/ixp4xx_hss.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"5.14","status":"affected"},{"version":"0","lessThan":"5.14","versionType":"semver","status":"unaffected"},{"version":"6.1.178","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.97","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/3f85fcd520aa703824b1958f35169925ddae2558","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/8f4c3c384092becbf4835a3f8ed8a3df1f544578","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/91850f582783098415a334f8bd0a84c87ff15a8c","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/db818b0e8af7bac16860116a19c341a63d6677b4","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/fd0b939ebd1eee29945a539c5ed65c35dddac8d6","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/ffba16e6f55948d94b7f16aa113d587c1c4c0643","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-72059","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:21:15.400","lastModified":"2026-08-15T06:21:15.400","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nnet: wwan: t7xx: destroy DMA pool on CLDMA late init failure\n\nt7xx_cldma_late_init() creates md_ctrl->gpd_dmapool before\ninitializing the TX and RX rings. If any ring initialization\nfails, the error path frees the already initialized rings but\nleaves the DMA pool allocated.\n\nDestroy md_ctrl->gpd_dmapool on the late-init failure path\nto avoid leaking the DMA pool."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/net/wwan/t7xx/t7xx_hif_cldma.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"39d439047f1dc88f98b755d6f3a53a4ef8f0de21","lessThan":"cef50f9f9045ff5e6a9d62c5110522df98fca645","versionType":"git","status":"affected"},{"version":"39d439047f1dc88f98b755d6f3a53a4ef8f0de21","lessThan":"fd01247bde1add970fae7f0003af085333a256e6","versionType":"git","status":"affected"},{"version":"39d439047f1dc88f98b755d6f3a53a4ef8f0de21","lessThan":"ebd84cb129fac7f7933628c40fccdfa8a62805de","versionType":"git","status":"affected"},{"version":"39d439047f1dc88f98b755d6f3a53a4ef8f0de21","lessThan":"e89b8829693e65217d587dceeaad4826c96c731b","versionType":"git","status":"affected"},{"version":"39d439047f1dc88f98b755d6f3a53a4ef8f0de21","lessThan":"0c0a8c7821485f32bdb4923fb22f2dd501a27d8a","versionType":"git","status":"affected"},{"version":"39d439047f1dc88f98b755d6f3a53a4ef8f0de21","lessThan":"2bd6f26d4ce1e87de4d736b1e8896daf3acf1c0e","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/net/wwan/t7xx/t7xx_hif_cldma.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"5.19","status":"affected"},{"version":"0","lessThan":"5.19","versionType":"semver","status":"unaffected"},{"version":"6.1.178","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.97","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/0c0a8c7821485f32bdb4923fb22f2dd501a27d8a","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/2bd6f26d4ce1e87de4d736b1e8896daf3acf1c0e","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/cef50f9f9045ff5e6a9d62c5110522df98fca645","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/e89b8829693e65217d587dceeaad4826c96c731b","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/ebd84cb129fac7f7933628c40fccdfa8a62805de","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/fd01247bde1add970fae7f0003af085333a256e6","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-72060","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:21:15.530","lastModified":"2026-08-15T06:21:15.530","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nnet: ethernet: ti: icssg: guard PA stat lookups\n\nicssg_ndo_get_stats64() unconditionally calls emac_get_stat_by_name()\nwith FW PA stat names regardless of whether the PA stats block is\npresent on the hardware.  emac_get_stat_by_name() already guards the\nPA stats lookup with `if (emac->prueth->pa_stats)`; when that pointer\nis NULL the lookup falls through to netdev_err() and returns -EINVAL.\nBecause ndo_get_stats64 is polled regularly by the networking stack\nthis produces thousands of log entries of the form:\n\n  icssg-prueth icssg1-eth end0: Invalid stats FW_RX_ERROR\n\nA secondary consequence is that the int(-EINVAL) return value is\nimplicitly widened to a near-ULLONG_MAX unsigned value when accumulated\ninto the __u64 fields of rtnl_link_stats64, silently corrupting the\nrx_errors, rx_dropped and tx_dropped counters reported by `ip -s link`.\n\nEvery other PA-aware code path in the driver is already guarded with\nthe same `if (emac->prueth->pa_stats)` check.  Apply the same guard\nhere."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/net/ethernet/ti/icssg/icssg_common.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"0d15a26b247d25cd012134bf8825128fedb15cc9","lessThan":"121c5f31c3fb70d4a23e8a084f5cb8b3ec63be8d","versionType":"git","status":"affected"},{"version":"0d15a26b247d25cd012134bf8825128fedb15cc9","lessThan":"b3763f7e22ecaa7ad79bf44bf41816d488edbcf8","versionType":"git","status":"affected"},{"version":"0d15a26b247d25cd012134bf8825128fedb15cc9","lessThan":"27b9daba50609335db6ca81e4cccf50ded21ec76","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/net/ethernet/ti/icssg/icssg_common.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.16","status":"affected"},{"version":"0","lessThan":"6.16","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/121c5f31c3fb70d4a23e8a084f5cb8b3ec63be8d","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/27b9daba50609335db6ca81e4cccf50ded21ec76","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/b3763f7e22ecaa7ad79bf44bf41816d488edbcf8","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-72061","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:21:15.637","lastModified":"2026-08-15T06:21:15.637","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nnet: sit: require CAP_NET_ADMIN in the device netns for changelink\n\nipip6_changelink() operates on at most two netns, dev_net(dev) and the\ntunnel link netns t->net. They differ once the device is created in or\nmoved to a netns other than the one the request runs in. The rtnl\nchangelink path checks CAP_NET_ADMIN only against dev_net(dev), so a\ncaller privileged there but not in t->net can rewrite a tunnel that\nlives in t->net.\n\nGate ipip6_changelink() on rtnl_dev_link_net_capable() at its top,\nbefore any attribute is parsed. sit was the one tunnel type not covered\nby the recent series that added this check to the other changelink()\nhandlers."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["net/ipv6/sit.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"5e6700b3bf98fe98d630bf9c939ad4c85ce95592","lessThan":"cb41b308e9d867725d965b291dd085028e36a480","versionType":"git","status":"affected"},{"version":"5e6700b3bf98fe98d630bf9c939ad4c85ce95592","lessThan":"c5a0ae895432596b2f464172da8218e2d84e2932","versionType":"git","status":"affected"},{"version":"5e6700b3bf98fe98d630bf9c939ad4c85ce95592","lessThan":"7d139dec96691cde96cb40ed293e2d13d994fb4f","versionType":"git","status":"affected"},{"version":"5e6700b3bf98fe98d630bf9c939ad4c85ce95592","lessThan":"388ccffbd2e7e5e4271f291085a7451865705305","versionType":"git","status":"affected"},{"version":"5e6700b3bf98fe98d630bf9c939ad4c85ce95592","lessThan":"c0ea1aedb37bb979e864ed7787975434bbd9db73","versionType":"git","status":"affected"},{"version":"5e6700b3bf98fe98d630bf9c939ad4c85ce95592","lessThan":"3118e97dae533fb45964b87bbed1801afcff7c65","versionType":"git","status":"affected"},{"version":"5e6700b3bf98fe98d630bf9c939ad4c85ce95592","lessThan":"99ae3248b33df94201915d9c32e7470cdf08cfcd","versionType":"git","status":"affected"},{"version":"5e6700b3bf98fe98d630bf9c939ad4c85ce95592","lessThan":"27ccb68e7cccead5d8c611665a45d23032d468b3","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["net/ipv6/sit.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"3.11","status":"affected"},{"version":"0","lessThan":"3.11","versionType":"semver","status":"unaffected"},{"version":"5.10.261","lessThanOrEqual":"5.10.*","versionType":"semver","status":"unaffected"},{"version":"5.15.212","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.178","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.97","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/27ccb68e7cccead5d8c611665a45d23032d468b3","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/3118e97dae533fb45964b87bbed1801afcff7c65","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/388ccffbd2e7e5e4271f291085a7451865705305","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/7d139dec96691cde96cb40ed293e2d13d994fb4f","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/99ae3248b33df94201915d9c32e7470cdf08cfcd","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/c0ea1aedb37bb979e864ed7787975434bbd9db73","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/c5a0ae895432596b2f464172da8218e2d84e2932","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/cb41b308e9d867725d965b291dd085028e36a480","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-72062","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:21:15.757","lastModified":"2026-08-15T06:21:15.757","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\ngpio: mt7621: avoid corruption of shared interrupt trigger state\n\nThe bank-shared fields like 'rising' and 'falling' are modified using\nnon-atomic read-modify-write operations. Since every gpio chip instance\nrepresents an entire bank of 32 pins, if 'mediatek_gpio_irq_type()' is\ncalled concurrently for different IRQs on the same bank a possible overwrite\nof each other's configuration is possible. Thus, protect this state with\n'gpio_generic_lock_irqsave' lock in the same way it is handled in irp_chip\n'mediatek_gpio_irq_mask()' and 'mediatek_gpio_irq_unmask()' callbacks."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/gpio/gpio-mt7621.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"4ba9c3afda41213ec98c30053e32963892e6dc7c","lessThan":"207d3ebf36f654a43a934addeb4d6775cb2dd667","versionType":"git","status":"affected"},{"version":"4ba9c3afda41213ec98c30053e32963892e6dc7c","lessThan":"877a243006788aaa586b2d087f27c9f3628071b0","versionType":"git","status":"affected"},{"version":"4ba9c3afda41213ec98c30053e32963892e6dc7c","lessThan":"d3b9026ef78da3018a7d2c5a9c9d611de6d45c47","versionType":"git","status":"affected"},{"version":"4ba9c3afda41213ec98c30053e32963892e6dc7c","lessThan":"a60a40c9ba30edd06d3fb4215fdf430ed968728e","versionType":"git","status":"affected"},{"version":"4ba9c3afda41213ec98c30053e32963892e6dc7c","lessThan":"1781172526d1092323af443fa03f00e6de560401","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/gpio/gpio-mt7621.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"4.19","status":"affected"},{"version":"0","lessThan":"4.19","versionType":"semver","status":"unaffected"},{"version":"6.6.148","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.101","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc2","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/1781172526d1092323af443fa03f00e6de560401","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/207d3ebf36f654a43a934addeb4d6775cb2dd667","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/877a243006788aaa586b2d087f27c9f3628071b0","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/a60a40c9ba30edd06d3fb4215fdf430ed968728e","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/d3b9026ef78da3018a7d2c5a9c9d611de6d45c47","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-72063","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:21:15.887","lastModified":"2026-08-15T06:21:15.887","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\ngpio: tegra: do not call pinctrl for GPIO direction\n\ntegra_gpio_direction_input() and tegra_gpio_direction_output() already\nprogram the GPIO controller direction registers directly. The additional\npinctrl_gpio_direction_input/output() calls do not add a Tegra pinctrl\noperation, because the Tegra pinmux ops provide GPIO request/free\nhandling but no gpio_set_direction hook.\n\nThe extra call still enters the pinctrl core and takes pctldev->mutex.\nShared GPIO users can call the direction path while holding their\nper-line spinlock, so this otherwise redundant pinctrl direction call can\nsleep in an atomic context.\n\nThis was found by our static analysis tool and then confirmed by manual\nreview of tegra_gpio_probe(), the Tegra GPIO direction callbacks and the\nTegra pinctrl ops. The reviewed path has a default non-sleeping\nstruct gpio_chip while the direction callback still enters the pinctrl\nmutex path.\n\nA directed runtime validation kept the same non-sleeping chip registration\nand drove:\n\n  gpio_shared_proxy_direction_output()\n  gpiod_direction_output_raw_commit()\n  tegra_gpio_direction_output()\n  pinctrl_gpio_direction_output()\n\nLockdep reported a sleep-in-atomic warning with the shared GPIO spinlock\nheld and pinctrl_get_device_gpio_range() plus tegra_gpio_direction_output()\non the stack.\n\nDo not mark the whole chip as can_sleep to paper over this: can_sleep\ndescribes whether get()/set() may sleep, and Tegra value access is MMIO.\nRemove the redundant pinctrl direction calls and keep pinctrl involvement\nin the existing request/free path."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/gpio/gpio-tegra.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"11da905412833d9b369a6a09a401f87149d674dc","lessThan":"e57a4845b0da60a7b9f052160878097826320954","versionType":"git","status":"affected"},{"version":"11da905412833d9b369a6a09a401f87149d674dc","lessThan":"cd17c5a1d9f186b57e9e2949be427803b7110a5c","versionType":"git","status":"affected"},{"version":"11da905412833d9b369a6a09a401f87149d674dc","lessThan":"ac761e66708d51dac35c4c7f1891ea991dc788f0","versionType":"git","status":"affected"},{"version":"11da905412833d9b369a6a09a401f87149d674dc","lessThan":"628c63f96f4564fa145f602af2d41daf9532201f","versionType":"git","status":"affected"},{"version":"11da905412833d9b369a6a09a401f87149d674dc","lessThan":"d3e91a95b2b0fc6336dbf3ec90d831a1654d2720","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/gpio/gpio-tegra.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"5.1","status":"affected"},{"version":"0","lessThan":"5.1","versionType":"semver","status":"unaffected"},{"version":"6.6.148","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.97","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/628c63f96f4564fa145f602af2d41daf9532201f","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/ac761e66708d51dac35c4c7f1891ea991dc788f0","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/cd17c5a1d9f186b57e9e2949be427803b7110a5c","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/d3e91a95b2b0fc6336dbf3ec90d831a1654d2720","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/e57a4845b0da60a7b9f052160878097826320954","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-72064","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:21:16.003","lastModified":"2026-08-15T06:21:16.003","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nnet: mana: Sync page pool RX frags for CPU\n\nMANA allocates RX buffers from page pool fragments when frag_count is\ngreater than 1. In that case the buffers remain DMA mapped by page pool\nand the RX completion path does not call dma_unmap_single(). As a result,\nthe implicit sync-for-CPU normally performed by dma_unmap_single() is\nmissing before the packet data is passed to the networking stack.\n\nThis breaks RX on configurations which require explicit DMA syncing, for\nexample when booted with swiotlb=force.\n\nFix this by recording the page pool page and DMA sync offset when the RX\nbuffer is allocated, and syncing the received packet range for CPU access\nbefore handing the RX buffer to the stack."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/net/ethernet/microsoft/mana/mana_en.c","include/net/mana/mana.h"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"730ff06d3f5cc2ce0348414b78c10528b767d4a3","lessThan":"bc650dd5ce6434286b96e2b26a41af81f679cc7c","versionType":"git","status":"affected"},{"version":"730ff06d3f5cc2ce0348414b78c10528b767d4a3","lessThan":"c72a0f09c57f92113df69f9b902d11c9e4b132f5","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/net/ethernet/microsoft/mana/mana_en.c","include/net/mana/mana.h"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.18","status":"affected"},{"version":"0","lessThan":"6.18","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc3","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/bc650dd5ce6434286b96e2b26a41af81f679cc7c","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/c72a0f09c57f92113df69f9b902d11c9e4b132f5","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-72065","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:21:16.100","lastModified":"2026-08-15T06:21:16.100","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nnet: mana: Validate the packet length reported by the NIC\n\nValidate the packet length reported in the RX CQE before passing it\nto skb processing. The CQE is supplied by the NIC device and should\nnot be blindly trusted."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/net/ethernet/microsoft/mana/mana_en.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"ca9c54d2d6a5ab2430c4eda364c77125d62e5e0f","lessThan":"2e276b14b6d378372bf0152df89286cbe7632fb0","versionType":"git","status":"affected"},{"version":"ca9c54d2d6a5ab2430c4eda364c77125d62e5e0f","lessThan":"6080189291d958604dcefe513a13900835ac982f","versionType":"git","status":"affected"},{"version":"ca9c54d2d6a5ab2430c4eda364c77125d62e5e0f","lessThan":"6d13eaa13341a8f80aaf86f78591e1b1d393711d","versionType":"git","status":"affected"},{"version":"ca9c54d2d6a5ab2430c4eda364c77125d62e5e0f","lessThan":"282c5214ca4eb3799158c76782646e86d2945d1b","versionType":"git","status":"affected"},{"version":"ca9c54d2d6a5ab2430c4eda364c77125d62e5e0f","lessThan":"2e2a83b4998af4384e677d3b2ac08565274279bf","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/net/ethernet/microsoft/mana/mana_en.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"5.13","status":"affected"},{"version":"0","lessThan":"5.13","versionType":"semver","status":"unaffected"},{"version":"6.6.148","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.101","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.42","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc3","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/282c5214ca4eb3799158c76782646e86d2945d1b","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/2e276b14b6d378372bf0152df89286cbe7632fb0","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/2e2a83b4998af4384e677d3b2ac08565274279bf","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/6080189291d958604dcefe513a13900835ac982f","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/6d13eaa13341a8f80aaf86f78591e1b1d393711d","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-72066","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:21:16.203","lastModified":"2026-08-15T06:21:16.203","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\ncpu: hotplug: Bound hotplug states sysfs output\n\nstates_show() adds CPU hotplug state names into a single sysfs buffer\nusing sprintf(). With enough registered states, this can write past the\nend of the PAGE_SIZE buffer.\n\nUse sysfs_emit_at() so output is bounded."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["kernel/cpu.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"98f8cdce1db580b99fce823a48eea2cb2bdb261e","lessThan":"2408be459c70ef4250da1a9e50f5478e6b250d61","versionType":"git","status":"affected"},{"version":"98f8cdce1db580b99fce823a48eea2cb2bdb261e","lessThan":"de4d3d8ae17dc8b4cf8c59436c4b7e2dc2491635","versionType":"git","status":"affected"},{"version":"98f8cdce1db580b99fce823a48eea2cb2bdb261e","lessThan":"998f66e9ce320f3433f60b948e3698b744754a46","versionType":"git","status":"affected"},{"version":"98f8cdce1db580b99fce823a48eea2cb2bdb261e","lessThan":"61a73a123ac7a7fbc57382531f8cb7092d569aba","versionType":"git","status":"affected"},{"version":"98f8cdce1db580b99fce823a48eea2cb2bdb261e","lessThan":"6cb15b81ff545840048fb0e1a6e827d560dbf367","versionType":"git","status":"affected"},{"version":"98f8cdce1db580b99fce823a48eea2cb2bdb261e","lessThan":"631d53102da9f469c96b882b770336bec095b833","versionType":"git","status":"affected"},{"version":"98f8cdce1db580b99fce823a48eea2cb2bdb261e","lessThan":"86f436567f2516a0083b210bedc933544826a2c3","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["kernel/cpu.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"4.6","status":"affected"},{"version":"0","lessThan":"4.6","versionType":"semver","status":"unaffected"},{"version":"5.15.212","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.178","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.97","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/2408be459c70ef4250da1a9e50f5478e6b250d61","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/61a73a123ac7a7fbc57382531f8cb7092d569aba","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/631d53102da9f469c96b882b770336bec095b833","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/6cb15b81ff545840048fb0e1a6e827d560dbf367","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/86f436567f2516a0083b210bedc933544826a2c3","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/998f66e9ce320f3433f60b948e3698b744754a46","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/de4d3d8ae17dc8b4cf8c59436c4b7e2dc2491635","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-72067","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:21:16.327","lastModified":"2026-08-15T06:21:16.327","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\ncpu: hotplug: Preserve per instance callback errors\n\ncpuhp_invoke_callback() unwinds earlier callbacks for the same\nhotplug state when one instance fails. The rollback path currently\nreuses ret, so a successful rollback can hide the original error and\nmake the failed transition look successful.\n\nKeep the rollback result separate from the original error."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["kernel/cpu.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"724a86881d03ee5794148e65142e24ed3621be66","lessThan":"fe9c8d641f6991614d1229a3ffd3e33b879bba9c","versionType":"git","status":"affected"},{"version":"724a86881d03ee5794148e65142e24ed3621be66","lessThan":"ef39758637cc5b603fb05b625c45a98aa306e338","versionType":"git","status":"affected"},{"version":"724a86881d03ee5794148e65142e24ed3621be66","lessThan":"95232281512b15338549171ed9a2acf21f946ffb","versionType":"git","status":"affected"},{"version":"724a86881d03ee5794148e65142e24ed3621be66","lessThan":"7a68257b90d8a9b6d605abc99469ded45ecba63b","versionType":"git","status":"affected"},{"version":"724a86881d03ee5794148e65142e24ed3621be66","lessThan":"77d4fa8a3ea1c3e8b996ac35e59aee9e77389905","versionType":"git","status":"affected"},{"version":"724a86881d03ee5794148e65142e24ed3621be66","lessThan":"f77117530fc3f5932ffb107182a6dd34006be9b6","versionType":"git","status":"affected"},{"version":"724a86881d03ee5794148e65142e24ed3621be66","lessThan":"9f7dc355f62c011e4afe8286cf71130d4bfb9d80","versionType":"git","status":"affected"},{"version":"724a86881d03ee5794148e65142e24ed3621be66","lessThan":"673db10729fb121ea1b16fe57791a0cb9eac1eb5","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["kernel/cpu.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"4.14","status":"affected"},{"version":"0","lessThan":"4.14","versionType":"semver","status":"unaffected"},{"version":"5.10.261","lessThanOrEqual":"5.10.*","versionType":"semver","status":"unaffected"},{"version":"5.15.212","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.178","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.97","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/673db10729fb121ea1b16fe57791a0cb9eac1eb5","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/77d4fa8a3ea1c3e8b996ac35e59aee9e77389905","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/7a68257b90d8a9b6d605abc99469ded45ecba63b","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/95232281512b15338549171ed9a2acf21f946ffb","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/9f7dc355f62c011e4afe8286cf71130d4bfb9d80","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/ef39758637cc5b603fb05b625c45a98aa306e338","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/f77117530fc3f5932ffb107182a6dd34006be9b6","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/fe9c8d641f6991614d1229a3ffd3e33b879bba9c","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-72068","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:21:16.467","lastModified":"2026-08-15T06:21:16.467","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nposix-cpu-timers: Use u64 multiplication in update_rlimit_cpu()\n\nupdate_rlimit_cpu() converts the RLIMIT_CPU value to nanoseconds with\n\n        u64 nsecs = rlim_new * NSEC_PER_SEC;\n\nOn 32-bit kernels both rlim_new (unsigned long) and NSEC_PER_SEC\n(1000000000L) are 32-bit, so the multiplication is performed in unsigned\nlong and truncated for rlim_new > 4 seconds before being widened to u64.\n\nThe same file already casts to u64 for the matching computation in\ncheck_process_timers():\n\n        u64 softns = (u64)soft * NSEC_PER_SEC;\n\nAs a result, the truncated value is installed into the CPUCLOCK_PROF\nexpiry cache (nextevt), causing the process CPU timer to be programmed\nto fire prematurely for any RLIMIT_CPU soft limit >= 5 seconds. The\nactual SIGXCPU/SIGKILL decision in check_process_timers() already casts\nto u64 and is therefore correct, so limit enforcement is not broken;\nonly the expiry-cache programming is wrong. Apply the same cast here so\nboth paths convert rlim_cur identically.\n\n64-bit kernels are unaffected."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["kernel/time/posix-cpu-timers.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"858cf3a8c59968e7c5f7c1a1192459a0d52d1ab4","lessThan":"feb5c87c8514444ba891b75a5a3eae57c64edaf8","versionType":"git","status":"affected"},{"version":"858cf3a8c59968e7c5f7c1a1192459a0d52d1ab4","lessThan":"384628d6cdde0fcd76868606fad3ad8293100afb","versionType":"git","status":"affected"},{"version":"858cf3a8c59968e7c5f7c1a1192459a0d52d1ab4","lessThan":"1fafc4d9b411645eb34de43362b966dc8fb3e263","versionType":"git","status":"affected"},{"version":"858cf3a8c59968e7c5f7c1a1192459a0d52d1ab4","lessThan":"cff8281bacd2866767e6194c3079d33b6c5a74f4","versionType":"git","status":"affected"},{"version":"858cf3a8c59968e7c5f7c1a1192459a0d52d1ab4","lessThan":"edf6babb9edd2d3e19229ade339081f439d4f478","versionType":"git","status":"affected"},{"version":"858cf3a8c59968e7c5f7c1a1192459a0d52d1ab4","lessThan":"ea6a188ee805e841a0e242f14d15953e0dfa74bb","versionType":"git","status":"affected"},{"version":"858cf3a8c59968e7c5f7c1a1192459a0d52d1ab4","lessThan":"571e1f10b5996ba3e4dc63ea77de4aa309c384ce","versionType":"git","status":"affected"},{"version":"858cf3a8c59968e7c5f7c1a1192459a0d52d1ab4","lessThan":"26aff38fefb1d6cd87e22525f41cc8f1aa61b24f","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["kernel/time/posix-cpu-timers.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"4.11","status":"affected"},{"version":"0","lessThan":"4.11","versionType":"semver","status":"unaffected"},{"version":"5.10.261","lessThanOrEqual":"5.10.*","versionType":"semver","status":"unaffected"},{"version":"5.15.212","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.178","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.97","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/1fafc4d9b411645eb34de43362b966dc8fb3e263","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/26aff38fefb1d6cd87e22525f41cc8f1aa61b24f","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/384628d6cdde0fcd76868606fad3ad8293100afb","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/571e1f10b5996ba3e4dc63ea77de4aa309c384ce","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/cff8281bacd2866767e6194c3079d33b6c5a74f4","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/ea6a188ee805e841a0e242f14d15953e0dfa74bb","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/edf6babb9edd2d3e19229ade339081f439d4f478","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/feb5c87c8514444ba891b75a5a3eae57c64edaf8","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-72069","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:21:16.607","lastModified":"2026-08-15T06:21:16.607","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nlocking/rt: Fix the incorrect RCU protection in rt_spin_unlock()\n\nrt_spin_unlock() releases the RCU protection before unlocking the\nlock. That opens the door for the following UAF scenario:\n\n T1\t\t\t\t\tT2\n spin_lock(&p->lock);\t\trcu_read_lock();\n invalidate(p);\t\t\tp = rcu_dereference(ptr);\n rcu_assign_pointer(ptr, NULL);\tif (!p) return;\n spin_unlock(&p->lock);\t\tspin_lock(&p->lock)\n \t\t\t\t   lock(&lock->lock);\n\t\t\t\t   rcu_read_lock();\n kfree_rcu(p);\t\t\trcu_read_unlock();\n\t\t\t\t....\n\t\t\t\tspin_unlock(&p->lock)\n\t\t\t\t  rcu_read_unlock(); // Ends grace period\n rcu_do_batch()\n   kfree(p);\n\t\t\t    UAF ->\t  rt_mutex_cmpxchg_release(&lock->lock...)\n\nRegular spinlocks keep preemption disabled accross the unlock operation,\nwhich provides full RCU protection, but the RT substitution fails to\nresemble that. Same applies for the rwlock substitution.\n\nMove the rcu_read_unlock() invocation past the unlock operations to match\nthe non-RT semantics. This makes it asymmetric vs. rt_xxx_lock(), but\nthat's harmless as the caller needs to hold RCU read lock across the lock\noperation. The migrate_enable() call stays before the unlock operation\nbecause there is no per CPU operation in the unlock path which would\nrequire migration to be kept disabled."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["kernel/locking/spinlock_rt.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"0f383b6dc96e976dfbf2721b0bf10bd96103b341","lessThan":"3cfaac77b3c32ac3940df28866de263c3f45d24c","versionType":"git","status":"affected"},{"version":"0f383b6dc96e976dfbf2721b0bf10bd96103b341","lessThan":"1f0d56d3f1e88f20f6e46109402f8c15d59bac37","versionType":"git","status":"affected"},{"version":"0f383b6dc96e976dfbf2721b0bf10bd96103b341","lessThan":"633cadbc0b8323f5cc140a285d2432089dbb534e","versionType":"git","status":"affected"},{"version":"0f383b6dc96e976dfbf2721b0bf10bd96103b341","lessThan":"83f9fb561c1c3917e19f95523dd933c7d30291aa","versionType":"git","status":"affected"},{"version":"0f383b6dc96e976dfbf2721b0bf10bd96103b341","lessThan":"89038cc87d80c77e7aa6f42a64b2573b74af339f","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["kernel/locking/spinlock_rt.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"5.15","status":"affected"},{"version":"0","lessThan":"5.15","versionType":"semver","status":"unaffected"},{"version":"6.6.148","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.101","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/1f0d56d3f1e88f20f6e46109402f8c15d59bac37","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/3cfaac77b3c32ac3940df28866de263c3f45d24c","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/633cadbc0b8323f5cc140a285d2432089dbb534e","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/83f9fb561c1c3917e19f95523dd933c7d30291aa","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/89038cc87d80c77e7aa6f42a64b2573b74af339f","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-72070","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:21:16.713","lastModified":"2026-08-15T06:21:16.713","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: libertas_tf: fix use-after-free in lbtf_free_adapter()\n\nlbtf_free_adapter() calls timer_delete(&priv->command_timer), which does\nnot wait for a running command_timer_fn() callback. lbtf_free_adapter()\nruns on the teardown path right before ieee80211_free_hw() frees priv,\nboth in lbtf_remove_card() and in the probe error path. command_timer is\narmed by mod_timer() in lbtf_cmd() whenever a firmware command is sent.\ncommand_timer_fn() dereferences priv. If a command times out as the\ndevice is removed, command_timer_fn() runs concurrently with teardown and\ndereferences priv after it has been freed.\n\nThis is the same use-after-free that commit 03cc8f90d053 (\"wifi: libertas:\nfix use-after-free in lbs_free_adapter()\") fixed in the sibling libertas\ndriver. The libertas_tf variant has the identical pattern and was left\nunchanged. Use timer_delete_sync() so any in-flight callback completes\nbefore priv is freed."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/net/wireless/marvell/libertas_tf/main.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"06b16ae5319251c26377afcb401e46056d5673f4","lessThan":"4714e95f5d61cb9c5c7c6c4e68b618f37bc6ffcf","versionType":"git","status":"affected"},{"version":"06b16ae5319251c26377afcb401e46056d5673f4","lessThan":"066b59e84f90d270cc15f0370166155aca507630","versionType":"git","status":"affected"},{"version":"06b16ae5319251c26377afcb401e46056d5673f4","lessThan":"fcff712d0e3d183843ec3916470ee6cc3455baad","versionType":"git","status":"affected"},{"version":"06b16ae5319251c26377afcb401e46056d5673f4","lessThan":"bcf7968cb97ce4312588042cf2712f04caff6d8f","versionType":"git","status":"affected"},{"version":"06b16ae5319251c26377afcb401e46056d5673f4","lessThan":"aa6dcd5c8dd9ba1d7d0f60093bcda41c0d6d438d","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/net/wireless/marvell/libertas_tf/main.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"2.6.28","status":"affected"},{"version":"0","lessThan":"2.6.28","versionType":"semver","status":"unaffected"},{"version":"6.6.148","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.101","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc4","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/066b59e84f90d270cc15f0370166155aca507630","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/4714e95f5d61cb9c5c7c6c4e68b618f37bc6ffcf","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/aa6dcd5c8dd9ba1d7d0f60093bcda41c0d6d438d","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/bcf7968cb97ce4312588042cf2712f04caff6d8f","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/fcff712d0e3d183843ec3916470ee6cc3455baad","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-72071","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:21:16.820","lastModified":"2026-08-15T06:21:16.820","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\ntracing/user_events: Fix use-after-free in user_event_mm_dup()\n\nuser_event_mm_dup() walks the parent mm's enabler list locklessly under\nrcu_read_lock() during fork() (from copy_process()); it does not take\nevent_mutex:\n\n\trcu_read_lock();\n\tlist_for_each_entry_rcu(enabler, &old_mm->enablers, mm_enablers_link)\n\t\tenabler->event = user_event_get(orig->event);\n\nuser_event_enabler_destroy() removes an enabler from that list with\nlist_del_rcu() and then, without waiting for a grace period, drops the\nenabler's user_event reference with user_event_put() and frees the enabler\nwith kfree(). A reader that loaded the enabler before the list_del_rcu()\ncan still be walking it, which leads to two use-after-frees:\n\n - kfree(enabler) frees the enabler while that reader dereferences\n   enabler->event.\n\n - user_event_put() may drop the last reference to the user_event, which\n   is then freed (via delayed_destroy_user_event() on a work queue), while\n   the same reader does user_event_get(orig->event) on it.\n\nBoth are reachable by an unprivileged task that can open user_events_data:\none multithreaded process that registers an enabler and then concurrently\nunregisters it and calls fork() triggers the race. KASAN reports a\nslab-use-after-free in user_event_mm_dup() during clone(), with a\n\"refcount_t: addition on 0\" warning when the user_event is freed.\n\nThe enabler use-after-free was found first; the user_event one was reported\nby XIAO WU, and the earlier enabler-only fix did not address it.\n\nDefer both the user_event_put() and the kfree(enabler) to a work item\nqueued with queue_rcu_work(), so they run only after an RCU grace period,\nonce all readers walking the enabler list have finished. The put must run\nin process context because user_event_put() takes event_mutex on the last\nreference, so a work queue is used rather than call_rcu(). The now-unlocked\nput lets the locked argument of user_event_enabler_destroy() be removed;\nall callers are updated."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["kernel/trace/trace_events_user.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"7235759084a4f8524a46bd2638885ff3b34ce279","lessThan":"25acb6711da6fa0382744fa92bd6d42a22c1ae68","versionType":"git","status":"affected"},{"version":"7235759084a4f8524a46bd2638885ff3b34ce279","lessThan":"95400e7039cdfeb0b53652d521d766f1698cae95","versionType":"git","status":"affected"},{"version":"7235759084a4f8524a46bd2638885ff3b34ce279","lessThan":"b33ac2d39953efb12f598c0dae242c5f644ea669","versionType":"git","status":"affected"},{"version":"7235759084a4f8524a46bd2638885ff3b34ce279","lessThan":"05b24f68f78ff3a1ef7f015f7327b35886b741f6","versionType":"git","status":"affected"},{"version":"7235759084a4f8524a46bd2638885ff3b34ce279","lessThan":"50fd6dd755c6e48a38af2fa4621167eea56829c2","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["kernel/trace/trace_events_user.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.4","status":"affected"},{"version":"0","lessThan":"6.4","versionType":"semver","status":"unaffected"},{"version":"6.6.148","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.97","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc3","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/05b24f68f78ff3a1ef7f015f7327b35886b741f6","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/25acb6711da6fa0382744fa92bd6d42a22c1ae68","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/50fd6dd755c6e48a38af2fa4621167eea56829c2","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/95400e7039cdfeb0b53652d521d766f1698cae95","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/b33ac2d39953efb12f598c0dae242c5f644ea669","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-72072","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:21:16.943","lastModified":"2026-08-15T06:21:16.943","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nnet/mlx5e: macsec: fix use-after-free of metadata_dst on RX SC delete\n\nWhen an offloaded MACsec RX SC is deleted, macsec_del_rxsc_ctx() freed\nthe per-SC metadata_dst with metadata_dst_free(), which kfree()s the\nobject unconditionally and ignores the dst reference count. The RX\ndatapath in mlx5e_macsec_offload_handle_rx_skb() looks up the SC under\nrcu_read_lock() via xa_load(), takes a reference with dst_hold() and\nattaches the dst to the skb with skb_dst_set(). A reader that already\nobtained the rx_sc pointer can race with the delete path and operate on\nfreed memory.\n\nFix the owner side by dropping the reference with dst_release() instead\nof freeing unconditionally, and convert the RX datapath to\ndst_hold_safe() so a reader racing the SC delete cannot attach a dst\nwhose last reference was just dropped; only attach it when a reference\nwas actually taken.\n\nmlx5e_macsec_add_rxsc() also published sc_xarray_element via xa_alloc()\nbefore rx_sc->md_dst was allocated and initialised, so a datapath reader\nthat looked the SC up by fs_id could observe rx_sc with md_dst still\nNULL or, on weakly-ordered architectures, a non-NULL md_dst pointer\nwhose contents were not yet visible. NULL-check the xa_load() result and\nmd_dst on the datapath, and reorder add_rxsc() so the xa_alloc() publish\nhappens only after md_dst is fully initialised; the xarray RCU publish\nthen pairs with the rcu_read_lock()/xa_load() in the datapath.\n\nNote: macsec_del_rxsc_ctx() also kfree()s rx_sc->sc_xarray_element\nwithout an RCU grace period while the same datapath reads it under\nrcu_read_lock(); that is a separate pre-existing issue left to a\nfollow-up patch.\n\nFound by 0sec automated security-research tooling (https://0sec.ai)."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/net/ethernet/mellanox/mlx5/core/en_accel/macsec.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"b7c9400cbc48c3713190b3bce4e0c87e924e4104","lessThan":"b1a4d0c568bbb52c7c04f4fce3c097dae89ed6cb","versionType":"git","status":"affected"},{"version":"b7c9400cbc48c3713190b3bce4e0c87e924e4104","lessThan":"218cc15a4c907659ad4b0e68c535c61594311205","versionType":"git","status":"affected"},{"version":"b7c9400cbc48c3713190b3bce4e0c87e924e4104","lessThan":"4a5073b7b30243658f58b2d2d35a823da7fd34d9","versionType":"git","status":"affected"},{"version":"b7c9400cbc48c3713190b3bce4e0c87e924e4104","lessThan":"ed3cc4218070d6b98bf5fb456dccae424fd38c4f","versionType":"git","status":"affected"},{"version":"b7c9400cbc48c3713190b3bce4e0c87e924e4104","lessThan":"088873af13590ebde10de2ade847f57a05ec61c6","versionType":"git","status":"affected"},{"version":"b7c9400cbc48c3713190b3bce4e0c87e924e4104","lessThan":"de74d8fd10291763d97b218f09adcc7513c975e4","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/net/ethernet/mellanox/mlx5/core/en_accel/macsec.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.1","status":"affected"},{"version":"0","lessThan":"6.1","versionType":"semver","status":"unaffected"},{"version":"6.1.178","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.97","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc2","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/088873af13590ebde10de2ade847f57a05ec61c6","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/218cc15a4c907659ad4b0e68c535c61594311205","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/4a5073b7b30243658f58b2d2d35a823da7fd34d9","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/b1a4d0c568bbb52c7c04f4fce3c097dae89ed6cb","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/de74d8fd10291763d97b218f09adcc7513c975e4","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/ed3cc4218070d6b98bf5fb456dccae424fd38c4f","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-72073","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:21:17.123","lastModified":"2026-08-15T06:21:17.123","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nmmc: vub300: fix use-after-free on probe failure\n\nThe vub300 driver lifetime-manages its controller state using\nvub300->kref, with vub300_delete() freeing the mmc host when the last\nreference is dropped. The probe error path after the inactivity timer has\nbeen armed still bypasses that lifetime rule, however, and falls through\nto mmc_free_host() directly if mmc_add_host() fails.\n\nThe race window is between arming the inactivity timer and reaching the\nprobe error unwind after mmc_add_host() fails:\n\n        probe thread                     timer/workqueue\n        ------------                     ---------------\n        kref_init(&vub300->kref)         ref = 1\n        kref_get(&vub300->kref)          ref = 2, timer ref\n        add_timer(inactivity_timer)      fires after one second\n        |\n        |   race window\n        |<---------------------------------------------------->\n        |\n        mmc_add_host(mmc)\n                                         inactivity timer fires\n                                         vub300_queue_dead_work()\n                                           kref_get()          ref = 3\n                                           queue_work(deadwork)\n        mmc_add_host() fails\n        timer_delete_sync()\n        mmc_free_host(mmc)\n          frees vub300\n                                         deadwork runs\n                                           use-after-free\n\nThe inactivity timeout is one second, so this would require\nmmc_add_host() to both fail and take more than one second to do so. This\nis unlikely to happen in practice, but the error path is still wrong.\n\ntimer_delete_sync() only waits for the timer callback itself. It does\nnot flush deadwork that the callback may already have queued. As a\nresult, queued deadwork can still hold a kref while the probe error path\ndirectly frees the backing mmc host, including the vub300 storage.\n\nFix this by using the same lifetime mechanism as disconnect. Clear\nvub300->interface so that the timer callback and any queued deadwork\nreturn early and drop their references, then drop the initial probe\nreference and return without falling through to err_free_host."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/mmc/host/vub300.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"0613ad2401f88bdeae5594c30afe318e93b14676","lessThan":"5b82af744e06cd741938c3da54fdbe564a7e52d9","versionType":"git","status":"affected"},{"version":"0613ad2401f88bdeae5594c30afe318e93b14676","lessThan":"618cf6b139503ec18ef93ffd663396aaf99b763a","versionType":"git","status":"affected"},{"version":"0613ad2401f88bdeae5594c30afe318e93b14676","lessThan":"a3b5f242997a3be7404112fd48784881560aea57","versionType":"git","status":"affected"},{"version":"41ed46bdbd2878cd6567abe0974a445f8b1b8ec8","versionType":"git","status":"affected"},{"version":"25f05d762ca5e1c685002a53dd44f68e78ca3feb","versionType":"git","status":"affected"},{"version":"a46e681151bbdacdf6b89ee8c4e5bad0555142bb","versionType":"git","status":"affected"},{"version":"3b29f8769d32016b2d89183db4d80c7a71b7e35e","versionType":"git","status":"affected"},{"version":"3049a3b927a40d89d4582ff1033cd7953be773c7","versionType":"git","status":"affected"},{"version":"afc898019e7bf18c5eb7a0ac19852fcb1b341b3c","versionType":"git","status":"affected"},{"version":"c9e85979b59cb86f0a15defa8199d740e2b36b90","versionType":"git","status":"affected"},{"version":"2044b2ea77945f372ef161d1bbf814e471767ff2","versionType":"git","status":"affected"},{"version":"4.9.337","lessThan":"4.10","versionType":"semver","status":"affected"},{"version":"4.14.303","lessThan":"4.15","versionType":"semver","status":"affected"},{"version":"4.19.270","lessThan":"4.20","versionType":"semver","status":"affected"},{"version":"5.4.229","lessThan":"5.5","versionType":"semver","status":"affected"},{"version":"5.10.163","lessThan":"5.11","versionType":"semver","status":"affected"},{"version":"5.15.86","lessThan":"5.16","versionType":"semver","status":"affected"},{"version":"6.0.16","lessThan":"6.1","versionType":"semver","status":"affected"},{"version":"6.1.2","lessThan":"6.2","versionType":"semver","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/mmc/host/vub300.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.2","status":"affected"},{"version":"0","lessThan":"6.2","versionType":"semver","status":"unaffected"},{"version":"6.18.42","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc4","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/5b82af744e06cd741938c3da54fdbe564a7e52d9","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/618cf6b139503ec18ef93ffd663396aaf99b763a","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/a3b5f242997a3be7404112fd48784881560aea57","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-72074","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:21:17.270","lastModified":"2026-08-15T06:21:17.270","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nInput: ims-pcu - fix type confusion in CDC union descriptor parsing\n\nThe driver currently trusts the bMasterInterface0 from the CDC union\ndescriptor without verifying that it matches the interface being\nprobed. This could lead to the driver overwriting the private data of\nanother interface.\n\nValidate that the control interface found in the descriptor is indeed\nthe one we are probing."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/input/misc/ims-pcu.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"628329d52474323938a03826941e166bc7c8eff4","lessThan":"ab87cd7789d00f441f60a016cbcff35abe76513c","versionType":"git","status":"affected"},{"version":"628329d52474323938a03826941e166bc7c8eff4","lessThan":"b5518c5632f3485849421b9c33b4db5ae6a54ed7","versionType":"git","status":"affected"},{"version":"628329d52474323938a03826941e166bc7c8eff4","lessThan":"163c3e7a1de6b3d5c85edb3bdf4cf087382103b0","versionType":"git","status":"affected"},{"version":"628329d52474323938a03826941e166bc7c8eff4","lessThan":"08bf4b6ee28987570f4b3f1954427621fa291bf5","versionType":"git","status":"affected"},{"version":"628329d52474323938a03826941e166bc7c8eff4","lessThan":"fa7f65c5315a25b310daae69ab527efd420e37fa","versionType":"git","status":"affected"},{"version":"628329d52474323938a03826941e166bc7c8eff4","lessThan":"0e8115a7ed9a99ff9495615a575a6c0f43566d10","versionType":"git","status":"affected"},{"version":"628329d52474323938a03826941e166bc7c8eff4","lessThan":"f4cf878dcc4f6f02e7a25294bfaed4361264995e","versionType":"git","status":"affected"},{"version":"628329d52474323938a03826941e166bc7c8eff4","lessThan":"ca459e237bc49567649c56bc72e4c602fb92fd67","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/input/misc/ims-pcu.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"3.10","status":"affected"},{"version":"0","lessThan":"3.10","versionType":"semver","status":"unaffected"},{"version":"5.10.261","lessThanOrEqual":"5.10.*","versionType":"semver","status":"unaffected"},{"version":"5.15.212","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.178","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.97","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/08bf4b6ee28987570f4b3f1954427621fa291bf5","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/0e8115a7ed9a99ff9495615a575a6c0f43566d10","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/163c3e7a1de6b3d5c85edb3bdf4cf087382103b0","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/ab87cd7789d00f441f60a016cbcff35abe76513c","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/b5518c5632f3485849421b9c33b4db5ae6a54ed7","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/ca459e237bc49567649c56bc72e4c602fb92fd67","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/f4cf878dcc4f6f02e7a25294bfaed4361264995e","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/fa7f65c5315a25b310daae69ab527efd420e37fa","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-72075","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:21:17.410","lastModified":"2026-08-15T06:21:17.410","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nInput: ims-pcu - fix race condition in reset_device sysfs callback\n\nThe ims_pcu_reset_device() sysfs callback calls ims_pcu_execute_command()\nwithout acquiring pcu->cmd_mutex. This can lead to data races and\ncorruption of the shared command buffer if triggered concurrently with\nother commands.\n\nAcquire pcu->cmd_mutex before calling ims_pcu_execute_command()."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/input/misc/ims-pcu.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"628329d52474323938a03826941e166bc7c8eff4","lessThan":"0fb84b1a3cdc74c453abc5f961c7d318c267ea4c","versionType":"git","status":"affected"},{"version":"628329d52474323938a03826941e166bc7c8eff4","lessThan":"129187ec3f868829f61f6f07381ca72fe642d0b7","versionType":"git","status":"affected"},{"version":"628329d52474323938a03826941e166bc7c8eff4","lessThan":"54c2237fc69541c75fe4cd321622ebb8ecc3587f","versionType":"git","status":"affected"},{"version":"628329d52474323938a03826941e166bc7c8eff4","lessThan":"f516cba88bf952d847e5c96d0e87f17eaae7ee6f","versionType":"git","status":"affected"},{"version":"628329d52474323938a03826941e166bc7c8eff4","lessThan":"025955847e1500ced4719ac178beff6a3b2f0e3c","versionType":"git","status":"affected"},{"version":"628329d52474323938a03826941e166bc7c8eff4","lessThan":"411b8c4b274737c3bf08e1e025801161603cfffc","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/input/misc/ims-pcu.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"3.10","status":"affected"},{"version":"0","lessThan":"3.10","versionType":"semver","status":"unaffected"},{"version":"6.1.178","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.97","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/025955847e1500ced4719ac178beff6a3b2f0e3c","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/0fb84b1a3cdc74c453abc5f961c7d318c267ea4c","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/129187ec3f868829f61f6f07381ca72fe642d0b7","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/411b8c4b274737c3bf08e1e025801161603cfffc","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/54c2237fc69541c75fe4cd321622ebb8ecc3587f","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/f516cba88bf952d847e5c96d0e87f17eaae7ee6f","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-72076","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:21:17.537","lastModified":"2026-08-15T06:21:17.537","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nInput: ims-pcu - fix out-of-bounds read in ims_pcu_irq() debug logging\n\nThe debug logging in ims_pcu_irq() unconditionally prints data from\npcu->urb_in_buf. However, if the interrupt fired for pcu->urb_ctrl, the\nactual data resides in pcu->urb_ctrl_buf. If urb->actual_length for the\ncontrol URB exceeds pcu->max_in_size, this leads to an out-of-bounds\nread.\n\nFix this by printing from the correct buffer associated with the URB."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/input/misc/ims-pcu.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"628329d52474323938a03826941e166bc7c8eff4","lessThan":"4d2553e9a76a11500ec670cbe16b7fd3da4832de","versionType":"git","status":"affected"},{"version":"628329d52474323938a03826941e166bc7c8eff4","lessThan":"b746e853721dee91e4234c033d1b90f4605705bb","versionType":"git","status":"affected"},{"version":"628329d52474323938a03826941e166bc7c8eff4","lessThan":"e6153407d7edabc6ff98f0fda415d556c0bcb57a","versionType":"git","status":"affected"},{"version":"628329d52474323938a03826941e166bc7c8eff4","lessThan":"3fd7c0ace245334f2a0bd29fdcb680ad56e9b275","versionType":"git","status":"affected"},{"version":"628329d52474323938a03826941e166bc7c8eff4","lessThan":"20fbf3ca0259d00664d1ede88837e1f11b49a88e","versionType":"git","status":"affected"},{"version":"628329d52474323938a03826941e166bc7c8eff4","lessThan":"9c964fc9507aeab74376ba9f892cf84ad6950dfe","versionType":"git","status":"affected"},{"version":"628329d52474323938a03826941e166bc7c8eff4","lessThan":"f97bfc1a0766802a99167b3dc62d1ee7dca929fe","versionType":"git","status":"affected"},{"version":"628329d52474323938a03826941e166bc7c8eff4","lessThan":"403b0a6970b1084bb27907c0f8225801fdd0fe1d","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/input/misc/ims-pcu.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"3.10","status":"affected"},{"version":"0","lessThan":"3.10","versionType":"semver","status":"unaffected"},{"version":"5.10.261","lessThanOrEqual":"5.10.*","versionType":"semver","status":"unaffected"},{"version":"5.15.212","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.178","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.97","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/20fbf3ca0259d00664d1ede88837e1f11b49a88e","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/3fd7c0ace245334f2a0bd29fdcb680ad56e9b275","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/403b0a6970b1084bb27907c0f8225801fdd0fe1d","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/4d2553e9a76a11500ec670cbe16b7fd3da4832de","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/9c964fc9507aeab74376ba9f892cf84ad6950dfe","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/b746e853721dee91e4234c033d1b90f4605705bb","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/e6153407d7edabc6ff98f0fda415d556c0bcb57a","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/f97bfc1a0766802a99167b3dc62d1ee7dca929fe","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-72077","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:21:17.660","lastModified":"2026-08-15T06:21:17.660","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nInput: ims-pcu - fix firmware leak in async update\n\nThe firmware object was not being released if validation failed.\nUse __free(firmware) to ensure the firmware is always released."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/input/misc/ims-pcu.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"628329d52474323938a03826941e166bc7c8eff4","lessThan":"a5dd47ea3904dedb1ae7a5fe0e6b44a458f0c5ec","versionType":"git","status":"affected"},{"version":"628329d52474323938a03826941e166bc7c8eff4","lessThan":"1f7bdfbe791aacad77db87f044e78ef60a93ae0d","versionType":"git","status":"affected"},{"version":"628329d52474323938a03826941e166bc7c8eff4","lessThan":"99c428d7ef644d3e394f3072f905040c16dab18d","versionType":"git","status":"affected"},{"version":"628329d52474323938a03826941e166bc7c8eff4","lessThan":"47a9889a9325b87698b6d6eaf3187a9af6e4773d","versionType":"git","status":"affected"},{"version":"628329d52474323938a03826941e166bc7c8eff4","lessThan":"d48795b5cd6828d36b707e8d62fc9e5c90e004ab","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/input/misc/ims-pcu.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"3.10","status":"affected"},{"version":"0","lessThan":"3.10","versionType":"semver","status":"unaffected"},{"version":"6.6.148","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.97","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/1f7bdfbe791aacad77db87f044e78ef60a93ae0d","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/47a9889a9325b87698b6d6eaf3187a9af6e4773d","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/99c428d7ef644d3e394f3072f905040c16dab18d","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/a5dd47ea3904dedb1ae7a5fe0e6b44a458f0c5ec","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/d48795b5cd6828d36b707e8d62fc9e5c90e004ab","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-72078","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:21:17.763","lastModified":"2026-08-15T06:21:17.763","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nInput: ims-pcu - validate control endpoint type\n\nThe driver currently assumes that the first endpoint of the control\ninterface is an interrupt IN endpoint without verifying it. A malicious\ndevice could provide a different endpoint type, which would then be\npassed to usb_fill_int_urb(), potentially leading to kernel warnings\nor undefined behavior.\n\nVerify that the control endpoint is an interrupt IN endpoint."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/input/misc/ims-pcu.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"628329d52474323938a03826941e166bc7c8eff4","lessThan":"5de5075a1f26166f172b6687cb66810a9b61e3eb","versionType":"git","status":"affected"},{"version":"628329d52474323938a03826941e166bc7c8eff4","lessThan":"7960d99332e03705ec622d92f31e0c77de8baac6","versionType":"git","status":"affected"},{"version":"628329d52474323938a03826941e166bc7c8eff4","lessThan":"5b96b4da96313dd799a3a40dcfd598d2e2c19217","versionType":"git","status":"affected"},{"version":"628329d52474323938a03826941e166bc7c8eff4","lessThan":"aa1885f87e60c80e59e50ffd5fb096bf02c83e05","versionType":"git","status":"affected"},{"version":"628329d52474323938a03826941e166bc7c8eff4","lessThan":"a630508a09b0c05f14bc0843ed409221a93751aa","versionType":"git","status":"affected"},{"version":"628329d52474323938a03826941e166bc7c8eff4","lessThan":"c8d3d83f2eaaf7659de76e8d44e8fc88ee346042","versionType":"git","status":"affected"},{"version":"628329d52474323938a03826941e166bc7c8eff4","lessThan":"cbfa059dfb48b9aa322e34fd44a093d9ca29ad7e","versionType":"git","status":"affected"},{"version":"628329d52474323938a03826941e166bc7c8eff4","lessThan":"baf56975806534268e24acf9a8abb1c447ce11e9","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/input/misc/ims-pcu.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"3.10","status":"affected"},{"version":"0","lessThan":"3.10","versionType":"semver","status":"unaffected"},{"version":"5.10.261","lessThanOrEqual":"5.10.*","versionType":"semver","status":"unaffected"},{"version":"5.15.212","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.178","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.97","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/5b96b4da96313dd799a3a40dcfd598d2e2c19217","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/5de5075a1f26166f172b6687cb66810a9b61e3eb","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/7960d99332e03705ec622d92f31e0c77de8baac6","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/a630508a09b0c05f14bc0843ed409221a93751aa","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/aa1885f87e60c80e59e50ffd5fb096bf02c83e05","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/baf56975806534268e24acf9a8abb1c447ce11e9","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/c8d3d83f2eaaf7659de76e8d44e8fc88ee346042","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/cbfa059dfb48b9aa322e34fd44a093d9ca29ad7e","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-72079","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:21:17.893","lastModified":"2026-08-15T06:21:17.893","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nInput: ims-pcu - fix use-after-free and double-free in disconnect\n\nims_pcu_disconnect() only intended to perform cleanup when the primary\n(control) interface is unbound. However, it currently relies on the\ninterface class to distinguish between control and data interfaces.\nA malicious device could present a data interface with the same class\nas the control interface, leading to premature cleanup and potential\nuse-after-free or double-free.\n\nSwitch to verifying that the interface being disconnected is indeed\nthe control interface."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/input/misc/ims-pcu.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"628329d52474323938a03826941e166bc7c8eff4","lessThan":"315f269ea04bc1477ab9bf351e939623d12a1621","versionType":"git","status":"affected"},{"version":"628329d52474323938a03826941e166bc7c8eff4","lessThan":"293388e42e5c0865204de6f36bfb8662156fce3b","versionType":"git","status":"affected"},{"version":"628329d52474323938a03826941e166bc7c8eff4","lessThan":"921abbb33887052e46b1b77299f87a3c741dc580","versionType":"git","status":"affected"},{"version":"628329d52474323938a03826941e166bc7c8eff4","lessThan":"6a6c373e6a82eddc522342c8a8db7072c65f2b56","versionType":"git","status":"affected"},{"version":"628329d52474323938a03826941e166bc7c8eff4","lessThan":"a4b3f4d42fbf58f06f0d49e37a9d0d9392eca338","versionType":"git","status":"affected"},{"version":"628329d52474323938a03826941e166bc7c8eff4","lessThan":"6aacc18004b1a915ccb8a829d30279a37988066e","versionType":"git","status":"affected"},{"version":"628329d52474323938a03826941e166bc7c8eff4","lessThan":"bf0b58ba489d0bdaa18c7dd8beeaeb954dd7dbb7","versionType":"git","status":"affected"},{"version":"628329d52474323938a03826941e166bc7c8eff4","lessThan":"462a999917755a3bf77448dfd64307963cf0a9f0","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/input/misc/ims-pcu.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"3.10","status":"affected"},{"version":"0","lessThan":"3.10","versionType":"semver","status":"unaffected"},{"version":"5.10.261","lessThanOrEqual":"5.10.*","versionType":"semver","status":"unaffected"},{"version":"5.15.212","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.178","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.97","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/293388e42e5c0865204de6f36bfb8662156fce3b","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/315f269ea04bc1477ab9bf351e939623d12a1621","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/462a999917755a3bf77448dfd64307963cf0a9f0","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/6a6c373e6a82eddc522342c8a8db7072c65f2b56","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/6aacc18004b1a915ccb8a829d30279a37988066e","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/921abbb33887052e46b1b77299f87a3c741dc580","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/a4b3f4d42fbf58f06f0d49e37a9d0d9392eca338","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/bf0b58ba489d0bdaa18c7dd8beeaeb954dd7dbb7","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-72080","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:21:18.027","lastModified":"2026-08-15T06:21:18.027","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nfs/resctrl: Fix use-after-free during unmount\n\nDuring unmount or failure teardown all mon_data structures that contain\nmonitoring event file private data are freed after which kernfs nodes are\nremoved. However, the RDT_DELETED flag is never set for the statically\nallocated default resource group.\n\nA concurrent reader of an event file associated with the default resource\ngroup may, after dropping kernfs active protection, block on rdtgroup_mutex\nwhile unmount proceeds to free the file private data and destroy the kernfs\nnode without waiting for the reader.\n\nWhen the mutex is released, the reader wakes up, observes that RDT_DELETED\nis not set for the default group, and dereferences the already-freed\nfile private data.\n\nThe scenario can be depicted as follows:\n  CPU0                                      CPU1\n   /*\n    * Default resource group's\n    * monitoring data accessible via\n    * kernfs file with kernfs_node::priv\n    * pointing to a struct mon_data.\n    * User opens the file for reading.\n    */\n   rdtgroup_mondata_show()                 /* arch encounters fatal error */\n    rdtgroup_kn_lock_live()                 resctrl_exit()\n     atomic_inc(&rdtgroup_default.waitcount) cpus_read_lock()\n     kernfs_break_active_protection(kn)      mutex_lock(&rdtgroup_mutex)\n     cpus_read_lock()                        resctrl_fs_teardown()\n     mutex_lock(&rdtgroup_mutex)              rmdir_all_sub()\n                                              mon_put_kn_priv()\n                                               /* Delete all mon_data structures */\n                                              rdtgroup_destroy_root()\n                                               kernfs_destroy_root()\n                                               rdtgroup_default.kn = NULL\n                                             mutex_unlock(&rdtgroup_mutex)\n     /*\n      * rdtgroup_default.flags is empty so\n      * rdtgroup_kn_lock_live() returns\n      * &rdtgroup_default\n      */\n     md = of->kn->priv;\n\n     /* md points to freed mon_data */\n\nSet RDT_DELETED for the default group unconditionally since the flag does\nnot lead to the freeing of this statically allocated group.\n\nDo not allow a new resctrl mount if there are any waiters on default group\nof previous mount. A new mount will re-initialize the default group that\nwould appear to waiters from previous mount as though the default group is\naccessible causing them to access the mon_data structures from the previous\nmount that have been removed."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["fs/resctrl/rdtgroup.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"2a65660385444e9d9deffe995c71ee20443ef76e","lessThan":"7b7bb07efe41bb646a93c4624aa2bb35df190342","versionType":"git","status":"affected"},{"version":"2a65660385444e9d9deffe995c71ee20443ef76e","lessThan":"7d330a1d663381579b9d5dafa642b1b3158a0ce2","versionType":"git","status":"affected"},{"version":"2a65660385444e9d9deffe995c71ee20443ef76e","lessThan":"52fce648607e0d6a76eeb443d78708c49df1c554","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["fs/resctrl/rdtgroup.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.16","status":"affected"},{"version":"0","lessThan":"6.16","versionType":"semver","status":"unaffected"},{"version":"6.18.42","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc3","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/52fce648607e0d6a76eeb443d78708c49df1c554","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/7b7bb07efe41bb646a93c4624aa2bb35df190342","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/7d330a1d663381579b9d5dafa642b1b3158a0ce2","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-72081","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:21:18.133","lastModified":"2026-08-15T06:21:18.133","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nscsi: elx: efct: Fix I/O leak on unsupported additional CDB\n\nefct_dispatch_fcp_cmd() allocates an efct_io before dispatching an\nunsolicited FCP command. If the command has an unsupported additional\nCDB, the function returns -EIO before handing the IO to the SCSI layer.\n\nFree the allocated IO before returning from this error path."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/scsi/elx/efct/efct_unsol.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"f45ae6aac0a077ca15a6e7baae0a62eef099ea7d","lessThan":"42a391d508e1f52fda5d81344e100a53c00898e3","versionType":"git","status":"affected"},{"version":"f45ae6aac0a077ca15a6e7baae0a62eef099ea7d","lessThan":"9d479f50a6067954259414aa66d816c7df081286","versionType":"git","status":"affected"},{"version":"f45ae6aac0a077ca15a6e7baae0a62eef099ea7d","lessThan":"8c689a8f229223cec4a821c65cfe40f8e8c56470","versionType":"git","status":"affected"},{"version":"f45ae6aac0a077ca15a6e7baae0a62eef099ea7d","lessThan":"235159f75ab6f95484494db4cc031663e5ee4680","versionType":"git","status":"affected"},{"version":"f45ae6aac0a077ca15a6e7baae0a62eef099ea7d","lessThan":"df87532e9212238509f23effd0ca39d9c3062d21","versionType":"git","status":"affected"},{"version":"f45ae6aac0a077ca15a6e7baae0a62eef099ea7d","lessThan":"94cbfed191248dc88c23fc881119bb399486ddfd","versionType":"git","status":"affected"},{"version":"f45ae6aac0a077ca15a6e7baae0a62eef099ea7d","lessThan":"9cb2d5291dbfe7bed565ead3337047dee9ed1064","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/scsi/elx/efct/efct_unsol.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"5.14","status":"affected"},{"version":"0","lessThan":"5.14","versionType":"semver","status":"unaffected"},{"version":"5.15.212","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.178","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.97","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc4","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/235159f75ab6f95484494db4cc031663e5ee4680","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/42a391d508e1f52fda5d81344e100a53c00898e3","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/8c689a8f229223cec4a821c65cfe40f8e8c56470","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/94cbfed191248dc88c23fc881119bb399486ddfd","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/9cb2d5291dbfe7bed565ead3337047dee9ed1064","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/9d479f50a6067954259414aa66d816c7df081286","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/df87532e9212238509f23effd0ca39d9c3062d21","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-72082","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:21:18.250","lastModified":"2026-08-15T06:21:18.250","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nscsi: elx: efct: Fix refcount leak in efct_hw_io_abort()\n\nWhen efct_hw_reqtag_alloc() fails in efct_hw_io_abort(), the error path\nreturns -ENOSPC without releasing the reference obtained via\nkref_get_unless_zero() earlier in the function. All other error paths\ncorrectly drop the reference. This causes a permanent reference leak on the\nio_to_abort object.\n\nAdditionally, the abort_in_progress flag is left set to true on this path,\nwhich means future abort attempts for the same I/O will immediately return\n-EINPROGRESS even though the abort was never submitted, effectively\nblocking recovery.\n\nFix this by adding the missing kref_put() call and reset abort_in_progress\nto false, matching the cleanup done in the efct_hw_wq_write() failure path\nbelow."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/scsi/elx/efct/efct_hw.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"63de51327a64c74e85611a0161eaae71256a3b6d","lessThan":"cf97ea7b164a1881c7219f5222219c9d0fac4204","versionType":"git","status":"affected"},{"version":"63de51327a64c74e85611a0161eaae71256a3b6d","lessThan":"1c6e186c722cfa9a58ebe841f91ab2ddf8570cc7","versionType":"git","status":"affected"},{"version":"63de51327a64c74e85611a0161eaae71256a3b6d","lessThan":"62cf39a9770a6f29df59fd0edb0a05234a8b07f2","versionType":"git","status":"affected"},{"version":"63de51327a64c74e85611a0161eaae71256a3b6d","lessThan":"faa59add4808fbf92e7d15bfd8770d2682c2b953","versionType":"git","status":"affected"},{"version":"63de51327a64c74e85611a0161eaae71256a3b6d","lessThan":"9b871369cbb4532f6715e044d6b9c4ceb036e5b6","versionType":"git","status":"affected"},{"version":"63de51327a64c74e85611a0161eaae71256a3b6d","lessThan":"747eaead2db298abfda2aa505f6d03775b40fe5f","versionType":"git","status":"affected"},{"version":"63de51327a64c74e85611a0161eaae71256a3b6d","lessThan":"2c007acf7b31c39c08ce4959451ad00b19be4c1f","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/scsi/elx/efct/efct_hw.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"5.14","status":"affected"},{"version":"0","lessThan":"5.14","versionType":"semver","status":"unaffected"},{"version":"5.15.212","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.178","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.97","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc4","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/1c6e186c722cfa9a58ebe841f91ab2ddf8570cc7","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/2c007acf7b31c39c08ce4959451ad00b19be4c1f","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/62cf39a9770a6f29df59fd0edb0a05234a8b07f2","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/747eaead2db298abfda2aa505f6d03775b40fe5f","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/9b871369cbb4532f6715e044d6b9c4ceb036e5b6","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/cf97ea7b164a1881c7219f5222219c9d0fac4204","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/faa59add4808fbf92e7d15bfd8770d2682c2b953","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-72083","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:21:20.167","lastModified":"2026-08-15T06:21:20.167","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nscsi: target: core: Fix iSCSI ISID use-after-free in REGISTER AND MOVE\n\ncore_scsi3_emulate_pro_register_and_move() maps the PERSISTENT RESERVE OUT\nparameter list with transport_kmap_data_sg() and parses the destination\nTransportID with target_parse_pr_out_transport_id(). For an iSCSI\nTransportID (FORMAT CODE 01b), iscsi_parse_pr_out_transport_id() returns\nthe ISID in iport_ptr as a raw pointer into that mapped buffer.\n\nThe function then unmaps the buffer with transport_kunmap_data_sg() before\ndereferencing iport_ptr in strcmp(), __core_scsi3_locate_pr_reg() and\ncore_scsi3_alloc_registration(). When the parameter list spans more than\none page (PARAMETER LIST LENGTH > 4096), transport_kmap_data_sg() uses\nvmap() and transport_kunmap_data_sg() does vunmap(), so the kernel virtual\naddress backing iport_ptr is torn down and every subsequent dereference is\na use-after-free read of the unmapped region.\n\nKeep the parameter list mapped until iport_ptr is no longer needed: drop\nthe early transport_kunmap_data_sg() and unmap once on the success path,\nright before returning. The error paths already unmap through the existing\n\"if (buf) transport_kunmap_data_sg(cmd)\" at the out: label, which now runs\non every post-map error exit because buf is no longer cleared early. Only\nreads of the mapping happen while spinlocks are held; the map and unmap\ncalls remain outside any lock. The sibling caller\ncore_scsi3_decode_spec_i_port() already uses the buffer before unmapping it\nand is left unchanged."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/target/target_core_pr.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"4949314c7283ea4f9ade182ca599583b89f7edd6","lessThan":"7d56f5c868d92c9d504a34a3ea450bce481c7f63","versionType":"git","status":"affected"},{"version":"4949314c7283ea4f9ade182ca599583b89f7edd6","lessThan":"59a2a5a37dc49a641ad6bc64aee34e5a61025ffd","versionType":"git","status":"affected"},{"version":"4949314c7283ea4f9ade182ca599583b89f7edd6","lessThan":"9f8076cc73dfa6b10155978c160587e986b22169","versionType":"git","status":"affected"},{"version":"4949314c7283ea4f9ade182ca599583b89f7edd6","lessThan":"a040004846f1fbe687f6ec76d9ccc27b4ead42e4","versionType":"git","status":"affected"},{"version":"4949314c7283ea4f9ade182ca599583b89f7edd6","lessThan":"05b3e37433cf2eaf8867f1c16528aa347bb212ab","versionType":"git","status":"affected"},{"version":"4949314c7283ea4f9ade182ca599583b89f7edd6","lessThan":"cb7bdae7fba404852ade34b0c1445fbaf3e54fbb","versionType":"git","status":"affected"},{"version":"4949314c7283ea4f9ade182ca599583b89f7edd6","lessThan":"ef2ee18fec92088c7d8877baf7674e89389ccd66","versionType":"git","status":"affected"},{"version":"4949314c7283ea4f9ade182ca599583b89f7edd6","lessThan":"fda6a1f3c3d7047b5ce5654487649c2daa738bfc","versionType":"git","status":"affected"},{"version":"d2227f84ba0e97906153ac83db13213fb2e3938d","versionType":"git","status":"affected"},{"version":"3.2.9","lessThan":"3.3","versionType":"semver","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/target/target_core_pr.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"3.3","status":"affected"},{"version":"0","lessThan":"3.3","versionType":"semver","status":"unaffected"},{"version":"5.10.261","lessThanOrEqual":"5.10.*","versionType":"semver","status":"unaffected"},{"version":"5.15.212","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.178","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.97","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc4","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/05b3e37433cf2eaf8867f1c16528aa347bb212ab","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/59a2a5a37dc49a641ad6bc64aee34e5a61025ffd","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/7d56f5c868d92c9d504a34a3ea450bce481c7f63","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/9f8076cc73dfa6b10155978c160587e986b22169","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/a040004846f1fbe687f6ec76d9ccc27b4ead42e4","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/cb7bdae7fba404852ade34b0c1445fbaf3e54fbb","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/ef2ee18fec92088c7d8877baf7674e89389ccd66","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/fda6a1f3c3d7047b5ce5654487649c2daa738bfc","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-72084","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:21:22.333","lastModified":"2026-08-15T06:21:22.333","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nscsi: target: Bound PR-OUT TransportID parsing to the received buffer\n\ncore_scsi3_decode_spec_i_port() and core_scsi3_emulate_register_and_move()\nhand the raw PERSISTENT RESERVE OUT parameter buffer to\ntarget_parse_pr_out_transport_id() without telling it how many bytes are\nvalid.  For an iSCSI TransportID (FORMAT CODE 01b),\niscsi_parse_pr_out_transport_id() locates the \",i,0x\" ISID separator with\nan unbounded strstr() (and on the error path prints the name with a further\nunbounded \"%s\").  An initiator can submit a TransportID whose iSCSI name\ncontains neither a \",i,0x\" substring nor a NUL terminator, filling the\nparameter list to its end, so the scan runs off the end of the buffer.\n\nWhen the parameter list spans more than one page the buffer is a multi-page\nvmap (transport_kmap_data_sg()), so the over-read walks into the trailing\nvmalloc guard page and oopses (KASAN: vmalloc-out-of-bounds in strstr).  It\nis reachable by any fabric that delivers a PR OUT to a device exported\nthrough an iSCSI TPG, including a guest via vhost-scsi.\n\nPass the number of received bytes down to the parser and validate the iSCSI\nTransportID's own self-described length (ADDITIONAL LENGTH + 4) once, up\nfront: reject it if it is below the spc4r17 minimum or larger than the\nreceived buffer, then bound the separator search, the ISID walk and the\nname copy by that length.  This is the length check the callers already\nperform after the parse (core_scsi3_decode_spec_i_port() compares tid_len\nagainst tpdl, core_scsi3_emulate_register_and_move() validates it against\ndata_length), moved ahead of the scan.  Also drop the unbounded \"%s\" of the\nunterminated name.\n\nAdd per-format explicit name-length checks before copying into i_str,\nrather than silently truncating with min_t: for FORMAT CODE 00b reject if\nthe descriptor body (tid_len - 4 bytes) cannot fit in\ni_str[TRANSPORT_IQN_LEN]; for FORMAT CODE 01b reject if the name portion\n(from &buf[4] up to the separator) cannot fit.  Both checks make the bounds\nintent explicit at each format branch.\n\nWhile here, also reject a FORMAT CODE 01b TransportID whose \",i,0x\"\nseparator sits at the very end of the descriptor: that leaves an empty ISID\nand points the returned port nexus pointer at buf + tid_len, one past the\ndescriptor, which the registration code (__core_scsi3_locate_pr_reg(),\n__core_scsi3_alloc_registration()) then dereferences as the ISID string --\nthe same over-read of the parameter buffer for a malformed descriptor."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/target/target_core_fabric_lib.c","drivers/target/target_core_internal.h","drivers/target/target_core_pr.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"c66ac9db8d4ad9994a02b3e933ea2ccc643e1fe5","lessThan":"842248047ef28dbf3b3f7f49a0ec315054d4dab8","versionType":"git","status":"affected"},{"version":"c66ac9db8d4ad9994a02b3e933ea2ccc643e1fe5","lessThan":"03fbc7de8d5e85fc8420e57e8304c855efd453ab","versionType":"git","status":"affected"},{"version":"c66ac9db8d4ad9994a02b3e933ea2ccc643e1fe5","lessThan":"6ca5de8782e67573a61a6736b6dc0ffe58dcdf59","versionType":"git","status":"affected"},{"version":"c66ac9db8d4ad9994a02b3e933ea2ccc643e1fe5","lessThan":"9298078a8f7d8181a04614a34ab655ccdf038204","versionType":"git","status":"affected"},{"version":"c66ac9db8d4ad9994a02b3e933ea2ccc643e1fe5","lessThan":"004ccd2d3b4ac36a300e05e01df152e5c02a5a82","versionType":"git","status":"affected"},{"version":"c66ac9db8d4ad9994a02b3e933ea2ccc643e1fe5","lessThan":"555a89846ed888d7401b3f7200934c0fbedcbb46","versionType":"git","status":"affected"},{"version":"c66ac9db8d4ad9994a02b3e933ea2ccc643e1fe5","lessThan":"d04a179085c262c9ed577d0a4cbc6482ff1fd9a3","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/target/target_core_fabric_lib.c","drivers/target/target_core_internal.h","drivers/target/target_core_pr.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"2.6.38","status":"affected"},{"version":"0","lessThan":"2.6.38","versionType":"semver","status":"unaffected"},{"version":"5.15.212","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.178","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.97","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc4","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/004ccd2d3b4ac36a300e05e01df152e5c02a5a82","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/03fbc7de8d5e85fc8420e57e8304c855efd453ab","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/555a89846ed888d7401b3f7200934c0fbedcbb46","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/6ca5de8782e67573a61a6736b6dc0ffe58dcdf59","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/842248047ef28dbf3b3f7f49a0ec315054d4dab8","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/9298078a8f7d8181a04614a34ab655ccdf038204","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/d04a179085c262c9ed577d0a4cbc6482ff1fd9a3","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-72085","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:21:22.470","lastModified":"2026-08-15T06:21:22.470","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nscsi: xen: scsiback: Free unsubmitted command instead of double-putting it\n\nscsiback_get_pend_req() obtains a command tag and returns a vscsibk_pend\nwhose embedded se_cmd has only been memset to 0, so its cmd_kref is 0;\nthe se_cmd is initialised (kref_init() via target_init_cmd()) only\nlater, in scsiback_cmd_exec(), on the successful VSCSIIF_ACT_SCSI_CDB\npath. The two error paths in scsiback_do_cmd_fn() taken before the\ncommand is submitted -- a failed scsiback_gnttab_data_map() and an\nunknown ring_req.act -- call\ntransport_generic_free_cmd(&pending_req->se_cmd, 0), which kref_put()s a\nrefcount of 0. That underflows it (\"refcount_t: underflow;\nuse-after-free\") and, as the release function is not run, leaks the\ncommand tag.\n\nImpact: a pvSCSI guest can leak every command tag of a LUN's session,\nstopping the LUN, by submitting requests with a bad grant reference or\nan unknown request type; under panic_on_warn the refcount underflow\npanics the host.\n\nAdd a helper that just returns the tag with target_free_tag() and sends\nthe error response. It frees the tag while the v2p reference still pins\nthe session, and snapshots the response fields beforehand because\nfreeing the tag can let another ring reuse the pending_req slot."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/xen/xen-scsiback.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"2dbcdf33dbf61f44b29adb52338282c3d7840d0e","lessThan":"9c0f6894982b1f13bda220707497b25ac9c95bdb","versionType":"git","status":"affected"},{"version":"2dbcdf33dbf61f44b29adb52338282c3d7840d0e","lessThan":"a13b789497a7fdd27d4d63f5c69d23db706ef0fe","versionType":"git","status":"affected"},{"version":"2dbcdf33dbf61f44b29adb52338282c3d7840d0e","lessThan":"fa588f28401102652068c4cc75e135507f4b5106","versionType":"git","status":"affected"},{"version":"2dbcdf33dbf61f44b29adb52338282c3d7840d0e","lessThan":"fcd64d4d97af5d9736f31040f8ed8cd4c17e4c45","versionType":"git","status":"affected"},{"version":"2dbcdf33dbf61f44b29adb52338282c3d7840d0e","lessThan":"f1516c56ac540da1769f264c3cfefe4499548a5d","versionType":"git","status":"affected"},{"version":"2dbcdf33dbf61f44b29adb52338282c3d7840d0e","lessThan":"1e97c404e44991fb087c38ccd7414f2d326f9b74","versionType":"git","status":"affected"},{"version":"2dbcdf33dbf61f44b29adb52338282c3d7840d0e","lessThan":"ca978f8a93d4d36841839bf2847d29b88c2591d6","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/xen/xen-scsiback.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"4.6","status":"affected"},{"version":"0","lessThan":"4.6","versionType":"semver","status":"unaffected"},{"version":"5.15.212","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.178","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.97","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc4","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/1e97c404e44991fb087c38ccd7414f2d326f9b74","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/9c0f6894982b1f13bda220707497b25ac9c95bdb","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/a13b789497a7fdd27d4d63f5c69d23db706ef0fe","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/ca978f8a93d4d36841839bf2847d29b88c2591d6","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/f1516c56ac540da1769f264c3cfefe4499548a5d","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/fa588f28401102652068c4cc75e135507f4b5106","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/fcd64d4d97af5d9736f31040f8ed8cd4c17e4c45","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-72086","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:21:22.593","lastModified":"2026-08-15T06:21:22.593","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nscsi: xen: scsiback: Free the command tag on the TMR submit-failure path\n\nscsiback_device_action() obtains a command tag in\nscsiback_get_pend_req() and submits a task-management request with\ntarget_submit_tmr(). When target_submit_tmr() fails it returns < 0 and\nscsiback jumps to the err: label, which sends a response but frees\nnothing, leaking the tag.\n\nImpact: a pvSCSI guest can leak the command tags of a LUN's session,\nstopping the LUN, by issuing VSCSIIF_ACT_SCSI_ABORT or RESET requests\nwhenever target_submit_tmr() fails.\n\ntransport_generic_free_cmd() cannot be used here. By the time\ntarget_submit_tmr() returns an error it has already run\n__target_init_cmd() (so se_cmd->cmd_kref is one, not zero), and on its\ntarget_get_sess_cmd() error path it has freed se_cmd->se_tmr_req via\ncore_tmr_release_req() while leaving SCF_SCSI_TMR_CDB set and the\npointer dangling. Letting the command release run target_free_cmd_mem()\nwould then double-free se_tmr_req.\n\nUse the same helper, which returns just the tag, on this path too."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/xen/xen-scsiback.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"2dbcdf33dbf61f44b29adb52338282c3d7840d0e","lessThan":"4567ce79fe2f84c3dcc3a91b22a377cf482d33ad","versionType":"git","status":"affected"},{"version":"2dbcdf33dbf61f44b29adb52338282c3d7840d0e","lessThan":"6c01f0439098f00a64b246dc27479602201382f7","versionType":"git","status":"affected"},{"version":"2dbcdf33dbf61f44b29adb52338282c3d7840d0e","lessThan":"18d4f86816592586b38513543b5e1f9553bc271f","versionType":"git","status":"affected"},{"version":"2dbcdf33dbf61f44b29adb52338282c3d7840d0e","lessThan":"fbc1bdede66d0f2cde83b75d6524ce1a815bb69f","versionType":"git","status":"affected"},{"version":"2dbcdf33dbf61f44b29adb52338282c3d7840d0e","lessThan":"255fb7b0cdc947b1c01929c7f133281342a3a6b5","versionType":"git","status":"affected"},{"version":"2dbcdf33dbf61f44b29adb52338282c3d7840d0e","lessThan":"1357fb32d42ad8da193e6da285f09e6452feabda","versionType":"git","status":"affected"},{"version":"2dbcdf33dbf61f44b29adb52338282c3d7840d0e","lessThan":"66aefc277ebb796ec285d550305535dc3fc0179f","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/xen/xen-scsiback.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"4.6","status":"affected"},{"version":"0","lessThan":"4.6","versionType":"semver","status":"unaffected"},{"version":"5.15.212","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.178","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.97","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc4","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/1357fb32d42ad8da193e6da285f09e6452feabda","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/18d4f86816592586b38513543b5e1f9553bc271f","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/255fb7b0cdc947b1c01929c7f133281342a3a6b5","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/4567ce79fe2f84c3dcc3a91b22a377cf482d33ad","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/66aefc277ebb796ec285d550305535dc3fc0179f","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/6c01f0439098f00a64b246dc27479602201382f7","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/fbc1bdede66d0f2cde83b75d6524ce1a815bb69f","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-72087","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:21:22.723","lastModified":"2026-08-15T06:21:22.723","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nscsi: lpfc: Fix memory leak in lpfc_sli4_driver_resource_setup()\n\nThe memory allocated for mboxq using mempool_alloc() is not freed in\nsome of the early exit error paths. Fix that by moving the\nmempool_free() call to an earlier point after last use."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/scsi/lpfc/lpfc_init.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"d79c9e9d4b3d9330ee38f392a7c98e0fc494f7f8","lessThan":"299f5baa1321a0951cc3ebbacc72b67433a65391","versionType":"git","status":"affected"},{"version":"d79c9e9d4b3d9330ee38f392a7c98e0fc494f7f8","lessThan":"c3f4e407661542d1d284fc889cf9f27afd11b3d3","versionType":"git","status":"affected"},{"version":"d79c9e9d4b3d9330ee38f392a7c98e0fc494f7f8","lessThan":"25cac8a302626f59ca84fa3339e2506c3ac761bc","versionType":"git","status":"affected"},{"version":"d79c9e9d4b3d9330ee38f392a7c98e0fc494f7f8","lessThan":"ed08497977820e002a62cb114440f365cc7a087f","versionType":"git","status":"affected"},{"version":"d79c9e9d4b3d9330ee38f392a7c98e0fc494f7f8","lessThan":"0ce5a37f7ddf2fc12210e8700350274da79fbb3a","versionType":"git","status":"affected"},{"version":"d79c9e9d4b3d9330ee38f392a7c98e0fc494f7f8","lessThan":"1bd28625e25be549ee7c47532e7c3ef91c682410","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/scsi/lpfc/lpfc_init.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"5.4","status":"affected"},{"version":"0","lessThan":"5.4","versionType":"semver","status":"unaffected"},{"version":"6.1.178","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.97","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc4","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/0ce5a37f7ddf2fc12210e8700350274da79fbb3a","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/1bd28625e25be549ee7c47532e7c3ef91c682410","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/25cac8a302626f59ca84fa3339e2506c3ac761bc","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/299f5baa1321a0951cc3ebbacc72b67433a65391","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/c3f4e407661542d1d284fc889cf9f27afd11b3d3","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/ed08497977820e002a62cb114440f365cc7a087f","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-72088","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:21:22.843","lastModified":"2026-08-15T06:21:22.843","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nscsi: hpsa: Fix DMA mapping leak on IOACCEL2 reset path\n\nIf phys_disk->in_reset is set, the function returns directly without\nundoing the resources acquired for the command. Add the missing error\ncleanup by unmapping the IOACCEL2 SG chain block when needed, unmapping\nthe SCSI command, and dropping the outstanding IOACCEL command count\nbefore returning."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/scsi/hpsa.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"c5dfd106414f3e038fee5c6f0800fd55ed07b41d","lessThan":"fca5edd748f00e87f2dd55a6333722b46af30e74","versionType":"git","status":"affected"},{"version":"c5dfd106414f3e038fee5c6f0800fd55ed07b41d","lessThan":"fb40928c59329a50eadb3ce8bfd7a67f490a6212","versionType":"git","status":"affected"},{"version":"c5dfd106414f3e038fee5c6f0800fd55ed07b41d","lessThan":"018cbce6ee158244bb76cf638e8e3054e240aea9","versionType":"git","status":"affected"},{"version":"c5dfd106414f3e038fee5c6f0800fd55ed07b41d","lessThan":"a61de4d7e22a9ab9a90094d0e180b378e09a1d2c","versionType":"git","status":"affected"},{"version":"c5dfd106414f3e038fee5c6f0800fd55ed07b41d","lessThan":"e7bde072cceefc564413b46d64017c47a2e9977d","versionType":"git","status":"affected"},{"version":"c5dfd106414f3e038fee5c6f0800fd55ed07b41d","lessThan":"d495b403d5b357dfe506b963bd7a78ecd5c7b667","versionType":"git","status":"affected"},{"version":"c5dfd106414f3e038fee5c6f0800fd55ed07b41d","lessThan":"782e1bf48672be44265c48e14602696c3c8ed904","versionType":"git","status":"affected"},{"version":"c5dfd106414f3e038fee5c6f0800fd55ed07b41d","lessThan":"e166bafc483e927150cb9b5f286c9191ea0df84e","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/scsi/hpsa.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"5.3","status":"affected"},{"version":"0","lessThan":"5.3","versionType":"semver","status":"unaffected"},{"version":"5.10.261","lessThanOrEqual":"5.10.*","versionType":"semver","status":"unaffected"},{"version":"5.15.212","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.178","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.97","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc4","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/018cbce6ee158244bb76cf638e8e3054e240aea9","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/782e1bf48672be44265c48e14602696c3c8ed904","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/a61de4d7e22a9ab9a90094d0e180b378e09a1d2c","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/d495b403d5b357dfe506b963bd7a78ecd5c7b667","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/e166bafc483e927150cb9b5f286c9191ea0df84e","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/e7bde072cceefc564413b46d64017c47a2e9977d","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/fb40928c59329a50eadb3ce8bfd7a67f490a6212","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/fca5edd748f00e87f2dd55a6333722b46af30e74","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-72089","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:21:22.980","lastModified":"2026-08-15T06:21:22.980","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\naccel/ivpu: Reject firmware log with size smaller than header\n\nfw_log_from_bo() validates the tracing buffer header_size and that the\nlog fits within the BO, but never checks that log->size is at least\nlog->header_size. fw_log_print_buffer() then computes:\n\n  u32 data_size = log->size - log->header_size;\n\nwhich underflows to a near-U32_MAX value when firmware reports a log whose\nsize is smaller than its header. That huge data_size defeats the\nlog_start/log_end bounds clamps added by commit dd1311bcf0e6 (\"accel/ivpu:\nAdd bounds checks for firmware log indices\"), so fw_log_print_lines() reads\nfar past the small real data region of the BO. A size of 0 also makes\nfw_log_from_bo() advance the offset by 0, causing the callers to loop\nforever on the same header.\n\nReject logs whose size is smaller than the header (which also rejects\nsize == 0)."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/accel/ivpu/ivpu_fw_log.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"d4e4257afa6ed5205eda993180401fc2c20e4b60","lessThan":"5592a207e158b738d9c1d27f208dbbea13ae7606","versionType":"git","status":"affected"},{"version":"d4e4257afa6ed5205eda993180401fc2c20e4b60","lessThan":"dc9a1cda2e46d0254730a6f93cfe48532895f33c","versionType":"git","status":"affected"},{"version":"d4e4257afa6ed5205eda993180401fc2c20e4b60","lessThan":"257321a1c036da417f5d9c47b95c7e58f62bf263","versionType":"git","status":"affected"},{"version":"d4e4257afa6ed5205eda993180401fc2c20e4b60","lessThan":"6920e62be4c969a68ce4ebc59da68c6cbc9512e5","versionType":"git","status":"affected"},{"version":"d4e4257afa6ed5205eda993180401fc2c20e4b60","lessThan":"ddb44baed257560f192b145ed36cf8c0a412de47","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/accel/ivpu/ivpu_fw_log.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.6","status":"affected"},{"version":"0","lessThan":"6.6","versionType":"semver","status":"unaffected"},{"version":"6.6.148","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.97","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc4","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/257321a1c036da417f5d9c47b95c7e58f62bf263","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/5592a207e158b738d9c1d27f208dbbea13ae7606","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/6920e62be4c969a68ce4ebc59da68c6cbc9512e5","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/dc9a1cda2e46d0254730a6f93cfe48532895f33c","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/ddb44baed257560f192b145ed36cf8c0a412de47","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-72090","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:21:23.077","lastModified":"2026-08-15T06:21:23.077","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\naccel/amdxdna: Use caller client for debug BO sync\n\namdxdna_drm_sync_bo_ioctl() looks up args->handle in the ioctl caller's\ndrm_file. For SYNC_DIRECT_FROM_DEVICE, it then calls\namdxdna_hwctx_sync_debug_bo(), but passes abo->client.\n\namdxdna_hwctx_sync_debug_bo() uses the passed client both as the handle\nnamespace for debug_bo_hdl and as the owner of the hardware context xarray.\nThose must match the file that supplied args->handle. The BO's stored\nclient pointer is object state, not the ioctl context.\n\nPass filp->driver_priv instead, matching the original handle lookup."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/accel/amdxdna/amdxdna_gem.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"7ea0468380216c10b73633b976d33efa8c12d375","lessThan":"216e43d93dd49ec253052741aa476e51a8c54cd8","versionType":"git","status":"affected"},{"version":"7ea0468380216c10b73633b976d33efa8c12d375","lessThan":"7caf2a2351d4053075670ff3e26a6815da0a9e1e","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/accel/amdxdna/amdxdna_gem.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.19","status":"affected"},{"version":"0","lessThan":"6.19","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/216e43d93dd49ec253052741aa476e51a8c54cd8","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/7caf2a2351d4053075670ff3e26a6815da0a9e1e","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-72091","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:21:23.180","lastModified":"2026-08-15T06:21:23.180","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\naccel/amdxdna: reject user command submission without a command BO\n\namdxdna_drm_submit_execbuf() passes the user-supplied command BO handle\nstraight into amdxdna_cmd_submit() with drv_cmd == NULL. When the handle\nis AMDXDNA_INVALID_BO_HANDLE (0), the block that fetches job->cmd_bo is\nskipped, leaving it NULL, and no check rejects it on the user path (the\n!job->cmd_bo guard lives inside the != INVALID branch).\n\nThe job is then armed and pushed to the DRM scheduler.\naie2_sched_job_run() takes the drv_cmd == NULL path and calls\namdxdna_cmd_set_state(job->cmd_bo) -> amdxdna_gem_vmap(NULL) ->\nto_gobj(NULL)->dev, a NULL pointer dereference in the drm_sched worker.\nA process with access to the accel node on a system with a probed AMD NPU\ncan trigger a kernel oops with a single AMDXDNA_EXEC_CMD ioctl\n(cmd_handles = 0).\n\nOnly internal driver commands (SYNC_DEBUG_BO / ATTACH_DEBUG_BO)\nlegitimately pass AMDXDNA_INVALID_BO_HANDLE, and they always set drv_cmd.\nReject the invalid handle for user submissions (drv_cmd == NULL) at the\nsubmit choke point so every user path is covered.\n\nFound by 0sec automated security-research tooling (https://0sec.ai)."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/accel/amdxdna/amdxdna_ctx.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"aac243092b707bb3018e951d470cc1a9bcbaba6c","lessThan":"fff6509d976f6fae423a5236391ccdbd7e0e9f06","versionType":"git","status":"affected"},{"version":"aac243092b707bb3018e951d470cc1a9bcbaba6c","lessThan":"261c1fe3327ad24508f54552c6366e3e4db82c15","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/accel/amdxdna/amdxdna_ctx.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.14","status":"affected"},{"version":"0","lessThan":"6.14","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc4","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/261c1fe3327ad24508f54552c6366e3e4db82c15","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/fff6509d976f6fae423a5236391ccdbd7e0e9f06","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-72092","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:21:23.273","lastModified":"2026-08-15T06:21:23.273","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\naccel/amdxdna: reject command submission on devices without a submit op\n\namdxdna_cmd_submit() calls xdna->dev_info->ops->cmd_submit()\nunconditionally, but only aie2_dev_ops defines that callback.\naie4_vf_ops (the AIE4 SR-IOV virtual function) does not, so a user\nAMDXDNA_EXEC_CMD ioctl on an AIE4 device reaches a NULL function-pointer\ncall and oopses the kernel. AIE4 submits work through a mapped user queue\nand doorbell, not this ioctl path.\n\nReject the submission early with -EOPNOTSUPP when the device provides no\ncmd_submit op, so the shared EXEC ioctl is a clean no-op on such devices.\n\nFound by 0sec automated security-research tooling (https://0sec.ai)."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/accel/amdxdna/amdxdna_ctx.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"aac243092b707bb3018e951d470cc1a9bcbaba6c","lessThan":"af7a4c2caa7a191d6e7ed33903b69f9901874cd0","versionType":"git","status":"affected"},{"version":"aac243092b707bb3018e951d470cc1a9bcbaba6c","lessThan":"f7d08603c87bae19ca3e424da5ab6d0aee81886e","versionType":"git","status":"affected"},{"version":"aac243092b707bb3018e951d470cc1a9bcbaba6c","lessThan":"38953513d7313992676d4136cd425cdb70c6278e","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/accel/amdxdna/amdxdna_ctx.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.14","status":"affected"},{"version":"0","lessThan":"6.14","versionType":"semver","status":"unaffected"},{"version":"6.18.42","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc4","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/38953513d7313992676d4136cd425cdb70c6278e","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/af7a4c2caa7a191d6e7ed33903b69f9901874cd0","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/f7d08603c87bae19ca3e424da5ab6d0aee81886e","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-72093","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:21:23.370","lastModified":"2026-08-15T06:21:23.370","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\naccel/amdxdna: Fix use-after-free in amdxdna_gem_dmabuf_mmap()\n\nWhen vm_insert_pages() fails, the error path calls vma->vm_ops->close(vma)\nwhich internally calls drm_gem_vm_close() → drm_gem_object_put(),\nreleasing the GEM object reference acquired at the start of the function.\nHowever, the close_vma label then falls through to put_obj, which calls\ndrm_gem_object_put() a second time on the same object.\n\nIf the first put releases the last reference, the object is freed and the\nsecond put accesses freed memory, causing a use-after-free.\n\nFix by returning directly from close_vma instead of falling through to\nput_obj, since the close handler already performs all necessary cleanup\nincluding the object put."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/accel/amdxdna/amdxdna_gem.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"e486147c912f653ef4b60a6c7dbd4168a4c56a9f","lessThan":"4e370b5289624f46a356dcc94f9f87025eaa6036","versionType":"git","status":"affected"},{"version":"e486147c912f653ef4b60a6c7dbd4168a4c56a9f","lessThan":"5da885c39baa70f570a8be35a78e85a351f33918","versionType":"git","status":"affected"},{"version":"e486147c912f653ef4b60a6c7dbd4168a4c56a9f","lessThan":"63bbf9ac5dde2ba85e7b39d0a0b7d540e6252ba4","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/accel/amdxdna/amdxdna_gem.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.16","status":"affected"},{"version":"0","lessThan":"6.16","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc3","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/4e370b5289624f46a356dcc94f9f87025eaa6036","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/5da885c39baa70f570a8be35a78e85a351f33918","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/63bbf9ac5dde2ba85e7b39d0a0b7d540e6252ba4","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-72094","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:21:23.477","lastModified":"2026-08-15T06:21:23.477","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\ndma-buf: dma-fence: Fix potential NULL pointer dereference\n\nThe commit mentioned in the fixes tag below introduced a mechanism\nthrough which fence producers can fully decouple from fence consumers.\nThis, desirable, mechanism is based on the fence's signaled-bit as the\n\"decoupling point\".\n\nA sophisticated interaction between RCU and atomic instructions attempts\nto ensure that fence consumers can still interact with fence producers\nthrough the dma_fence_ops (callback pointers into the producer).\n\nThis is the desired behavior: to check for decoupling, the signaled-bit\nis first checked. If it's not yet signaled, RCU ensures that the ops\npointer cannot yet be NULL.\n\nHereby, dma_fence_signal_timestamp_locked() first sets the signaled-bit,\nand then sets the ops pointer to NULL. Readers first load the ops\npointer, and then check through the signaled-bit whether the pointer can\nlegally be accessed.\n\nThese set and load operations could occur out of order on weakly ordered\nplatforms. This problem can be solved very elegantly by using the ops\npointer itself as the synchronization point. The pointer is either NULL,\nor cannot become NULL while it is being used thanks to RCU.\n\nReplace the signaled-bit check in dma_fence_timeline_name() and\ndma_fence_driver_name()."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/dma-buf/dma-fence.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"f4cc3ab824d6772a48ca9d9c74ac623b3309985d","lessThan":"15ecfdf0ef6f6d874d0a26690d300857b39ebfd0","versionType":"git","status":"affected"},{"version":"f4cc3ab824d6772a48ca9d9c74ac623b3309985d","lessThan":"035219a760edb35ae9a9e96beba7f122e26a997b","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/dma-buf/dma-fence.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"7.1","status":"affected"},{"version":"0","lessThan":"7.1","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc2","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/035219a760edb35ae9a9e96beba7f122e26a997b","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/15ecfdf0ef6f6d874d0a26690d300857b39ebfd0","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-72095","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:21:23.573","lastModified":"2026-08-15T06:21:23.573","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\ndma-fence: Make dma_fence_dedup_array() robust against 0-count input\n\ndma_fence_dedup_array() returns 1 when called with num_fences == 0:\nthe for-loop body never executes, j stays at 0, and the final\n`return ++j` yields 1. This contradicts both the kernel-doc (\"Return:\nNumber of unique fences remaining in the array\") and the natural\nexpectation that 0 input gives 0 output.\n\nThe caller __dma_fence_unwrap_merge() bails out via the\n`if (count == 0 || count == 1)` fast path and so is save.\n\nBut amdgpu_userq_wait_*() could reach the dedup call with a zero local\ncount and dereference an uninitialized fence slot in the array.\n\nMake the contract match the documentation by returning 0 early. This\nalso skips an unnecessary sort() call on an empty array."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/dma-buf/dma-fence-unwrap.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"575ec9b0c2f11f40535ea737ed5a64792780d1ef","lessThan":"7aa8f3dba53422465dbe1be8dbb7240304462bb2","versionType":"git","status":"affected"},{"version":"575ec9b0c2f11f40535ea737ed5a64792780d1ef","lessThan":"e2d9a2ea178a5da0b4a6693e8ebca5c7fc4d7051","versionType":"git","status":"affected"},{"version":"575ec9b0c2f11f40535ea737ed5a64792780d1ef","lessThan":"77a9298741f8f9e8b963c977f5582ab21c6d3427","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/dma-buf/dma-fence-unwrap.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.16","status":"affected"},{"version":"0","lessThan":"6.16","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc2","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/77a9298741f8f9e8b963c977f5582ab21c6d3427","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/7aa8f3dba53422465dbe1be8dbb7240304462bb2","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/e2d9a2ea178a5da0b4a6693e8ebca5c7fc4d7051","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-72096","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:21:23.680","lastModified":"2026-08-15T06:21:23.680","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\ndm-verity: make error counter atomic\n\nThe error counter \"v->corrupted_errs\" was not atomic, thus it could be\nsubject to race conditions. The call to\ndm_audit_log_target(\"max-corrupted-errors\") may be skipped due to the\nraces."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/md/dm-verity-target.c","drivers/md/dm-verity.h"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"65ff5b7ddf0541f2b6e5cc59c47bfbf6cbcd91b8","lessThan":"ac99781115d37d10894653b47941d9d8fc26fa64","versionType":"git","status":"affected"},{"version":"65ff5b7ddf0541f2b6e5cc59c47bfbf6cbcd91b8","lessThan":"3303e5c6501e3638ded8e9402d703805b00ce64e","versionType":"git","status":"affected"},{"version":"65ff5b7ddf0541f2b6e5cc59c47bfbf6cbcd91b8","lessThan":"089e05b644d5aa786c21af467c80b24d691becb1","versionType":"git","status":"affected"},{"version":"65ff5b7ddf0541f2b6e5cc59c47bfbf6cbcd91b8","lessThan":"752e214b2c6f15b40b0d873a2ce27733ce0884c6","versionType":"git","status":"affected"},{"version":"65ff5b7ddf0541f2b6e5cc59c47bfbf6cbcd91b8","lessThan":"8ec4d9c5a5cf4b61fc087f871465b1f79b393325","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/md/dm-verity-target.c","drivers/md/dm-verity.h"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"4.1","status":"affected"},{"version":"0","lessThan":"4.1","versionType":"semver","status":"unaffected"},{"version":"6.6.148","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.97","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc3","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/089e05b644d5aa786c21af467c80b24d691becb1","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/3303e5c6501e3638ded8e9402d703805b00ce64e","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/752e214b2c6f15b40b0d873a2ce27733ce0884c6","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/8ec4d9c5a5cf4b61fc087f871465b1f79b393325","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/ac99781115d37d10894653b47941d9d8fc26fa64","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-72097","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:21:23.790","lastModified":"2026-08-15T06:21:23.790","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\ndm-verity: fix a possible NULL pointer dereference\n\nFix a possible NULL pointer dereference dm_verity_loadpin_is_bdev_trusted\nif the device has no table."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/md/dm-verity-loadpin.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"b6c1c5745ccc68ac5d57c7ffb51ea25a86d0e97b","lessThan":"7d4f1d307ac0f4f55cebeb192a90a235aa060ed1","versionType":"git","status":"affected"},{"version":"b6c1c5745ccc68ac5d57c7ffb51ea25a86d0e97b","lessThan":"1f04b390add2e14c5b36829a0a1529c4eb65a2e1","versionType":"git","status":"affected"},{"version":"b6c1c5745ccc68ac5d57c7ffb51ea25a86d0e97b","lessThan":"32f8231c81bd45ab92d49b646a154551f7d54f4f","versionType":"git","status":"affected"},{"version":"b6c1c5745ccc68ac5d57c7ffb51ea25a86d0e97b","lessThan":"f15eaa3801f2f9207dff156f1ab3e7436ce52bb1","versionType":"git","status":"affected"},{"version":"b6c1c5745ccc68ac5d57c7ffb51ea25a86d0e97b","lessThan":"81f41d989a32458ff3512f6b05458eaf8926579c","versionType":"git","status":"affected"},{"version":"b6c1c5745ccc68ac5d57c7ffb51ea25a86d0e97b","lessThan":"e72b793ae440f6900fb17a4b8518c707b5cd3e17","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/md/dm-verity-loadpin.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.0","status":"affected"},{"version":"0","lessThan":"6.0","versionType":"semver","status":"unaffected"},{"version":"6.1.178","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.97","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc3","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/1f04b390add2e14c5b36829a0a1529c4eb65a2e1","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/32f8231c81bd45ab92d49b646a154551f7d54f4f","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/7d4f1d307ac0f4f55cebeb192a90a235aa060ed1","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/81f41d989a32458ff3512f6b05458eaf8926579c","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/e72b793ae440f6900fb17a4b8518c707b5cd3e17","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/f15eaa3801f2f9207dff156f1ab3e7436ce52bb1","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-72098","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:21:23.897","lastModified":"2026-08-15T06:21:23.897","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\ndm-verity: fix buffer overflow in FEC calculation\n\nThere's a buffer overflow in dm-verity-fec:\n\nif (neras && *neras <= v->fec->roots)\n\tfio->erasures[(*neras)++] = i;\n\nThis allows *neras to reach roots + 1 (the post-increment pushes it past\nroots). This value is then passed as no_eras to decode_rs8(). Inside the\nRS decoder (lib/reed_solomon/decode_rs.c:113-121), the erasure locator\npolynomial loop writes lambda[j] where j can reach nroots + 1 — one\nelement past the end of lambda[] (which is sized nroots + 1, valid\nindices 0..nroots). The out-of-bounds write lands on syn[0], corrupting\nthe syndrome buffer."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/md/dm-verity-fec.c","drivers/md/dm-verity-fec.h"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"a739ff3f543afbb4a041c16cd0182c8e8d366e70","lessThan":"5488d3a69d205e28f74f18857b853aa12e778e66","versionType":"git","status":"affected"},{"version":"a739ff3f543afbb4a041c16cd0182c8e8d366e70","lessThan":"f7990c2b0f08b8841fcd2652d1d7002f5994a7a7","versionType":"git","status":"affected"},{"version":"a739ff3f543afbb4a041c16cd0182c8e8d366e70","lessThan":"31d6e6c0ba8d5a7bd59660035a089307100c5e8e","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/md/dm-verity-fec.c","drivers/md/dm-verity-fec.h"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"4.5","status":"affected"},{"version":"0","lessThan":"4.5","versionType":"semver","status":"unaffected"},{"version":"6.18.42","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc3","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/31d6e6c0ba8d5a7bd59660035a089307100c5e8e","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/5488d3a69d205e28f74f18857b853aa12e778e66","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/f7990c2b0f08b8841fcd2652d1d7002f5994a7a7","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-72099","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:21:24.000","lastModified":"2026-08-15T06:21:24.000","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\ndm-integrity: don't increment hash_offset twice\n\nhash_offset is already incremented in the loop \"for (i = 0; i < to_copy;\ni++, ts--)\". Do not increment it again."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/md/dm-integrity.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"84597a44a9d86ac949900441cea7da0af0f2f473","lessThan":"cf9feed8c131e303ecf2afebe6f791be018818ad","versionType":"git","status":"affected"},{"version":"84597a44a9d86ac949900441cea7da0af0f2f473","lessThan":"4f4e43337e9ef322595201cfc24def50fd624219","versionType":"git","status":"affected"},{"version":"84597a44a9d86ac949900441cea7da0af0f2f473","lessThan":"5dfd8042635278613da3b88553e25ade2103cd58","versionType":"git","status":"affected"},{"version":"84597a44a9d86ac949900441cea7da0af0f2f473","lessThan":"829476c06496aab018f14127c055adb164d1a750","versionType":"git","status":"affected"},{"version":"84597a44a9d86ac949900441cea7da0af0f2f473","lessThan":"edf025f083854f80032b73a1aad69a3c90db236f","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/md/dm-integrity.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"5.7","status":"affected"},{"version":"0","lessThan":"5.7","versionType":"semver","status":"unaffected"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.97","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc3","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/4f4e43337e9ef322595201cfc24def50fd624219","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/5dfd8042635278613da3b88553e25ade2103cd58","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/829476c06496aab018f14127c055adb164d1a750","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/cf9feed8c131e303ecf2afebe6f791be018818ad","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/edf025f083854f80032b73a1aad69a3c90db236f","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-72100","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:21:24.123","lastModified":"2026-08-15T06:21:24.123","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\ndm-integrity: fix a bug if the bio is out of limits\n\nIf dm_integrity_check_limits fails, the code would exit with\nDM_MAPIO_KILL. However, the range would be already locked at this point,\nand it wouldn't be unlocked, resulting in a deadlock. Let's move the\nlimit check up, so that when it exits, no resources are leaked."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/md/dm-integrity.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"fb0987682c629c1d2c476f35f6fde405a5e304a4","lessThan":"f7989286175f32db8605e767a1a2efc62e894dc8","versionType":"git","status":"affected"},{"version":"fb0987682c629c1d2c476f35f6fde405a5e304a4","lessThan":"aa5113e7155f4ea81d2c0303ab5cb272d4b32627","versionType":"git","status":"affected"},{"version":"fb0987682c629c1d2c476f35f6fde405a5e304a4","lessThan":"3d1afaa074622859678b1a1e7c1b9c0af74c89b0","versionType":"git","status":"affected"},{"version":"fb0987682c629c1d2c476f35f6fde405a5e304a4","lessThan":"5a266764fadaff8b5c1fe37a186ebf9b09cb953e","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/md/dm-integrity.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.11","status":"affected"},{"version":"0","lessThan":"6.11","versionType":"semver","status":"unaffected"},{"version":"6.12.97","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc3","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/3d1afaa074622859678b1a1e7c1b9c0af74c89b0","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/5a266764fadaff8b5c1fe37a186ebf9b09cb953e","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/aa5113e7155f4ea81d2c0303ab5cb272d4b32627","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/f7989286175f32db8605e767a1a2efc62e894dc8","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-72101","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:21:24.223","lastModified":"2026-08-15T06:21:24.223","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\ndm-integrity: fix leaking uninitialized kernel memory\n\nIf hash size is less than device's tuple size, dm-integrity is supposed\nto zero the remaining space. There was a bug in the code that zeroing\ndidn't work. This commit fixes it."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/md/dm-integrity.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"fb0987682c629c1d2c476f35f6fde405a5e304a4","lessThan":"50af3e51dc709384701dbc721b4bd865285c5f2c","versionType":"git","status":"affected"},{"version":"fb0987682c629c1d2c476f35f6fde405a5e304a4","lessThan":"0c4e9bb1d4101030f55c869f18bd3ece39a77bbb","versionType":"git","status":"affected"},{"version":"fb0987682c629c1d2c476f35f6fde405a5e304a4","lessThan":"8f0af8493009a61b4313e0a8c6e03fbc36fd43f9","versionType":"git","status":"affected"},{"version":"fb0987682c629c1d2c476f35f6fde405a5e304a4","lessThan":"7bb03b2b01b814a9fc14afbfc2cbb2cca5b34750","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/md/dm-integrity.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.11","status":"affected"},{"version":"0","lessThan":"6.11","versionType":"semver","status":"unaffected"},{"version":"6.12.101","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc3","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/0c4e9bb1d4101030f55c869f18bd3ece39a77bbb","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/50af3e51dc709384701dbc721b4bd865285c5f2c","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/7bb03b2b01b814a9fc14afbfc2cbb2cca5b34750","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/8f0af8493009a61b4313e0a8c6e03fbc36fd43f9","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-72102","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:21:24.340","lastModified":"2026-08-15T06:21:24.340","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\ndm_early_create: fix freeing used table on dm_resume failure\n\nIf dm_resume fails, the kernel attempts to free table with\ndm_table_destroy, but the table was already instantiated with\ndm_swap_table. This commit skips the call to dm_table_destroy in this\ncase."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/md/dm-ioctl.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6bbc923dfcf57d6b97388819a7393835664c7a8e","lessThan":"3ba377a47a093cc19647ca7f102acd33a211d472","versionType":"git","status":"affected"},{"version":"6bbc923dfcf57d6b97388819a7393835664c7a8e","lessThan":"72c3283a2abd60ecef295e02270f22ef1dfccd25","versionType":"git","status":"affected"},{"version":"6bbc923dfcf57d6b97388819a7393835664c7a8e","lessThan":"d6066145347e14db84c35b445e309f095d0d8125","versionType":"git","status":"affected"},{"version":"6bbc923dfcf57d6b97388819a7393835664c7a8e","lessThan":"259ce9e3fc3a3f8c4e393a2072b8f34302eb4d5a","versionType":"git","status":"affected"},{"version":"6bbc923dfcf57d6b97388819a7393835664c7a8e","lessThan":"5f6500d44a912d4aed664600966706d76b81d9af","versionType":"git","status":"affected"},{"version":"6bbc923dfcf57d6b97388819a7393835664c7a8e","lessThan":"92e3c93d60be1f2425738cd66dbadac7d6bc0cd1","versionType":"git","status":"affected"},{"version":"6bbc923dfcf57d6b97388819a7393835664c7a8e","lessThan":"7d8ed7cb844df21e4d93af11250fb3a5cb861147","versionType":"git","status":"affected"},{"version":"6bbc923dfcf57d6b97388819a7393835664c7a8e","lessThan":"366665416f20527ff7cad548a32d1ddf23195740","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/md/dm-ioctl.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"5.1","status":"affected"},{"version":"0","lessThan":"5.1","versionType":"semver","status":"unaffected"},{"version":"5.10.261","lessThanOrEqual":"5.10.*","versionType":"semver","status":"unaffected"},{"version":"5.15.212","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.178","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.97","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc3","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/259ce9e3fc3a3f8c4e393a2072b8f34302eb4d5a","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/366665416f20527ff7cad548a32d1ddf23195740","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/3ba377a47a093cc19647ca7f102acd33a211d472","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/5f6500d44a912d4aed664600966706d76b81d9af","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/72c3283a2abd60ecef295e02270f22ef1dfccd25","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/7d8ed7cb844df21e4d93af11250fb3a5cb861147","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/92e3c93d60be1f2425738cd66dbadac7d6bc0cd1","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/d6066145347e14db84c35b445e309f095d0d8125","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-72103","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:21:24.460","lastModified":"2026-08-15T06:21:24.460","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\ndm: avoid leaking the caller's thread keyring via the table device file\n\nThe refactoring in commit a28d893eb327 (\"md: port block device access to file\")\naccidentally causes the caller's thread keyring to be kept alive long\nbeyond the caller's lifetime.\n\nAs a result, \"cryptsetup luksSuspend\" silently fails to wipe the\nLUKS volume key from memory.\n\nIn detail: \"cryptsetup luksOpen\" uses its supposedly ephemeral thread\nkeyring to pass the volume key to the kernel. dm-crypt's\ncrypt_set_keyring_key() copies the key material into its own\ncrypt_config structure and then drops its own reference to the key in\nthe keyring with key_put().\n\nWith this fix, restoring pre-v6.9 behavior, the copy in the thread\nkeyring is then promptly garbage collected, such that exactly one copy\nof the volume key remains. This single copy is correctly wiped from\nmemory on \"cryptsetup luksSuspend\".\n\nWithout this fix, the thread keyring and the volume key in it remains.\nThis second copy is only freed on \"luksClose\". \"luksSuspend\" neither\nknows about this copy nor has any way to remove it, so the key remains\nrecoverable from RAM after a suspend that is documented to have wiped it.\n\nThis fix should not introduce new security problems, as the code is\nanyway gated by CAP_SYS_ADMIN. The device-mapper core, not the calling\ntask, is the legitimate owner of this long-lived file."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/md/dm.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"a28d893eb3270cf62c10dd8777af0d8452cdc072","lessThan":"d3eb8451d529ea452740d1a2bc395a1d20c48133","versionType":"git","status":"affected"},{"version":"a28d893eb3270cf62c10dd8777af0d8452cdc072","lessThan":"8ced1d242c34e342defcccdb00663354f212aae6","versionType":"git","status":"affected"},{"version":"a28d893eb3270cf62c10dd8777af0d8452cdc072","lessThan":"f00105be6a593920e9bc7949a069d4a116888851","versionType":"git","status":"affected"},{"version":"a28d893eb3270cf62c10dd8777af0d8452cdc072","lessThan":"981ccd97f7153d310dfa92a534525bbaf46752c2","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/md/dm.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.9","status":"affected"},{"version":"0","lessThan":"6.9","versionType":"semver","status":"unaffected"},{"version":"6.12.101","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.42","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc3","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/8ced1d242c34e342defcccdb00663354f212aae6","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/981ccd97f7153d310dfa92a534525bbaf46752c2","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/d3eb8451d529ea452740d1a2bc395a1d20c48133","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/f00105be6a593920e9bc7949a069d4a116888851","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-72104","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:21:24.563","lastModified":"2026-08-15T06:21:24.563","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\ndm-pcache: reject option groups without values\n\nThe pcache target parses optional arguments as name/value pairs.  A\ntable that advertises one optional argument and supplies only a\nrecognized option name, for example \"cache_mode\", reaches\nparse_cache_opts() with argc == 1.  The parser consumes the name,\ndecrements argc to zero, then calls dm_shift_arg() again for the value.\ndm_shift_arg() returns NULL when no arguments remain, and the following\nstrcmp() dereferences that NULL pointer.\n\nCheck that each recognized option has a value before consuming it.  This\nkeeps valid \"cache_mode writeback\" and \"data_crc true/false\" tables\nunchanged while making malformed tables fail during target construction\nwith a precise missing-value error."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/md/dm-pcache/dm_pcache.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"1d57628ff95b32d5cfa8d8f50e07690c161e9cf0","lessThan":"1247615aadb74c89c1b2f01a6de7df9dab92ecb3","versionType":"git","status":"affected"},{"version":"1d57628ff95b32d5cfa8d8f50e07690c161e9cf0","lessThan":"0cbe13fe540330d31e5273bbf8cbd66bc7c9cb5a","versionType":"git","status":"affected"},{"version":"1d57628ff95b32d5cfa8d8f50e07690c161e9cf0","lessThan":"d9c631e3fbd44246a2be781d26cfacbb9b8ec127","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/md/dm-pcache/dm_pcache.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.18","status":"affected"},{"version":"0","lessThan":"6.18","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc3","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/0cbe13fe540330d31e5273bbf8cbd66bc7c9cb5a","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/1247615aadb74c89c1b2f01a6de7df9dab92ecb3","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/d9c631e3fbd44246a2be781d26cfacbb9b8ec127","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-72105","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:21:24.673","lastModified":"2026-08-15T06:21:24.673","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\ndm-log: fix a bitset_size overflow on 32bit machines\n\nCommit c20e36b7631d (\"dm log: fix out-of-bounds write due to\nregion_count overflow\") made sure that region_count could fit in an\nunsigned int. But the bitmap memory isn't allocated based on\nregion_count. It uses bitset_size (a size_t variable). The first step of\ncalculating bitset_size is to set it to region_count, rounded up to a\nmultiple of BITS_PER_LONG. If region_size is less than BITS_PER_LONG\nsmaller than UINT_MAX, it will get rounded up to 2^32. On a 32bit\narchitecture, this will make bitset_size wrap around to 0 and fail,\ndespite region_count being valid.\n\nSince bitset_size gets divided by 8, it can hold any valid region_count.\nIt just needs a special case to handle the rollover. If it is 0, the\nvalue rolled over, and bitset size should be set to the number of bytes\nneeded to hold 2^32 bits."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/md/dm-log.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"44ab8875ae4a2842bde2d756bed195d375e0debb","lessThan":"cdc4ddf9db2cb79f4ab86b1a509b7ac21b0b6cf5","versionType":"git","status":"affected"},{"version":"defe483e47173768c227532694dc78cb65db5f09","lessThan":"4b0de5a3ac1fd42acb0dc1f80ac5747e3287d723","versionType":"git","status":"affected"},{"version":"3ec74da927b4e171a6fc0e77b1188ba4d019af51","lessThan":"567602fa72d57169365cbc589e0b8c3be900636d","versionType":"git","status":"affected"},{"version":"d4ac87567f86a55c3c92e9a5144dcd943a9772a1","lessThan":"d05e0edfecf5260e6dddd28b2f0cce02bfc6ed7a","versionType":"git","status":"affected"},{"version":"12bd5b88e91a02785244ff1d20fb157e96e9cdc8","lessThan":"1c3412b584e1fb6c665ff33ba7259253bc0082cb","versionType":"git","status":"affected"},{"version":"b455903eed4558982be0811f5b7f44f6bbc4ff57","lessThan":"e0b0163a65758ec3a2361ae1cea407898c27f21e","versionType":"git","status":"affected"},{"version":"c20e36b7631d83e7535877f08af8b0af72c44b1a","lessThan":"79feb87ab2396d49b9b65e4bb815d33cc71cba47","versionType":"git","status":"affected"},{"version":"c20e36b7631d83e7535877f08af8b0af72c44b1a","lessThan":"9743132a41f4d9d0e54c5f2adcb821b04796bab1","versionType":"git","status":"affected"},{"version":"4ec8323b9f0764a14d532b1ae9b87f8a9fecb867","versionType":"git","status":"affected"},{"version":"5.10.258","lessThan":"5.10.261","versionType":"semver","status":"affected"},{"version":"5.15.209","lessThan":"5.15.212","versionType":"semver","status":"affected"},{"version":"6.1.175","lessThan":"6.1.178","versionType":"semver","status":"affected"},{"version":"6.6.141","lessThan":"6.6.145","versionType":"semver","status":"affected"},{"version":"6.12.91","lessThan":"6.12.97","versionType":"semver","status":"affected"},{"version":"6.18.33","lessThan":"6.18.40","versionType":"semver","status":"affected"},{"version":"7.0.10","lessThan":"7.1","versionType":"semver","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/md/dm-log.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"7.1","status":"affected"},{"version":"0","lessThan":"7.1","versionType":"semver","status":"unaffected"},{"version":"5.10.261","lessThanOrEqual":"5.10.*","versionType":"semver","status":"unaffected"},{"version":"5.15.212","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.178","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.97","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc3","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/1c3412b584e1fb6c665ff33ba7259253bc0082cb","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/4b0de5a3ac1fd42acb0dc1f80ac5747e3287d723","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/567602fa72d57169365cbc589e0b8c3be900636d","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/79feb87ab2396d49b9b65e4bb815d33cc71cba47","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/9743132a41f4d9d0e54c5f2adcb821b04796bab1","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/cdc4ddf9db2cb79f4ab86b1a509b7ac21b0b6cf5","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/d05e0edfecf5260e6dddd28b2f0cce02bfc6ed7a","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/e0b0163a65758ec3a2361ae1cea407898c27f21e","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-72106","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:21:24.803","lastModified":"2026-08-15T06:21:24.803","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\ndm-ioctl: fix a possible overflow in list_version_get_info\n\nsizeof(tt->version) is 12 bytes, but the code writes 16 bytes into the\noutput buffer - info->vers->version[0], info->vers->version[1],\ninfo->vers->version[2] and info->vers->next. This can cause buffer\noverflow.\n\nFix this buffer overflow by replacing \"sizeof(tt->version)\" with\n\"sizeof(struct dm_target_versions)\"."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/md/dm-ioctl.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"29536a9ff146d9bbd618959857ed2e691cda1d21","versionType":"git","status":"affected"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"e0f5842c4e2a7dbefb52a2dc6711789bc6963e55","versionType":"git","status":"affected"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"d61c12573ed9768690fdcb2bc38846a1bcb01358","versionType":"git","status":"affected"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"df50c24c6447c18886ed126d3d81cc7e155ea8b6","versionType":"git","status":"affected"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"76c6f845dc0c614304a6e6ee619b552f97cf24b3","versionType":"git","status":"affected"},{"version":"0","lessThan":"6.6.145","versionType":"semver","status":"affected"},{"version":"0","lessThan":"6.12.97","versionType":"semver","status":"affected"},{"version":"0","lessThan":"6.18.40","versionType":"semver","status":"affected"},{"version":"0","lessThan":"7.1.5","versionType":"semver","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/md/dm-ioctl.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.97","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc3","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/29536a9ff146d9bbd618959857ed2e691cda1d21","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/76c6f845dc0c614304a6e6ee619b552f97cf24b3","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/d61c12573ed9768690fdcb2bc38846a1bcb01358","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/df50c24c6447c18886ed126d3d81cc7e155ea8b6","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/e0f5842c4e2a7dbefb52a2dc6711789bc6963e55","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-72107","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:21:24.920","lastModified":"2026-08-15T06:21:24.920","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\ndm era: fix out-of-bounds memory access for non-zero start sector\n\ndm-era tracks writes in target-relative blocks, but era_map() calculates\nthe writeset block before applying the target offset.  Tables with a\nnon-zero start sector can therefore pass an absolute mapped-device block\nto metadata_current_marked().\n\nIf the absolute block is beyond the current writeset size,\nwriteset_marked() tests past the end of the in-core bitset.  KASAN reports\nthis as a vmalloc-out-of-bounds access.\n\nApply the target offset before calculating the era block so writeset\nlookups use the target-relative block number."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/md/dm-era-target.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"eec40579d84873dfb7021eb24c50360f073237c5","lessThan":"fe94a0b14010a3c267ff9a2508afb4f27ff1c5bf","versionType":"git","status":"affected"},{"version":"eec40579d84873dfb7021eb24c50360f073237c5","lessThan":"e3ffa8e492e5cdee62d916ee3e9244ccce2b73c5","versionType":"git","status":"affected"},{"version":"eec40579d84873dfb7021eb24c50360f073237c5","lessThan":"9946a7176bd8c25ddd6e5f1799c54e572ee6bf0f","versionType":"git","status":"affected"},{"version":"eec40579d84873dfb7021eb24c50360f073237c5","lessThan":"7e1822f83c5a1ee7b4a19e98edde8770a10b4c71","versionType":"git","status":"affected"},{"version":"eec40579d84873dfb7021eb24c50360f073237c5","lessThan":"db5f9b4601f0012038e5a2628aedec2f47933380","versionType":"git","status":"affected"},{"version":"eec40579d84873dfb7021eb24c50360f073237c5","lessThan":"1fcb5e29dd7a5b85adb9d8b539911741d878e829","versionType":"git","status":"affected"},{"version":"eec40579d84873dfb7021eb24c50360f073237c5","lessThan":"bafe3e720cdac38cd7ea4eb7852a8f2dbe1bbfe6","versionType":"git","status":"affected"},{"version":"eec40579d84873dfb7021eb24c50360f073237c5","lessThan":"a868196f03c2b19418ae3d2b69e195d668a271e5","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/md/dm-era-target.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"3.15","status":"affected"},{"version":"0","lessThan":"3.15","versionType":"semver","status":"unaffected"},{"version":"5.10.261","lessThanOrEqual":"5.10.*","versionType":"semver","status":"unaffected"},{"version":"5.15.212","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.178","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.97","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc3","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/1fcb5e29dd7a5b85adb9d8b539911741d878e829","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/7e1822f83c5a1ee7b4a19e98edde8770a10b4c71","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/9946a7176bd8c25ddd6e5f1799c54e572ee6bf0f","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/a868196f03c2b19418ae3d2b69e195d668a271e5","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/bafe3e720cdac38cd7ea4eb7852a8f2dbe1bbfe6","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/db5f9b4601f0012038e5a2628aedec2f47933380","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/e3ffa8e492e5cdee62d916ee3e9244ccce2b73c5","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/fe94a0b14010a3c267ff9a2508afb4f27ff1c5bf","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-72108","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:21:25.047","lastModified":"2026-08-15T06:21:25.047","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\ndm thin metadata: fix metadata snapshot consistency on commit failure\n\n__reserve_metadata_snap() and __release_metadata_snap() modify the\nsuperblock's held_root directly in the block_manager's buffer. If the\nsubsequent metadata commit fails, the held_root gets flushed to disk\nthrough the abort_transaction path, resulting in inconsistent metadata.\n\nReproducer 1: __reserve_metadata_snap()\n\n1. Create a 2 MiB metadata device and make the region after the 14th\n   block inaccessible, to trigger metadata commit failure in the\n   subsequent reserve_metadata_snap operation. The 14th block will be\n   the shadow destination for the index block.\n\ndmsetup create tmeta --table \"0 112 linear /dev/sdc 0\n112 3984 error\"\n\n2. Create a 16 MiB thin-pool\n\ndmsetup create tdata --table \"0 32768 zero\"\ndd if=/dev/zero of=/dev/mapper/tmeta bs=4k count=1\ndmsetup create tpool --table \"0 32768 thin-pool /dev/mapper/tmeta \\\n/dev/mapper/tdata 128 0 1 skip_block_zeroing\"\n\n3. Take a metadata snapshot to trigger metadata commit failure and\n   transaction abort. However, the held_root is written to disk,\n   breaking metadata consistency.\n\ndmsetup message tpool 0 \"reserve_metadata_snap\"\n\nthin_check v1.2.2 result:\n\nBad reference count for metadata block 6.  Expected 2, but space map contains 1.\nBad reference count for metadata block 7.  Expected 2, but space map contains 1.\nBad reference count for metadata block 13.  Expected 1, but space map contains 0.\n\nReproducer 2: __release_metadata_snap()\n\n1. Create a 2 MiB metadata device and make the region after the 16th\n   block inaccessible, to trigger metadata commit failure in the\n   subsequent release_metadata_snap operation. The 16th block will be\n   the shadow destination for the index block.\n\ndmsetup create tmeta --table \"0 128 linear /dev/sdc 0\n128 3968 error\"\n\n2. Create a 16 MiB thin-pool\n\ndmsetup create tdata --table \"0 32768 zero\"\ndd if=/dev/zero of=/dev/mapper/tmeta bs=4k count=1\ndmsetup create tpool --table \"0 32768 thin-pool /dev/mapper/tmeta \\\n/dev/mapper/tdata 128 0 1 skip_block_zeroing\"\n\n3. Reserve then release the metadata snapshot, to trigger metadata\n   commit failure and transaction abort. The held_root gets removed\n   from the on-disk superblock, causing inconsistent metadata.\n\ndmsetup message tpool 0 \"reserve_metadata_snap\"\ndmsetup message tpool 0 \"release_metadata_snap\"\n\nthin_check v1.2.2 result:\n\nBad reference count for metadata block 6.  Expected 1, but space map contains 2.\nBad reference count for metadata block 7.  Expected 1, but space map contains 2.\n1 metadata blocks have leaked.\n\nFix by deferring the held_root update to commit time.\n\nAdditionally, move the existing-snapshot check in __reserve_metadata_snap\nbefore the shadow operation to avoid unnecessary work. In\n__release_metadata_snap, clear pmd->held_root before btree deletion so\npartial failure leaks blocks rather than leaving a stale reference, and\nunlock the snapshot block before decrementing its refcount."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/md/dm-thin-metadata.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"991d9fa02da0dd1f843dc011376965e0c8c6c9b5","lessThan":"4af993468193cf4cd32ba5748786e7801945f7d2","versionType":"git","status":"affected"},{"version":"991d9fa02da0dd1f843dc011376965e0c8c6c9b5","lessThan":"abf2fae92cbe68945028987d498cc72f8f0e23a8","versionType":"git","status":"affected"},{"version":"991d9fa02da0dd1f843dc011376965e0c8c6c9b5","lessThan":"5efb1a7734ed4035fa4fdc3716bdb84621f27cf6","versionType":"git","status":"affected"},{"version":"991d9fa02da0dd1f843dc011376965e0c8c6c9b5","lessThan":"3dc9ae1029320d77472c44965e572f176949cd63","versionType":"git","status":"affected"},{"version":"991d9fa02da0dd1f843dc011376965e0c8c6c9b5","lessThan":"b5f9a31c51cbb374a1713c3494f8660ab070f035","versionType":"git","status":"affected"},{"version":"991d9fa02da0dd1f843dc011376965e0c8c6c9b5","lessThan":"7f76245960a332f39b08cc556e675d1765dc5bbb","versionType":"git","status":"affected"},{"version":"991d9fa02da0dd1f843dc011376965e0c8c6c9b5","lessThan":"9f1a0d27586ceab055e6b050e3731ce3c6b2c4f0","versionType":"git","status":"affected"},{"version":"991d9fa02da0dd1f843dc011376965e0c8c6c9b5","lessThan":"5bcd4d3058ebaf46ad2e163829d87dd4870c7a45","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/md/dm-thin-metadata.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"3.2","status":"affected"},{"version":"0","lessThan":"3.2","versionType":"semver","status":"unaffected"},{"version":"5.10.261","lessThanOrEqual":"5.10.*","versionType":"semver","status":"unaffected"},{"version":"5.15.212","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.178","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.97","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc3","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/3dc9ae1029320d77472c44965e572f176949cd63","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/4af993468193cf4cd32ba5748786e7801945f7d2","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/5bcd4d3058ebaf46ad2e163829d87dd4870c7a45","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/5efb1a7734ed4035fa4fdc3716bdb84621f27cf6","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/7f76245960a332f39b08cc556e675d1765dc5bbb","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/9f1a0d27586ceab055e6b050e3731ce3c6b2c4f0","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/abf2fae92cbe68945028987d498cc72f8f0e23a8","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/b5f9a31c51cbb374a1713c3494f8660ab070f035","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-72109","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:21:25.203","lastModified":"2026-08-15T06:21:25.203","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nnet: sparx5: unregister blocking notifier on init failure\n\nsparx5_register_notifier_blocks() registers the switchdev blocking\nnotifier before allocating the ordered workqueue. If the workqueue\nallocation fails, the error path unregisters the switchdev and netdevice\nnotifiers, but leaves the blocking notifier registered.\n\nAdd a separate error label for the workqueue allocation failure path and\nunregister the switchdev blocking notifier there."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/net/ethernet/microchip/sparx5/sparx5_switchdev.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"d6fce5141929697a27f029c633433d487f6f62cb","lessThan":"fbc65b17508ed5464b7106e7fa5f15251ca1b603","versionType":"git","status":"affected"},{"version":"d6fce5141929697a27f029c633433d487f6f62cb","lessThan":"e5afc6d3fabdf1f605d63c4b34a3df6c359e81f3","versionType":"git","status":"affected"},{"version":"d6fce5141929697a27f029c633433d487f6f62cb","lessThan":"cf419c869e0d03aad4b6f4ecf0a813851930dfe7","versionType":"git","status":"affected"},{"version":"d6fce5141929697a27f029c633433d487f6f62cb","lessThan":"d6084c47389fd6978a5d66b0d58206a548c792a9","versionType":"git","status":"affected"},{"version":"d6fce5141929697a27f029c633433d487f6f62cb","lessThan":"8a3c44a003176282ee4306b7c96e5a536c6f0707","versionType":"git","status":"affected"},{"version":"d6fce5141929697a27f029c633433d487f6f62cb","lessThan":"17f113e7b622dc850992ade540181717de6a8561","versionType":"git","status":"affected"},{"version":"d6fce5141929697a27f029c633433d487f6f62cb","lessThan":"483be61b4a9a6df3b7cb277e8f189e082dee4cb8","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/net/ethernet/microchip/sparx5/sparx5_switchdev.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"5.14","status":"affected"},{"version":"0","lessThan":"5.14","versionType":"semver","status":"unaffected"},{"version":"5.15.212","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.178","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.97","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/17f113e7b622dc850992ade540181717de6a8561","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/483be61b4a9a6df3b7cb277e8f189e082dee4cb8","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/8a3c44a003176282ee4306b7c96e5a536c6f0707","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/cf419c869e0d03aad4b6f4ecf0a813851930dfe7","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/d6084c47389fd6978a5d66b0d58206a548c792a9","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/e5afc6d3fabdf1f605d63c4b34a3df6c359e81f3","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/fbc65b17508ed5464b7106e7fa5f15251ca1b603","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-72110","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:21:25.320","lastModified":"2026-08-15T06:21:25.320","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nbpf,fork: wipe ->bpf_storage before bailouts that access it\n\nCurrently, copy_process() can bail out to free_task() before p->bpf_storage\nhas been initialized, with this call graph (shown here for the\n!CONFIG_MEMCG case):\n\ncopy_process\n  dup_task_struct\n    arch_dup_task_struct\n      [copies the entire task_struct, including ->bpf_storage member]\n  [RLIMIT_NPROC check fails]\n  delayed_free_task\n    free_task\n      bpf_task_storage_free\n        rcu_dereference(task->bpf_storage)\n        bpf_local_storage_destroy\n\nIn this case, the nascent task's ->bpf_storage member that\nbpf_local_storage_destroy() operates on is a plain copy of the parent's\n->bpf_storage pointer, not a real initialized pointer.\nThis leads to badness (kernel hangs, UAF).\n\nThis is reachable as long as the process calling fork() has been inserted\ninto a task storage map."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["kernel/fork.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"a10787e6d58c24b51e91c19c6d16c5da89fcaa4b","lessThan":"c3fd6f28c7ce1142a3b23dbb840eaa4777de1d74","versionType":"git","status":"affected"},{"version":"a10787e6d58c24b51e91c19c6d16c5da89fcaa4b","lessThan":"9cff220ddb65b022cc668bb652200742476e744c","versionType":"git","status":"affected"},{"version":"a10787e6d58c24b51e91c19c6d16c5da89fcaa4b","lessThan":"c4f626ddf2350652ad2f79daf1f10847f3f6eabd","versionType":"git","status":"affected"},{"version":"a10787e6d58c24b51e91c19c6d16c5da89fcaa4b","lessThan":"43f0005f81b8ce3be962d653cde8db9022f1e9b0","versionType":"git","status":"affected"},{"version":"a10787e6d58c24b51e91c19c6d16c5da89fcaa4b","lessThan":"9b51a6155d14389876916726430da30eabb1d4ed","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["kernel/fork.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"5.13","status":"affected"},{"version":"0","lessThan":"5.13","versionType":"semver","status":"unaffected"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.97","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc2","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/43f0005f81b8ce3be962d653cde8db9022f1e9b0","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/9b51a6155d14389876916726430da30eabb1d4ed","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/9cff220ddb65b022cc668bb652200742476e744c","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/c3fd6f28c7ce1142a3b23dbb840eaa4777de1d74","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/c4f626ddf2350652ad2f79daf1f10847f3f6eabd","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-72111","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:21:25.447","lastModified":"2026-08-15T06:21:25.447","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nbpf: Reset register bounds before narrowing retval range in check_mem_access()\n\nWhen the BPF verifier processes a context load of an LSM hook return\nvalue, it calls __mark_reg_s32_range() to narrow the register to the\nhook's valid range. However, __mark_reg_s32_range() intersects the new\nrange with the register's existing bounds using max_t()/min_t() rather\nthan replacing them.\n\nIf the destination register carries stale bounds from a prior instruction\n(e.g. BPF_MOV64_IMM), the intersection can produce a range narrower than\nreality. The verifier then believes it knows the register's exact value,\nwhile at runtime the actual hook return value is loaded, creating a\nverifier/runtime mismatch that can be used to bypass BPF memory safety\nchecks.\n\nThe else branch already calls mark_reg_unknown() to reset register state\nbefore any narrowing. Apply the same reset in the is_retval path so\nstale bounds are cleared before __mark_reg_s32_range() intersects."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["kernel/bpf/verifier.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"5d99e198be279045e6ecefe220f5c52f8ce9bfd5","lessThan":"bde92f65042ec14389782dd223f706bf6b59ce5d","versionType":"git","status":"affected"},{"version":"5d99e198be279045e6ecefe220f5c52f8ce9bfd5","lessThan":"0993dc5fc619c0b25ab1310cb11d65e78351c0fe","versionType":"git","status":"affected"},{"version":"5d99e198be279045e6ecefe220f5c52f8ce9bfd5","lessThan":"5a55f9aecc08990940e70f0c7048a80850c5a16a","versionType":"git","status":"affected"},{"version":"5d99e198be279045e6ecefe220f5c52f8ce9bfd5","lessThan":"5e0b273e0a62cc04ec338c7b502797c66c2ed42a","versionType":"git","status":"affected"},{"version":"1050727d83e70449991c29dd1cf29fe936a63da3","versionType":"git","status":"affected"},{"version":"27ca3e20fe80be85a92b10064dfeb56cb2564b1c","versionType":"git","status":"affected"},{"version":"6.10.13","lessThan":"6.11","versionType":"semver","status":"affected"},{"version":"6.11.2","lessThan":"6.12","versionType":"semver","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["kernel/bpf/verifier.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.12","status":"affected"},{"version":"0","lessThan":"6.12","versionType":"semver","status":"unaffected"},{"version":"6.12.103","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/0993dc5fc619c0b25ab1310cb11d65e78351c0fe","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/5a55f9aecc08990940e70f0c7048a80850c5a16a","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/5e0b273e0a62cc04ec338c7b502797c66c2ed42a","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/bde92f65042ec14389782dd223f706bf6b59ce5d","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-72112","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:21:25.563","lastModified":"2026-08-15T06:21:25.563","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nio_uring/bpf-ops: reject re-registration of an already-bound ops\n\nio_install_bpf() only rejects a second registration on the ctx side\n(ctx->bpf_ops) and sets the per-map back-pointer ops->priv\nunconditionally. The struct_ops link path never advances a map past\nBPF_STRUCT_OPS_STATE_READY, so the same io_uring_bpf_ops map can be\nregistered more than once, and bpf_io_reg() re-resolves the target ring\nvia fget(ops->ring_fd) on every call. A caller can therefore point the\nsame ring_fd at a different io_ring_ctx between two BPF_LINK_CREATE\ncalls.\n\nThe second registration passes the ctx->bpf_ops check (the new ctx has\nnone) and overwrites ops->priv, orphaning the first ctx. Teardown\n(io_eject_bpf()/bpf_io_unreg()) only reaches a ctx through ops->priv, so\nthe orphaned ctx is never torn down: its ctx->loop_step keeps pointing\ninto the struct_ops trampoline, which is freed once the map is gone. A\nlater io_uring_enter() on the orphaned ring then calls the dangling\nctx->loop_step from io_run_loop() -- a use-after-free of freed\nexecutable memory, reachable by a task with CAP_BPF + CAP_PERFMON.\n\nReject registration when ops->priv is already set, as hid_bpf_reg()\ndoes for its struct_ops."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["io_uring/bpf-ops.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"98f37634b12b17ad5c56db8fb63cf9d7dc55d74c","lessThan":"0639ea767fe04c288a8d6cb826100fe3d95d4936","versionType":"git","status":"affected"},{"version":"98f37634b12b17ad5c56db8fb63cf9d7dc55d74c","lessThan":"3afc64c61ce906a04f073ca350b46de10e8302f9","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["io_uring/bpf-ops.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"7.1","status":"affected"},{"version":"0","lessThan":"7.1","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc4","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/0639ea767fe04c288a8d6cb826100fe3d95d4936","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/3afc64c61ce906a04f073ca350b46de10e8302f9","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-72113","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:21:25.680","lastModified":"2026-08-15T06:21:25.680","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\ncan: bcm: add missing device refcount for CAN filter removal\n\nsashiko-bot remarked a problem with a concurrent device unregistration\nin isotp.c which also is present in the bcm.c code. A former fix for raw.c\ncommit c275a176e4b6 (\"can: raw: add missing refcount for memory leak fix\")\nintroduced a netdevice_tracker which solves the issue for bcm.c too.\n\nbcm_release(), bcm_delete_rx_op() and bcm_notifier() relied on\ndev_get_by_index(ifindex) to re-find the device for an rx_op before\nunregistering its filter. If a concurrent NETDEV_UNREGISTER has already\nunlisted the device from the ifindex table, that lookup fails and\ncan_rx_unregister() is silently skipped, leaving a stale CAN filter\npointing at the soon-to-be-freed bcm_op/socket.\n\nHold a netdev_hold()/netdev_put() tracked reference on op->rx_reg_dev\nfrom the moment the rx filter is registered in bcm_rx_setup() until it\nis unregistered in bcm_rx_unreg(), and use that reference directly in\nbcm_release() and bcm_delete_rx_op() instead of re-looking the device\nup by ifindex."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["net/can/bcm.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"ffd980f976e7fd666c2e61bf8ab35107efd11828","lessThan":"84aa4807816e405c1bf87114fc63e06d244281ef","versionType":"git","status":"affected"},{"version":"ffd980f976e7fd666c2e61bf8ab35107efd11828","lessThan":"633bda66fbf309f5de5e1ad6defe8e6b1d77a20f","versionType":"git","status":"affected"},{"version":"ffd980f976e7fd666c2e61bf8ab35107efd11828","lessThan":"b024c21c9066f6957b7d4a8f2037e4b000c5e041","versionType":"git","status":"affected"},{"version":"ffd980f976e7fd666c2e61bf8ab35107efd11828","lessThan":"04d23061bbf18d5d81022eb21e9d32e99d24468d","versionType":"git","status":"affected"},{"version":"ffd980f976e7fd666c2e61bf8ab35107efd11828","lessThan":"d59948293ea34b6337ce2b5febab8510de70048c","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["net/can/bcm.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"2.6.25","status":"affected"},{"version":"0","lessThan":"2.6.25","versionType":"semver","status":"unaffected"},{"version":"6.6.148","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.101","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.42","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc4","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/04d23061bbf18d5d81022eb21e9d32e99d24468d","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/633bda66fbf309f5de5e1ad6defe8e6b1d77a20f","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/84aa4807816e405c1bf87114fc63e06d244281ef","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/b024c21c9066f6957b7d4a8f2037e4b000c5e041","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/d59948293ea34b6337ce2b5febab8510de70048c","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-72114","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:21:25.803","lastModified":"2026-08-15T06:21:25.803","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\ncan: bcm: validate frame length in bcm_rx_setup() for RTR replies\n\nbcm_tx_setup() validates cf->len against the CAN/CAN FD DLC limits\nbefore installing frames for TX_SETUP, but bcm_rx_setup() never did\nthe same for the RTR-reply frame configured via RX_SETUP with\nRX_RTR_FRAME."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["net/can/bcm.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"ffd980f976e7fd666c2e61bf8ab35107efd11828","lessThan":"7d966cdee006911d3957e1a4e72cb93c39cd8c1e","versionType":"git","status":"affected"},{"version":"ffd980f976e7fd666c2e61bf8ab35107efd11828","lessThan":"1b475c0c72f44622a320a4386ce9e76f85e69bc7","versionType":"git","status":"affected"},{"version":"ffd980f976e7fd666c2e61bf8ab35107efd11828","lessThan":"deb6a697cce3f021e731df543597f37a5e54caab","versionType":"git","status":"affected"},{"version":"ffd980f976e7fd666c2e61bf8ab35107efd11828","lessThan":"59bfddea64159594feb62ef11b7d7a33c8ee3783","versionType":"git","status":"affected"},{"version":"ffd980f976e7fd666c2e61bf8ab35107efd11828","lessThan":"62ec41f364648be79d54d94d0d240ee326948afd","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["net/can/bcm.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"2.6.25","status":"affected"},{"version":"0","lessThan":"2.6.25","versionType":"semver","status":"unaffected"},{"version":"6.6.148","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.101","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.42","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc4","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/1b475c0c72f44622a320a4386ce9e76f85e69bc7","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/59bfddea64159594feb62ef11b7d7a33c8ee3783","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/62ec41f364648be79d54d94d0d240ee326948afd","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/7d966cdee006911d3957e1a4e72cb93c39cd8c1e","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/deb6a697cce3f021e731df543597f37a5e54caab","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-72115","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:21:25.900","lastModified":"2026-08-15T06:21:25.900","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\ncan: bcm: track a single source interface for ANYDEV timeout/throttle ops\n\nAn ANYDEV rx op (ifindex == 0) with an active RX timeout and/or\nthrottle timer has no defined semantics when matching frames arrive\nfrom several interfaces: bcm_rx_handler() can run concurrently for\nthe same op on different CPUs, racing hrtimer_cancel()/\nbcm_rx_starttimer() against bcm_rx_timeout_handler() and causing\nspurious RX_TIMEOUT notifications and last_frames corruption. The\nsame concurrency lets throttled multiplex frames from different\ninterfaces clobber the single rx_ifindex/rx_stamp fields shared by\nthe op.\n\nAdd op->if_detected to track the first interface that delivers a\nmatching frame while a timeout/throttle timer is configured, and\nreject frames from any other interface for that op. The claim is\ndecided in bcm_rx_handler() before hrtimer_cancel() touches\nop->timer, so a rejected frame can never disturb the claimed\ninterface's watchdog. RTR-mode ops are excluded via RX_RTR_FRAME,\nindependent of kt_ival1/kt_ival2, since those may briefly hold a\nstale value from an earlier non-RTR configuration.\n\nThe claim is released in bcm_notify() on NETDEV_UNREGISTER and in\nbcm_rx_setup() when SETTIMER reconfigures the timer values.\n\nA (re-)claim is only possible on CAN devices in NETREG_REGISTERED\ndev->reg_state to cover the release in bcm_notify() where reg_state\nbecomes NETREG_UNREGISTERING until synchronize_net()."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["net/can/bcm.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"ffd980f976e7fd666c2e61bf8ab35107efd11828","lessThan":"18b45251e74e35668f0dd0c470549384ae191ecf","versionType":"git","status":"affected"},{"version":"ffd980f976e7fd666c2e61bf8ab35107efd11828","lessThan":"3ff8c24b421070a2db99a5cdb86edc9ff339418e","versionType":"git","status":"affected"},{"version":"ffd980f976e7fd666c2e61bf8ab35107efd11828","lessThan":"eca8b44d51fc6ab61022258ec968e55e3073b79e","versionType":"git","status":"affected"},{"version":"ffd980f976e7fd666c2e61bf8ab35107efd11828","lessThan":"b6317022b685a430a3ae420456716e3c0c02ef4b","versionType":"git","status":"affected"},{"version":"ffd980f976e7fd666c2e61bf8ab35107efd11828","lessThan":"2f5976f54a04e9f18b25283036ac3136be453b17","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["net/can/bcm.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"2.6.25","status":"affected"},{"version":"0","lessThan":"2.6.25","versionType":"semver","status":"unaffected"},{"version":"6.6.148","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.101","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.42","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc4","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/18b45251e74e35668f0dd0c470549384ae191ecf","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/2f5976f54a04e9f18b25283036ac3136be453b17","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/3ff8c24b421070a2db99a5cdb86edc9ff339418e","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/b6317022b685a430a3ae420456716e3c0c02ef4b","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/eca8b44d51fc6ab61022258ec968e55e3073b79e","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-72116","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:21:26.020","lastModified":"2026-08-15T06:21:26.020","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\ncan: bcm: fix stale rx/tx ops after device removal\n\nRX: an RX_SETUP update(!) for an existing op skipped can_rx_register()\nunconditionally, even when a concurrent NETDEV_UNREGISTER had already\ntorn down its registration (op->rx_reg_dev == NULL). This silently\ndid not re-enable frame delivery for that updated filter. bcm_rx_setup()\nnow re-registers in that case, while leaving rx_ops with ifindex = 0\n(all CAN devices) which never carry a tracked rx_reg_dev registered as-is.\n\nTX: bcm_notify() only handled bo->rx_ops on NETDEV_UNREGISTER, leaving\ntx_ops with an active cyclic transmission re-arming its hrtimer\nindefinitely to execute bcm_tx_timeout_handler(). Cancelling the hrtimer\nprevents the runaway timer and any injection into a later reused ifindex,\nsince nothing else calls bcm_can_tx() for the op until an explicit\nTX_SETUP update re-arms it.\n\nUnlike bcm_rx_unreg(), which clears the tracked rx_reg_dev for rx_ops,\nthe ifindex is intentionally left unchanged for tx_ops. bcm_tx_setup()\nalways rejects ifindex 0, so clearing it would strand the op: neither a\nlater TX_SETUP (bcm_find_op()) nor TX_DELETE (bcm_delete_tx_op()) could\never find it again, since both require an exact ifindex match."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["net/can/bcm.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"ffd980f976e7fd666c2e61bf8ab35107efd11828","lessThan":"60d8a7942f4ed2d975207aaeba1adb576707e53d","versionType":"git","status":"affected"},{"version":"ffd980f976e7fd666c2e61bf8ab35107efd11828","lessThan":"f749e4564952d60e96930c09f2be99955d07c22e","versionType":"git","status":"affected"},{"version":"ffd980f976e7fd666c2e61bf8ab35107efd11828","lessThan":"6be3e1fedf03eab36a2c09d755d1171287b2014b","versionType":"git","status":"affected"},{"version":"ffd980f976e7fd666c2e61bf8ab35107efd11828","lessThan":"b31d0933509c5a35c0be5736a2ce8df0d1bf112c","versionType":"git","status":"affected"},{"version":"ffd980f976e7fd666c2e61bf8ab35107efd11828","lessThan":"3b762c0d950383ab7a002686c9136b9aa55d2d70","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["net/can/bcm.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"2.6.25","status":"affected"},{"version":"0","lessThan":"2.6.25","versionType":"semver","status":"unaffected"},{"version":"6.6.148","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.101","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.42","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc4","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/3b762c0d950383ab7a002686c9136b9aa55d2d70","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/60d8a7942f4ed2d975207aaeba1adb576707e53d","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/6be3e1fedf03eab36a2c09d755d1171287b2014b","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/b31d0933509c5a35c0be5736a2ce8df0d1bf112c","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/f749e4564952d60e96930c09f2be99955d07c22e","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-72117","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:21:26.123","lastModified":"2026-08-15T06:21:26.123","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\ncan: bcm: fix data race on rx_stamp/rx_ifindex in bcm_rx_handler()\n\nFor an rx op subscribed on all interfaces (ifindex == 0), the same op\nis registered once in the shared per-netns wildcard filter list, so\nbcm_rx_handler() can run concurrently on different CPUs for frames\narriving on different net devices.\n\nop->rx_stamp and op->rx_ifindex were written before bcm_rx_update_lock was\ntaken, allowing concurrent writers to race each other - including a torn\nstore of the 64-bit rx_stamp on 32-bit platforms.\n\nBeyond a torn store bcm_send_to_user() must report the timestamp/ifindex\nof the very same frame whose content it is delivering. So the assignment\nis placed in the same unbroken bcm_rx_update_lock section as the content\ncomparison.\n\nAs a side effect, the RTR-request frame feature (which never reach\nbcm_send_to_user()) no longer updates rx_stamp/rx_ifindex, since only\nthe notification path needs them."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["net/can/bcm.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"ffd980f976e7fd666c2e61bf8ab35107efd11828","lessThan":"5f246b96ab47523ec9b8ea870b5c567a3cb1eb1c","versionType":"git","status":"affected"},{"version":"ffd980f976e7fd666c2e61bf8ab35107efd11828","lessThan":"656ff69ef235699035e57d9e1ae417e62a38aa7f","versionType":"git","status":"affected"},{"version":"ffd980f976e7fd666c2e61bf8ab35107efd11828","lessThan":"136de17f38630307991c59aa7080012a99451783","versionType":"git","status":"affected"},{"version":"ffd980f976e7fd666c2e61bf8ab35107efd11828","lessThan":"c312b750bb5ac3348cfc85dab25e90937bd4d251","versionType":"git","status":"affected"},{"version":"ffd980f976e7fd666c2e61bf8ab35107efd11828","lessThan":"58fd6cbc8541216af1d7ed272ea7ac2b66d50fd8","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["net/can/bcm.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"2.6.25","status":"affected"},{"version":"0","lessThan":"2.6.25","versionType":"semver","status":"unaffected"},{"version":"6.6.148","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.101","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.42","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc4","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/136de17f38630307991c59aa7080012a99451783","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/58fd6cbc8541216af1d7ed272ea7ac2b66d50fd8","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/5f246b96ab47523ec9b8ea870b5c567a3cb1eb1c","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/656ff69ef235699035e57d9e1ae417e62a38aa7f","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/c312b750bb5ac3348cfc85dab25e90937bd4d251","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-72118","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:21:26.240","lastModified":"2026-08-15T06:21:26.240","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\ncan: bcm: fix CAN frame rx/tx statistics\n\nKCSAN detected a data race within the bcm_rx_handler() when two CAN frames\nhave been simultaneously received and processed in a single rx op by two\ndifferent CPUs.\n\nUse atomic operations with (signed) long data types to access the\nstatistics in the hot path to fix the KCSAN complaint.\n\nAdditionally simplify the update and check of statistics overflow by\nusing the atomic operations in separate bcm_update_[rx|tx]_stats()\nfunctions. The rx variant runs under bcm_rx_update_lock to prevent\nraces when resetting the two rx counters; the tx variant runs under\nbcm_tx_lock and only needs to guard its own counter's overflow.\n\nAs the rx path resets its values already at LONG_MAX / 100, there is\nno conflict between the two locking domains (bcm_rx_update_lock vs.\nbcm_tx_lock) even for ops that use both paths.\n\nThe rx statistics update and the frames_filtered update in\nbcm_rx_changed() were previously performed in two separate\nbcm_rx_update_lock sections. For an rx op subscribed on all interfaces\n(ifindex == 0), bcm_rx_handler() can run concurrently on different\nCPUs, so a counter reset by one CPU between these two sections could\nleave frames_filtered larger than frames_abs on another CPU, producing\na bogus (even negative) reduction percentage in procfs. Update the\nstatistics in the same critical section as bcm_rx_changed() to close\nthis gap, which also removes the now unneeded extra lock/unlock pair\naround the traffic_flags calculation."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["net/can/bcm.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"ffd980f976e7fd666c2e61bf8ab35107efd11828","lessThan":"8b2783172d92edd650de6006ebd1c800937021ab","versionType":"git","status":"affected"},{"version":"ffd980f976e7fd666c2e61bf8ab35107efd11828","lessThan":"970caff5c1a63702c80e08d920256bcb5f88ecc5","versionType":"git","status":"affected"},{"version":"ffd980f976e7fd666c2e61bf8ab35107efd11828","lessThan":"8104bcdb2612fdda95169ddc3b49747b2ff98d24","versionType":"git","status":"affected"},{"version":"ffd980f976e7fd666c2e61bf8ab35107efd11828","lessThan":"df47f07cdc801a6afe05a486b5a343c3e532a93c","versionType":"git","status":"affected"},{"version":"ffd980f976e7fd666c2e61bf8ab35107efd11828","lessThan":"e6c24ba95fc3f1b5e1dcd28b1c6e59ef61a9daa5","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["net/can/bcm.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"2.6.25","status":"affected"},{"version":"0","lessThan":"2.6.25","versionType":"semver","status":"unaffected"},{"version":"6.6.148","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.101","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.42","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc4","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/8104bcdb2612fdda95169ddc3b49747b2ff98d24","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/8b2783172d92edd650de6006ebd1c800937021ab","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/970caff5c1a63702c80e08d920256bcb5f88ecc5","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/df47f07cdc801a6afe05a486b5a343c3e532a93c","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/e6c24ba95fc3f1b5e1dcd28b1c6e59ef61a9daa5","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-72119","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:21:26.363","lastModified":"2026-08-15T06:21:26.363","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\ncan: bcm: extend bcm_tx_lock usage for data and timer updates\n\nStage new CAN frame content for an existing tx op into a kmalloc()'d\nbuffer and validate it there, mirroring the approach already used in\nbcm_rx_setup(). Only copy the validated data into op->frames while\nholding op->bcm_tx_lock, so bcm_can_tx() and bcm_tx_timeout_handler()\ncan no longer observe a partially updated or unvalidated frame.\n\nAdd a missing error path for memcpy_from_msg() when copying CAN frame\ndata from userspace.\n\nAlso move the kt_ival1/kt_ival2/ival1/ival2 updates in bcm_tx_setup()\nunder op->bcm_tx_lock, and read kt_ival1/kt_ival2/count under the same\nlock in bcm_tx_set_expiry() and bcm_tx_timeout_handler(), closing the\ntorn 64-bit ktime_t read on 32-bit platforms."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["net/can/bcm.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"76c84c3728178b2d38d5604e399dfe8b0752645e","lessThan":"52f06e7603780de100233713ddaf971d422e10ef","versionType":"git","status":"affected"},{"version":"cc55dd28c20a6611e30596019b3b2f636819a4c0","lessThan":"972fd66bb08fdef1090abe43196ca8da07216d13","versionType":"git","status":"affected"},{"version":"c2aba69d0c36a496ab4f2e81e9c2b271f2693fd7","lessThan":"bd46f55dec608daa44b45dcf3328517630ad8e40","versionType":"git","status":"affected"},{"version":"c2aba69d0c36a496ab4f2e81e9c2b271f2693fd7","lessThan":"337f966c00662d81ad82cf5a4bbb150b2e32c0d4","versionType":"git","status":"affected"},{"version":"c2aba69d0c36a496ab4f2e81e9c2b271f2693fd7","lessThan":"12ce799f7ab1e05bd8fbf79e46f403bfe5597ebc","versionType":"git","status":"affected"},{"version":"8f1c022541bf5a923c8d6fa483112c15250f30a4","versionType":"git","status":"affected"},{"version":"7595de7bc56e0e52b74e56c90f7e247bf626d628","versionType":"git","status":"affected"},{"version":"fbd8fdc2b218e979cfe422b139b8f74c12419d1f","versionType":"git","status":"affected"},{"version":"2a437b86ac5a9893c902f30ef66815bf13587bf6","versionType":"git","status":"affected"},{"version":"c4e8a172501e677ebd8ea9d9161d97dc4df56fbd","versionType":"git","status":"affected"},{"version":"6.6.93","lessThan":"6.6.148","versionType":"semver","status":"affected"},{"version":"6.12.31","lessThan":"6.12.101","versionType":"semver","status":"affected"},{"version":"5.4.294","lessThan":"5.5","versionType":"semver","status":"affected"},{"version":"5.10.238","lessThan":"5.11","versionType":"semver","status":"affected"},{"version":"5.15.185","lessThan":"5.16","versionType":"semver","status":"affected"},{"version":"6.1.141","lessThan":"6.2","versionType":"semver","status":"affected"},{"version":"6.14.9","lessThan":"6.15","versionType":"semver","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["net/can/bcm.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.15","status":"affected"},{"version":"0","lessThan":"6.15","versionType":"semver","status":"unaffected"},{"version":"6.6.148","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.101","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.42","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc4","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/12ce799f7ab1e05bd8fbf79e46f403bfe5597ebc","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/337f966c00662d81ad82cf5a4bbb150b2e32c0d4","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/52f06e7603780de100233713ddaf971d422e10ef","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/972fd66bb08fdef1090abe43196ca8da07216d13","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/bd46f55dec608daa44b45dcf3328517630ad8e40","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-72120","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:21:26.507","lastModified":"2026-08-15T06:21:26.507","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\ncan: bcm: add missing rcu list annotations and operations\n\nsashiko-bot remarked the missing use of list_add_rcu() in\nbcm_[rx|tx]_setup() to have a proper initialized bcm_op structure\nwhen bcm_proc_show() traverses the bcm_op's under rcu_read_lock().\n\nTo cover all initial settings of the bcm_op's the list_add_rcu() calls\nare moved to the end of the setup code.\n\nWhile at it, also fix the mirroring removal side: bcm_release() called\nbcm_remove_op() - which frees the op via call_rcu() - on ops that were\nstill linked in bo->tx_ops/bo->rx_ops, without list_del_rcu() first.\nUnlink each op with list_del_rcu() before handing it to bcm_remove_op(),\nmatching the existing pattern in bcm_delete_tx_op()/bcm_delete_rx_op()."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["net/can/bcm.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"659701c0b954ccdb4a916a4ad59bbc16e726d42c","lessThan":"8357255e56dc1aaa437e3c53ee9385de984e0d57","versionType":"git","status":"affected"},{"version":"0622846db728a5332b917c797c733e202c4620ae","lessThan":"8e1c7257c81577130f5ce90f69b2a2c3ce63f957","versionType":"git","status":"affected"},{"version":"6d7d458c41b98a5c1670cbd36f2923c37de51cf5","lessThan":"eb1c26eab4d1f0b4450439b4b88c3e73faf1da98","versionType":"git","status":"affected"},{"version":"1f912f8484e9c4396378c39460bbea0af681f319","lessThan":"f53bdab85e64eb57d6899a30d1307fd5a3639cc7","versionType":"git","status":"affected"},{"version":"63567ecd99a24495208dc860d50fb17440043006","lessThan":"4e22e8b505f877573bbdfdbcb680babad9b2f7a1","versionType":"git","status":"affected"},{"version":"dac5e6249159ac255dad9781793dbe5908ac9ddb","lessThan":"b06a4a397ac826603f39875cb7c7819a41365196","versionType":"git","status":"affected"},{"version":"dac5e6249159ac255dad9781793dbe5908ac9ddb","lessThan":"30f7bb922cb7e7f072a56c7cb7a5efccd2ceca1d","versionType":"git","status":"affected"},{"version":"dac5e6249159ac255dad9781793dbe5908ac9ddb","lessThan":"7b2c3eabc4dafc062a25e10711154f2107526a78","versionType":"git","status":"affected"},{"version":"19f553a1ddf260da6570ed8f8d91a8c87f49b63a","versionType":"git","status":"affected"},{"version":"7c9db92d5f0eadca30884af75c53d601edc512ee","versionType":"git","status":"affected"},{"version":"5.10.238","lessThan":"5.10.261","versionType":"semver","status":"affected"},{"version":"5.15.185","lessThan":"5.15.212","versionType":"semver","status":"affected"},{"version":"6.1.141","lessThan":"6.1.178","versionType":"semver","status":"affected"},{"version":"6.6.93","lessThan":"6.6.145","versionType":"semver","status":"affected"},{"version":"6.12.31","lessThan":"6.12.97","versionType":"semver","status":"affected"},{"version":"5.4.294","lessThan":"5.5","versionType":"semver","status":"affected"},{"version":"6.14.9","lessThan":"6.15","versionType":"semver","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["net/can/bcm.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.15","status":"affected"},{"version":"0","lessThan":"6.15","versionType":"semver","status":"unaffected"},{"version":"5.10.261","lessThanOrEqual":"5.10.*","versionType":"semver","status":"unaffected"},{"version":"5.15.212","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.178","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.97","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc4","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/30f7bb922cb7e7f072a56c7cb7a5efccd2ceca1d","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/4e22e8b505f877573bbdfdbcb680babad9b2f7a1","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/7b2c3eabc4dafc062a25e10711154f2107526a78","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/8357255e56dc1aaa437e3c53ee9385de984e0d57","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/8e1c7257c81577130f5ce90f69b2a2c3ce63f957","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/b06a4a397ac826603f39875cb7c7819a41365196","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/eb1c26eab4d1f0b4450439b4b88c3e73faf1da98","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/f53bdab85e64eb57d6899a30d1307fd5a3639cc7","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-72121","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:21:26.650","lastModified":"2026-08-15T06:21:26.650","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\ncan: bcm: add locking when updating filter and timer values\n\nKCSAN detected a simultaneous access to timer values that can be\noverwritten in bcm_rx_setup() when updating timer and filter content\nwhile bcm_rx_handler(), bcm_rx_timeout_handler() or bcm_rx_thr_handler()\nrun concurrently on incoming CAN traffic.\n\nProtect the timer (ival1/ival2/kt_ival1/kt_ival2/kt_lastmsg) and filter\n(nframes/flags/frames/last_frames) updates in bcm_rx_setup() with a new\nper-op bcm_rx_update_lock, taken with the matching scope in the RX\nhandlers. memcpy_from_msg() is staged into a temporary buffer before the\nlock is taken, since it can sleep and must not run under a spinlock.\n\nhrtimer_cancel() is always called without bcm_rx_update_lock held, since\nbcm_rx_timeout_handler()/bcm_rx_thr_handler() take the same lock and a\nrunning callback would otherwise deadlock against the canceller.\n\nAlso close a related race: bcm_rx_setup() cleared the RTR flag in the\nstored reply frame's can_id as a separate, unprotected step after the\nframe content was already installed, so a concurrent bcm_rx_handler()\ncould transmit a stale reply with CAN_RTR_FLAG still set. Fold that\nnormalization into the initial frame preparation instead (on the staged\nbuffer for updates, directly on op->frames pre-registration for new\nops), so the installed frame is always atomically self-consistent.\n\nbcm_rx_handler()'s RX_RTR_FRAME check now takes a lock-protected\nsnapshot of op->flags before deciding whether to call bcm_can_tx(),\nbut does not hold the lock across that call.\n\nAlso take a lock-protected snapshot of the currframe in bcm_can_tx()\nto avoid partly overwrites by content updates in bcm_tx_setup().\nFinally check if a TX_RESET_MULTI_IDX/SETTIMER might have reset\nop->currframe between the two locked sections in bcm_can_tx().\n\nOmit calling hrtimer_forward() with zero interval in bcm_rx_thr_handler().\nkt_ival2 may have been concurrently cleared by bcm_rx_setup() before it\ncancels this timer, so check kt_ival2 inside the bcm_rx_update_lock."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["net/can/bcm.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"76c84c3728178b2d38d5604e399dfe8b0752645e","lessThan":"a7eb6db1cd3f7b556a301dc1265945ad112089f7","versionType":"git","status":"affected"},{"version":"cc55dd28c20a6611e30596019b3b2f636819a4c0","lessThan":"834cbca3b12e46887f7a9b35f1981a888360ea4c","versionType":"git","status":"affected"},{"version":"c2aba69d0c36a496ab4f2e81e9c2b271f2693fd7","lessThan":"19b1994069dd29478ba767de1f98f14a088198dc","versionType":"git","status":"affected"},{"version":"c2aba69d0c36a496ab4f2e81e9c2b271f2693fd7","lessThan":"fc9f5ee1b073bd233d9c604e338af4ebb42cbc33","versionType":"git","status":"affected"},{"version":"c2aba69d0c36a496ab4f2e81e9c2b271f2693fd7","lessThan":"749179c2e25b95d22499ed29096b3e02d6dfd2b4","versionType":"git","status":"affected"},{"version":"8f1c022541bf5a923c8d6fa483112c15250f30a4","versionType":"git","status":"affected"},{"version":"7595de7bc56e0e52b74e56c90f7e247bf626d628","versionType":"git","status":"affected"},{"version":"fbd8fdc2b218e979cfe422b139b8f74c12419d1f","versionType":"git","status":"affected"},{"version":"2a437b86ac5a9893c902f30ef66815bf13587bf6","versionType":"git","status":"affected"},{"version":"c4e8a172501e677ebd8ea9d9161d97dc4df56fbd","versionType":"git","status":"affected"},{"version":"6.6.93","lessThan":"6.6.148","versionType":"semver","status":"affected"},{"version":"6.12.31","lessThan":"6.12.101","versionType":"semver","status":"affected"},{"version":"5.4.294","lessThan":"5.5","versionType":"semver","status":"affected"},{"version":"5.10.238","lessThan":"5.11","versionType":"semver","status":"affected"},{"version":"5.15.185","lessThan":"5.16","versionType":"semver","status":"affected"},{"version":"6.1.141","lessThan":"6.2","versionType":"semver","status":"affected"},{"version":"6.14.9","lessThan":"6.15","versionType":"semver","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["net/can/bcm.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.15","status":"affected"},{"version":"0","lessThan":"6.15","versionType":"semver","status":"unaffected"},{"version":"6.6.148","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.101","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.42","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc4","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/19b1994069dd29478ba767de1f98f14a088198dc","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/749179c2e25b95d22499ed29096b3e02d6dfd2b4","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/834cbca3b12e46887f7a9b35f1981a888360ea4c","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/a7eb6db1cd3f7b556a301dc1265945ad112089f7","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/fc9f5ee1b073bd233d9c604e338af4ebb42cbc33","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-72122","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:21:29.437","lastModified":"2026-08-15T06:21:29.437","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\ncan: bcm: fix lockless bound/ifindex race and silent RX_SETUP failure\n\nbcm_sendmsg() reads bo->ifindex and checks bo->bound before taking\nlock_sock(), while bcm_notify(), bcm_connect() and bcm_release() all\nmutate both fields under that same lock. Because the lockless reads\nand the locked writes are unordered with respect to each other, a\nracing bcm_notify() (device unregister) or bcm_connect() (concurrent\nbind on another thread sharing the socket) can make bcm_sendmsg()\nobserve an inconsistent combination, e.g. a stale bound=1 together\nwith the now-cleared ifindex=0, silently turning a socket bound to a\nspecific CAN interface into one that also matches \"any\" interface.\n\nKeep the lockless bo->bound check purely as a fast-path reject, and\nmove the ifindex read (and a bo->bound re-check) into the locked\nsection, where every writer already serializes. This removes the\npossibility of observing the two fields torn against each other,\nrather than trying to fix it with more READ_ONCE()/WRITE_ONCE() pairs\non two independently updated fields. Annotate the now-purely-lockless\nbo->bound accesses consistently across all its write sites.\n\nAlso fix bcm_rx_setup() silently returning success when the target\ndevice disappears concurrently instead of reporting -ENODEV, so a\nbroken RX op is no longer left registered as if it had succeeded."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["net/can/bcm.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"ffd980f976e7fd666c2e61bf8ab35107efd11828","lessThan":"9e60c586faeaed80d55ab8ce2a4b8e56133bc395","versionType":"git","status":"affected"},{"version":"ffd980f976e7fd666c2e61bf8ab35107efd11828","lessThan":"ffa80a2af27c97453861a5128e537214a31cd18a","versionType":"git","status":"affected"},{"version":"ffd980f976e7fd666c2e61bf8ab35107efd11828","lessThan":"6bcc5cd247c2934373bc2a1cdf8bf12321169543","versionType":"git","status":"affected"},{"version":"ffd980f976e7fd666c2e61bf8ab35107efd11828","lessThan":"0f6f9f95294b4cbb26ba02209e893e3bd91237c3","versionType":"git","status":"affected"},{"version":"ffd980f976e7fd666c2e61bf8ab35107efd11828","lessThan":"b70f1a15533afeeec5d07f20bec3f3867ab1c7b6","versionType":"git","status":"affected"},{"version":"ffd980f976e7fd666c2e61bf8ab35107efd11828","lessThan":"35f0ac19efb1a3f6c5e12c00e475a9ec2d9c3a6d","versionType":"git","status":"affected"},{"version":"ffd980f976e7fd666c2e61bf8ab35107efd11828","lessThan":"b9c6ac6fb4e01b34575816066e5d3890a57b3c86","versionType":"git","status":"affected"},{"version":"ffd980f976e7fd666c2e61bf8ab35107efd11828","lessThan":"d9b091d9d22fee81ec53fb55d2032951993ceadb","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["net/can/bcm.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"2.6.25","status":"affected"},{"version":"0","lessThan":"2.6.25","versionType":"semver","status":"unaffected"},{"version":"5.10.261","lessThanOrEqual":"5.10.*","versionType":"semver","status":"unaffected"},{"version":"5.15.212","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.178","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.97","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc4","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/0f6f9f95294b4cbb26ba02209e893e3bd91237c3","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/35f0ac19efb1a3f6c5e12c00e475a9ec2d9c3a6d","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/6bcc5cd247c2934373bc2a1cdf8bf12321169543","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/9e60c586faeaed80d55ab8ce2a4b8e56133bc395","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/b70f1a15533afeeec5d07f20bec3f3867ab1c7b6","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/b9c6ac6fb4e01b34575816066e5d3890a57b3c86","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/d9b091d9d22fee81ec53fb55d2032951993ceadb","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/ffa80a2af27c97453861a5128e537214a31cd18a","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-72123","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:21:29.577","lastModified":"2026-08-15T06:21:29.577","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\ncan: bcm: defer rx_op deallocation to workqueue to fix thrtimer UAF\n\nCommit f1b4e32aca08 (\"can: bcm: use call_rcu() instead of costly\nsynchronize_rcu()\") replaced synchronize_rcu() in bcm_delete_rx_op()\nwith call_rcu() and introduced the RX_NO_AUTOTIMER flag.\n\nHowever, this flag check was omitted for thrtimer in the packet rx\nfast-path. During BCM RX operation teardown, a concurrent RCU reader\n(bcm_rx_handler) can race and re-arm thrtimer via\nbcm_rx_update_and_send() after call_rcu() has been scheduled.  Once\nthe RCU grace period elapses, bcm_op is freed.  The subsequently\nfiring thrtimer then dereferences the deallocated op, causing a UAF.\n\nAdding flag checks to the rx fast-path (bcm_rx_update_and_send) does not\nfully close the TOCTOU race and introduces latency for every CAN frame.\nConversely, calling hrtimer_cancel() directly inside the RCU callback\n(softirq context) is fatal as hrtimer_cancel() can sleep, triggering\na \"scheduling while atomic\" panic.\n\nResolve this by deferring the timer cancellation and memory free to a\ndedicated unbound workqueue (bcm_wq).  The RCU callback now queues a\nwork item to bcm_wq, which safely cancels both timers and deallocates\nmemory in sleepable process context.  A dedicated workqueue is used to\nprevent system-wide WQ saturation and is cleanly flushed/destroyed\non module unload to avoid rmmod page faults.\n\nSince the deferred work can now outlive the calling context by an\nunbounded amount, also take a reference on op->sk when it is assigned\nand drop it only once the deferred work has cancelled both timers, so a\nsocket can no longer be freed out from under a still-armed timer whose\ncallback (bcm_send_to_user()) dereferences op->sk."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["net/can/bcm.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"f1b4e32aca0811aa011c76e5d6cf2fa19224b386","lessThan":"3cf4fd5316f449811d8baf1bc6978ef5a7b743a9","versionType":"git","status":"affected"},{"version":"f1b4e32aca0811aa011c76e5d6cf2fa19224b386","lessThan":"4177762f70646ac48a2af382e45a795cbd295198","versionType":"git","status":"affected"},{"version":"f1b4e32aca0811aa011c76e5d6cf2fa19224b386","lessThan":"6fd08e8d826c3aa4cc7021f5f9cdbb7fa7441d3f","versionType":"git","status":"affected"},{"version":"f1b4e32aca0811aa011c76e5d6cf2fa19224b386","lessThan":"cd830e0bc25ee2d38cbfbdbb3cd77c5f53b2b6d5","versionType":"git","status":"affected"},{"version":"f1b4e32aca0811aa011c76e5d6cf2fa19224b386","lessThan":"ce2d4b121fb7545e1ed588e860c8e5fd5ad45224","versionType":"git","status":"affected"},{"version":"f1b4e32aca0811aa011c76e5d6cf2fa19224b386","lessThan":"68973f9db76144825e4f35dfdc80fb8279eb2d57","versionType":"git","status":"affected"},{"version":"fbac09a3b8890003c0c55294c00709f3ae5501bb","versionType":"git","status":"affected"},{"version":"5b48f5711f1c630841ab78dcc061de902f0e37bf","versionType":"git","status":"affected"},{"version":"85cd41070df992d3c0dfd828866fdd243d3b774a","versionType":"git","status":"affected"},{"version":"f34f2a18e47b73e48f90a757e1f4aaa8c7d665a1","versionType":"git","status":"affected"},{"version":"edb4baffb9483141a50fb7f7146cfe4a4c0c2db8","versionType":"git","status":"affected"},{"version":"4.19.252","lessThan":"4.20","versionType":"semver","status":"affected"},{"version":"5.4.205","lessThan":"5.5","versionType":"semver","status":"affected"},{"version":"5.10.130","lessThan":"5.11","versionType":"semver","status":"affected"},{"version":"5.15.54","lessThan":"5.16","versionType":"semver","status":"affected"},{"version":"5.18.11","lessThan":"5.19","versionType":"semver","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["net/can/bcm.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"5.19","status":"affected"},{"version":"0","lessThan":"5.19","versionType":"semver","status":"unaffected"},{"version":"6.1.178","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.97","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc4","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/3cf4fd5316f449811d8baf1bc6978ef5a7b743a9","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/4177762f70646ac48a2af382e45a795cbd295198","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/68973f9db76144825e4f35dfdc80fb8279eb2d57","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/6fd08e8d826c3aa4cc7021f5f9cdbb7fa7441d3f","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/cd830e0bc25ee2d38cbfbdbb3cd77c5f53b2b6d5","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/ce2d4b121fb7545e1ed588e860c8e5fd5ad45224","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-72124","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:21:29.720","lastModified":"2026-08-15T06:21:29.720","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\ncan: isotp: serialize TX state transitions under so->rx_lock\n\nThe TX state machine (so->tx.state) is driven from three contexts:\nsendmsg() claiming and progressing a transfer, the RX path consuming\nFlow Control/echo frames, and two hrtimers timing out a stalled\ntransfer. Mixing a lock-free cmpxchg() claim in sendmsg() with\nhrtimer_cancel() calls made under so->rx_lock elsewhere left windows\nwhere a frame or timer callback could act on a state that had already\nmoved on, corrupting an unrelated transfer.\n\nso->rx_lock now covers the full lifecycle of a TX claim: sendmsg()\ntakes it to check so->tx.state is ISOTP_IDLE, switch it to\nISOTP_SENDING, bump so->tx_gen and drain the previous transfer's\ntimers - all as one critical section. isotp_rcv_fc()/isotp_rcv_cf()\nalready run under this lock via isotp_rcv(), and isotp_rcv_echo() now\ntakes it itself, so none of them can ever observe a transfer mid-claim.\nThis also means a transfer can no longer be handed to sendmsg()'s\ncleanup paths (signal or send error) while another thread is\nconcurrently claiming or finishing it, so those paths can cancel\ntimers and reset the state unconditionally.\n\nisotp_release() claims the socket the same way, so a racing sendmsg()\nsees a consistent ISOTP_SHUTDOWN and skips arming its timer or sending.\n\nOnly the hrtimer callbacks stay outside so->rx_lock, since they run\nunder so->rx_lock's cancellation elsewhere and taking it themselves\nwould deadlock. so->tx_gen lets them recognize whether the transfer\nthey timed out is still the one currently active, so they don't\nreport an error against a transfer that has since completed or been\nsuperseded."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["net/can/isotp.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"e057dd3fc20ffb3d7f150af46542a51b59b90127","lessThan":"0b05eca9589f609e2491b528dccf683168a4cda8","versionType":"git","status":"affected"},{"version":"e057dd3fc20ffb3d7f150af46542a51b59b90127","lessThan":"a7d90e7b5e75d7406c889fe36e9a61ee364a00cb","versionType":"git","status":"affected"},{"version":"e057dd3fc20ffb3d7f150af46542a51b59b90127","lessThan":"37beb16e08cae94cc05840c7274225e3b0b38ae7","versionType":"git","status":"affected"},{"version":"e057dd3fc20ffb3d7f150af46542a51b59b90127","lessThan":"4f1fdf1a1c317bcac0c6b6c8e12642c9983de1ca","versionType":"git","status":"affected"},{"version":"e057dd3fc20ffb3d7f150af46542a51b59b90127","lessThan":"cf070fe33bfbd1a4c21236078fadb35dd223a157","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["net/can/isotp.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"5.10","status":"affected"},{"version":"0","lessThan":"5.10","versionType":"semver","status":"unaffected"},{"version":"6.6.148","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.101","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc4","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/0b05eca9589f609e2491b528dccf683168a4cda8","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/37beb16e08cae94cc05840c7274225e3b0b38ae7","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/4f1fdf1a1c317bcac0c6b6c8e12642c9983de1ca","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/a7d90e7b5e75d7406c889fe36e9a61ee364a00cb","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/cf070fe33bfbd1a4c21236078fadb35dd223a157","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-72125","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:21:29.840","lastModified":"2026-08-15T06:21:29.840","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\ncan: isotp: fix use-after-free race with concurrent NETDEV_UNREGISTER\n\nisotp_release() looked up the bound network device via dev_get_by_index()\nusing the stored ifindex. During device unregistration the device is\nunlisted from the ifindex hash before the NETDEV_UNREGISTER notifier\nchain runs, so a concurrent isotp_release() could find no device, skip\ncan_rx_unregister() entirely, and still proceed to free the socket.\nSince isotp_release() had already removed itself from the isotp\nnotifier list at that point, isotp_notify() would never get a chance to\nclean up either, leaving a stale CAN filter that keeps pointing at the\nfreed socket.\n\nFix this the same way raw.c already does: hold a tracked reference to\nthe bound net_device in the socket (so->dev/so->dev_tracker) from\nbind() onward instead of re-resolving it from the ifindex, and\nserialize bind()/release() with rtnl_lock() so that so->dev is always\nconsistent with what the NETDEV_UNREGISTER notifier sees. so->dev\nstays valid regardless of ifindex-hash unlisting, and is only ever\ncleared by whichever of isotp_release()/isotp_notify() gets there\nfirst, so the filter is always removed exactly once.\n\nisotp_bind() now rejects a (re)bind with -EAGAIN while so->[tx|rx].state\nisn't ISOTP_IDLE yet, so a timer left running by a prior\nNETDEV_UNREGISTER can't act on a newly bound so->ifindex. Both checks\nshare the same lock_sock() section, so there is no window in which a\nconcurrent isotp_notify() clearing so->bound could be missed."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["net/can/isotp.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"e057dd3fc20ffb3d7f150af46542a51b59b90127","lessThan":"0b811c4bbe3ec9ad611e90a540fe8b51b3bb8a96","versionType":"git","status":"affected"},{"version":"e057dd3fc20ffb3d7f150af46542a51b59b90127","lessThan":"43884dc7963beef2328f507f4fe680bdc173eb80","versionType":"git","status":"affected"},{"version":"e057dd3fc20ffb3d7f150af46542a51b59b90127","lessThan":"7bef39ba76eb7307ed22a50329e0f5776dbeda58","versionType":"git","status":"affected"},{"version":"e057dd3fc20ffb3d7f150af46542a51b59b90127","lessThan":"e442b62ba5a7756c17e05a77b32cdd085a2b6138","versionType":"git","status":"affected"},{"version":"e057dd3fc20ffb3d7f150af46542a51b59b90127","lessThan":"20bab8b88baac140ca3701116e1d486c7f51e311","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["net/can/isotp.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"5.10","status":"affected"},{"version":"0","lessThan":"5.10","versionType":"semver","status":"unaffected"},{"version":"6.6.148","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.101","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc4","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/0b811c4bbe3ec9ad611e90a540fe8b51b3bb8a96","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/20bab8b88baac140ca3701116e1d486c7f51e311","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/43884dc7963beef2328f507f4fe680bdc173eb80","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/7bef39ba76eb7307ed22a50329e0f5776dbeda58","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/e442b62ba5a7756c17e05a77b32cdd085a2b6138","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-72126","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:21:29.963","lastModified":"2026-08-15T06:21:29.963","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\ncan: isotp: use unconditional synchronize_rcu() in isotp_release()\n\nisotp_notify() unregisters the (RCU) CAN filters via can_rx_unregister()\nand clears so->bound without waiting for a grace period. isotp_release()\nuses so->bound to decide whether it needs to call synchronize_rcu()\nbefore cancelling so->rxtimer, so when NETDEV_UNREGISTER runs first it\nskips that synchronize_rcu() and can cancel the timer while an\nin-flight isotp_rcv() is still executing and about to re-arm it via\nisotp_send_fc(), leading to a use-after-free timer callback on the\nfreed socket.\n\nsakisho-bot remarked a problem with rtnl_lock held in isotp_notify(),\ntherefore make isotp_release() always call synchronize_rcu() before\ncancelling the timers, regardless of so->bound. This still closes the\noriginal race (isotp_notify() clearing so->bound without waiting for\nin-flight isotp_rcv() callers before isotp_release() cancels the RX\ntimer) without adding any RCU wait to the netdevice notifier path."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["net/can/isotp.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"22bfa94db2ef6900c790884fa9461486516626e9","lessThan":"945d9894502cd9124f5d676181c542ed2000f7c0","versionType":"git","status":"affected"},{"version":"14a4696bc3118ba49da28f79280e1d55603aa737","lessThan":"59672aa4bcd8d32172c1ff6a179583981d6acabc","versionType":"git","status":"affected"},{"version":"14a4696bc3118ba49da28f79280e1d55603aa737","lessThan":"15413a082df69175c2f96aeab4c26fe1ff7cff03","versionType":"git","status":"affected"},{"version":"14a4696bc3118ba49da28f79280e1d55603aa737","lessThan":"6280eda96e0707264849fa7d036fed873c1f8a6d","versionType":"git","status":"affected"},{"version":"14a4696bc3118ba49da28f79280e1d55603aa737","lessThan":"cb6abc584a1bfab107ac003d64948a4aef1730aa","versionType":"git","status":"affected"},{"version":"14a4696bc3118ba49da28f79280e1d55603aa737","lessThan":"b88a511308779c225005d7994b8744561bdbafbc","versionType":"git","status":"affected"},{"version":"14a4696bc3118ba49da28f79280e1d55603aa737","lessThan":"b8278ff605187ef3fa0f2705e93251cce4c4f8ee","versionType":"git","status":"affected"},{"version":"14a4696bc3118ba49da28f79280e1d55603aa737","lessThan":"9b1a02e0d980ac6b0e36a90378f847062f81d7e4","versionType":"git","status":"affected"},{"version":"80c6ddf771df2ef786f28c1ca5919b3f1080091b","versionType":"git","status":"affected"},{"version":"ebf91625b3e404bd2b4b694c7ee71c1e8f8bd08f","versionType":"git","status":"affected"},{"version":"5.10.50","lessThan":"5.10.261","versionType":"semver","status":"affected"},{"version":"5.12.17","lessThan":"5.13","versionType":"semver","status":"affected"},{"version":"5.13.2","lessThan":"5.14","versionType":"semver","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["net/can/isotp.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"5.14","status":"affected"},{"version":"0","lessThan":"5.14","versionType":"semver","status":"unaffected"},{"version":"5.10.261","lessThanOrEqual":"5.10.*","versionType":"semver","status":"unaffected"},{"version":"5.15.212","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.178","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.97","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc4","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/15413a082df69175c2f96aeab4c26fe1ff7cff03","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/59672aa4bcd8d32172c1ff6a179583981d6acabc","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/6280eda96e0707264849fa7d036fed873c1f8a6d","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/945d9894502cd9124f5d676181c542ed2000f7c0","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/9b1a02e0d980ac6b0e36a90378f847062f81d7e4","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/b8278ff605187ef3fa0f2705e93251cce4c4f8ee","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/b88a511308779c225005d7994b8744561bdbafbc","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/cb6abc584a1bfab107ac003d64948a4aef1730aa","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-72127","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:21:30.113","lastModified":"2026-08-15T06:21:30.113","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nnetdev-genl: report NAPI thread PID in the caller's pid namespace\n\nnetdev_nl_napi_fill_one() reports the NAPI kthread PID in NETDEV_A_NAPI_PID\nusing task_pid_nr(), which returns the PID in the initial pid namespace.\n\nNETDEV_CMD_NAPI_GET does not have GENL_ADMIN_PERM and the netdev genl family\nis netnsok, so a caller in a child pid namespace can issue it. That caller\nthen sees the kthread's global PID, even though the kthread is not visible\nin its pid namespace, where the value should be 0.\n\nTranslate the PID through the caller's pid namespace, the same way commit\n3799c2570982 (\"io_uring/fdinfo: translate SqThread PID through caller's\npid_ns\") did for the io_uring SQPOLL thread. The doit and dumpit paths both\nrun synchronously in the caller's context, so task_active_pid_ns(current) is\nthe caller's pid namespace."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["net/core/netdev-genl.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"db4704f4e4dfce835e934609fca735a648ce26e8","lessThan":"fb18095389fe81f140d39585a2624aca9d42227e","versionType":"git","status":"affected"},{"version":"db4704f4e4dfce835e934609fca735a648ce26e8","lessThan":"5e4c8e08ce95730c87d6ada0bdbe1131a3c06393","versionType":"git","status":"affected"},{"version":"db4704f4e4dfce835e934609fca735a648ce26e8","lessThan":"fd750b694f1f9e1ecb8ca19314e4e21edbb15f42","versionType":"git","status":"affected"},{"version":"db4704f4e4dfce835e934609fca735a648ce26e8","lessThan":"1f24c0d01db214c9e661915e9972404c96ca73c0","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["net/core/netdev-genl.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.8","status":"affected"},{"version":"0","lessThan":"6.8","versionType":"semver","status":"unaffected"},{"version":"6.12.97","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/1f24c0d01db214c9e661915e9972404c96ca73c0","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/5e4c8e08ce95730c87d6ada0bdbe1131a3c06393","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/fb18095389fe81f140d39585a2624aca9d42227e","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/fd750b694f1f9e1ecb8ca19314e4e21edbb15f42","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-72128","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:21:30.217","lastModified":"2026-08-15T06:21:30.217","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nnvmet: fix refcount leak in nvmet_sq_create()\n\nIn nvmet_sq_create(), a reference on the ctrl is taken\nvia kref_get_unless_zero() before calling nvmet_check_sqid().\nIf nvmet_check_sqid() fails, the function returns the error\ndirectly without releasing the reference, leading to a leak.\n\nFix this by jumping to the \"ctrl_put\" label, which already\nperforms the necessary nvmet_ctrl_put(ctrl). This ensures the\nreference is properly released on this error path."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/nvme/target/core.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"1eb380caf5275bba1d3d6182dde1fd740f331743","lessThan":"26355295ce21cb046546085c3a81abe68160a784","versionType":"git","status":"affected"},{"version":"1eb380caf5275bba1d3d6182dde1fd740f331743","lessThan":"fcef60ed5f714a24104eb021d6397a67955ebeff","versionType":"git","status":"affected"},{"version":"1eb380caf5275bba1d3d6182dde1fd740f331743","lessThan":"34b9a83c50660148bde01cde16451dbe78369749","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/nvme/target/core.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.14","status":"affected"},{"version":"0","lessThan":"6.14","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/26355295ce21cb046546085c3a81abe68160a784","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/34b9a83c50660148bde01cde16451dbe78369749","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/fcef60ed5f714a24104eb021d6397a67955ebeff","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-72129","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:21:30.320","lastModified":"2026-08-15T06:21:30.320","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nnvmet-rdma: handle inline data with a nonzero offset\n\nnvmet_rdma_use_inline_sg() maps the host-controlled inline data offset\ninto the per-command inline scatterlist.  The bounds check admits any\noffset with off + len <= inline_data_size, but the mapping still assumes\nthe data begins in the first inline page:\n\n\tsg->offset = off;\n\tsg->length = min_t(int, len, PAGE_SIZE - off);\n\nWhen a port is configured with inline_data_size > PAGE_SIZE (settable up\nto max(SZ_16K, PAGE_SIZE)), an offset in (PAGE_SIZE, inline_data_size]\nmakes \"PAGE_SIZE - off\" underflow, so sg->length is set to ~4 GiB and\nthe block backend reads far past the first inline page.  num_pages(len)\nalso ignores the offset, so an in-bounds offset whose [off, off+len)\nspan crosses a page boundary under-counts the scatterlist.\n\nMap the offset properly: split it into a page index and an in-page\noffset, start the scatterlist at that page, and size the page count from\npage_off + len.  Because the request scatterlist may now start at\ninline_sg[page_idx] rather than inline_sg[0], generalize the inline-SGL\nidentity test in nvmet_rdma_release_rsp() to a range test; otherwise the\npersistent inline scatterlist is mistaken for an allocated one and\nnvmet_req_free_sgls() frees an inline page (and warns in\nfree_large_kmalloc())."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/nvme/target/rdma.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"0d5ee2b2ab4f6776c361bc975c2323bc8b5cf349","lessThan":"c2106ba1b14d644a5203bea1a50dbe25dcad713c","versionType":"git","status":"affected"},{"version":"0d5ee2b2ab4f6776c361bc975c2323bc8b5cf349","lessThan":"bf8bcc1c137d54a62a428b00051fdbb13660673b","versionType":"git","status":"affected"},{"version":"0d5ee2b2ab4f6776c361bc975c2323bc8b5cf349","lessThan":"11401371152b228448a41d79c6de1c938f93049a","versionType":"git","status":"affected"},{"version":"0d5ee2b2ab4f6776c361bc975c2323bc8b5cf349","lessThan":"7c96581169c9d9a7d0726e554313acfbead6141c","versionType":"git","status":"affected"},{"version":"0d5ee2b2ab4f6776c361bc975c2323bc8b5cf349","lessThan":"42a8ea3acd883f4f210d9e54e0975b1e2292b529","versionType":"git","status":"affected"},{"version":"0d5ee2b2ab4f6776c361bc975c2323bc8b5cf349","lessThan":"2944113ad5fbcdf5d349d857c03d2a44b6de75b8","versionType":"git","status":"affected"},{"version":"0d5ee2b2ab4f6776c361bc975c2323bc8b5cf349","lessThan":"98bcdfa619150b2f41fa15bac140dbaf2584ad05","versionType":"git","status":"affected"},{"version":"0d5ee2b2ab4f6776c361bc975c2323bc8b5cf349","lessThan":"48c0162f647bb47e6084ffbc71b8f213f5e2f4f8","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/nvme/target/rdma.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"4.19","status":"affected"},{"version":"0","lessThan":"4.19","versionType":"semver","status":"unaffected"},{"version":"5.10.261","lessThanOrEqual":"5.10.*","versionType":"semver","status":"unaffected"},{"version":"5.15.212","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.178","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.97","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/11401371152b228448a41d79c6de1c938f93049a","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/2944113ad5fbcdf5d349d857c03d2a44b6de75b8","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/42a8ea3acd883f4f210d9e54e0975b1e2292b529","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/48c0162f647bb47e6084ffbc71b8f213f5e2f4f8","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/7c96581169c9d9a7d0726e554313acfbead6141c","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/98bcdfa619150b2f41fa15bac140dbaf2584ad05","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/bf8bcc1c137d54a62a428b00051fdbb13660673b","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/c2106ba1b14d644a5203bea1a50dbe25dcad713c","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-72130","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:21:30.453","lastModified":"2026-08-15T06:21:30.453","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nnvmet-auth: reject short AUTH_RECEIVE buffers\n\nnvmet_execute_auth_receive() trusts the AUTH_RECEIVE allocation length\nafter checking only that it is nonzero and matches the transfer length.\nIn the SUCCESS1 and FAILURE1/default states, that lets a remote NVMe-oF\ninitiator reach the fixed-size DH-HMAC-CHAP response builders with a\nkmalloc() buffer shorter than the response, so nvmet_auth_success1() and\nnvmet_auth_failure1() write past the allocation; both only WARN_ON the\nshort length and then format the message anyway.\n\nImpact: A remote NVMe-oF initiator with access to an auth-enabled target\ncan trigger a 16-byte heap out-of-bounds write via a one-byte\nAUTH_RECEIVE allocation length.\n\nCompute the minimum response length for the current DH-HMAC-CHAP step in\nnvmet_auth_receive_data_len() and report a zero data length when the\nhost-supplied allocation length is shorter, so the existing zero-length\ncheck in nvmet_execute_auth_receive() rejects the command before any\nbuilder runs. The SUCCESS1 minimum is sizeof(struct\nnvmf_auth_dhchap_success1_data) plus the HMAC hash length, because the\nresponse hash is written into the rval[] flexible-array tail, so the\nminimum is state dependent rather than a flat sizeof. CHALLENGE keeps its\nexisting variable-length guard in nvmet_auth_challenge().\n\nThis is reachable only when in-band DH-HMAC-CHAP authentication is\nconfigured on the target."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/nvme/target/fabrics-cmd-auth.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"db1312dd95488b5e6ff362ff66fcf953a46b1821","lessThan":"80bf7b7f676e3987bbe06af3c359bd56ac91a5a9","versionType":"git","status":"affected"},{"version":"db1312dd95488b5e6ff362ff66fcf953a46b1821","lessThan":"2eaa3ad450141cfcf187bb43cb8335eb336b5f87","versionType":"git","status":"affected"},{"version":"db1312dd95488b5e6ff362ff66fcf953a46b1821","lessThan":"bc111698b46e43eddd8664cceaa621cd559e99a0","versionType":"git","status":"affected"},{"version":"db1312dd95488b5e6ff362ff66fcf953a46b1821","lessThan":"779575bc35c687697ba69e904f2cd22e60112534","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/nvme/target/fabrics-cmd-auth.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.0","status":"affected"},{"version":"0","lessThan":"6.0","versionType":"semver","status":"unaffected"},{"version":"6.12.101","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/2eaa3ad450141cfcf187bb43cb8335eb336b5f87","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/779575bc35c687697ba69e904f2cd22e60112534","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/80bf7b7f676e3987bbe06af3c359bd56ac91a5a9","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/bc111698b46e43eddd8664cceaa621cd559e99a0","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-72131","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:21:30.557","lastModified":"2026-08-15T06:21:30.557","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nnvme-apple: Prevent shared tags across queues on Apple A11\n\nOn Apple A11, tags of pending commands must be unique across the admin\nand IO queues, else the firmware crashes with\n\"duplicate tag error for tag N\", with N being the tag.\n\nApply the existing workaround for M1 of reserving two tags for the admin\nqueue to A11."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/nvme/host/apple.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"04d8ecf37b5e06d16228a4d37d8548c17cf70461","lessThan":"59cef6abc924a84824b0c3f563a7fe74cd5fc7a4","versionType":"git","status":"affected"},{"version":"04d8ecf37b5e06d16228a4d37d8548c17cf70461","lessThan":"b7d9aaedf024bb6c0bb6a205848861d888eb1afa","versionType":"git","status":"affected"},{"version":"04d8ecf37b5e06d16228a4d37d8548c17cf70461","lessThan":"6fe0687245e8406bf26143bd45eb16441bbe5280","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/nvme/host/apple.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.18","status":"affected"},{"version":"0","lessThan":"6.18","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/59cef6abc924a84824b0c3f563a7fe74cd5fc7a4","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/6fe0687245e8406bf26143bd45eb16441bbe5280","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/b7d9aaedf024bb6c0bb6a205848861d888eb1afa","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-72132","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:21:30.657","lastModified":"2026-08-15T06:21:30.657","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nNFS: Charge unstable writes by request size, not folio size\n\nnfs_folio_mark_unstable() and nfs_folio_clear_commit() charge and\nuncharge NR_WRITEBACK/WB_WRITEBACK by folio_nr_pages(folio) once per\n*request* added to or removed from a commit list. This is correct only\nwhen a folio has a single associated request. When pg_test splits a\nfolio into N sub-folio requests (e.g. pNFS flexfiles striping with a\nstripe unit smaller than the folio size, or plain wsize-limited\nsplitting), each of the N requests independently charges the whole\nfolio's page count, inflating the accounting by a factor of N per\nfolio. With large folios and small stripe units this reaches multiple\norders of magnitude: a 2 MiB folio split into 512 4 KiB requests can\ncharge up to 512x its real size, pushing global dirty+writeback\naccounting past the system's dirty threshold and forcing every\nbuffered writer on the host into the hard-throttle path, including\nunrelated in-kernel NFS server threads sharing the box.\n\nCharge each request only for the pages it actually covers."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["fs/nfs/internal.h","fs/nfs/pnfs_nfs.c","fs/nfs/write.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"0c493b5cf16e28d761b6e77c7c32aa0e7af70813","lessThan":"a442c258320b689f13d2205eaeeddf8b0e630288","versionType":"git","status":"affected"},{"version":"0c493b5cf16e28d761b6e77c7c32aa0e7af70813","lessThan":"1f646e23372f3444dc5f0bcb5404a49d26756add","versionType":"git","status":"affected"},{"version":"0c493b5cf16e28d761b6e77c7c32aa0e7af70813","lessThan":"0ffc032294a29601b1019dba91aa1a930d90df17","versionType":"git","status":"affected"},{"version":"0c493b5cf16e28d761b6e77c7c32aa0e7af70813","lessThan":"a192b6c149c6ea10cc88869accb78165eb454456","versionType":"git","status":"affected"},{"version":"0c493b5cf16e28d761b6e77c7c32aa0e7af70813","lessThan":"27934d02cbeb8a957dd11c985a579e58d30c5270","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["fs/nfs/internal.h","fs/nfs/pnfs_nfs.c","fs/nfs/write.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.3","status":"affected"},{"version":"0","lessThan":"6.3","versionType":"semver","status":"unaffected"},{"version":"6.6.148","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.97","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc3","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/0ffc032294a29601b1019dba91aa1a930d90df17","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/1f646e23372f3444dc5f0bcb5404a49d26756add","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/27934d02cbeb8a957dd11c985a579e58d30c5270","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/a192b6c149c6ea10cc88869accb78165eb454456","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/a442c258320b689f13d2205eaeeddf8b0e630288","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-72133","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:21:30.760","lastModified":"2026-08-15T06:21:30.760","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nspi: uniphier: Fix completion initialization order before devm_request_irq()\n\nThe driver calls devm_request_irq() before initializing the completion\nused by the interrupt handler. Because the interrupt may occur immediately\nafter devm_request_irq(), the handler may execute before init_completion().\n\nThis may result in calling complete() on an uninitialized completion,\ncausing undefined behavior. This has been observed with KASAN.\n\nFix this by initializing the completion before registering the IRQ."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/spi/spi-uniphier.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"5ba155a4d4cc8e4cdd3db6df7d03271a3bd91177","lessThan":"b9fcf0db433d79648ace74bc2b8b88f91e306304","versionType":"git","status":"affected"},{"version":"5ba155a4d4cc8e4cdd3db6df7d03271a3bd91177","lessThan":"82a5746c4c9e94f6f816ec7edea6ddc24417c6a5","versionType":"git","status":"affected"},{"version":"5ba155a4d4cc8e4cdd3db6df7d03271a3bd91177","lessThan":"f4bb0a91f7badd6d15ac8d783a1169d9e1e95c17","versionType":"git","status":"affected"},{"version":"5ba155a4d4cc8e4cdd3db6df7d03271a3bd91177","lessThan":"49f6705d80b5e6175d8435d9c72b66bd516a8e89","versionType":"git","status":"affected"},{"version":"5ba155a4d4cc8e4cdd3db6df7d03271a3bd91177","lessThan":"8b5798ce0007874c14611b8ee4ce6c749855260e","versionType":"git","status":"affected"},{"version":"5ba155a4d4cc8e4cdd3db6df7d03271a3bd91177","lessThan":"d44b828eb551bd59ba9f22457825cc3db3a39fc1","versionType":"git","status":"affected"},{"version":"5ba155a4d4cc8e4cdd3db6df7d03271a3bd91177","lessThan":"077a7bc1c32d3da9670c5e282ea3e5ac8a94be59","versionType":"git","status":"affected"},{"version":"5ba155a4d4cc8e4cdd3db6df7d03271a3bd91177","lessThan":"f3ad1c87d8201e54b66bd6072442f0b5d5a308ee","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/spi/spi-uniphier.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"4.19","status":"affected"},{"version":"0","lessThan":"4.19","versionType":"semver","status":"unaffected"},{"version":"5.10.261","lessThanOrEqual":"5.10.*","versionType":"semver","status":"unaffected"},{"version":"5.15.212","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.178","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.97","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/077a7bc1c32d3da9670c5e282ea3e5ac8a94be59","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/49f6705d80b5e6175d8435d9c72b66bd516a8e89","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/82a5746c4c9e94f6f816ec7edea6ddc24417c6a5","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/8b5798ce0007874c14611b8ee4ce6c749855260e","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/b9fcf0db433d79648ace74bc2b8b88f91e306304","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/d44b828eb551bd59ba9f22457825cc3db3a39fc1","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/f3ad1c87d8201e54b66bd6072442f0b5d5a308ee","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/f4bb0a91f7badd6d15ac8d783a1169d9e1e95c17","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-72134","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:21:30.880","lastModified":"2026-08-15T06:21:30.880","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nspi: imx: reconfigure for PIO when DMA cannot be started\n\nWhen spi_imx_can_dma() selects DMA, the ECSPI is configured for DMA:\nspi_imx_setupxfer() sets CTRL.SMC and clears dynamic_burst, and\nspi_imx_dma_transfer() programs the dynamic-burst BURST_LENGTH and the\nSDMA watermarks.\n\nIf the DMA descriptor cannot be prepared (dmaengine_prep_slave_single()\nreturns NULL), the transfer is failed with SPI_TRANS_FAIL_NO_START and\nfalls back to PIO. The dynamic-burst DMA path uses its own bounce\nbuffers instead of the SPI core's mapping, so xfer->{tx,rx}_sg_mapped\nare not set and the core's DMA->PIO retry is skipped; the driver falls\nback to PIO internally. But none of the DMA-mode configuration is\nundone, so the PIO transfer runs with CTRL.SMC set, the wrong burst\nlength and dynamic_burst cleared, and the transferred data is corrupted.\n\nThis is easily hit on i.MX8MP boards that describe ECSPI DMA in the\ndevice tree but run SDMA on ROM firmware (no external sdma-imx7d.bin):\nevery ECSPI DMA prepare fails. An Infineon SLB9670 TPM on ECSPI1 then\nreturns shifted TPM2_GetCapability data, is flagged \"field failure\nmode\", /dev/tpmrm0 is never created.\n\nSet controller->fallback before re-running spi_imx_setupxfer() so the\nECSPI is reconfigured exactly like a normal PIO transfer. With\ncontroller->fallback set, spi_imx_setupxfer() sees spi_imx_can_dma()\nreturn false, so it clears spi_imx->usedma and reprograms the controller\n(clears CTRL.SMC, restores dynamic_burst and the PIO burst length). No\nexplicit spi_imx->usedma = false is needed: setupxfer() already updates\nit from the can_dma() result."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/spi/spi-imx.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"faa8e404ad8e686cb98c51dc507fdcacfb8020ce","lessThan":"40dee2d3e9994aed9efe7bed40eb0e4d38d5a25c","versionType":"git","status":"affected"},{"version":"faa8e404ad8e686cb98c51dc507fdcacfb8020ce","lessThan":"245404c26563aafb36aafb01298f148db1851be3","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/spi/spi-imx.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"7.0","status":"affected"},{"version":"0","lessThan":"7.0","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/245404c26563aafb36aafb01298f148db1851be3","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/40dee2d3e9994aed9efe7bed40eb0e4d38d5a25c","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-72135","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:21:30.973","lastModified":"2026-08-15T06:21:30.973","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\ntpm: Make the TPM character devices non-seekable\n\nThe TPM character devices expose a sequential command/response\ninterface, but their open handlers leave FMODE_PREAD and FMODE_PWRITE\nenabled.\n\nAfter a command leaves a response pending, pread(fd, buf, 16, 0x1400)\npasses 0x1400 as *off to tpm_common_read(). The transfer length is\nbounded by response_length, but the offset is used unchecked when\nforming data_buffer + *off. A sufficiently large offset therefore causes\nan out-of-bounds heap read through copy_to_user() and, if the copy\nsucceeds, an out-of-bounds zero-write through the following memset().\n\nPositional I/O does not provide coherent semantics for this interface.\nAn arbitrary pread offset cannot represent how much of a response has\nbeen consumed sequentially. The write callback always stores a command\nat the start of data_buffer, while pwrite() does not update file->f_pos\nand can leave the sequential read cursor stale.\n\nCall nonseekable_open() from both open handlers. This removes\nFMODE_PREAD and FMODE_PWRITE, causing positional reads and writes to\nfail with -ESPIPE before reaching the TPM callbacks, and explicitly\nmarks the files non-seekable. Normal read() and write() continue to use\nthe existing sequential f_pos cursor, leaving the response state machine\nunchanged.\n\nTested on Linux 6.12 with KASAN and a swtpm TPM2 device:\n\n - sequential partial reads returned the complete response\n - pread() and preadv() with offset 0x1400 returned -ESPIPE\n - pwrite() and pwritev() with offset zero returned -ESPIPE\n - the pending response remained intact after the rejected operations\n - a subsequent normal command/response cycle completed normally\n - no KASAN report was produced."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/char/tpm/tpm-dev.c","drivers/char/tpm/tpmrm-dev.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"9488585b21bef0df1217e510c7134905d1d376a7","lessThan":"ed0ffc2c016629e40ba041ed0424a772d8b02e2c","versionType":"git","status":"affected"},{"version":"9488585b21bef0df1217e510c7134905d1d376a7","lessThan":"232dcf908eb7eb9d8046a9597975caf44270966e","versionType":"git","status":"affected"},{"version":"9488585b21bef0df1217e510c7134905d1d376a7","lessThan":"dda695fab5e21f923d29e8cb01df256468ddfbd1","versionType":"git","status":"affected"},{"version":"9488585b21bef0df1217e510c7134905d1d376a7","lessThan":"9c513dabd4540f811585a2087f23069767a284da","versionType":"git","status":"affected"},{"version":"9488585b21bef0df1217e510c7134905d1d376a7","lessThan":"21a13f932972bc9836f58c44fcd47c62abdecd95","versionType":"git","status":"affected"},{"version":"9488585b21bef0df1217e510c7134905d1d376a7","lessThan":"ada4b9a5087ea7f30dd8e4c6411a4fb6547eb1ed","versionType":"git","status":"affected"},{"version":"9488585b21bef0df1217e510c7134905d1d376a7","lessThan":"947b773caaa548672184df025271b29bdc80b0f1","versionType":"git","status":"affected"},{"version":"9488585b21bef0df1217e510c7134905d1d376a7","lessThan":"f20d61c22bcaf172d6790b6500e3838e532e71c8","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/char/tpm/tpm-dev.c","drivers/char/tpm/tpmrm-dev.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"5.0","status":"affected"},{"version":"0","lessThan":"5.0","versionType":"semver","status":"unaffected"},{"version":"5.10.261","lessThanOrEqual":"5.10.*","versionType":"semver","status":"unaffected"},{"version":"5.15.212","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.178","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.97","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc3","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/21a13f932972bc9836f58c44fcd47c62abdecd95","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/232dcf908eb7eb9d8046a9597975caf44270966e","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/947b773caaa548672184df025271b29bdc80b0f1","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/9c513dabd4540f811585a2087f23069767a284da","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/ada4b9a5087ea7f30dd8e4c6411a4fb6547eb1ed","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/dda695fab5e21f923d29e8cb01df256468ddfbd1","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/ed0ffc2c016629e40ba041ed0424a772d8b02e2c","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/f20d61c22bcaf172d6790b6500e3838e532e71c8","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-72136","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:21:31.103","lastModified":"2026-08-15T06:21:31.103","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nxfrm: xfrm_interface: require CAP_NET_ADMIN in the device netns for changelink\n\nxfrmi_changelink() operates on at most two netns, dev_net(dev) and the\ninterface link netns xi->net. They differ once the device is created in\nor moved to a netns other than the one the request runs in. The rtnl\nchangelink path checks CAP_NET_ADMIN only against dev_net(dev), so a\ncaller privileged there but not in xi->net can rewrite an interface that\nlives in xi->net.\n\nGate xfrmi_changelink() on rtnl_dev_link_net_capable() at its top,\nbefore any attribute is parsed."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["net/xfrm/xfrm_interface_core.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"f203b76d78092faf248db3f851840fbecf80b40e","lessThan":"04c1aa57d08471b1953bf27c84ac9b3d78d71831","versionType":"git","status":"affected"},{"version":"f203b76d78092faf248db3f851840fbecf80b40e","lessThan":"bdfd1c21d90e628a58a9de79e024cdfcbedfa15c","versionType":"git","status":"affected"},{"version":"f203b76d78092faf248db3f851840fbecf80b40e","lessThan":"80ec68bba11f7f387c0e4099c2d7b2c84943eb99","versionType":"git","status":"affected"},{"version":"f203b76d78092faf248db3f851840fbecf80b40e","lessThan":"e9c90756f10da334fb31552e52c61f1dba69f491","versionType":"git","status":"affected"},{"version":"f203b76d78092faf248db3f851840fbecf80b40e","lessThan":"37b61946d278c7deb0d40ba8f2b6fc0478d61dab","versionType":"git","status":"affected"},{"version":"f203b76d78092faf248db3f851840fbecf80b40e","lessThan":"8ca2a19a987a7d1cb4c916ed9723a1c6993b4276","versionType":"git","status":"affected"},{"version":"f203b76d78092faf248db3f851840fbecf80b40e","lessThan":"3ba2b2ef7d6a63b190f15cfc2b4ba0fba59928ea","versionType":"git","status":"affected"},{"version":"f203b76d78092faf248db3f851840fbecf80b40e","lessThan":"095515d89b19b6cc19dfcdc846f97403ed1ebce3","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["net/xfrm/xfrm_interface_core.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"4.19","status":"affected"},{"version":"0","lessThan":"4.19","versionType":"semver","status":"unaffected"},{"version":"5.10.261","lessThanOrEqual":"5.10.*","versionType":"semver","status":"unaffected"},{"version":"5.15.212","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.178","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.97","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/04c1aa57d08471b1953bf27c84ac9b3d78d71831","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/095515d89b19b6cc19dfcdc846f97403ed1ebce3","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/37b61946d278c7deb0d40ba8f2b6fc0478d61dab","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/3ba2b2ef7d6a63b190f15cfc2b4ba0fba59928ea","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/80ec68bba11f7f387c0e4099c2d7b2c84943eb99","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/8ca2a19a987a7d1cb4c916ed9723a1c6993b4276","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/bdfd1c21d90e628a58a9de79e024cdfcbedfa15c","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/e9c90756f10da334fb31552e52c61f1dba69f491","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-72137","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:21:31.223","lastModified":"2026-08-15T06:21:31.223","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nxfrm: nat_keepalive: avoid double free on send error\n\nnat_keepalive_send() frees the keepalive skb whenever the IPv4 or IPv6\nsend helper reports an error.\n\nThat cleanup is only correct before the skb is handed to the output\npath. Once ip_build_and_send_pkt() or ip6_xmit() takes ownership, the\nnetworking stack may already have consumed the skb before returning an\nerror, so freeing it again is unsafe.\n\nHandle the pre-handoff failure cases inside nat_keepalive_send_ipv4()\nand nat_keepalive_send_ipv6(), where the caller still owns the skb, and\nkeep nat_keepalive_send() responsible only for family dispatch and the\nunsupported-family cleanup path."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["net/xfrm/xfrm_nat_keepalive.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"f531d13bdfe3f4f084aaa8acae2cb0f02295f5ae","lessThan":"d0a4dc7efa825bce60a8da8f7d43c864a159abde","versionType":"git","status":"affected"},{"version":"f531d13bdfe3f4f084aaa8acae2cb0f02295f5ae","lessThan":"5b0c4c916f202b8fd13d12afb6af62b385622f81","versionType":"git","status":"affected"},{"version":"f531d13bdfe3f4f084aaa8acae2cb0f02295f5ae","lessThan":"a8a7e6a9ff8a4c1f067694ddbd44be67fdf36693","versionType":"git","status":"affected"},{"version":"f531d13bdfe3f4f084aaa8acae2cb0f02295f5ae","lessThan":"226f4a490d1a938fc838d8f8c46a4eca864c0d78","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["net/xfrm/xfrm_nat_keepalive.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.11","status":"affected"},{"version":"0","lessThan":"6.11","versionType":"semver","status":"unaffected"},{"version":"6.12.101","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc4","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/226f4a490d1a938fc838d8f8c46a4eca864c0d78","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/5b0c4c916f202b8fd13d12afb6af62b385622f81","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/a8a7e6a9ff8a4c1f067694ddbd44be67fdf36693","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/d0a4dc7efa825bce60a8da8f7d43c864a159abde","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-72138","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:21:31.337","lastModified":"2026-08-15T06:21:31.337","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nxen/gntdev: fix error handling in ioctl\n\nWhen gntdev_ioctl_map_grant_ref() fails to copy the operation result\nback to userspace after successfully adding the mapping to the list,\nthe error path returns -EFAULT without releasing the reference\nacquired by gntdev_alloc_map(). The mapping remains in priv->maps\nwith a refcount of 1, causing a memory leak and a dangling list\nentry.\n\nAdditionally, gntdev_add_map() may modify map->index to avoid overlap\nwith existing mappings. Therefore, the index returned to userspace\nmust be obtained after gntdev_add_map() completes.\n\nFix this by holding the mutex across gntdev_add_map(), retrieving\nthe correct index, and copy_to_user(). If copy_to_user() fails,\nremove the mapping from the list and release the reference while\nstill holding the lock.\n\n\nFix these issues by properly handling all error cases."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/xen/gntdev.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"68b025c813c2eb41ff25628e3d4952d5185eb1a4","lessThan":"52dc40ef0cfee6ae89b7524967e73f0ba37906d7","versionType":"git","status":"affected"},{"version":"68b025c813c2eb41ff25628e3d4952d5185eb1a4","lessThan":"1dd9cb98fe228e017fff9efb33862ff38c741b65","versionType":"git","status":"affected"},{"version":"68b025c813c2eb41ff25628e3d4952d5185eb1a4","lessThan":"6df926130aee6cab9b5d2e5b7862e49ccac348dc","versionType":"git","status":"affected"},{"version":"68b025c813c2eb41ff25628e3d4952d5185eb1a4","lessThan":"311011f8cc206c5af2877b03e3f627ee1b8fe024","versionType":"git","status":"affected"},{"version":"68b025c813c2eb41ff25628e3d4952d5185eb1a4","lessThan":"18a693733f7ad004e1ab0466693121ca70cd95dd","versionType":"git","status":"affected"},{"version":"68b025c813c2eb41ff25628e3d4952d5185eb1a4","lessThan":"16d3ccdabb8dee9be2cdcd6d3f9a125572ec0454","versionType":"git","status":"affected"},{"version":"68b025c813c2eb41ff25628e3d4952d5185eb1a4","lessThan":"6883269a323609f68f6faa903f8f8ff3d191cec8","versionType":"git","status":"affected"},{"version":"68b025c813c2eb41ff25628e3d4952d5185eb1a4","lessThan":"45ca1afe2fd14c04e37227e79d3f8455831d8408","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/xen/gntdev.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"2.6.39","status":"affected"},{"version":"0","lessThan":"2.6.39","versionType":"semver","status":"unaffected"},{"version":"5.10.261","lessThanOrEqual":"5.10.*","versionType":"semver","status":"unaffected"},{"version":"5.15.212","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.178","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.97","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc2","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/16d3ccdabb8dee9be2cdcd6d3f9a125572ec0454","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/18a693733f7ad004e1ab0466693121ca70cd95dd","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/1dd9cb98fe228e017fff9efb33862ff38c741b65","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/311011f8cc206c5af2877b03e3f627ee1b8fe024","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/45ca1afe2fd14c04e37227e79d3f8455831d8408","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/52dc40ef0cfee6ae89b7524967e73f0ba37906d7","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/6883269a323609f68f6faa903f8f8ff3d191cec8","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/6df926130aee6cab9b5d2e5b7862e49ccac348dc","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-72139","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:21:31.460","lastModified":"2026-08-15T06:21:31.460","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\ntcp: defer md5sig_info kfree past RCU grace period in tcp_connect\n\nThe md5+ao reconciliation in tcp_connect() (net/ipv4/tcp_output.c)\nhas two symmetric branches:\n\n\tif (needs_md5) {\n\t\ttcp_ao_destroy_sock(sk, false);\n\t} else if (needs_ao) {\n\t\ttcp_clear_md5_list(sk);\n\t\tkfree(rcu_replace_pointer(tp->md5sig_info, NULL, ...));\n\t}\n\nBoth branches free a per-socket auth-info object while the socket is\nin TCP_SYN_SENT and is already on the inet ehash (inserted by\ninet_hash_connect() in tcp_v4_connect()). Both branches are reachable\nby softirq RX-path readers that load the corresponding info pointer\nvia implicit RCU before bh_lock_sock_nested() is taken.\n\nThe needs_md5 branch is fixed in the prior patch by re-introducing\nthe call_rcu() free in tcp_ao_destroy_sock(): the equivalent per-key\nloop runs inside tcp_ao_info_free_rcu(), the RCU callback, so by the\ntime it frees each tcp_ao_key all softirq readers that captured the\ncontainer have already completed rcu_read_unlock().\n\nThe needs_ao branch is not symmetric in the same way. The container\nfree can be deferred via kfree_rcu(md5sig, rcu) -- struct\ntcp_md5sig_info already has the required rcu member\n(include/net/tcp.h:1999-2002), and the rest of the tree already does\nthis in the tcp_md5sig_info_add() rollback paths\n(net/ipv4/tcp_ipv4.c:1410, 1436). But the per-key teardown is done\nby tcp_clear_md5_list() in process context BEFORE the container's\nRCU grace period: it walks &md5sig->head and frees each\ntcp_md5sig_key with bare hlist_del + kfree. A concurrent softirq\nreader in __tcp_md5_do_lookup() / __tcp_md5_do_lookup_exact()\n(tcp_ipv4.c:1253, 1298) walks the same list via\nhlist_for_each_entry_rcu() and races with that bare kfree on the\nkeys themselves -- a per-key slab use-after-free of the same class\nas the TCP-AO bug, on the same race window.\n\nFix this in two halves:\n\n  1. Convert the bare kfree() in tcp_connect() to kfree_rcu() so the\n     md5sig_info container joins the rest of the md5sig lifecycle.\n     The local-variable lift is mechanical and required because\n     kfree_rcu() is a macro that expects an lvalue.\n\n  2. Make tcp_clear_md5_list() RCU-safe by replacing hlist_del +\n     kfree(key) with hlist_del_rcu + kfree_rcu(key, rcu). struct\n     tcp_md5sig_key already carries the rcu member\n     (include/net/tcp.h:1995) and tcp_md5_do_del()\n     (net/ipv4/tcp_ipv4.c:1456) already uses kfree_rcu, so this\n     restores the lifecycle invariant the rest of the file follows\n     rather than introducing a one-off.\n\nThe other caller of tcp_clear_md5_list() is tcp_md5_destruct_sock()\n(net/ipv4/tcp.c:412), which runs from the sock destructor when the\nsocket is already unhashed and unreachable; the extra grace period\nthere is unnecessary but harmless. Making the helper unconditionally\nRCU-safe is the cleaner contract.\n\nThe needs_ao branch is not reachable by the userns reproducer used\nto demonstrate the AO-side splat (the repro installs both keys but\nends up in the needs_md5 branch because the connect peer matches\nthe MD5 key, not the AO key); however the symmetric race exists\nand a maintainer touching this code should not have to think about\nwhich branch escapes RCU and which one does not.\n\n[also credits to Qihang, who found that this races with tcp-diag]"}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["net/ipv4/tcp_ipv4.c","net/ipv4/tcp_output.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"51e547e8c89c661f6fbede4a28b1d33b13625683","lessThan":"33a1bee413628378fd036a4f2b17ba86b0bc560c","versionType":"git","status":"affected"},{"version":"51e547e8c89c661f6fbede4a28b1d33b13625683","lessThan":"da48b9bf1eb95a9cfd09d615ca58cfc2b03de369","versionType":"git","status":"affected"},{"version":"51e547e8c89c661f6fbede4a28b1d33b13625683","lessThan":"b74cd55038905d5e74c1de109ab78a30b2ea0e1f","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["net/ipv4/tcp_ipv4.c","net/ipv4/tcp_output.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.18","status":"affected"},{"version":"0","lessThan":"6.18","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc2","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/33a1bee413628378fd036a4f2b17ba86b0bc560c","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/b74cd55038905d5e74c1de109ab78a30b2ea0e1f","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/da48b9bf1eb95a9cfd09d615ca58cfc2b03de369","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-72140","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:21:31.587","lastModified":"2026-08-15T06:21:31.587","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\ni2c: mlxbf: Fix use-after-free in mlxbf_i2c_init_resource()\n\nIf devm_platform_get_and_ioremap_resource() returns an error,\nmlxbf_i2c_init_resource() frees tmp_res before reading tmp_res->io to\nget the error code. This results in a use-after-free.\n\nSave the error code before freeing tmp_res."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/i2c/busses/i2c-mlxbf.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"b5b5b32081cd206baa6e58cca7f112d9723785d6","lessThan":"6a108c9f5a81bb7b29dbb1398be0089655b6bfd2","versionType":"git","status":"affected"},{"version":"b5b5b32081cd206baa6e58cca7f112d9723785d6","lessThan":"c4d9b6a0c9645366d9e4af8a6ac8347bd4c841aa","versionType":"git","status":"affected"},{"version":"b5b5b32081cd206baa6e58cca7f112d9723785d6","lessThan":"b398cbbbb9dd76210682a8c9aabd34c5168800b9","versionType":"git","status":"affected"},{"version":"b5b5b32081cd206baa6e58cca7f112d9723785d6","lessThan":"5290a52533e09c38374963f4bb0b35121fe555c7","versionType":"git","status":"affected"},{"version":"b5b5b32081cd206baa6e58cca7f112d9723785d6","lessThan":"ce960a1b2caa4ad08291f28d8bcf17ad5a864e54","versionType":"git","status":"affected"},{"version":"b5b5b32081cd206baa6e58cca7f112d9723785d6","lessThan":"e6a395a71f4652261d09b572a03c96052662a056","versionType":"git","status":"affected"},{"version":"b5b5b32081cd206baa6e58cca7f112d9723785d6","lessThan":"fb267770bf822064f510c9b46743f533d8fa8a5f","versionType":"git","status":"affected"},{"version":"b5b5b32081cd206baa6e58cca7f112d9723785d6","lessThan":"71356737a7a55c76fee847563e3d33f8e6dc6b6d","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/i2c/busses/i2c-mlxbf.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"5.10","status":"affected"},{"version":"0","lessThan":"5.10","versionType":"semver","status":"unaffected"},{"version":"5.10.261","lessThanOrEqual":"5.10.*","versionType":"semver","status":"unaffected"},{"version":"5.15.212","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.178","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.97","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc4","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/5290a52533e09c38374963f4bb0b35121fe555c7","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/6a108c9f5a81bb7b29dbb1398be0089655b6bfd2","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/71356737a7a55c76fee847563e3d33f8e6dc6b6d","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/b398cbbbb9dd76210682a8c9aabd34c5168800b9","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/c4d9b6a0c9645366d9e4af8a6ac8347bd4c841aa","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/ce960a1b2caa4ad08291f28d8bcf17ad5a864e54","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/e6a395a71f4652261d09b572a03c96052662a056","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/fb267770bf822064f510c9b46743f533d8fa8a5f","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-72141","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:21:31.717","lastModified":"2026-08-15T06:21:31.717","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\ni2c: imx: fix locked bus on SMBus block-read of 0 (IRQ)\n\nSMBus 3.1 6.5.7 allows a Block Read byte count of 0, but the\ninterrupt-driven block-read state machine rejects it as -EPROTO. Worse,\nit returns without a NACK+STOP: the next receive cycle has already\nstarted, so the target keeps holding SDA and the bus stays stuck until a\npower cycle of this i2c controller.\n\nAccept count=0: NACK the in-flight dummy byte (TXAK) and set msg->len to\n2 so i2c_imx_isr_read_continue() emits STOP via its normal last-byte\npath. The dummy byte is discarded; block-read callers only consume\nbuf[0..count-1].\n\nReading I2DR has likewise already armed the next byte on the\ncount > I2C_SMBUS_BLOCK_MAX error path, so NACK it (TXAK) before aborting\nwith -EPROTO; otherwise the failing transfer's STOP cannot complete and\nthe bus stays held.\n\nThe atomic path regressed earlier (v3.16) and is fixed separately; this\npatch covers only the v6.13 state-machine rework."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/i2c/busses/i2c-imx.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"5f5c2d4579ca6836f5604cca979debd68ecfe23f","lessThan":"5d3240f42a667e29262aff76fdebfcdac4980626","versionType":"git","status":"affected"},{"version":"5f5c2d4579ca6836f5604cca979debd68ecfe23f","lessThan":"56ddfc18ea8f7d77747658892873eb632b2ed530","versionType":"git","status":"affected"},{"version":"5f5c2d4579ca6836f5604cca979debd68ecfe23f","lessThan":"07fd9385f0d87dff4b34f355f68adf701080cb24","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/i2c/busses/i2c-imx.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.13","status":"affected"},{"version":"0","lessThan":"6.13","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc4","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/07fd9385f0d87dff4b34f355f68adf701080cb24","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/56ddfc18ea8f7d77747658892873eb632b2ed530","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/5d3240f42a667e29262aff76fdebfcdac4980626","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-72142","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:21:31.827","lastModified":"2026-08-15T06:21:31.827","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\ni2c: imx: fix locked bus on SMBus block-read of 0 (atomic)\n\nSMBus 3.1 6.5.7 allows a Block Read byte count of 0, but the atomic\n(polling) path rejects it as -EPROTO. Worse, it returns without a\nNACK+STOP: the next receive cycle has already started, so the target\nkeeps holding SDA and the bus stays stuck until a power cycle for\nthis i2c controller.\n\nReading I2DR to obtain the count likewise arms the next byte on the\ncount > I2C_SMBUS_BLOCK_MAX path, which also returned -EPROTO directly\nand left the bus held.\n\nHandle both: NACK the in-flight dummy byte (TXAK) and extend msgs->len so\nthe existing last-byte handling emits STOP; the dummy byte is discarded.\nA count of 0 is a valid empty block read; a count above\nI2C_SMBUS_BLOCK_MAX is still reported as -EPROTO, but only after the bus\nhas been released.\n\nThe interrupt-driven path has the same flaw from a later commit and is\nfixed separately, as it carries a different Fixes: tag and stable range."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/i2c/busses/i2c-imx.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"8e8782c71595a5ad29e234ce6b3d2fce787fb07a","lessThan":"016ef0f6ca4bc9bf0330ac41bd2ea349759643e3","versionType":"git","status":"affected"},{"version":"8e8782c71595a5ad29e234ce6b3d2fce787fb07a","lessThan":"c882e8cc68fb993700dc21fd6e754001e6297934","versionType":"git","status":"affected"},{"version":"8e8782c71595a5ad29e234ce6b3d2fce787fb07a","lessThan":"6d2c973926d0612360693bc559be2ffde836151b","versionType":"git","status":"affected"},{"version":"8e8782c71595a5ad29e234ce6b3d2fce787fb07a","lessThan":"60ed00d46616a9232e42ea7a3e3c0273d7cf7543","versionType":"git","status":"affected"},{"version":"8e8782c71595a5ad29e234ce6b3d2fce787fb07a","lessThan":"cb2fc37857693b55909fb77dc2c87cfbc1cdc476","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/i2c/busses/i2c-imx.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"3.16","status":"affected"},{"version":"0","lessThan":"3.16","versionType":"semver","status":"unaffected"},{"version":"6.6.148","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.101","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc4","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/016ef0f6ca4bc9bf0330ac41bd2ea349759643e3","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/60ed00d46616a9232e42ea7a3e3c0273d7cf7543","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/6d2c973926d0612360693bc559be2ffde836151b","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/c882e8cc68fb993700dc21fd6e754001e6297934","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/cb2fc37857693b55909fb77dc2c87cfbc1cdc476","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-72143","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:21:31.953","lastModified":"2026-08-15T06:21:31.953","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nplatform/x86: ISST: Restore SST-PP control to all domains\n\nThe SST-PP control offset is only restored to power domain 0 after\nresume. During suspend, control values are read and stored for all\npower domains.\n\nUse pd_info->sst_base instead of power_domain_info->sst_base, which\nonly points to power domain 0 base address."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/platform/x86/intel/speed_select_if/isst_tpmi_core.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"e3704ce5d7156ee837461be99841f312c64700b0","lessThan":"cea03d67db3a880893360bdbb1b0b8d9b33b1799","versionType":"git","status":"affected"},{"version":"dc7901b5a1563a9c9eb29b3b0b0dac3162065cd8","lessThan":"2a42f651cce91e9cbe65fe933622c522cbb1868b","versionType":"git","status":"affected"},{"version":"dc7901b5a1563a9c9eb29b3b0b0dac3162065cd8","lessThan":"2565a28cdcdcb035e151d285efcba26bccb3726e","versionType":"git","status":"affected"},{"version":"2624f3bf45a830cb3b8c8b967b23a72139700562","versionType":"git","status":"affected"},{"version":"6.18.16","lessThan":"6.18.40","versionType":"semver","status":"affected"},{"version":"6.19.6","lessThan":"6.20","versionType":"semver","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/platform/x86/intel/speed_select_if/isst_tpmi_core.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"7.0","status":"affected"},{"version":"0","lessThan":"7.0","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/2565a28cdcdcb035e151d285efcba26bccb3726e","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/2a42f651cce91e9cbe65fe933622c522cbb1868b","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/cea03d67db3a880893360bdbb1b0b8d9b33b1799","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-72144","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:21:32.067","lastModified":"2026-08-15T06:21:32.067","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nplatform/x86: dell-laptop: fix missing cleanups in init error path\n\ndell_init() initializes several resources after dell_setup_rfkill(),\nincluding the optional touchpad LED, keyboard backlight LED, battery\nhook, debugfs directory and dell-laptop notifier.\n\nIf a later LED or backlight registration fails, the error path only\ntears down the battery hook and rfkill resources. This leaves the\nnotifier, debugfs directory, keyboard backlight LED and optional\ntouchpad LED registered after dell_init() returns an error.\n\nAdd the missing cleanup calls before tearing down rfkill."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/platform/x86/dell/dell-laptop.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"037accfa14b28ecf49d9060063929c4b4cde373f","lessThan":"e4908b3bed755f73870416b971e162a8d0ef0aef","versionType":"git","status":"affected"},{"version":"037accfa14b28ecf49d9060063929c4b4cde373f","lessThan":"6bd76d5421a72d2526c9be8f01f55bee960f899f","versionType":"git","status":"affected"},{"version":"037accfa14b28ecf49d9060063929c4b4cde373f","lessThan":"1e41ca4a7fba2e680d6950e9511245255fffa46c","versionType":"git","status":"affected"},{"version":"037accfa14b28ecf49d9060063929c4b4cde373f","lessThan":"b351e082711d12f075a36a6cd67709693689315f","versionType":"git","status":"affected"},{"version":"037accfa14b28ecf49d9060063929c4b4cde373f","lessThan":"6e9cab2247e5b243ae2d907ce7c948a8a9c8d61a","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/platform/x86/dell/dell-laptop.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"2.6.37","status":"affected"},{"version":"0","lessThan":"2.6.37","versionType":"semver","status":"unaffected"},{"version":"6.6.148","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.97","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/1e41ca4a7fba2e680d6950e9511245255fffa46c","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/6bd76d5421a72d2526c9be8f01f55bee960f899f","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/6e9cab2247e5b243ae2d907ce7c948a8a9c8d61a","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/b351e082711d12f075a36a6cd67709693689315f","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/e4908b3bed755f73870416b971e162a8d0ef0aef","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-72145","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:21:32.167","lastModified":"2026-08-15T06:21:32.167","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nplatform/x86/intel/tpmi: use cleanup helpers in mem_write()\n\nIn mem_write(), the temporary array returned by\nparse_int_array_user() must be released on all exit paths.\nConvert the array variable to use cleanup.h scope-based\ncleanup so it is freed automatically on return.\n\nThis also moves the array declaration next to\nparse_int_array_user() as required by cleanup.h usage\nguidelines."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/platform/x86/intel/vsec_tpmi.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"8e0a2fc68ec369f2b6755994da1d318d0898a9d9","lessThan":"2137f21542900233a42bf00578817f9b8dfecadc","versionType":"git","status":"affected"},{"version":"8e0a2fc68ec369f2b6755994da1d318d0898a9d9","lessThan":"a221557958e3a82d8565729d445a7385963f30b6","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/platform/x86/intel/vsec_tpmi.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"7.1","status":"affected"},{"version":"0","lessThan":"7.1","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/2137f21542900233a42bf00578817f9b8dfecadc","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/a221557958e3a82d8565729d445a7385963f30b6","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-72146","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:21:32.267","lastModified":"2026-08-15T06:21:32.267","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\ndmaengine: sh: rz-dmac: Move interrupt request after everything is set up\n\nOnce the interrupt is requested, the interrupt handler may run immediately.\nSince the IRQ handler can access channel->ch_base, which is initialized\nonly after requesting the IRQ, this may lead to invalid memory access.\nLikewise, the IRQ thread may access uninitialized data (the ld_free,\nld_queue, and ld_active lists), which may also lead to issues.\n\nRequest the interrupts only after everything is set up. To keep the error\npath simpler, use dmam_alloc_coherent() instead of dma_alloc_coherent()."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/dma/sh/rz-dmac.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"5000d37042a61ca556fde2782ca40dbfa802ea16","lessThan":"5b12de6229d662864ee22c11d4876652b40120f0","versionType":"git","status":"affected"},{"version":"5000d37042a61ca556fde2782ca40dbfa802ea16","lessThan":"2a4d9e2234c3f817bb0ddbc8680d09ce9be84f93","versionType":"git","status":"affected"},{"version":"5000d37042a61ca556fde2782ca40dbfa802ea16","lessThan":"ec9f66c91bffdb69d309bae6dfb387562db7ebc8","versionType":"git","status":"affected"},{"version":"5000d37042a61ca556fde2782ca40dbfa802ea16","lessThan":"07ae600bd353b22f31a8f1007269744fafc7f123","versionType":"git","status":"affected"},{"version":"5000d37042a61ca556fde2782ca40dbfa802ea16","lessThan":"731712403ddb39d1a76a11abf339a0615bc85de7","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/dma/sh/rz-dmac.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"5.15","status":"affected"},{"version":"0","lessThan":"5.15","versionType":"semver","status":"unaffected"},{"version":"6.6.148","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.101","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.42","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/07ae600bd353b22f31a8f1007269744fafc7f123","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/2a4d9e2234c3f817bb0ddbc8680d09ce9be84f93","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/5b12de6229d662864ee22c11d4876652b40120f0","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/731712403ddb39d1a76a11abf339a0615bc85de7","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/ec9f66c91bffdb69d309bae6dfb387562db7ebc8","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-72147","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:21:32.373","lastModified":"2026-08-15T06:21:32.373","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\ndmaengine: dw-edma-pcie: Reject devices without driver data\n\ndw_edma_pcie_probe() treats the PCI device ID driver_data as the\ntemplate for the controller layout and copies it unconditionally. A\ndevice bound dynamically via sysfs can match the driver without that\ndata, which leads to a NULL pointer dereference.\n\nReject such matches before enabling the device."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/dma/dw-edma/dw-edma-pcie.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"41aaff2a2ac01c5f5415f9de9cd7015ac2b8d569","lessThan":"2733b5dcb5a4ba4446f7bac954b97e4501dcaa64","versionType":"git","status":"affected"},{"version":"41aaff2a2ac01c5f5415f9de9cd7015ac2b8d569","lessThan":"a1042599fa8f9e313be176eb1ea1ae199f983419","versionType":"git","status":"affected"},{"version":"41aaff2a2ac01c5f5415f9de9cd7015ac2b8d569","lessThan":"043acb00e4edd4b9ffb9dd0e357482dcd9086486","versionType":"git","status":"affected"},{"version":"41aaff2a2ac01c5f5415f9de9cd7015ac2b8d569","lessThan":"044f7b3252d4fb2143d4999eec2800c08f1001ed","versionType":"git","status":"affected"},{"version":"41aaff2a2ac01c5f5415f9de9cd7015ac2b8d569","lessThan":"11d7cfe0c119691b2dafbb699bbca90258c678aa","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/dma/dw-edma/dw-edma-pcie.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"5.3","status":"affected"},{"version":"0","lessThan":"5.3","versionType":"semver","status":"unaffected"},{"version":"6.6.148","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.101","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.42","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/043acb00e4edd4b9ffb9dd0e357482dcd9086486","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/044f7b3252d4fb2143d4999eec2800c08f1001ed","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/11d7cfe0c119691b2dafbb699bbca90258c678aa","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/2733b5dcb5a4ba4446f7bac954b97e4501dcaa64","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/a1042599fa8f9e313be176eb1ea1ae199f983419","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-72148","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:21:32.483","lastModified":"2026-08-15T06:21:32.483","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\ndmaengine: dw-edma: Add spinlock to protect DONE_INT_MASK and ABORT_INT_MASK\n\nThe DONE_INT_MASK and ABORT_INT_MASK registers are shared by all DMA\nchannels, and modifying them requires a read-modify-write sequence.\nBecause this operation is not atomic, concurrent calls to\ndw_edma_v0_core_start() can introduce race conditions if two channels\nupdate these registers simultaneously.\n\nAdd a spinlock to serialize access to these registers and prevent race\nconditions.\n\n[den: update dw_edma.lock comment]"}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/dma/dw-edma/dw-edma-core.h","drivers/dma/dw-edma/dw-edma-v0-core.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"7e4b8a4fbe2cecab0959e862604803d063f50029","lessThan":"2247cc25a91fb1b5b86586ed55fdd5b725a7477c","versionType":"git","status":"affected"},{"version":"7e4b8a4fbe2cecab0959e862604803d063f50029","lessThan":"3ee0f478bb29b4ee892b178179a9a76ddd194149","versionType":"git","status":"affected"},{"version":"7e4b8a4fbe2cecab0959e862604803d063f50029","lessThan":"21a9834f56d6249aaa6ca7c2d8c182d66c48c3e1","versionType":"git","status":"affected"},{"version":"7e4b8a4fbe2cecab0959e862604803d063f50029","lessThan":"ddbc4a8a4fe296f1fa2e59f7d176fc7c773df640","versionType":"git","status":"affected"},{"version":"7e4b8a4fbe2cecab0959e862604803d063f50029","lessThan":"1553ca96e9df158d8f37137cf4bf5fb0dc981d94","versionType":"git","status":"affected"},{"version":"7e4b8a4fbe2cecab0959e862604803d063f50029","lessThan":"8ffba0171c6bbce5f093c6dba5a02c0805b31203","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/dma/dw-edma/dw-edma-core.h","drivers/dma/dw-edma/dw-edma-v0-core.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"5.3","status":"affected"},{"version":"0","lessThan":"5.3","versionType":"semver","status":"unaffected"},{"version":"6.1.178","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.97","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/1553ca96e9df158d8f37137cf4bf5fb0dc981d94","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/21a9834f56d6249aaa6ca7c2d8c182d66c48c3e1","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/2247cc25a91fb1b5b86586ed55fdd5b725a7477c","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/3ee0f478bb29b4ee892b178179a9a76ddd194149","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/8ffba0171c6bbce5f093c6dba5a02c0805b31203","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/ddbc4a8a4fe296f1fa2e59f7d176fc7c773df640","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-72149","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:21:32.610","lastModified":"2026-08-15T06:21:32.610","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\ndmaengine: tegra: Fix burst size calculation\n\nCurrently, the Tegra GPC DMA hardware requires the transfer length to\nbe a multiple of the max burst size configured for the channel. When a\nclient requests a transfer where the length is not evenly divisible by\nthe configured max burst size, the DMA hangs with partial burst at\nthe end.\n\nFix this by reducing the burst size to the largest power-of-2 value\nthat evenly divides the transfer length. For example, a 40-byte\ntransfer with a 16-byte max burst will now use an 8-byte burst\n(40 / 8 = 5 complete bursts) instead of causing a hang.\n\nThis issue was observed with the PL011 UART driver where TX DMA\ntransfers of arbitrary lengths were stuck."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/dma/tegra186-gpc-dma.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"ee17028009d49fffed8cc963455d33b1fd3f1d08","lessThan":"735951baa311c66353405dcac39375dd66441db0","versionType":"git","status":"affected"},{"version":"ee17028009d49fffed8cc963455d33b1fd3f1d08","lessThan":"8f0f5de1091119679d87f60dfb1acbff4b2a0ed3","versionType":"git","status":"affected"},{"version":"ee17028009d49fffed8cc963455d33b1fd3f1d08","lessThan":"a3b76b54e06d73166af4d1a284a0e0711889060c","versionType":"git","status":"affected"},{"version":"ee17028009d49fffed8cc963455d33b1fd3f1d08","lessThan":"7926c1e4be86379945fb5f168888ac4d2aaf6c91","versionType":"git","status":"affected"},{"version":"ee17028009d49fffed8cc963455d33b1fd3f1d08","lessThan":"6e37e9e230c7e848bd8e8cd4db15bb18bcf11ad1","versionType":"git","status":"affected"},{"version":"ee17028009d49fffed8cc963455d33b1fd3f1d08","lessThan":"4651df83b6c796daead3447e8fd874322918ee4f","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/dma/tegra186-gpc-dma.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"5.19","status":"affected"},{"version":"0","lessThan":"5.19","versionType":"semver","status":"unaffected"},{"version":"6.1.178","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.97","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/4651df83b6c796daead3447e8fd874322918ee4f","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/6e37e9e230c7e848bd8e8cd4db15bb18bcf11ad1","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/735951baa311c66353405dcac39375dd66441db0","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/7926c1e4be86379945fb5f168888ac4d2aaf6c91","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/8f0f5de1091119679d87f60dfb1acbff4b2a0ed3","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/a3b76b54e06d73166af4d1a284a0e0711889060c","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-72150","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:21:32.727","lastModified":"2026-08-15T06:21:32.727","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nsunrpc: fix uninitialized xprt_create_args structure\n\nThe xprt_create_args structure is allocated on the stack without\ninitialization in rpc_sysfs_xprt_switch_add_xprt_store(). While some\nfields are manually populated, critical fields like srcaddr, bc_xps,\nand flags contain uninitialized stack garbage.\n\nThis can lead to:\n1. Kernel panic when xs_setup_xprt() dereferences garbage srcaddr\n2. Information leak if srcaddr points to sensitive stack data\n3. Unpredictable behavior if flags has random bits set\n\nThe fix is to zero-initialize the structure to ensure all unused\nfields are NULL/0, preventing the transport setup code from acting\non garbage data."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["net/sunrpc/sysfs.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"933654508b2bc36e2c3c086c0365e2403fb2141f","versionType":"git","status":"affected"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"7d3ce3bd23c062a7c1c6d372d1b08e48b9e17cc3","versionType":"git","status":"affected"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"17d90b68c3a3d7d7e95b49e1fe9381a723f637a8","versionType":"git","status":"affected"},{"version":"0","lessThan":"6.18.40","versionType":"semver","status":"affected"},{"version":"0","lessThan":"7.1.5","versionType":"semver","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["net/sunrpc/sysfs.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/17d90b68c3a3d7d7e95b49e1fe9381a723f637a8","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/7d3ce3bd23c062a7c1c6d372d1b08e48b9e17cc3","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/933654508b2bc36e2c3c086c0365e2403fb2141f","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-72151","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:21:32.823","lastModified":"2026-08-15T06:21:32.823","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\ntpm: tpm2-sessions: wait for async KPP completion in tpm_buf_append_salt\n\ntpm_buf_append_salt() in drivers/char/tpm/tpm2-sessions.c calls\ncrypto_kpp_generate_public_key() and crypto_kpp_compute_shared_secret()\nwithout installing a completion callback, discards both return values,\nand immediately frees the kpp_request via kpp_request_free(). When the\nresolved ecdh-nist-p256 KPP backend is asynchronous (atmel-ecc, HPRE,\nkeembay-ocs), either operation returns -EINPROGRESS and the deferred\ncompletion worker dereferences the freed request.\n\nThe path fires automatically from the hwrng_fillfn kernel thread via\ntpm_get_random -> tpm2_get_random -> tpm2_start_auth_session ->\ntpm_buf_append_salt on every entropy poll, without any userland action.\n\nInstall crypto_req_done as the completion callback, wrap both KPP\noperations in crypto_wait_req(), and propagate errors to the caller.\nThe wait is a no-op for synchronous backends."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/char/tpm/tpm2-sessions.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"1085b8276bb4239daa7008f0dcd5c973e4bd690f","lessThan":"111e520efbe82b324bc42b1999b723c0619eea6d","versionType":"git","status":"affected"},{"version":"1085b8276bb4239daa7008f0dcd5c973e4bd690f","lessThan":"934d1cd40e2893bf7a041b54f6afd1c008d7a21c","versionType":"git","status":"affected"},{"version":"1085b8276bb4239daa7008f0dcd5c973e4bd690f","lessThan":"493333f167926c7adab8e7563e21ad71d8af84fa","versionType":"git","status":"affected"},{"version":"1085b8276bb4239daa7008f0dcd5c973e4bd690f","lessThan":"73851a7c43dfa52d2ed9415889b33daf85da0ed9","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/char/tpm/tpm2-sessions.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.10","status":"affected"},{"version":"0","lessThan":"6.10","versionType":"semver","status":"unaffected"},{"version":"6.12.97","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/111e520efbe82b324bc42b1999b723c0619eea6d","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/493333f167926c7adab8e7563e21ad71d8af84fa","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/73851a7c43dfa52d2ed9415889b33daf85da0ed9","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/934d1cd40e2893bf7a041b54f6afd1c008d7a21c","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-72152","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:21:32.923","lastModified":"2026-08-15T06:21:32.923","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\ntpm: tpm_tis_spi: Use wait_woken() in wait_for_tmp_stat()\n\nwait_event_interruptible_timeout() evaluates its condition after setting\nthe current task state to TASK_INTERRUPTIBLE.\n\nWith CONFIG_DEBUG_ATOMIC_SLEEP this triggers a warning when the IRQ wait\npath is used:\n\n    tpm_tis_status()\n      tpm_tis_spi_read_bytes()\n        tpm_tis_spi_transfer_full()\n          spi_bus_lock()\n            mutex_lock()\n\nAddress this with the following measures:\n\n1. Call wait_tpm_stat_cond() only while tasking is running.\n2. Use wait_woken() to wait for changes."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/char/tpm/tpm_tis_core.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"1a339b658d9dbe1471f67b78237cf8fa08bbbeb5","lessThan":"c9acbe38797bc1aa3c22a1ab72452e210af6e0ff","versionType":"git","status":"affected"},{"version":"1a339b658d9dbe1471f67b78237cf8fa08bbbeb5","lessThan":"6b068a97958aa00a901a9b5083d74114b21f7b66","versionType":"git","status":"affected"},{"version":"1a339b658d9dbe1471f67b78237cf8fa08bbbeb5","lessThan":"bb63a0530e8e6de3aaf29cd5ba487db2490128ef","versionType":"git","status":"affected"},{"version":"1a339b658d9dbe1471f67b78237cf8fa08bbbeb5","lessThan":"ba33b4f9d3423accd2c91a0b0b0680cd589922f2","versionType":"git","status":"affected"},{"version":"1a339b658d9dbe1471f67b78237cf8fa08bbbeb5","lessThan":"4bb3e1bc142dc9c3240ceed1b3ab031aa9cb1723","versionType":"git","status":"affected"},{"version":"1a339b658d9dbe1471f67b78237cf8fa08bbbeb5","lessThan":"c0c9cfb3b75def8bf200a2d4db09015806acfeaf","versionType":"git","status":"affected"},{"version":"cd4ae0b05126cc9461a2e50ccb745e5583cc91e2","versionType":"git","status":"affected"},{"version":"cf503dbe5c22c6ab9797e1cf864a11597d711c3a","versionType":"git","status":"affected"},{"version":"d229e7ecc0cb29996688f0fa98c5eb6128b81e3a","versionType":"git","status":"affected"},{"version":"4.9.128","lessThan":"4.10","versionType":"semver","status":"affected"},{"version":"4.14.71","lessThan":"4.15","versionType":"semver","status":"affected"},{"version":"4.18.9","lessThan":"4.19","versionType":"semver","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/char/tpm/tpm_tis_core.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"4.19","status":"affected"},{"version":"0","lessThan":"4.19","versionType":"semver","status":"unaffected"},{"version":"6.1.178","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.97","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/4bb3e1bc142dc9c3240ceed1b3ab031aa9cb1723","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/6b068a97958aa00a901a9b5083d74114b21f7b66","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/ba33b4f9d3423accd2c91a0b0b0680cd589922f2","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/bb63a0530e8e6de3aaf29cd5ba487db2490128ef","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/c0c9cfb3b75def8bf200a2d4db09015806acfeaf","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/c9acbe38797bc1aa3c22a1ab72452e210af6e0ff","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-72153","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:21:33.030","lastModified":"2026-08-15T06:21:33.030","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nirqchip/crossbar: Use correct index in crossbar_domain_free()\n\ncrossbar_domain_free() resets the domain data and then uses the nulled\nout irq_data->hwirq member as index to reset the irq_map[] entry and to\nwrite the relevant crossbar register with a safe entry. That means it\nnever frees the correct index and keeps the crossbar register connection\nto the source interrupt active.\n\nIf it would not reset the domain data, then this would be even worse as\nirq_data->hwirq holds the source interrupt number, but both the map and\nregister index need the corresponding GIC SPI number and not the source\ninterrupt number. This might even result in an out of bounds access as\nthe source interrupt number can be higher than the maximal index space.\n\nFix this by using the GIC SPI index from the parent domain's irq_data."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/irqchip/irq-crossbar.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"783d31863fb826f1a3754a2d5959a022a1b12d54","lessThan":"13bdb5140405ff283f9052e65ee1d5c2303765c7","versionType":"git","status":"affected"},{"version":"783d31863fb826f1a3754a2d5959a022a1b12d54","lessThan":"1c48dc6a0c1ef47a9fa24611e60bc2f4ee4dd0df","versionType":"git","status":"affected"},{"version":"783d31863fb826f1a3754a2d5959a022a1b12d54","lessThan":"ccc3664679763d2d6f067c28729bdff627bb72d0","versionType":"git","status":"affected"},{"version":"783d31863fb826f1a3754a2d5959a022a1b12d54","lessThan":"424130169dc03b84ea604685409726d61bcec859","versionType":"git","status":"affected"},{"version":"783d31863fb826f1a3754a2d5959a022a1b12d54","lessThan":"cca649a23a5fc8aae536fc27a0546c67690a4078","versionType":"git","status":"affected"},{"version":"783d31863fb826f1a3754a2d5959a022a1b12d54","lessThan":"36ca587f55a2c04468a89fd16174bb2f78dc04ec","versionType":"git","status":"affected"},{"version":"783d31863fb826f1a3754a2d5959a022a1b12d54","lessThan":"e5be5d452d5f1efbb3342da2b00029be6c99034e","versionType":"git","status":"affected"},{"version":"783d31863fb826f1a3754a2d5959a022a1b12d54","lessThan":"043db005a8d6932dc7d217c86307e9af0bc10ddc","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/irqchip/irq-crossbar.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"4.1","status":"affected"},{"version":"0","lessThan":"4.1","versionType":"semver","status":"unaffected"},{"version":"5.10.261","lessThanOrEqual":"5.10.*","versionType":"semver","status":"unaffected"},{"version":"5.15.212","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.178","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.97","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/043db005a8d6932dc7d217c86307e9af0bc10ddc","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/13bdb5140405ff283f9052e65ee1d5c2303765c7","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/1c48dc6a0c1ef47a9fa24611e60bc2f4ee4dd0df","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/36ca587f55a2c04468a89fd16174bb2f78dc04ec","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/424130169dc03b84ea604685409726d61bcec859","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/cca649a23a5fc8aae536fc27a0546c67690a4078","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/ccc3664679763d2d6f067c28729bdff627bb72d0","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/e5be5d452d5f1efbb3342da2b00029be6c99034e","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-72154","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:21:33.153","lastModified":"2026-08-15T06:21:33.153","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nopenrisc: Fix jump_label smp syncing\n\nThe original commit 8c30b0018f9d (\"openrisc: Add jump label support\")\ncopies from arm64 and does not properly consider how icache invalidation\non remote cores works in OpenRISC.  On OpenRISC remote icaches need to\nbe invalidated otherwise static key's may remain state after updating.\n\nFix SMP cache syncing by:\n\n 1. Properly invalidate remote core icaches on SMP systems by using\n    icache_all_inv.  The old code uses kick_all_cpus_sync() which runs a\n    no-op IPI function call on remote CPU's which does execute a lot of\n    code and flushes many cache lines in the process, but does not flush\n    all and it's not correct on OpenRISC.\n 2. For architectures that do not have WRITETHROUGH caches be sure\n    to flush the dcache after patching.\n\nTo test this I first reproduced the issue using a custom test module\n[0].  The test confirmed that some icache lines maintained stale\nstatic_key code sequences after calling static_branch_enable().  After\nthis patch there are no longer jump_label coherency issues.\n\n[0] https://github.com/stffrdhrn/or1k-utils/tree/master/tests/smp_static_key_test"}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["arch/openrisc/kernel/jump_label.c","arch/openrisc/kernel/patching.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"8c30b0018f9d93391573e091960d257fd9de120a","lessThan":"3fac46068fe4cea22ed373432b9173a915e8e60d","versionType":"git","status":"affected"},{"version":"8c30b0018f9d93391573e091960d257fd9de120a","lessThan":"57740658042daf591c57d6e700d9a304d5972552","versionType":"git","status":"affected"},{"version":"8c30b0018f9d93391573e091960d257fd9de120a","lessThan":"aca063c9024522e4e5b9a9d1927433f6a01785a3","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["arch/openrisc/kernel/jump_label.c","arch/openrisc/kernel/patching.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.18","status":"affected"},{"version":"0","lessThan":"6.18","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/3fac46068fe4cea22ed373432b9173a915e8e60d","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/57740658042daf591c57d6e700d9a304d5972552","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/aca063c9024522e4e5b9a9d1927433f6a01785a3","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-72155","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:21:33.250","lastModified":"2026-08-15T06:21:33.250","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nmtd: spi-nor: swp: Improve locking user experience\n\nIn the case of the first block being locked (or the few first blocks),\nif the user want to fully unlock the device it has two possibilities:\n- either it asks to unlock the entire device, and this works;\n- or it asks to unlock just the block(s) that are currently locked,\n  which fails.\n\nIt fails because the conditions \"can_be_top\" and \"can_be_bottom\" are\ntrue. Indeed, in this case, we unlock everything, so the TB bit does not\nmatter. However in the current implementation, use_top would be true (as\nthis is the favourite option) and lock_len, which in practice should be\nreduced down to 0, is set to \"nor->params->size - (ofs + len)\" which is\na positive number. This is wrong.\n\nAn easy way is to simply add an extra condition. In the unlock() path,\nif we can achieve the same result from both sides, it means we unlock\neverything and lock_len must simply be 0. A comment is added to clarify\nthat logic."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/mtd/spi-nor/swp.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"3dd8012a8eeb3702fa17450ec1a16a3f38af138d","lessThan":"9a0d8dec3d11ca95d67537ea8fa6ee2730a5038a","versionType":"git","status":"affected"},{"version":"3dd8012a8eeb3702fa17450ec1a16a3f38af138d","lessThan":"dc341272cf8e15a2c511db3c4df5dab8adf70ad0","versionType":"git","status":"affected"},{"version":"3dd8012a8eeb3702fa17450ec1a16a3f38af138d","lessThan":"6110ab5ffd84e8daa654652446a03ce2f77580a7","versionType":"git","status":"affected"},{"version":"3dd8012a8eeb3702fa17450ec1a16a3f38af138d","lessThan":"c0806df5cf806545160f3fdac3c888926ceac557","versionType":"git","status":"affected"},{"version":"3dd8012a8eeb3702fa17450ec1a16a3f38af138d","lessThan":"12d4d69221159e6d0e72400ec81195d691169b53","versionType":"git","status":"affected"},{"version":"3dd8012a8eeb3702fa17450ec1a16a3f38af138d","lessThan":"e1d456b26bf23e30db305a6184e8abd9ab68bbf2","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/mtd/spi-nor/swp.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"4.6","status":"affected"},{"version":"0","lessThan":"4.6","versionType":"semver","status":"unaffected"},{"version":"6.1.178","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.97","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/12d4d69221159e6d0e72400ec81195d691169b53","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/6110ab5ffd84e8daa654652446a03ce2f77580a7","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/9a0d8dec3d11ca95d67537ea8fa6ee2730a5038a","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/c0806df5cf806545160f3fdac3c888926ceac557","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/dc341272cf8e15a2c511db3c4df5dab8adf70ad0","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/e1d456b26bf23e30db305a6184e8abd9ab68bbf2","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-72156","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:21:33.373","lastModified":"2026-08-15T06:21:33.373","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nfpga: microchip-spi: fix zero header_size OOB read in mpf_ops_parse_header()\n\nmpf_ops_parse_header() reads header_size from the bitstream at\nMPF_HEADER_SIZE_OFFSET (24). When header_size is zero, the expression\n*(buf + header_size - 1) reads one byte before the buffer start.\n\nSince initial_header_size is set to 71 in mpf_ops, the fpga-mgr core\nguarantees the buffer is large enough to reach MPF_HEADER_SIZE_OFFSET.\nThe only real gap is the zero header_size case, which cannot be\nresolved by providing a larger buffer, so return -EINVAL."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/fpga/microchip-spi.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"5f8d4a9008307e0bf210906948953386935d361c","lessThan":"e45ec24d8e986d79a8e07f49a816c414ad283622","versionType":"git","status":"affected"},{"version":"5f8d4a9008307e0bf210906948953386935d361c","lessThan":"0d3766fecd9b2db39a18b48021c15c522997ec25","versionType":"git","status":"affected"},{"version":"5f8d4a9008307e0bf210906948953386935d361c","lessThan":"a1baee24df72ec8fd1d6925c1d5162ffff4ee3bf","versionType":"git","status":"affected"},{"version":"5f8d4a9008307e0bf210906948953386935d361c","lessThan":"c9ef79e34bc1eac4fd59051e5c7b96a74e59d46f","versionType":"git","status":"affected"},{"version":"5f8d4a9008307e0bf210906948953386935d361c","lessThan":"3da8eaf5469eda2353b72038d644fabddb848ce1","versionType":"git","status":"affected"},{"version":"5f8d4a9008307e0bf210906948953386935d361c","lessThan":"43a1974da6bc7ce8f4d1dc1d03d56997428c29c3","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/fpga/microchip-spi.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.0","status":"affected"},{"version":"0","lessThan":"6.0","versionType":"semver","status":"unaffected"},{"version":"6.1.178","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.97","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/0d3766fecd9b2db39a18b48021c15c522997ec25","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/3da8eaf5469eda2353b72038d644fabddb848ce1","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/43a1974da6bc7ce8f4d1dc1d03d56997428c29c3","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/a1baee24df72ec8fd1d6925c1d5162ffff4ee3bf","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/c9ef79e34bc1eac4fd59051e5c7b96a74e59d46f","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/e45ec24d8e986d79a8e07f49a816c414ad283622","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-72157","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:21:33.497","lastModified":"2026-08-15T06:21:33.497","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nnet: thunderbolt: Fix frags[] overflow by bounding frame_count\n\ntbnet_poll() assembles a multi-frame ThunderboltIP packet into one skb. The\nfirst frame goes into the skb linear area and every further frame is added as\na page fragment.\n\n\tskb_add_rx_frag(skb, skb_shinfo(skb)->nr_frags,\n\t\t\tpage, hdr_size, frame_size,\n\t\t\tTBNET_RX_PAGE_SIZE - hdr_size);\n\nA packet of frame_count frames therefore ends up with frame_count - 1\nfragments. tbnet_check_frame() only bounds the peer supplied frame_count to\nTBNET_RING_SIZE / 4 (64), which is far above MAX_SKB_FRAGS (17 by default). A\npeer that sends a packet of 19 or more small frames pushes nr_frags past\nMAX_SKB_FRAGS, so skb_add_rx_frag() writes past skb_shinfo()->frags[] and\ncorrupts memory after the shared info.\n\nTighten the start of packet bound to MAX_SKB_FRAGS + 1 so a packet can never\nproduce more fragments than frags[] can hold. This matches the recent skb\nfrags overflow fixes in other receive paths, for example f0813bcd2d9d (\"net:\nwwan: t7xx: fix potential skb->frags overflow in RX path\") and 600dc40554dc\n(\"net: usb: cdc-phonet: fix skb frags[] overflow in rx_complete()\")."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/net/thunderbolt/main.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"e69b6c02b4c3b8d03be7136f90dd9551ad5a5a5e","lessThan":"2b3b4e5ff5a58ad32817824b0310e63908b12052","versionType":"git","status":"affected"},{"version":"e69b6c02b4c3b8d03be7136f90dd9551ad5a5a5e","lessThan":"e27beb4536cbf1d59e2d8c2840e87d972aba906f","versionType":"git","status":"affected"},{"version":"e69b6c02b4c3b8d03be7136f90dd9551ad5a5a5e","lessThan":"e5824d5b841d99a2bcdd4e2c256643293bbc22c1","versionType":"git","status":"affected"},{"version":"e69b6c02b4c3b8d03be7136f90dd9551ad5a5a5e","lessThan":"fe6b606fbf0c3beb94ccf17fcf31d8c2138264e3","versionType":"git","status":"affected"},{"version":"e69b6c02b4c3b8d03be7136f90dd9551ad5a5a5e","lessThan":"55d9895f89970501fe126d1026b586b04a224c27","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/net/thunderbolt/main.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"4.15","status":"affected"},{"version":"0","lessThan":"4.15","versionType":"semver","status":"unaffected"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.97","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/2b3b4e5ff5a58ad32817824b0310e63908b12052","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/55d9895f89970501fe126d1026b586b04a224c27","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/e27beb4536cbf1d59e2d8c2840e87d972aba906f","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/e5824d5b841d99a2bcdd4e2c256643293bbc22c1","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/fe6b606fbf0c3beb94ccf17fcf31d8c2138264e3","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-72158","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:21:33.617","lastModified":"2026-08-15T06:21:33.617","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nfpga: dfl: add bounds check in dfh_get_param_size()\n\ndfh_get_param_size() can return a parameter size larger than the feature\nregion because the loop bounds check is evaluated before incrementing\nsize. If the EOP (End of Parameters) bit is set in the same iteration,\nthe inflated size is returned without re-validation against max.\n\nThis can cause create_feature_instance() to call memcpy_fromio() with a\nsize exceeding the ioremap'd region when a malicious FPGA device provides\ncrafted DFHv1 parameter headers.\n\nAdd a bounds check after the size increment to ensure the accumulated\nsize never exceeds the feature boundary."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/fpga/dfl.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"4747ab89b4a652f835494fcf8342aaa0efb9b0fd","lessThan":"b2f6220e929b2a43605331d0139e65dc1640c05c","versionType":"git","status":"affected"},{"version":"4747ab89b4a652f835494fcf8342aaa0efb9b0fd","lessThan":"3b622aa447cf26104f96a8be39539367863bc6b6","versionType":"git","status":"affected"},{"version":"4747ab89b4a652f835494fcf8342aaa0efb9b0fd","lessThan":"012683accbb7d2bcf1264f2a0ecd6aa1dcea4d68","versionType":"git","status":"affected"},{"version":"4747ab89b4a652f835494fcf8342aaa0efb9b0fd","lessThan":"f3df5386e3bb54626c117bd85e0158d45fb4aea9","versionType":"git","status":"affected"},{"version":"4747ab89b4a652f835494fcf8342aaa0efb9b0fd","lessThan":"9e8bc49f91f3f81d957c4f1c1f09fe94e2f88f6a","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/fpga/dfl.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.3","status":"affected"},{"version":"0","lessThan":"6.3","versionType":"semver","status":"unaffected"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.97","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/012683accbb7d2bcf1264f2a0ecd6aa1dcea4d68","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/3b622aa447cf26104f96a8be39539367863bc6b6","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/9e8bc49f91f3f81d957c4f1c1f09fe94e2f88f6a","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/b2f6220e929b2a43605331d0139e65dc1640c05c","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/f3df5386e3bb54626c117bd85e0158d45fb4aea9","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-72159","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:21:33.720","lastModified":"2026-08-15T06:21:33.720","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nocfs2: reject non-inline dinodes with i_size and zero i_clusters\n\nOn a volume mounted without OCFS2_FEATURE_INCOMPAT_SPARSE_ALLOC, a\nnon-inline regular file with non-zero i_size and zero i_clusters is\nstructurally malformed: the extent map declares no allocated clusters yet\nthe size header claims content exists.  Keep rejecting that shape, but\nexpress it through a shared predicate so the same invariant is available\nto normal inode reads and online filecheck.\n\nThe same zero-cluster shape is also malformed for non-inline directories. \nocfs2 directory growth allocates backing storage before advancing i_size,\nand ocfs2_dir_foreach_blk_el() later walks until ctx->pos reaches\ni_size_read(inode).  A forged directory dinode with a huge i_size and no\nclusters would repeatedly fail on holes while advancing through the\nclaimed size.\n\nSparse regular files remain exempt: on sparse-alloc volumes, truncate can\nlegitimately grow i_size without allocating clusters.  System inodes and\ninline-data dinodes also retain their separate storage rules.\n\nMirror the check in ocfs2_filecheck_validate_inode_block() as well. \nfilecheck reports through its own error namespace, so malformed\nsize/cluster state is logged as a filecheck invalid-inode result rather\nthan via ocfs2_error(), but it must not proceed into\nocfs2_populate_inode()."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["fs/ocfs2/inode.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"b657c95c11088d77fc1bfc9c84d940f778bf9d12","lessThan":"416d3e5f8a30ed04fe21ba7dc73c2841c3b56265","versionType":"git","status":"affected"},{"version":"b657c95c11088d77fc1bfc9c84d940f778bf9d12","lessThan":"ed0f938f946f16b772e99cb8c277ab57828e5be4","versionType":"git","status":"affected"},{"version":"b657c95c11088d77fc1bfc9c84d940f778bf9d12","lessThan":"83f6756a7b71adec0a41ae68e079a38906d59c6c","versionType":"git","status":"affected"},{"version":"b657c95c11088d77fc1bfc9c84d940f778bf9d12","lessThan":"38c1ef7ce50eb4af0f89038b8aba12396ddb9233","versionType":"git","status":"affected"},{"version":"b657c95c11088d77fc1bfc9c84d940f778bf9d12","lessThan":"d837068eefbc2651fe5789bf75a0f945710f7b8e","versionType":"git","status":"affected"},{"version":"b657c95c11088d77fc1bfc9c84d940f778bf9d12","lessThan":"2174c68f623b74bd8690a4a6a4a52882d8ac3dc3","versionType":"git","status":"affected"},{"version":"b657c95c11088d77fc1bfc9c84d940f778bf9d12","lessThan":"3bfeb436d4be6a2beb56cab344770e93e6b07260","versionType":"git","status":"affected"},{"version":"b657c95c11088d77fc1bfc9c84d940f778bf9d12","lessThan":"7ebc672fab7a76e1e47e0f2fc1ee48118d27fde4","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["fs/ocfs2/inode.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"2.6.29","status":"affected"},{"version":"0","lessThan":"2.6.29","versionType":"semver","status":"unaffected"},{"version":"5.10.261","lessThanOrEqual":"5.10.*","versionType":"semver","status":"unaffected"},{"version":"5.15.212","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.178","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.97","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/2174c68f623b74bd8690a4a6a4a52882d8ac3dc3","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/38c1ef7ce50eb4af0f89038b8aba12396ddb9233","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/3bfeb436d4be6a2beb56cab344770e93e6b07260","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/416d3e5f8a30ed04fe21ba7dc73c2841c3b56265","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/7ebc672fab7a76e1e47e0f2fc1ee48118d27fde4","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/83f6756a7b71adec0a41ae68e079a38906d59c6c","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/d837068eefbc2651fe5789bf75a0f945710f7b8e","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/ed0f938f946f16b772e99cb8c277ab57828e5be4","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-72160","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:21:33.850","lastModified":"2026-08-15T06:21:33.850","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nocfs2: reject dinodes with non-canonical i_mode type\n\nPatch series \"ocfs2: harden inode validators against forged metadata\", v2.\n\nThis series adds three structural checks to OCFS2 dinode validation so\nmalformed on-disk fields are rejected before ocfs2_populate_inode() copies\nthem into the in-core inode.\n\nThe checks cover:\n\n  - i_mode values whose type bits do not name a canonical POSIX file\n    type;\n  - non-device dinodes whose id1.dev1.i_rdev field is non-zero; and\n  - non-inline dinodes that claim non-zero i_size while i_clusters is\n    zero, covering directories unconditionally and regular files on\n    non-sparse volumes.\n\nThe normal read path reports these through ocfs2_error(), matching the\nexisting suballoc-slot, inline-data, chain-list, and refcount checks.  The\nonline filecheck path uses the same structural predicates but keeps its\nown reporting contract, returning OCFS2_FILECHECK_ERR_INVALIDINO instead\nof calling ocfs2_error().\n\n\nThis patch (of 3):\n\nocfs2_validate_inode_block() currently accepts any non-zero i_mode value. \nocfs2_populate_inode() then copies that mode verbatim into inode->i_mode\nand dispatches on i_mode & S_IFMT to the file/dir/symlink/special_file\niops; an unrecognised type falls through to ocfs2_special_file_iops and\ninit_special_inode().\n\nReject dinodes whose type bits do not name one of the seven canonical\nPOSIX file types.  Use fs_umode_to_ftype(), the same generic file-type\nconversion helper OCFS2 already uses for directory entries, so the\naccepted inode type set matches the kernel file-type vocabulary instead of\nopen-coding a local switch.\n\nApply the same structural check to the online filecheck read path. \nfilecheck keeps its own error namespace, so it reports malformed i_mode\nthrough the filecheck logger and OCFS2_FILECHECK_ERR_INVALIDINO instead of\ncalling ocfs2_error(), but it must not allow a malformed dinode to proceed\ninto ocfs2_populate_inode()."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["fs/ocfs2/inode.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"b657c95c11088d77fc1bfc9c84d940f778bf9d12","lessThan":"2e3aac33988ef4e4170141db8e995693ea38357c","versionType":"git","status":"affected"},{"version":"b657c95c11088d77fc1bfc9c84d940f778bf9d12","lessThan":"fb024ea29f6cb1f01745e5f2e31646f3acb9aa6f","versionType":"git","status":"affected"},{"version":"b657c95c11088d77fc1bfc9c84d940f778bf9d12","lessThan":"157d31ef45038d89cd19620105e082d43c8e41e0","versionType":"git","status":"affected"},{"version":"b657c95c11088d77fc1bfc9c84d940f778bf9d12","lessThan":"a5b555bcabbb0aff8745ad181768eaf9d964c1ee","versionType":"git","status":"affected"},{"version":"b657c95c11088d77fc1bfc9c84d940f778bf9d12","lessThan":"82afe13558354390d8a592a5334d5f4fd72c0e5c","versionType":"git","status":"affected"},{"version":"b657c95c11088d77fc1bfc9c84d940f778bf9d12","lessThan":"4db3b6a2a8ecf2a89d26a4090ace4072c6fad050","versionType":"git","status":"affected"},{"version":"b657c95c11088d77fc1bfc9c84d940f778bf9d12","lessThan":"b858f2d57cfc9d57ce61b86051d603dc0ebccd40","versionType":"git","status":"affected"},{"version":"b657c95c11088d77fc1bfc9c84d940f778bf9d12","lessThan":"5366a017099c6a3c443be908a05f26fd72af12a1","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["fs/ocfs2/inode.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"2.6.29","status":"affected"},{"version":"0","lessThan":"2.6.29","versionType":"semver","status":"unaffected"},{"version":"5.10.261","lessThanOrEqual":"5.10.*","versionType":"semver","status":"unaffected"},{"version":"5.15.212","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.178","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.97","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/157d31ef45038d89cd19620105e082d43c8e41e0","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/2e3aac33988ef4e4170141db8e995693ea38357c","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/4db3b6a2a8ecf2a89d26a4090ace4072c6fad050","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/5366a017099c6a3c443be908a05f26fd72af12a1","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/82afe13558354390d8a592a5334d5f4fd72c0e5c","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/a5b555bcabbb0aff8745ad181768eaf9d964c1ee","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/b858f2d57cfc9d57ce61b86051d603dc0ebccd40","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/fb024ea29f6cb1f01745e5f2e31646f3acb9aa6f","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-72161","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:21:33.983","lastModified":"2026-08-15T06:21:33.983","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nocfs2: add journal NULL check in ocfs2_checkpoint_inode()\n\nDuring unmount, ocfs2_journal_shutdown() frees the journal and sets\nosb->journal to NULL. Later, when VFS evicts remaining cached inodes,\nocfs2_evict_inode() -> ocfs2_clear_inode() -> ocfs2_checkpoint_inode()\n-> ocfs2_ci_fully_checkpointed() dereferences osb->journal, causing a\nNULL pointer dereference.\n\nFix this by adding a NULL check for osb->journal in\nocfs2_checkpoint_inode(). If the journal is NULL, it has already been\nfully flushed and destroyed during shutdown, so there is nothing to\ncheckpoint."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["fs/ocfs2/journal.h"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"da5e7c87827e8caa6a1eeec6d95dcf74ab592a01","lessThan":"24daf13422e8328fd588c34a017bdef1949910e8","versionType":"git","status":"affected"},{"version":"da5e7c87827e8caa6a1eeec6d95dcf74ab592a01","lessThan":"7da7e4ac21895fe34cceffcfc99497cc2750da99","versionType":"git","status":"affected"},{"version":"da5e7c87827e8caa6a1eeec6d95dcf74ab592a01","lessThan":"eb6a13834c23e291f1170cb1b489ec255edfa5a3","versionType":"git","status":"affected"},{"version":"da5e7c87827e8caa6a1eeec6d95dcf74ab592a01","lessThan":"499714de42ab4d2e778cbb10186684142a1222eb","versionType":"git","status":"affected"},{"version":"da5e7c87827e8caa6a1eeec6d95dcf74ab592a01","lessThan":"63921f790234b221e4b15c56c72888b13250f81d","versionType":"git","status":"affected"},{"version":"da5e7c87827e8caa6a1eeec6d95dcf74ab592a01","lessThan":"a291c77c034b7a81849ce9b71cc9ecda9e587d89","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["fs/ocfs2/journal.h"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"5.16","status":"affected"},{"version":"0","lessThan":"5.16","versionType":"semver","status":"unaffected"},{"version":"6.1.178","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.97","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/24daf13422e8328fd588c34a017bdef1949910e8","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/499714de42ab4d2e778cbb10186684142a1222eb","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/63921f790234b221e4b15c56c72888b13250f81d","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/7da7e4ac21895fe34cceffcfc99497cc2750da99","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/a291c77c034b7a81849ce9b71cc9ecda9e587d89","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/eb6a13834c23e291f1170cb1b489ec255edfa5a3","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-72162","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:21:34.117","lastModified":"2026-08-15T06:21:34.117","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nocfs2: fix UBSAN array-index-out-of-bounds in ocfs2_sum_rightmost_rec\n\n[BUG]\nOn-disk corruption setting l_next_free_rec to 0 in an inode's embedded\nextent list triggers a UBSAN panic on the next write to that file.\n\n[CAUSE]\nocfs2_sum_rightmost_rec() computes\ni = le16_to_cpu(el->l_next_free_rec) - 1\nand accesses el->l_recs[i] without validating i. When l_next_free_rec\nis 0, i becomes -1; when l_next_free_rec exceeds l_count, i falls\npast the end of the array. Either case violates the\n__counted_by_le(l_count) annotation on l_recs[] and triggers UBSAN.\n\n[FIX]\nValidate the inode's embedded extent list when the inode is read, in\nocfs2_validate_inode_block(): l_count must be non-zero and no larger\nthan the inode block can hold, and l_next_free_rec must not exceed\nl_count. A corrupt list is rejected at read time, before the b-tree\ncode can index l_recs[] out of bounds."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["fs/ocfs2/inode.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"671889c553ea55e2da6a4f3b15f4c0fa40f2f0d1","versionType":"git","status":"affected"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"858aa4965ffa8c0d4bb5dd835ac4f1c9a1dcab85","versionType":"git","status":"affected"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"452a8467be8143747292218212671deeb186d2ae","versionType":"git","status":"affected"},{"version":"0","lessThan":"6.18.40","versionType":"semver","status":"affected"},{"version":"0","lessThan":"7.1.5","versionType":"semver","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["fs/ocfs2/inode.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/452a8467be8143747292218212671deeb186d2ae","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/671889c553ea55e2da6a4f3b15f4c0fa40f2f0d1","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/858aa4965ffa8c0d4bb5dd835ac4f1c9a1dcab85","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-72163","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:21:34.217","lastModified":"2026-08-15T06:21:34.217","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nocfs2: fix NULL h_transaction deref in ocfs2_assure_trans_credits\n\n[BUG]\nA direct write over unwritten extents can panic the kernel in\nocfs2_assure_trans_credits() when the journal aborts during DIO\ncompletion. The crash is a general protection fault from a NULL pointer\ndereference.\n\n[CAUSE]\nocfs2_dio_end_io_write() loops over a direct write's unwritten extents,\nmarking each written under a single journal handle. If the journal\naborts (for example after an I/O error) while the extent tree is being\nupdated, the handle is left aborted with its transaction pointer\ncleared. The extent merge treats that failure as not critical and\nreports success, so the loop keeps using the handle.\nocfs2_assure_trans_credits() reads the handle's remaining credits\nwithout first checking whether the handle is aborted, and that read\ndereferences the cleared transaction pointer.\n\n[FIX]\nA journal abort is recorded in the handle itself, so callers are\nexpected to test the handle rather than rely on a returned error.\nMake ocfs2_assure_trans_credits() do that, as the other ocfs2 journal\nhelpers already do, and return -EROFS when the handle is aborted."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["fs/ocfs2/journal.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"a68b896aa56e435506453ec8835bc991ec3ae687","lessThan":"2d80e9c56718435a9c9f5f24dbc954989aead579","versionType":"git","status":"affected"},{"version":"320273b5649bbcee87f9e65343077189699d2a7a","lessThan":"942b818b396c24c452681803ff291552317d2ef1","versionType":"git","status":"affected"},{"version":"9ea2d1c6789722d58ec191f14f9a02518d55b6b4","lessThan":"7146d191dae3a8efdb957993fb61a55713186266","versionType":"git","status":"affected"},{"version":"c05ffb693bfb42a48ef3ee88a55b57392984e111","lessThan":"f14aaaa130356ee4adb44de947c098637c70df8f","versionType":"git","status":"affected"},{"version":"be346c1a6eeb49d8fda827d2a9522124c2f72f36","lessThan":"6ad7532a23bc94076efe9f1486dd7f7493c090ff","versionType":"git","status":"affected"},{"version":"be346c1a6eeb49d8fda827d2a9522124c2f72f36","lessThan":"bd73971fad89d5ee4ea0ba9b92d2ea08733c4a64","versionType":"git","status":"affected"},{"version":"be346c1a6eeb49d8fda827d2a9522124c2f72f36","lessThan":"253ed993e0b36997ec7b04c1ff76103b38241de2","versionType":"git","status":"affected"},{"version":"be346c1a6eeb49d8fda827d2a9522124c2f72f36","lessThan":"f9ab30c96b0f00c20c6dac93681bdae3a033d229","versionType":"git","status":"affected"},{"version":"331d1079d58206ff7dc5518185f800b412f89bc6","versionType":"git","status":"affected"},{"version":"5.10.221","lessThan":"5.10.261","versionType":"semver","status":"affected"},{"version":"5.15.162","lessThan":"5.15.212","versionType":"semver","status":"affected"},{"version":"6.1.97","lessThan":"6.1.178","versionType":"semver","status":"affected"},{"version":"6.6.37","lessThan":"6.6.145","versionType":"semver","status":"affected"},{"version":"6.9.8","lessThan":"6.10","versionType":"semver","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["fs/ocfs2/journal.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.10","status":"affected"},{"version":"0","lessThan":"6.10","versionType":"semver","status":"unaffected"},{"version":"5.10.261","lessThanOrEqual":"5.10.*","versionType":"semver","status":"unaffected"},{"version":"5.15.212","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.178","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.97","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/253ed993e0b36997ec7b04c1ff76103b38241de2","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/2d80e9c56718435a9c9f5f24dbc954989aead579","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/6ad7532a23bc94076efe9f1486dd7f7493c090ff","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/7146d191dae3a8efdb957993fb61a55713186266","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/942b818b396c24c452681803ff291552317d2ef1","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/bd73971fad89d5ee4ea0ba9b92d2ea08733c4a64","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/f14aaaa130356ee4adb44de947c098637c70df8f","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/f9ab30c96b0f00c20c6dac93681bdae3a033d229","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-72164","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:21:34.357","lastModified":"2026-08-15T06:21:34.357","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nocfs2: avoid moving extents to occupied clusters\n\nFor non-auto OCFS2_IOC_MOVE_EXT operations, userspace supplies a physical\nme_goal.  ocfs2_move_extent() initializes new_phys_cpos from that goal and\nexpects ocfs2_probe_alloc_group() to replace it with a free run in the\ntarget block group.\n\nThe probe currently leaves *phys_cpos unchanged if the scan reaches the\nend of the group without finding a free run.  An occupied goal at the last\nbit can therefore survive the probe and be passed to\n__ocfs2_move_extent(), which copies file data into a cluster still owned\nby another inode before the bitmap is updated.\n\nWhen the probe does find a free run, it also subtracts move_len from the\nending bit.  The start of an N-bit run ending at i is i - N + 1, so the\ncurrent calculation can report the bit immediately before the free run.\n\nClear *phys_cpos before scanning and use the correct free-run start. \nCallers already treat a zero result as -ENOSPC, so failed probes no longer\ncontinue with an occupied caller-controlled goal."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["fs/ocfs2/move_extents.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"e6b5859cccfa0fec02f3c5b1069481efc7186f47","lessThan":"3112afebf2a76e522fbaabcbb0c47aafbdc35932","versionType":"git","status":"affected"},{"version":"e6b5859cccfa0fec02f3c5b1069481efc7186f47","lessThan":"35486b291b8fbde6c4d0b1c79e565c6260d3329d","versionType":"git","status":"affected"},{"version":"e6b5859cccfa0fec02f3c5b1069481efc7186f47","lessThan":"19f7b04924b20b81dabbeed19d5542792ba5b6d6","versionType":"git","status":"affected"},{"version":"e6b5859cccfa0fec02f3c5b1069481efc7186f47","lessThan":"e281d892ce5870a50fdc718cb3bfc3dd5b62c728","versionType":"git","status":"affected"},{"version":"e6b5859cccfa0fec02f3c5b1069481efc7186f47","lessThan":"0d0c5c17b18bdbc592ac26ab4d1de7e3dbf9be1e","versionType":"git","status":"affected"},{"version":"e6b5859cccfa0fec02f3c5b1069481efc7186f47","lessThan":"d5d5a21fb33cd9b963aea99da81e4dacd452cd95","versionType":"git","status":"affected"},{"version":"e6b5859cccfa0fec02f3c5b1069481efc7186f47","lessThan":"4d1953d3aeb4a7f6623083e1839068ee1c157db2","versionType":"git","status":"affected"},{"version":"e6b5859cccfa0fec02f3c5b1069481efc7186f47","lessThan":"22920541c35a9f23f219038ba5874c843a7c4419","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["fs/ocfs2/move_extents.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"3.0","status":"affected"},{"version":"0","lessThan":"3.0","versionType":"semver","status":"unaffected"},{"version":"5.10.261","lessThanOrEqual":"5.10.*","versionType":"semver","status":"unaffected"},{"version":"5.15.212","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.178","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.97","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/0d0c5c17b18bdbc592ac26ab4d1de7e3dbf9be1e","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/19f7b04924b20b81dabbeed19d5542792ba5b6d6","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/22920541c35a9f23f219038ba5874c843a7c4419","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/3112afebf2a76e522fbaabcbb0c47aafbdc35932","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/35486b291b8fbde6c4d0b1c79e565c6260d3329d","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/4d1953d3aeb4a7f6623083e1839068ee1c157db2","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/d5d5a21fb33cd9b963aea99da81e4dacd452cd95","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/e281d892ce5870a50fdc718cb3bfc3dd5b62c728","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-72165","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:21:34.490","lastModified":"2026-08-15T06:21:34.490","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nmtd: rawnand: fix condition in 'nand_select_target()'\n\n'cs' here must be in range [0:nanddev_ntargets[."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/mtd/nand/raw/nand_base.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"32813e288414fecce18f37f8f0d0414a64b45c56","lessThan":"483a8a8581ee1274ec70e2561492096d4a7305e6","versionType":"git","status":"affected"},{"version":"32813e288414fecce18f37f8f0d0414a64b45c56","lessThan":"c2a131fb6882c98aada739479cc96df8748d0c24","versionType":"git","status":"affected"},{"version":"32813e288414fecce18f37f8f0d0414a64b45c56","lessThan":"e6df4fea1dc86c058e1918136c9b9d8e80c4be1b","versionType":"git","status":"affected"},{"version":"32813e288414fecce18f37f8f0d0414a64b45c56","lessThan":"3da4eb15c7b421c2d97c402bb7bd607c44822995","versionType":"git","status":"affected"},{"version":"32813e288414fecce18f37f8f0d0414a64b45c56","lessThan":"fbc7c8a1167b2eb56b2fd8598c29a3d5e9f8676e","versionType":"git","status":"affected"},{"version":"32813e288414fecce18f37f8f0d0414a64b45c56","lessThan":"4bbfcf9c7e46cae58257150bf834853559382e28","versionType":"git","status":"affected"},{"version":"32813e288414fecce18f37f8f0d0414a64b45c56","lessThan":"8f575fc17360827ca1d1940a84f3c7ee40407a10","versionType":"git","status":"affected"},{"version":"32813e288414fecce18f37f8f0d0414a64b45c56","lessThan":"8507c2cc9e4fa402401819f44d1e8a5ef4d11d8b","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/mtd/nand/raw/nand_base.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"5.2","status":"affected"},{"version":"0","lessThan":"5.2","versionType":"semver","status":"unaffected"},{"version":"5.10.261","lessThanOrEqual":"5.10.*","versionType":"semver","status":"unaffected"},{"version":"5.15.212","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.178","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.97","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/3da4eb15c7b421c2d97c402bb7bd607c44822995","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/483a8a8581ee1274ec70e2561492096d4a7305e6","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/4bbfcf9c7e46cae58257150bf834853559382e28","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/8507c2cc9e4fa402401819f44d1e8a5ef4d11d8b","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/8f575fc17360827ca1d1940a84f3c7ee40407a10","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/c2a131fb6882c98aada739479cc96df8748d0c24","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/e6df4fea1dc86c058e1918136c9b9d8e80c4be1b","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/fbc7c8a1167b2eb56b2fd8598c29a3d5e9f8676e","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-72166","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:21:34.620","lastModified":"2026-08-15T06:21:34.620","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nnet/9p: fix infinite loop in p9_client_rpc on fatal signal\n\nWhen p9_client_rpc() is called with type P9_TFLUSH and the transport\nhas no peer (e.g. fd transport backed by pipes with no 9p server),\na fatal signal causes an infinite loop:\n\n  again:\n\terr = io_wait_event_killable(req->wq, ...)\n\t/* SIGKILL wakes the task, returns -ERESTARTSYS */\n\n\tif (err == -ERESTARTSYS && c->status == Connected &&\n\t\ttype == P9_TFLUSH) {\n\t\tsigpending = 1;\n\t\tclear_thread_flag(TIF_SIGPENDING);\n\t\tgoto again;\n\t}\n\nclear_thread_flag() clears TIF_SIGPENDING before jumping back to\nio_wait_event_killable(). signal_pending_state() checks TIF_SIGPENDING,\nfinds it zero, and the task goes to sleep again. The task can only wake\non the next signal delivery that calls signal_wake_up() and sets\nTIF_SIGPENDING again. When that happens the loop repeats, clears\nTIF_SIGPENDING, and sleeps again indefinitely.\n\nThis is triggered in practice by coredump_wait(): when a thread in a\nmulti-threaded process causes a coredump (e.g. via SIGSYS from Syscall\nUser Dispatch), coredump_wait() sends SIGKILL to all other threads and\nwaits for them to call mm_release(). If one of those threads is blocked\nin p9_client_rpc() over an fd transport with no peer, it enters the\nP9_TFLUSH loop and never calls mm_release(), so coredump_wait() stalls\nforever:\n\nINFO: task syz.0.18:676 blocked for more than 143 seconds.\n      Not tainted 6.12.77+ #1\ntask:syz.0.18 state:D stack:27600 pid:676 tgid:673 ppid:630 flags:0x00000004\nCall Trace:\n <TASK>\n context_switch kernel/sched/core.c:5344 [inline]\n __schedule+0xcb4/0x5d50 kernel/sched/core.c:6724\n __schedule_loop kernel/sched/core.c:6801 [inline]\n schedule+0xe5/0x350 kernel/sched/core.c:6816\n schedule_timeout+0x253/0x290 kernel/time/timer.c:2593\n do_wait_for_common kernel/sched/completion.c:95 [inline]\n __wait_for_common+0x409/0x600 kernel/sched/completion.c:116\n wait_for_common kernel/sched/completion.c:127 [inline]\n wait_for_completion_state+0x1d/0x40 kernel/sched/completion.c:264\n coredump_wait fs/coredump.c:448 [inline]\n do_coredump+0x854/0x4350 fs/coredump.c:629\n get_signal+0x1425/0x2730 kernel/signal.c:2903\n arch_do_signal_or_restart+0x81/0x880 arch/x86/kernel/signal.c:337\n exit_to_user_mode_loop kernel/entry/common.c:111 [inline]\n exit_to_user_mode_prepare include/linux/entry-common.h:328 [inline]\n __syscall_exit_to_user_mode_work kernel/entry/common.c:207 [inline]\n syscall_exit_to_user_mode+0xf9/0x160 kernel/entry/common.c:218\n do_syscall_64+0x102/0x220 arch/x86/entry/common.c:84\n entry_SYSCALL_64_after_hwframe+0x77/0x7f\n </TASK>\n\nFix: check fatal_signal_pending() before clearing TIF_SIGPENDING in the\nP9_TFLUSH retry loop. At that point TIF_SIGPENDING is still set, so\nfatal_signal_pending() works correctly. If a fatal signal is pending,\njump to recalc_sigpending to restore TIF_SIGPENDING and return\n-ERESTARTSYS to the caller.\n\nThe same defect is present in stable kernels back to 5.4. On those\nkernels the infinite loop is broken earlier by a second SIGKILL from\nthe parent process (e.g. kill_and_wait() retrying after a timeout),\nresulting in a zombie process and a shutdown delay rather than a\npermanent D-state hang, but the underlying flaw is the same.\n\nFound by Linux Verification Center (linuxtesting.org) with Syzkaller."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["net/9p/client.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"91b8534fa8f5e01f249b1bf8df0a2540053549ad","lessThan":"378481cc60a937ef8ea4ef6e4f95f0dbc4e21414","versionType":"git","status":"affected"},{"version":"91b8534fa8f5e01f249b1bf8df0a2540053549ad","lessThan":"4f621ae3a2d99b0bac50e8d66cbf7f68323c01e8","versionType":"git","status":"affected"},{"version":"91b8534fa8f5e01f249b1bf8df0a2540053549ad","lessThan":"f62a1f245a71680033260a6f6d74011cc3acb3cd","versionType":"git","status":"affected"},{"version":"91b8534fa8f5e01f249b1bf8df0a2540053549ad","lessThan":"dc892cbb1e4341d427b1f940ebd6abd69bf8e479","versionType":"git","status":"affected"},{"version":"91b8534fa8f5e01f249b1bf8df0a2540053549ad","lessThan":"a8874c34c4a973f9922908a4b8be1d1278f01e42","versionType":"git","status":"affected"},{"version":"91b8534fa8f5e01f249b1bf8df0a2540053549ad","lessThan":"823886a1b089b49bcd349bc8bd3417b7910cd1ac","versionType":"git","status":"affected"},{"version":"91b8534fa8f5e01f249b1bf8df0a2540053549ad","lessThan":"6b4f48728faa8bb514368f7eacda05565dea8696","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["net/9p/client.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"2.6.28","status":"affected"},{"version":"0","lessThan":"2.6.28","versionType":"semver","status":"unaffected"},{"version":"5.15.212","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.178","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.97","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/378481cc60a937ef8ea4ef6e4f95f0dbc4e21414","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/4f621ae3a2d99b0bac50e8d66cbf7f68323c01e8","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/6b4f48728faa8bb514368f7eacda05565dea8696","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/823886a1b089b49bcd349bc8bd3417b7910cd1ac","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/a8874c34c4a973f9922908a4b8be1d1278f01e42","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/dc892cbb1e4341d427b1f940ebd6abd69bf8e479","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/f62a1f245a71680033260a6f6d74011cc3acb3cd","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-72167","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:21:34.763","lastModified":"2026-08-15T06:21:34.763","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nmtd: rawnand: pl353: fix probe resource allocation\n\nDuring probe(), the devm_ioremap() is called with the parent device\ninstead of the current one. So when the module is unloaded, the register\narea isn't released.\n\nTarget the pl35x device in the devm_ioremap() instead of its parent."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/mtd/nand/raw/pl35x-nand-controller.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"08d8c62164a322eb923034acacf25246b775593a","lessThan":"593201a8f43864cb7e25197095f6716a589584fd","versionType":"git","status":"affected"},{"version":"08d8c62164a322eb923034acacf25246b775593a","lessThan":"862c6738833b5b01c801cc47023272f5eaa9a7b2","versionType":"git","status":"affected"},{"version":"08d8c62164a322eb923034acacf25246b775593a","lessThan":"afddc648403511b6d2e978e73686c77549bc72b3","versionType":"git","status":"affected"},{"version":"08d8c62164a322eb923034acacf25246b775593a","lessThan":"c4c9180b3b23f82e1ec429350b420c45c5b5100e","versionType":"git","status":"affected"},{"version":"08d8c62164a322eb923034acacf25246b775593a","lessThan":"ace3a0c839f3bfe1779c6708e7709c824b96dc2f","versionType":"git","status":"affected"},{"version":"08d8c62164a322eb923034acacf25246b775593a","lessThan":"3c44f6c62f652d3ac9d03beb8a199e6388256cdd","versionType":"git","status":"affected"},{"version":"08d8c62164a322eb923034acacf25246b775593a","lessThan":"19ed11aee966d91beebdef9d32ce926474872f79","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/mtd/nand/raw/pl35x-nand-controller.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"5.14","status":"affected"},{"version":"0","lessThan":"5.14","versionType":"semver","status":"unaffected"},{"version":"5.15.212","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.178","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.97","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/19ed11aee966d91beebdef9d32ce926474872f79","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/3c44f6c62f652d3ac9d03beb8a199e6388256cdd","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/593201a8f43864cb7e25197095f6716a589584fd","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/862c6738833b5b01c801cc47023272f5eaa9a7b2","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/ace3a0c839f3bfe1779c6708e7709c824b96dc2f","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/afddc648403511b6d2e978e73686c77549bc72b3","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/c4c9180b3b23f82e1ec429350b420c45c5b5100e","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-72168","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:21:34.890","lastModified":"2026-08-15T06:21:34.890","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nmtd: maps: vmu-flash: fix fault in unaligned fixup\n\nUse kzalloc_obj() / kzalloc_objs() to allocate the memcard structs,\ninstead of kmalloc_obj() / kmalloc_objs() to prevent access to\nuninitialized data.\n\nFixes runtime error: Fault in unaligned fixup: 0000 [#1] at\nmtd_get_fact_prot_info."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/mtd/maps/vmu-flash.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"47a72688fae7298e1ad5fdc9bff7e04b6a549620","lessThan":"01928835d80829e615a492aa66c629b953ec7bef","versionType":"git","status":"affected"},{"version":"47a72688fae7298e1ad5fdc9bff7e04b6a549620","lessThan":"19360c25135fccb6bbafbee49a5f66baf9a311af","versionType":"git","status":"affected"},{"version":"47a72688fae7298e1ad5fdc9bff7e04b6a549620","lessThan":"455519f6b70f46ac6cbf41a75ac76ec5e59040f2","versionType":"git","status":"affected"},{"version":"47a72688fae7298e1ad5fdc9bff7e04b6a549620","lessThan":"79d1661502c6e4b6f626185cef72cf2fa78116e1","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/mtd/maps/vmu-flash.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"2.6.30","status":"affected"},{"version":"0","lessThan":"2.6.30","versionType":"semver","status":"unaffected"},{"version":"6.12.101","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.42","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/01928835d80829e615a492aa66c629b953ec7bef","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/19360c25135fccb6bbafbee49a5f66baf9a311af","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/455519f6b70f46ac6cbf41a75ac76ec5e59040f2","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/79d1661502c6e4b6f626185cef72cf2fa78116e1","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-72169","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:21:34.993","lastModified":"2026-08-15T06:21:34.993","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nkho: make sure scratch size is always aligned by CMA_MIN_ALIGNMENT_BYTES\n\nWhen using scratch_scale, the scratch sizes are rounded up to\nCMA_MIN_ALIGNMENT_BYTES since they will be released as MIGRATE_CMA. This\nis not done when using fixed scratch sizes via command line. This can\nresult in user specifying a size which is not aligned, and thus kernel\nreleasing a pageblock that is only partially scratch.\n\nDo the rounding up for both cases in scratch_size_update()."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["kernel/liveupdate/kexec_handover.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"3dc92c311498c4d307cfdd0c6c3ac9355b50f683","lessThan":"b8271be34bce151597da5b5179e0648c281322a4","versionType":"git","status":"affected"},{"version":"3dc92c311498c4d307cfdd0c6c3ac9355b50f683","lessThan":"9fefab759f59bf891bef7be15aee4bc7caec7ec3","versionType":"git","status":"affected"},{"version":"3dc92c311498c4d307cfdd0c6c3ac9355b50f683","lessThan":"0e39380a7316122e1b00012b3f3cd3e318b3e7d3","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["kernel/liveupdate/kexec_handover.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.16","status":"affected"},{"version":"0","lessThan":"6.16","versionType":"semver","status":"unaffected"},{"version":"6.18.42","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/0e39380a7316122e1b00012b3f3cd3e318b3e7d3","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/9fefab759f59bf891bef7be15aee4bc7caec7ec3","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/b8271be34bce151597da5b5179e0648c281322a4","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-72170","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:21:35.100","lastModified":"2026-08-15T06:21:35.100","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\n9p: skip nlink update in cacheless mode to fix WARN_ON\n\nv9fs_dec_count() unconditionally calls drop_nlink() on regular files,\neven when the inode's nlink is already zero. In cacheless mode the\nclient refetches inode metadata from the server (the source of truth)\non every operation, so by the time v9fs_remove() returns, the locally\ncached nlink may already reflect the post-unlink value:\n\n  1. Client initiates unlink, server processes it and sets nlink to 0\n  2. Client refetches inode metadata (nlink=0) before unlink returns\n  3. Client's v9fs_remove() completes successfully\n  4. Client calls v9fs_dec_count() which calls drop_nlink() on nlink=0\n\nThis race is easily triggered under heavy unlink workloads, such as\nstress-ng's unlink stressor, producing the following warning:\n\n  WARNING: fs/inode.c:417 at drop_nlink+0x4c/0xc8\n  Call trace:\n   drop_nlink+0x4c/0xc8\n   v9fs_remove+0x1e0/0x250 [9p]\n   v9fs_vfs_unlink+0x20/0x38 [9p]\n   vfs_unlink+0x13c/0x258\n   ...\n\nIn cacheless mode the server is authoritative and the inode is on its\nway out, so locally adjusting nlink buys nothing. Skip v9fs_dec_count()\nentirely when neither CACHE_META nor CACHE_LOOSE is set, which both\navoids the warning and removes a class of nlink races (two concurrent\nunlinkers observing nlink > 0 and both calling drop_nlink()) that an\nnlink == 0 guard alone would only narrow rather than close."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["fs/9p/vfs_inode.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"ac89b2ef9b55924bcf922251f043ba73a32d05bb","lessThan":"a5a682b016ef5b5384e28f6d652d47a8f8e73d37","versionType":"git","status":"affected"},{"version":"ac89b2ef9b55924bcf922251f043ba73a32d05bb","lessThan":"de79c3f3643841b8659a71958df7cf2a66bfd409","versionType":"git","status":"affected"},{"version":"ac89b2ef9b55924bcf922251f043ba73a32d05bb","lessThan":"8d610017c992de705b304d3d727a6e3a86af6149","versionType":"git","status":"affected"},{"version":"ac89b2ef9b55924bcf922251f043ba73a32d05bb","lessThan":"8faccac11e1369adddf5d80f4a45af93f13b2e1a","versionType":"git","status":"affected"},{"version":"ac89b2ef9b55924bcf922251f043ba73a32d05bb","lessThan":"574aa0b4799470ac814479f1138d19efe6262255","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["fs/9p/vfs_inode.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"4.17","status":"affected"},{"version":"0","lessThan":"4.17","versionType":"semver","status":"unaffected"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.97","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/574aa0b4799470ac814479f1138d19efe6262255","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/8d610017c992de705b304d3d727a6e3a86af6149","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/8faccac11e1369adddf5d80f4a45af93f13b2e1a","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/a5a682b016ef5b5384e28f6d652d47a8f8e73d37","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/de79c3f3643841b8659a71958df7cf2a66bfd409","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-72171","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:21:35.220","lastModified":"2026-08-15T06:21:35.220","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nmtd: slram: remove failed entries from the device list\n\nregister_device() links a new slram_mtdlist entry before allocating all\nof the state needed by the entry. If a later allocation, memremap(), or\nmtd_device_register() fails, the partially initialized entry remains on\nthe global list. A later cleanup can then dereference or free invalid\nstate from that failed entry.\n\nUnwind the partially initialized entry and clear the list tail on each\nfailure path after the entry has been linked."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/mtd/devices/slram.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"9ee674ab10f755bbedbcbb8e76745d2bb8de88d1","versionType":"git","status":"affected"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"e97415b8254d9cc131b7bb1c80fcf38123269b9a","versionType":"git","status":"affected"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"f40acf577bb0fb0829f285ecfeb27d817840601c","versionType":"git","status":"affected"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"200b8bc5b6065b02f3775cf131f14b8e1156a00a","versionType":"git","status":"affected"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"2fd0cbbb34447ccddab67a2a638a07c6d94cae7a","versionType":"git","status":"affected"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"d8dcbbfa0d695a5244059aa34a2e81f3e8df1082","versionType":"git","status":"affected"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"bdcdfc2464659789032edfad15ff5f7a166f5d7b","versionType":"git","status":"affected"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"36f1648644d769c496a8e47e53603e863e358d73","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/mtd/devices/slram.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"2.6.12","status":"affected"},{"version":"0","lessThan":"2.6.12","versionType":"semver","status":"unaffected"},{"version":"5.10.261","lessThanOrEqual":"5.10.*","versionType":"semver","status":"unaffected"},{"version":"5.15.212","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.178","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.97","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/200b8bc5b6065b02f3775cf131f14b8e1156a00a","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/2fd0cbbb34447ccddab67a2a638a07c6d94cae7a","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/36f1648644d769c496a8e47e53603e863e358d73","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/9ee674ab10f755bbedbcbb8e76745d2bb8de88d1","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/bdcdfc2464659789032edfad15ff5f7a166f5d7b","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/d8dcbbfa0d695a5244059aa34a2e81f3e8df1082","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/e97415b8254d9cc131b7bb1c80fcf38123269b9a","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/f40acf577bb0fb0829f285ecfeb27d817840601c","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-72172","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:21:35.353","lastModified":"2026-08-15T06:21:35.353","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nmm/mm_init: fix uninitialized struct pages for ZONE_DEVICE\n\nIf DAX memory is hotplugged into an unoccupied subsection of an early\nsection, section_activate() reuses the unoptimized boot memmap.  However,\ncompound_nr_pages() still assumes that vmemmap optimization is in effect\nand initializes only the reduced number of struct pages.  As a result, the\nremaining tail struct pages are left uninitialized, which can later lead\nto unexpected behavior or crashes.\n\nFix this by treating early sections as unoptimized when calculating how\nmany struct pages to initialize."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["mm/mm_init.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6fd3620b342861de9547ea01d28f664892ef51a1","lessThan":"511a60e71aec308b24722cffc1912bf6befb87bf","versionType":"git","status":"affected"},{"version":"6fd3620b342861de9547ea01d28f664892ef51a1","lessThan":"11f2826e9ee6f24aaa774e3dcd75abbe4b3091b6","versionType":"git","status":"affected"},{"version":"6fd3620b342861de9547ea01d28f664892ef51a1","lessThan":"da5234df0941665f3a3f5b80f3dab94046537be0","versionType":"git","status":"affected"},{"version":"6fd3620b342861de9547ea01d28f664892ef51a1","lessThan":"b91e27bce37cab9f35de0059278ebe457ca9878b","versionType":"git","status":"affected"},{"version":"6fd3620b342861de9547ea01d28f664892ef51a1","lessThan":"cd681403a87085562499d60325b7b45d3be11217","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["mm/mm_init.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"5.19","status":"affected"},{"version":"0","lessThan":"5.19","versionType":"semver","status":"unaffected"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.97","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/11f2826e9ee6f24aaa774e3dcd75abbe4b3091b6","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/511a60e71aec308b24722cffc1912bf6befb87bf","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/b91e27bce37cab9f35de0059278ebe457ca9878b","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/cd681403a87085562499d60325b7b45d3be11217","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/da5234df0941665f3a3f5b80f3dab94046537be0","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-72173","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:21:35.460","lastModified":"2026-08-15T06:21:35.460","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nfs/proc/task_mmu: do not warn on seeing non-migration pmd entry\n\nPatch series \"mm/hmm: A fix and a selftest\", v3.\n\nPatch 1 fixes a stale warning present from the time when only migration\nsoftleaf entries were supported at the PMD level.\n\nPatch 2 adds some code into hmm-tests.c which exercises the pagemap path\nfor PMD device-private entries.\n\n\nThis patch (of 2):\n\npagemap_pmd_range_thp() warns if a non-present PMD is not a migration\nentry.  This became false once device-private entries at the PMD level\nwere added.\n\nTherefore, remove the stale migration-only assertion."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["fs/proc/task_mmu.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"a30b48bf1b244f11bf9b6d20cdccfe0c2264130c","lessThan":"319caaca072adc564ac9c5357ed013909f23d5ab","versionType":"git","status":"affected"},{"version":"a30b48bf1b244f11bf9b6d20cdccfe0c2264130c","lessThan":"cd1fc0e3c1f67c0c31dfc215e5d9b771133dedc0","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["fs/proc/task_mmu.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.19","status":"affected"},{"version":"0","lessThan":"6.19","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/319caaca072adc564ac9c5357ed013909f23d5ab","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/cd1fc0e3c1f67c0c31dfc215e5d9b771133dedc0","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-72174","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:21:35.567","lastModified":"2026-08-15T06:21:35.567","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nfs/proc/task_mmu: fix hugetlb self-deadlock in pagemap_scan_pte_hole()\n\nA PAGEMAP_SCAN ioctl requesting PM_SCAN_WP_MATCHING on a hugetlb VMA hangs\nthe calling thread, unkillably, as soon as the scan reaches an unpopulated\npart of the range:\n\n  do_pagemap_scan()\n    walk_page_range()\n      walk_hugetlb_range()\n        hugetlb_vma_lock_read()           # take the vma lock for read ...\n        pagemap_scan_pte_hole()           # ... ->pte_hole() for a hole\n          uffd_wp_range()\n            change_protection()\n              hugetlb_change_protection()\n                hugetlb_vma_lock_write()  # ... and block taking it for write\n\nwalk_hugetlb_range() holds the hugetlb vma lock for read across the whole\nwalk.  A present entry goes to ->hugetlb_entry(); an unpopulated one goes\nto ->pte_hole(), i.e.  pagemap_scan_pte_hole().  To write-protect the hole\nthat handler calls uffd_wp_range(), which on a hugetlb VMA reaches\nhugetlb_change_protection() and takes the same vma lock for write.  The\nthread then blocks in down_write() waiting for the read lock it is itself\nholding.\n\nThe populated path avoids this: pagemap_scan_hugetlb_entry()\nwrite-protects the entry inline under the page-table lock and never enters\nhugetlb_change_protection().\n\nDo the same for holes.  Fault in the page table and install the uffd-wp\nmarker directly with make_uffd_wp_huge_pte() under the page-table lock,\nrather than routing through uffd_wp_range().  That is the same sequence\nhugetlb_change_protection() runs for an unpopulated entry, minus the vma\nwrite lock -- which is safe to skip because PMD sharing is disabled on\nuffd-wp VMAs (hugetlb_unshare_all_pmds() runs at registration), leaving\nnothing for that lock to serialise against."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["fs/proc/task_mmu.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"52526ca7fdb905a768a93f8faa418e9b988fc34b","lessThan":"a6ac03652d9edc30c2912037ac83beb42cc67f8e","versionType":"git","status":"affected"},{"version":"52526ca7fdb905a768a93f8faa418e9b988fc34b","lessThan":"43b987ed35be9be21a303d1036d4241fec9943df","versionType":"git","status":"affected"},{"version":"52526ca7fdb905a768a93f8faa418e9b988fc34b","lessThan":"18b8a9700610299819d21fd0ea85d24726d17f65","versionType":"git","status":"affected"},{"version":"52526ca7fdb905a768a93f8faa418e9b988fc34b","lessThan":"e92d92bbafb264dc0518d52b846a3c07ed8d523f","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["fs/proc/task_mmu.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.7","status":"affected"},{"version":"0","lessThan":"6.7","versionType":"semver","status":"unaffected"},{"version":"6.12.97","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/18b8a9700610299819d21fd0ea85d24726d17f65","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/43b987ed35be9be21a303d1036d4241fec9943df","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/a6ac03652d9edc30c2912037ac83beb42cc67f8e","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/e92d92bbafb264dc0518d52b846a3c07ed8d523f","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-72175","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:21:35.677","lastModified":"2026-08-15T06:21:35.677","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nfs/proc/task_mmu: fix make_uffd_wp_huge_pte() prot-update race\n\nPatch series \"userfaultfd/pagemap: pre-existing fixes\".\n\nThese are pre-existing bug fixes that were carried at the front of the\nuserfaultfd RWP working-set-tracking series up to v5 [1].  Per review\nfeedback that fixes should not sit in the middle of a feature series, they\nare split out and sent on their own; the RWP series is reposted rebased on\ntop of this.\n\nAll six were flagged by the Sashiko AI review of the RWP series and carry\nindependent of RWP, apply to mm-new directly, and carry Cc: stable@.\n\n  1: fs/proc/task_mmu: a missing huge_ptep_modify_prot_start() in\n     make_uffd_wp_huge_pte() can lose hardware Dirty/Accessed updates\n     when PAGEMAP_SCAN write-protects a hugetlb PTE.\n\n  2: fs/proc/task_mmu: pagemap_scan_hugetlb_entry() compares the range\n     against HPAGE_SIZE rather than the hstate page size, so it never\n     write-protects gigantic hugetlb pages.\n\n  3: fs/proc/task_mmu: PAGEMAP_SCAN with PM_SCAN_WP_MATCHING over an\n     unpopulated hugetlb range self-deadlocks -- pagemap_scan_pte_hole()\n     calls uffd_wp_range() while walk_hugetlb_range() holds the hugetlb\n     vma lock for read, and hugetlb_change_protection() then takes it\n     for write. Install the marker inline instead.\n\n  4: mm/huge_memory: change_non_present_huge_pmd() drops pmd_swp_uffd_wp\n     on a device-private PMD permission downgrade, silently losing the\n     uffd-wp marker.\n\n  5: userfaultfd: must_wait() applies pte_write() to a locklessly read\n     PTE without checking pte_present(), so swap/migration entries\n     decode random offset bits and a thread can stay parked on a stale\n     fault.\n\n  6: userfaultfd: __VMA_UFFD_FLAGS feeds VMA_UFFD_MINOR_BIT (41) to\n     mk_vma_flags() unconditionally, an out-of-bounds write into the\n     single-word vma_flags_t on 32-bit. Build the mask from config-gated\n     per-mode masks so an unavailable bit is never materialised.\n\n\nThis patch (of 6):\n\nmake_uffd_wp_huge_pte() arms the UFFD_WP bit on a present HugeTLB PTE by\ncalling huge_ptep_modify_prot_commit() with a ptent snapshot that was\nfetched without the corresponding huge_ptep_modify_prot_start().  The\nstart helper is what atomically clears the entry so the kernel-owned\nsnapshot stays consistent until the commit; without it, the hardware may\nset Dirty or Accessed in the live PTE between the original read and the\ncommit, and huge_ptep_modify_prot_commit() (whose generic implementation\njust calls set_huge_pte_at()) then writes the stale snapshot back over the\nlive hardware bits, losing the update.\n\nThe non-hugetlb sibling make_uffd_wp_pte() does this correctly via\nptep_modify_prot_start() / ptep_modify_prot_commit().  Mirror that pattern\nfor the present-PTE branch.  The migration case stays as-is -- migration\nentries are non-present, so there's no hardware update to race against."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["fs/proc/task_mmu.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"52526ca7fdb905a768a93f8faa418e9b988fc34b","lessThan":"50a25249a6355db74c2c1b6be541b4caab9f3655","versionType":"git","status":"affected"},{"version":"52526ca7fdb905a768a93f8faa418e9b988fc34b","lessThan":"8e39ed92d7c5c6bfc08dc45153916f49a4e98bab","versionType":"git","status":"affected"},{"version":"52526ca7fdb905a768a93f8faa418e9b988fc34b","lessThan":"6b7f774b8882445d9174681747d37c42548686a4","versionType":"git","status":"affected"},{"version":"52526ca7fdb905a768a93f8faa418e9b988fc34b","lessThan":"04718f7c9290f95385f0dd328758753dc1c36dec","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["fs/proc/task_mmu.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.7","status":"affected"},{"version":"0","lessThan":"6.7","versionType":"semver","status":"unaffected"},{"version":"6.12.101","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.42","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/04718f7c9290f95385f0dd328758753dc1c36dec","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/50a25249a6355db74c2c1b6be541b4caab9f3655","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/6b7f774b8882445d9174681747d37c42548686a4","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/8e39ed92d7c5c6bfc08dc45153916f49a4e98bab","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-72176","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:21:35.810","lastModified":"2026-08-15T06:21:35.810","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nmm/damon/sysfs-schemes: put stats for scheme_add_dirs() internal error\n\ndamon_sysfs_scheme_add_dirs() setup the tried_regions directory after the\nstats directory setup is completed.  When the tried_regions directory\nsetup is failed, the setup function ensures the reference for the tried\nregions directory is released.  Hence the error path should put references\non setup succeeded directory objects, starting from the stats directory. \nHowever, the error path is putting the tried_regions directory instead of\nthe stats directory.\n\nAs a direct result, the stats directory object is leaked.  Worse yet, if\nthe tried_regions directory setup failed from the initial allocation, the\nscheme->tried_regions field remains uninitialized.  The following\nkobject_put(&scheme->tried_regions->kobj) call in the error path will\ndereference the uninitialized memory.  The setup failures should not be\ncommon.  But once it happens, the consequence is quite bad.\n\nFix this issue by correctly putting the stats directory instead of the\ntried_regions directory.\n\nThe issue was discovered [1] by Sashiko."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["mm/damon/sysfs-schemes.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"5181b75f438d2e5b7f27bf48c6ea88a87c2882b7","lessThan":"50a753171d255895e5dd41566986b48dcec06f31","versionType":"git","status":"affected"},{"version":"5181b75f438d2e5b7f27bf48c6ea88a87c2882b7","lessThan":"f63d6e5ba72aeacdee4fddc902bd7616cd62b919","versionType":"git","status":"affected"},{"version":"5181b75f438d2e5b7f27bf48c6ea88a87c2882b7","lessThan":"40a04601a3f66cabd6629c258a07af645a658865","versionType":"git","status":"affected"},{"version":"5181b75f438d2e5b7f27bf48c6ea88a87c2882b7","lessThan":"6b6b5d7c2c957136b92c00b77b7175259f13082b","versionType":"git","status":"affected"},{"version":"5181b75f438d2e5b7f27bf48c6ea88a87c2882b7","lessThan":"05ea83ee88ca70f8932906d9f2617ff996f45b50","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["mm/damon/sysfs-schemes.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.2","status":"affected"},{"version":"0","lessThan":"6.2","versionType":"semver","status":"unaffected"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.97","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc3","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/05ea83ee88ca70f8932906d9f2617ff996f45b50","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/40a04601a3f66cabd6629c258a07af645a658865","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/50a753171d255895e5dd41566986b48dcec06f31","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/6b6b5d7c2c957136b92c00b77b7175259f13082b","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/f63d6e5ba72aeacdee4fddc902bd7616cd62b919","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-72177","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:21:35.937","lastModified":"2026-08-15T06:21:35.937","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nmm/damon/sysfs-schemes: fix dir put orders in access_pattern_add_dirs()\n\nPatch series \"mm/damon/sysfs-schemes: fix wrong directories put orders in\nerror paths\".\n\nError paths of damon_sysfs_access_pattern_add_dirs() and\ndamon_sysfs_scheme_add_dirs() functions put references to directories in\nwrong orders.  As a result, uninitialized memory dereference and/or\nmemory leak can happen.  Fix those.\n\n\nThis patch (of 2):\n\nIn access_pattern_add_dirs(), error handling path puts references starting\nfrom setup failed directories.  If the failure happpened from the initial\nallication in the setup functions, uninitialized memory dereference\nhappen.  The allocation failures will not commonly happen, but the\nconsequence is quite bad.  Fix the wrong reference put orders.\n\nThe issue was discovered [1] by Sashiko."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["mm/damon/sysfs-schemes.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"7e84b1f8212a038ebeee06de56db7181148fa0cd","lessThan":"0710cc97962ca3bcabaa15ce7fead300faf726cd","versionType":"git","status":"affected"},{"version":"7e84b1f8212a038ebeee06de56db7181148fa0cd","lessThan":"a8c0592a80e954825f2ba29e7f32893f1df762f2","versionType":"git","status":"affected"},{"version":"7e84b1f8212a038ebeee06de56db7181148fa0cd","lessThan":"e03442b0c48bdb034f5b7cf9f3b76d8025576071","versionType":"git","status":"affected"},{"version":"7e84b1f8212a038ebeee06de56db7181148fa0cd","lessThan":"f18c561eb9c51f1ba3adb6117926a98a66599848","versionType":"git","status":"affected"},{"version":"7e84b1f8212a038ebeee06de56db7181148fa0cd","lessThan":"ee59df7a886a35113f309e3eb791060c46f79bb1","versionType":"git","status":"affected"},{"version":"7e84b1f8212a038ebeee06de56db7181148fa0cd","lessThan":"d58fdbe37a829fd2e5803dd4e5a72992dd8c5368","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["mm/damon/sysfs-schemes.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"5.18","status":"affected"},{"version":"0","lessThan":"5.18","versionType":"semver","status":"unaffected"},{"version":"6.1.178","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.97","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc3","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/0710cc97962ca3bcabaa15ce7fead300faf726cd","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/a8c0592a80e954825f2ba29e7f32893f1df762f2","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/d58fdbe37a829fd2e5803dd4e5a72992dd8c5368","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/e03442b0c48bdb034f5b7cf9f3b76d8025576071","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/ee59df7a886a35113f309e3eb791060c46f79bb1","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/f18c561eb9c51f1ba3adb6117926a98a66599848","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-72178","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:21:36.047","lastModified":"2026-08-15T06:21:36.047","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nmm/damon/core: always put unsuccessfully committed target pids\n\ndamon_commit_target() puts and gets the destination and the source target\npids.  It puts the destination target pid because it will be overwritten\nby the source target pid.  It gets the source pid because the caller is\nsupposed to eventually put the pids.  In more detail, the caller will call\ndamon_destroy_ctx() after damon_commit_ctx() to destroy the entire source\ncontext.  And in this case, [f]vaddr operation set's cleanup_target()\ncallback will put the pids.\n\nThe commit operation is made at the context level.  The operation can fail\nin multiple places including in the middle and after the targets commit\noperations.  For any such failures, immediately the error is returned to\nthe damon_commit_ctx() caller.  If some or all of the source target pids\nwere committed to the destination during the unsuccessful context commit\nattempt, those pids should be put twice.\n\nThe source context will do the put operations using the above explained\nroutine.  However, let's suppose the destination context was not\noriginally using [f]vaddr operation set and the commit failed before the\nops of the source context is committed.  The destination does not have the\ncleanup_target() ops callback, so it cannot put the pids via the\ndamon_destroy_ctx().\n\nAs a result, the pids are leaked.  The issue in the real world would be\nnot very common.  The commit feature is for changing parameters of running\nDAMON context while inheriting internal status like the monitoring\nresults.  The monitoring results of a physical address range ain't have\nthings that are beneficial to be inherited to a virtual address ranges\nmonitoring.  So the problem-causing DAMON control would be not very common\nin the real world.  That said, it is a supported feature.  And\ndamon_commit_target() failure due to memory allocation is relatively\nrealistic [1] if there are a huge number of target regions.\n\nFix by putting the pids in the commit operation in case of the failures.\n\nThe issue was discovered [2] by Sashiko."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["mm/damon/core.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"83dc7bbaecae6e69e338355e9a137f0e7a0ecc40","lessThan":"ea07e045611ca00f1ec7e448fd43e655d311158b","versionType":"git","status":"affected"},{"version":"83dc7bbaecae6e69e338355e9a137f0e7a0ecc40","lessThan":"3b91c35961fa5553b4dd36db1f06e3b4acbfc05d","versionType":"git","status":"affected"},{"version":"83dc7bbaecae6e69e338355e9a137f0e7a0ecc40","lessThan":"837f619f1d98e967bd63e51ecd1e77bfa468992d","versionType":"git","status":"affected"},{"version":"83dc7bbaecae6e69e338355e9a137f0e7a0ecc40","lessThan":"6a66c557a2ab2609575bafd15e093669c05f9711","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["mm/damon/core.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.11","status":"affected"},{"version":"0","lessThan":"6.11","versionType":"semver","status":"unaffected"},{"version":"6.12.97","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/3b91c35961fa5553b4dd36db1f06e3b4acbfc05d","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/6a66c557a2ab2609575bafd15e093669c05f9711","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/837f619f1d98e967bd63e51ecd1e77bfa468992d","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/ea07e045611ca00f1ec7e448fd43e655d311158b","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-72179","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:21:36.180","lastModified":"2026-08-15T06:21:36.180","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nriscv: cacheinfo: Fix node reference leak in populate_cache_leaves\n\nCurrently, the while loop drops the reference to prev in each iteration.\nIf the loop terminates early due to a break, the final of_node_put(np)\ncorrectly drops the reference to the current node.\n\nHowever, if the loop terminates naturally because np == NULL, calling\nof_node_put(np) is a no-op. This leaves the last valid node stored in\nprev without its reference dropped, resulting in a node reference leak.\n\nFix this by changing the final `of_node_put(np)` to `of_node_put(prev)`."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["arch/riscv/kernel/cacheinfo.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"94f9bf118f1e294b3f2092f8bde02860f5e3ea3f","lessThan":"2560c97f63bb99b26d9f19b23a4f66ea24c9dc14","versionType":"git","status":"affected"},{"version":"94f9bf118f1e294b3f2092f8bde02860f5e3ea3f","lessThan":"51afb7da697b698996351740b4f39fb05ce2afd4","versionType":"git","status":"affected"},{"version":"94f9bf118f1e294b3f2092f8bde02860f5e3ea3f","lessThan":"880ac50b0bfae06d7ab5f1843253adfb86aa173a","versionType":"git","status":"affected"},{"version":"94f9bf118f1e294b3f2092f8bde02860f5e3ea3f","lessThan":"f322955d9a1c344ed943752f05aacea7bc22e025","versionType":"git","status":"affected"},{"version":"94f9bf118f1e294b3f2092f8bde02860f5e3ea3f","lessThan":"36e4843fe39ea2f17f4de6d59fba26271916c184","versionType":"git","status":"affected"},{"version":"94f9bf118f1e294b3f2092f8bde02860f5e3ea3f","lessThan":"bf4a195f063b0a0805c1417f6aad1dd32ea48f0f","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["arch/riscv/kernel/cacheinfo.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"5.0","status":"affected"},{"version":"0","lessThan":"5.0","versionType":"semver","status":"unaffected"},{"version":"6.1.178","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.97","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/2560c97f63bb99b26d9f19b23a4f66ea24c9dc14","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/36e4843fe39ea2f17f4de6d59fba26271916c184","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/51afb7da697b698996351740b4f39fb05ce2afd4","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/880ac50b0bfae06d7ab5f1843253adfb86aa173a","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/bf4a195f063b0a0805c1417f6aad1dd32ea48f0f","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/f322955d9a1c344ed943752f05aacea7bc22e025","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-72180","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:21:36.293","lastModified":"2026-08-15T06:21:36.293","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nmm/huge_memory: preserve pmd_swp_uffd_wp on device-private PMD downgrade\n\nchange_non_present_huge_pmd() rewrites a writable device-private PMD swap\nentry into a readable one without carrying pmd_swp_uffd_wp() across.  The\nPTE-level change_softleaf_pte() does this correctly; mirror that here,\nmatching what copy_huge_pmd() does for the fork path.  Without the carry,\na plain mprotect() over a UFFD_WP-marked device-private THP strips the bit\nand the trap is bypassed on swap-in."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["mm/huge_memory.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"368076f52ebeecd33e10a9f80905d7508b6b6149","lessThan":"2611f7521c6c124b1bef1be4fc319e0ca144502f","versionType":"git","status":"affected"},{"version":"368076f52ebeecd33e10a9f80905d7508b6b6149","lessThan":"f7e2c21bd1f57cd5350eecdfdb5d6025ca6afbab","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["mm/huge_memory.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.19","status":"affected"},{"version":"0","lessThan":"6.19","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/2611f7521c6c124b1bef1be4fc319e0ca144502f","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/f7e2c21bd1f57cd5350eecdfdb5d6025ca6afbab","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-72181","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:21:36.393","lastModified":"2026-08-15T06:21:36.393","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nmips: sched: Fix CPUMASK_OFFSTACK memory corruption\n\nThis patch addresses a critical memory management flaw. When\nCONFIG_CPUMASK_OFFSTACK is enabled, cpumask_var_t is a pointer.\nConsequently, sizeof(new_mask) evaluates to the pointer size, causing\ncopy_from_user() to clobber the mask pointer. Furthermore, the old\nlogic performed copy_from_user() before allocating the mask.\n\nFix this by allocating new_mask first. To handle variable-sized user\nmasks correctly, use cpumask_size() to truncate overly large user masks\nor pad undersized masks with zeros before copying the data directly into\nthe allocated buffer."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["arch/mips/kernel/mips-mt-fpaff.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"295cbf6d63165fe4253cf1d9ceadcda47a318b48","lessThan":"d20ee42f8226607b5693b2bc2f115ca2d270221a","versionType":"git","status":"affected"},{"version":"295cbf6d63165fe4253cf1d9ceadcda47a318b48","lessThan":"15ba8053fe4162c933855f1676fb321cdb6251c7","versionType":"git","status":"affected"},{"version":"295cbf6d63165fe4253cf1d9ceadcda47a318b48","lessThan":"3446ffb5d03c36f9ce88ede7ca5be319a2968d96","versionType":"git","status":"affected"},{"version":"295cbf6d63165fe4253cf1d9ceadcda47a318b48","lessThan":"87a56c1e8e36d06ebe8640432f911538ded7827d","versionType":"git","status":"affected"},{"version":"295cbf6d63165fe4253cf1d9ceadcda47a318b48","lessThan":"1caee6e084a96ada94658f261ced377d85af3f03","versionType":"git","status":"affected"},{"version":"295cbf6d63165fe4253cf1d9ceadcda47a318b48","lessThan":"a1dd41d00c57efb1fbc6f361c5f48c9d00cca51c","versionType":"git","status":"affected"},{"version":"295cbf6d63165fe4253cf1d9ceadcda47a318b48","lessThan":"98e37db4a34d3af3fb2f4648295c25b5e40b20e3","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["arch/mips/kernel/mips-mt-fpaff.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"2.6.23","status":"affected"},{"version":"0","lessThan":"2.6.23","versionType":"semver","status":"unaffected"},{"version":"5.15.212","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.178","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.97","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/15ba8053fe4162c933855f1676fb321cdb6251c7","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/1caee6e084a96ada94658f261ced377d85af3f03","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/3446ffb5d03c36f9ce88ede7ca5be319a2968d96","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/87a56c1e8e36d06ebe8640432f911538ded7827d","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/98e37db4a34d3af3fb2f4648295c25b5e40b20e3","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/a1dd41d00c57efb1fbc6f361c5f48c9d00cca51c","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/d20ee42f8226607b5693b2bc2f115ca2d270221a","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-72182","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:21:36.510","lastModified":"2026-08-15T06:21:36.510","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\npower: supply: charger-manager: fix refcount leak in is_full_charged()\n\nIn is_full_charged(), power_supply_get_by_name() is called to\nobtain a reference to the fuel_gauge power supply. If the\nvoltage check (uV >= desc->fullbatt_uV) succeeds, the function\nreturns true directly without releasing the reference, leaking\nthe refcount.\n\nFix this by setting a flag and jumping to the out label where\npower_supply_put() properly drops the reference."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/power/supply/charger-manager.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"e132fc6bb89bd307cfcdb8ba24afcd1985261485","lessThan":"afe3202c30bdff0635818ab525fe2694309d2692","versionType":"git","status":"affected"},{"version":"e132fc6bb89bd307cfcdb8ba24afcd1985261485","lessThan":"93b99b63ad5657225faf702670ddfeddf1f0ae29","versionType":"git","status":"affected"},{"version":"e132fc6bb89bd307cfcdb8ba24afcd1985261485","lessThan":"6f75912cc6ff4c05ff13af351c4eea49b6b3c078","versionType":"git","status":"affected"},{"version":"e132fc6bb89bd307cfcdb8ba24afcd1985261485","lessThan":"e44ad91e9f75f3e3ccbdb85ffe699471f9675e5b","versionType":"git","status":"affected"},{"version":"e132fc6bb89bd307cfcdb8ba24afcd1985261485","lessThan":"3999f47e4bbf864e3c7fbfd813fb2f651e6b5714","versionType":"git","status":"affected"},{"version":"e132fc6bb89bd307cfcdb8ba24afcd1985261485","lessThan":"193e6471e985c2f25d09b3fe96ec52f4eab89bd4","versionType":"git","status":"affected"},{"version":"e132fc6bb89bd307cfcdb8ba24afcd1985261485","lessThan":"e8631b883338ea4c3b5d8ddfbe16407af9f0b4b9","versionType":"git","status":"affected"},{"version":"e132fc6bb89bd307cfcdb8ba24afcd1985261485","lessThan":"4373cfa38ead58f980362c841b0d0bdf8c4d956c","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/power/supply/charger-manager.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"5.10","status":"affected"},{"version":"0","lessThan":"5.10","versionType":"semver","status":"unaffected"},{"version":"5.10.261","lessThanOrEqual":"5.10.*","versionType":"semver","status":"unaffected"},{"version":"5.15.212","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.178","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.97","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/193e6471e985c2f25d09b3fe96ec52f4eab89bd4","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/3999f47e4bbf864e3c7fbfd813fb2f651e6b5714","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/4373cfa38ead58f980362c841b0d0bdf8c4d956c","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/6f75912cc6ff4c05ff13af351c4eea49b6b3c078","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/93b99b63ad5657225faf702670ddfeddf1f0ae29","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/afe3202c30bdff0635818ab525fe2694309d2692","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/e44ad91e9f75f3e3ccbdb85ffe699471f9675e5b","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/e8631b883338ea4c3b5d8ddfbe16407af9f0b4b9","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-72183","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:21:36.640","lastModified":"2026-08-15T06:21:36.640","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nlandlock: Fix LANDLOCK_SCOPE_SIGNAL bypass on the SIGIO path\n\nLANDLOCK_SCOPE_SIGNAL must prevent a sandboxed process from signaling\nprocesses outside its Landlock domain.  It can be bypassed through the\nasynchronous SIGIO delivery path.\n\nA sandboxed process that owns any file or socket can arm it with\nfcntl(fd, F_SETOWN, -pgid), fcntl(fd, F_SETSIG, SIGKILL) and O_ASYNC, so\nthat an I/O event makes the kernel deliver the chosen signal to the\nwhole process group.  As the head of its process group's task list (the\ndefault position right after fork()) that group can also hold the\nnon-sandboxed process that launched it, e.g. a supervisor or a security\nmonitor.  The sandbox can thus kill or signal the processes\nLANDLOCK_SCOPE_SIGNAL is meant to protect from it.\n\nThe scope is enforced in hook_file_send_sigiotask() against the Landlock\ndomain recorded at F_SETOWN time, not the live domain of the sender.\ncontrol_current_fowner() decides whether to record that domain and skips\nrecording it when the fowner target is in the caller's thread group,\nwhich is safe only for a single-task target (PIDTYPE_PID, PIDTYPE_TGID).\nFor a process group (PIDTYPE_PGID) pid_task() returns only one member;\nrecording is skipped whenever that member shares the caller's thread\ngroup, and hook_file_send_sigiotask() then lets the signal fan out to\nthe whole group unchecked.\n\nRecord the domain for every non single-process target so the scope is\nenforced against each group member at delivery time.\n\nThat recording is necessary but not sufficient on its own: the kernel\nsignals a process group through its members' thread-group leaders, and\nthe leader of the registrant's own process can carry a different\nLandlock domain than the sibling thread that armed the owner.\ndomain_is_scoped() would then deny that leader, even though commit\n18eb75f3af40 (\"landlock: Always allow signals between threads of the\nsame process\") requires same-process delivery to be allowed.\nhook_task_kill() avoids this by evaluating same_thread_group() live, per\nrecipient; the SIGIO path instead delegates the whole decision to a\nsingle registration-time check, which a process-group fan-out cannot\nhonor.\n\nSo also record the registrant's thread group next to its domain and\nexempt it at delivery: hook_file_send_sigiotask() allows the signal\nwhenever the recipient belongs to the registrant's own process,\nrestoring the same-process guarantee while keeping out-of-domain group\nmembers blocked.  The direct kill() path (hook_task_kill) already\nevaluates the live domain and is unaffected.\n\n[mic: Check pid_type earlier and improve comment, fix commit message,\nfix comment formatting]"}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["security/landlock/fs.c","security/landlock/fs.h","security/landlock/task.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"332facfa80751b80006c2f95b13c6d208ab0aee1","lessThan":"7a92e9fd1d496a610b40e0c4253fd54e7496f5ab","versionType":"git","status":"affected"},{"version":"18eb75f3af40be1f0fc2025d4ff821711222a2fd","lessThan":"1f18aac2637220b5847d073447498e81ddca10b2","versionType":"git","status":"affected"},{"version":"18eb75f3af40be1f0fc2025d4ff821711222a2fd","lessThan":"04916f7dc6d37cd478b06c86398c34a6963ac8c9","versionType":"git","status":"affected"},{"version":"18eb75f3af40be1f0fc2025d4ff821711222a2fd","lessThan":"4b80320ca7ed03d6e683f95b6066565dc97b9f92","versionType":"git","status":"affected"},{"version":"6861348d863c0eaa4af67492d640a9644a829c59","versionType":"git","status":"affected"},{"version":"0906a9685d7057aea982e970da3e1cf3e5aca68b","versionType":"git","status":"affected"},{"version":"6.12.24","lessThan":"6.12.101","versionType":"semver","status":"affected"},{"version":"6.13.12","lessThan":"6.14","versionType":"semver","status":"affected"},{"version":"6.14.3","lessThan":"6.15","versionType":"semver","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["security/landlock/fs.c","security/landlock/fs.h","security/landlock/task.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.15","status":"affected"},{"version":"0","lessThan":"6.15","versionType":"semver","status":"unaffected"},{"version":"6.12.101","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/04916f7dc6d37cd478b06c86398c34a6963ac8c9","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/1f18aac2637220b5847d073447498e81ddca10b2","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/4b80320ca7ed03d6e683f95b6066565dc97b9f92","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/7a92e9fd1d496a610b40e0c4253fd54e7496f5ab","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-72184","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:21:36.763","lastModified":"2026-08-15T06:21:36.763","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nntfs: fix hole runlist memory leak in insert range error path\n\nntfs_non_resident_attr_insert_range() allocates hole_rl before mapping the\nwhole runlist. If ntfs_attr_map_whole_runlist() fails, the error path drops\nni->runlist.lock and returns without freeing hole_rl. This leaks memory\nof sizeof(*hole_rl) * 2 bytes.\n\nFix this memory leak by freeing hole_rl before returning from\nthat error path, matching the later error paths in the same function."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["fs/ntfs/attrib.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"495e90fa334828d4119061e2726af51d0a0fb4ed","lessThan":"7d7f72cb21a829682f6d8968af4fbe413789d1fd","versionType":"git","status":"affected"},{"version":"495e90fa334828d4119061e2726af51d0a0fb4ed","lessThan":"06769b8f23b4b645b270c438649fff79768fb6fe","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["fs/ntfs/attrib.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"7.1","status":"affected"},{"version":"0","lessThan":"7.1","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc3","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/06769b8f23b4b645b270c438649fff79768fb6fe","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/7d7f72cb21a829682f6d8968af4fbe413789d1fd","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-72185","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:21:36.870","lastModified":"2026-08-15T06:21:36.870","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nntfs: fix WARN_ON for resident attribute in ntfs_map_runlist_nolock()\n\nWhen ntfs_map_runlist_nolock() needs to look up the attribute extent\ncontaining a target VCN (ctx_needs_reset == true), it calls\nntfs_attr_lookup() and then expects the result to be a non-resident\nattribute, since only non-resident attributes have a mapping pairs\narray to decompress.\n\nA crafted NTFS image can place a resident attribute where a non-resident\none is expected, causing ntfs_attr_lookup() to succeed but return a\nresident attribute record.  Previously this was caught only by a\nWARN_ON(), which does not stop execution.  The code then falls through to\nread a->data.non_resident.highest_vcn from what is actually a resident\nattribute, accessing the wrong union member and corrupting the VCN range\ncheck.\n\nThe caller path triggering this warning during mount is:\n\n  ntfs_map_runlist_nolock\n  ntfs_empty_logfile\n  load_system_files\n  ntfs_fill_super\n\nIn this path ctx is NULL, so ntfs_map_runlist_nolock() allocates a\ntemporary search context internally and sets ctx_needs_reset = true.\nThe existing resident-attribute guard in the ctx != NULL branch already\nreturns -EIO silently for the same condition; make the ctx_needs_reset\npath consistent by replacing the WARN_ON() with the same -EIO error\nreturn.\n\nThis causes the crafted image to be rejected with a mount error instead\nof triggering a kernel warning."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["fs/ntfs/attrib.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"495e90fa334828d4119061e2726af51d0a0fb4ed","lessThan":"b397b1238a217264bb02f963a1a1eadf71906375","versionType":"git","status":"affected"},{"version":"495e90fa334828d4119061e2726af51d0a0fb4ed","lessThan":"b8d6c528e9d57d263fee1a648409f84a68b2561d","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["fs/ntfs/attrib.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"7.1","status":"affected"},{"version":"0","lessThan":"7.1","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc3","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/b397b1238a217264bb02f963a1a1eadf71906375","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/b8d6c528e9d57d263fee1a648409f84a68b2561d","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-72186","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:21:36.973","lastModified":"2026-08-15T06:21:36.973","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nntfs: make system files immutable to prevent corruption\n\nWhen a system file such as $Bitmap is exposed via show_sys_files and\nwritten from userspace, the volume is corrupted and, because the cluster\nallocator scans $Bitmap through the same inode's page cache, a write to\n$Bitmap also deadlocks writeback against the folio it already holds locked.\n\nThese files are maintained by the driver itself and have no valid reason\nto be written through the file interface. Mark base metadata files\n(mft_no < FILE_first_user) as immutable during inode read so the VFS\nrejects write, mmap, truncate and unlink with -EPERM. Directories are\nskipped so the root and $Extend remain usable. Internal metadata updates\ndo not go through the VFS write path and are unaffected."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["fs/ntfs/inode.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"af0db57d4293cc9fe6ce99fb5592dc2652228c9d","lessThan":"8f313e92522ac41d273ea137db13ea8a8df2beed","versionType":"git","status":"affected"},{"version":"af0db57d4293cc9fe6ce99fb5592dc2652228c9d","lessThan":"f72df3a4c33b64de3418ec74d1ad4f028e09d161","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["fs/ntfs/inode.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"7.1","status":"affected"},{"version":"0","lessThan":"7.1","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc3","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/8f313e92522ac41d273ea137db13ea8a8df2beed","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/f72df3a4c33b64de3418ec74d1ad4f028e09d161","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-72187","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:21:37.077","lastModified":"2026-08-15T06:21:37.077","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nntfs: avoid self-deadlock during inode eviction\n\nAn attribute-list update performed while allocating clusters can drop the\nlast reference to the temporary attribute inode. Evicting that inode\ndrops its reference to the base inode and can invoke ntfs_drop_big_inode()\nfor the base inode from within the base inode's own writeback path.\n\nIf the base inode is unlinked, ntfs_drop_big_inode() calls\ntruncate_setsize(), which waits for the inode's folio writeback to\ncomplete. The same writeback worker is responsible for completing that\nwriteback, so it waits for itself indefinitely.\n\nPrevent this self-deadlock by grabbing a reference to the base inode at the\nbeginning of ntfs_writepages() and releasing it at the end of the function.\nThis defers eviction until all bios have been submitted, allowing the wait\nfor folio writeback to complete safely."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["fs/ntfs/aops.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"b041ca562526b3c4a71b41b80ba5e520eac636ad","lessThan":"5a5f877c5df7605e9bae524a25ec0df9b9cb8ea8","versionType":"git","status":"affected"},{"version":"b041ca562526b3c4a71b41b80ba5e520eac636ad","lessThan":"77dc384207d5fa63ba97c3bf3285fe1215a1cbf6","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["fs/ntfs/aops.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"7.1","status":"affected"},{"version":"0","lessThan":"7.1","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc3","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/5a5f877c5df7605e9bae524a25ec0df9b9cb8ea8","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/77dc384207d5fa63ba97c3bf3285fe1215a1cbf6","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-72188","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:21:37.197","lastModified":"2026-08-15T06:21:37.197","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nntfs: sanitize MFT references returned from ntfs_lookup_inode_by_name()\n\nntfs_lookup_inode_by_name() returns MFT references read from directory\nindex entries on disk. These values are untrusted, but the function can\ncurrently return an error-marked MFT reference to its callers without\nvalidating it.\n\nCallers later decode lookup failures with MREF_ERR(). A crafted NTFS image\ncan set the MREF error bit while leaving the low bits as an arbitrary\nvalue, causing callers to consume a bogus pseudo-errno instead of treating\nthe lookup result as corrupted on-disk metadata.\n\nFix this at the source by normalizing every error-marked MFT reference\nreturned from ntfs_lookup_inode_by_name() to ERR_MREF(-EIO). Apply this to\nall four directory lookup return paths so every caller gets a validated\nresult without needing additional checks or an API change.\n\nThis keeps the sanitization in the common lookup helper, which is cleaner\nthan duplicating validation in each caller."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["fs/ntfs/dir.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"1e9ea7e04472d4e5e12e58c881eaacfb3e49b669","lessThan":"83f396d881c4fd312c7fd5fff2c157fc21104464","versionType":"git","status":"affected"},{"version":"1e9ea7e04472d4e5e12e58c881eaacfb3e49b669","lessThan":"d97a36bae86a9a4021562ded2987f904e6bcb1d7","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["fs/ntfs/dir.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"7.1","status":"affected"},{"version":"0","lessThan":"7.1","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc3","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/83f396d881c4fd312c7fd5fff2c157fc21104464","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/d97a36bae86a9a4021562ded2987f904e6bcb1d7","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-72189","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:21:37.313","lastModified":"2026-08-15T06:21:37.313","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nntfs: fail attrlist updates when the superblock is inactive\n\ngeneric_shutdown_super() clears SB_ACTIVE before evicting cached inodes.\nIf eviction selects the fake inode for a base inode's unnamed\n$ATTRIBUTE_LIST attribute, ntfs_evict_big_inode() drops the fake inode's\nreference on the base inode while the fake inode is still hashed and marked\nI_FREEING.\n\nThat iput can synchronously write back the base inode. The writeback path\nmay update mapping pairs and call ntfs_attrlist_update(), which\nunconditionally calls ntfs_attr_iget() for the same $ATTRIBUTE_LIST fake\ninode. VFS then finds the I_FREEING inode and waits for eviction to finish,\nbut the current task is still inside that eviction path, causing a\nself-deadlock in find_inode().\n\nFix this by mirroring the teardown guard used by __ntfs_write_inode():\nonce SB_ACTIVE has been cleared, do not try to iget the attribute-list\nfake inode. Return -EIO so teardown aborts the update instead of waiting on\nthe inode it is evicting."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["fs/ntfs/attrlist.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"495e90fa334828d4119061e2726af51d0a0fb4ed","lessThan":"d5379035355c0dcb1e92a2544d40f48441e1d637","versionType":"git","status":"affected"},{"version":"495e90fa334828d4119061e2726af51d0a0fb4ed","lessThan":"0ebe8f625ab0520217a425d7cd366e4670484941","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["fs/ntfs/attrlist.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"7.1","status":"affected"},{"version":"0","lessThan":"7.1","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc3","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/0ebe8f625ab0520217a425d7cd366e4670484941","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/d5379035355c0dcb1e92a2544d40f48441e1d637","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-72190","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:21:37.430","lastModified":"2026-08-15T06:21:37.430","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nntfs: fix mrec_lock ABBA deadlock in rename\n\nntfs_file_fsync(), ntfs_dir_fsync() and __ntfs_write_inode() lock an\ninode's mrec_lock before taking the mrec_lock of its parent directory.\n\nntfs_rename() takes old_ni->mrec_lock and old_dir_ni->mrec_lock\nbefore taking new_ni->mrec_lock for an existing target, or\nnew_dir_ni->mrec_lock for a cross-directory rename.\nThis can deadlock when ntfs_file_fsync() or __ntfs_write_inode() holds\nthe target inode, or when ntfs_dir_fsync() holds a child target\ndirectory, while rename() holds the parent directory and waits for the\ntarget.\n\nFix this by locking the existing target inode before taking any parent\ndirectory mrec_lock. For cross-directory renames where the target parent\nis a descendant of the source parent, lock the target parent before the\nsource parent so the directory order matches the child-to-parent order used\nby ntfs_file_fsync(), ntfs_dir_fsync(), and __ntfs_write_inode()."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["fs/ntfs/namei.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"af0db57d4293cc9fe6ce99fb5592dc2652228c9d","lessThan":"b3d09502b80dfe0bab9090ca532710da389f6c7f","versionType":"git","status":"affected"},{"version":"af0db57d4293cc9fe6ce99fb5592dc2652228c9d","lessThan":"eb94f5a41a193a425e09a63cb75dffd151d8f42e","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["fs/ntfs/namei.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"7.1","status":"affected"},{"version":"0","lessThan":"7.1","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc3","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/b3d09502b80dfe0bab9090ca532710da389f6c7f","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/eb94f5a41a193a425e09a63cb75dffd151d8f42e","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-72191","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:21:37.537","lastModified":"2026-08-15T06:21:37.537","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nntfs3: validate split-point offset in indx_insert_into_buffer\n\nindx_insert_into_buffer() computes\n\n    used = used1 - to_copy - sp_size;\n    memmove(de_t, Add2Ptr(sp, sp_size), used - le32_to_cpu(hdr1->de_off));\n\nwhere sp and sp_size come from hdr_find_split().  hdr_find_split()\nwalks entries by le16_to_cpu(e->size) without validating that each\nstep stays within hdr->used or that the size field is at least\nsizeof(struct NTFS_DE).  index_hdr_check(), the on-load gatekeeper,\nonly validates header-level fields (used, total, de_off) and does\nnot walk per-entry sizes.\n\nA crafted NTFS image whose leaf INDEX_HDR reports used == total but\ncontains one interior NTFS_DE with size = 0xFFF0 therefore passes\nvalidation, descends to indx_insert_into_buffer() through the\nntfs_create() -> indx_insert_entry() path, and makes hdr_find_split()\nreturn an sp whose sp_size (0xFFF0) greatly exceeds the remaining\nbytes in the buffer.  The u32 subtraction underflows and the memmove\ncount becomes a near-4-GiB value, producing an out-of-bounds kernel\nwrite that corrupts adjacent allocations and panics the kernel.\n\nReproduced on 7.0.0-rc7 with UML + KASAN via a crafted image and a\nsingle 'touch' inside the mounted directory; crash site resolves to\nfs/ntfs3/index.c at the memmove.  Trigger requires only local mount\nof an attacker-supplied filesystem image (USB, loopback, or removable\nmedia auto-mount).\n\nReject the split whenever the chosen sp plus its declared size\nalready extends past hdr1->used.  This is the minimal fix; it\npreserves the existing hdr_find_split() contract and relies on the\nsame out: cleanup path as the pre-existing error returns.\n\nA prior OOB read in the very same indx_insert_into_buffer() memmove\nwas fixed in commit b8c44949044e (\"fs/ntfs3: Fix OOB read in\nindx_insert_into_buffer\") by tightening hdr_find_e(), but that fix\ndoes not cover the split-point size field path addressed here: sp is\nreturned by hdr_find_split(), not hdr_find_e(), and the underflow is\ndriven by sp->size rather than hdr->used exceeding hdr->total."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["fs/ntfs3/index.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"82cae269cfa953032fbb8980a7d554d60fb00b17","lessThan":"b232eb5c9fe11ec2368e9b565db69c724c35fbd2","versionType":"git","status":"affected"},{"version":"82cae269cfa953032fbb8980a7d554d60fb00b17","lessThan":"7bf74e6baf810fe325f111996496c678fc6e244f","versionType":"git","status":"affected"},{"version":"82cae269cfa953032fbb8980a7d554d60fb00b17","lessThan":"f3624cc069195001c88df7a291af215f2133ff2c","versionType":"git","status":"affected"},{"version":"82cae269cfa953032fbb8980a7d554d60fb00b17","lessThan":"1758a564b6ebe7f4a82f23c9851d1cae15549457","versionType":"git","status":"affected"},{"version":"82cae269cfa953032fbb8980a7d554d60fb00b17","lessThan":"f1df9d771df47aa40de6d70949c28720ae1e430d","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["fs/ntfs3/index.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"5.15","status":"affected"},{"version":"0","lessThan":"5.15","versionType":"semver","status":"unaffected"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.97","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/1758a564b6ebe7f4a82f23c9851d1cae15549457","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/7bf74e6baf810fe325f111996496c678fc6e244f","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/b232eb5c9fe11ec2368e9b565db69c724c35fbd2","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/f1df9d771df47aa40de6d70949c28720ae1e430d","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/f3624cc069195001c88df7a291af215f2133ff2c","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-72192","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:21:37.663","lastModified":"2026-08-15T06:21:37.663","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nntfs3: bound to_move in indx_insert_into_root before hdr_insert_head\n\nindx_insert_into_root() promotes a full resident $INDEX_ROOT into\n$INDEX_ALLOCATION and copies all non-last resident root entries into\na newly allocated INDEX_BUFFER via hdr_insert_head(). The source\nbyte count 'to_move' is summed from the on-disk resident entry sizes\nand is independent of the destination buffer size, which comes from\nroot->index_block_size (via indx->index_bits).\n\nA crafted NTFS image that keeps a valid, full resident root but\nshrinks root->index_block_size down to 512 after the root has been\npopulated makes hdr_insert_head() memcpy attacker-controlled resident\nentry bytes past the end of the kmalloc(1u << indx->index_bits)\nallocation returned by indx_new(). For a 512-byte destination and a\nresident root whose non-last entries total 560 bytes, the memcpy\noverruns by 120 bytes and a following memmove extends the highest\nwritten offset to 136 bytes past the allocation. The overflow bytes\nare a direct copy of on-disk entries (via kmemdup), so they are\nfully attacker-controlled.\n\nThe write is reachable from unprivileged open(O_CREAT) on a mounted\ncrafted NTFS image: a single sufficiently long create in a directory\nwhose resident root is already full forces root promotion and\ntriggers the copy.\n\nThis is a controlled out-of-bounds write of 120-136 bytes past a\nkmalloc(index_block_size) allocation, with attacker-controlled\ncontent. It is a bounded adjacent-heap corruption primitive; it is\nnot an arbitrary-address write. Successful exploitation into a named\nvictim object depends on the surrounding slab layout.\n\nReject the copy at the sink. The destination's INDEX_HDR already\nreports hdr_total (the payload capacity of the new buffer) and\nhdr_used (the bytes already consumed by the terminal END entry\ninstalled by indx_new()); require that to_move fits in the remaining\npayload before calling hdr_insert_head(). On mismatch, fail with\n-EINVAL and mark the filesystem as having a detected on-disk\ninconsistency, which is the same behaviour as the surrounding\nvalidation in this function."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["fs/ntfs3/index.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"82cae269cfa953032fbb8980a7d554d60fb00b17","lessThan":"0af83b8155cc848e9f5d2c36e20a70d024214649","versionType":"git","status":"affected"},{"version":"82cae269cfa953032fbb8980a7d554d60fb00b17","lessThan":"cb3161deebcaf8d36d3115abf452c633f2180fc1","versionType":"git","status":"affected"},{"version":"82cae269cfa953032fbb8980a7d554d60fb00b17","lessThan":"53c5f3b2da3774b41534728aba295c098c9efa19","versionType":"git","status":"affected"},{"version":"82cae269cfa953032fbb8980a7d554d60fb00b17","lessThan":"194b00c99ba971fa7cf6acd747a36032c6de54eb","versionType":"git","status":"affected"},{"version":"82cae269cfa953032fbb8980a7d554d60fb00b17","lessThan":"aaa1f956c0fc41089a4a534da7df91552a08a47c","versionType":"git","status":"affected"},{"version":"82cae269cfa953032fbb8980a7d554d60fb00b17","lessThan":"d240f5f9d036b8180224954d9873f172b6be4dd8","versionType":"git","status":"affected"},{"version":"82cae269cfa953032fbb8980a7d554d60fb00b17","lessThan":"9b6926ac9c970ae0b2c2fe6289b16e9aa10b6a67","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["fs/ntfs3/index.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"5.15","status":"affected"},{"version":"0","lessThan":"5.15","versionType":"semver","status":"unaffected"},{"version":"5.15.212","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.178","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.97","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/0af83b8155cc848e9f5d2c36e20a70d024214649","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/194b00c99ba971fa7cf6acd747a36032c6de54eb","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/53c5f3b2da3774b41534728aba295c098c9efa19","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/9b6926ac9c970ae0b2c2fe6289b16e9aa10b6a67","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/aaa1f956c0fc41089a4a534da7df91552a08a47c","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/cb3161deebcaf8d36d3115abf452c633f2180fc1","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/d240f5f9d036b8180224954d9873f172b6be4dd8","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-72193","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:21:37.797","lastModified":"2026-08-15T06:21:37.797","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nntfs3: cap RESTART_TABLE free-chain walker at rt->used\n\nA crafted NTFS3 disk image triggers an in-kernel infinite loop at\nmount time, hanging the mounting thread and firing the soft-lockup\nwatchdog within ~22s on multi-CPU hosts (panic with\nkernel.softlockup_panic=1).  The bug is reachable from desktop USB\nauto-mount on distributions where udisks2 routes the NTFS signature\nto the in-tree ntfs3 driver (Arch family and an increasing fraction\nof Fedora / openSUSE / RHEL deployments); CAP_SYS_ADMIN-class manual\nmount elsewhere.\n\ncheck_rstbl()'s second walker iterates the free-entry singly-linked\nlist headed by rt->first_free with no upper bound on iteration count:\n\n  for (off = ff; off;) {\n      if (off == RESTART_ENTRY_ALLOCATED)\n          return false;\n      off = le32_to_cpu(*(__le32 *)Add2Ptr(rt, off));\n      if (off > ts - sizeof(__le32))\n          return false;\n  }\n\nThe existing guards cover three exits: end-of-list (off == 0), the\nin-use marker (off == RESTART_ENTRY_ALLOCATED), and out-of-bounds\n(off > ts - sizeof(__le32)).  None of the three prevents an\nin-bounds cycle.\n\nA crafted on-disk RESTART_TABLE whose free chain contains a\nself-loop or A->B->A cycle whose offsets satisfy:\n\n  - in range [sizeof(struct RESTART_TABLE), ts - sizeof(__le32)]\n  - (off - sizeof(struct RESTART_TABLE)) % rsize == 0\n\npasses all existing guards and spins the mount-time thread forever.\nReproduced in UML by hand-forging a 2 MB NTFS3 image whose journal\nRESTART_TABLE first_free = 0x18 and whose entry at offset 0x18\nstores 0x18 as its next pointer; mount of the forged image with\nthe in-tree ntfs3 driver never returns.\n\nBound the walker by rt->used.  Each entry on a legitimate free\nchain is unique, and the total slot count is ne = le16_to_cpu\n(rt->used).  A traversal that visits more than ne slots is by\nconstruction malformed; reject it as a corrupt RESTART_TABLE.\n\nAfter this patch, mount of the forged image returns with -EINVAL\nand a log_replay failure message, and mkntfs-produced legitimate\nimages mount cleanly (verified in the same UML harness)."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["fs/ntfs3/fslog.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"b46acd6a6a627d876898e1c84d3f84902264b445","lessThan":"8128bec895075253c779d67afdc90ae513265fca","versionType":"git","status":"affected"},{"version":"b46acd6a6a627d876898e1c84d3f84902264b445","lessThan":"7972df425687daa70d971fe6ed415e78683133dd","versionType":"git","status":"affected"},{"version":"b46acd6a6a627d876898e1c84d3f84902264b445","lessThan":"7ac4c86915c24c208a0f0611b71d9676686fe756","versionType":"git","status":"affected"},{"version":"b46acd6a6a627d876898e1c84d3f84902264b445","lessThan":"29b86dbe88cbbef53bb9aaec2e279359f8c450f8","versionType":"git","status":"affected"},{"version":"b46acd6a6a627d876898e1c84d3f84902264b445","lessThan":"0fad25687d4d3fa1fdd313d31b9cb5817c425029","versionType":"git","status":"affected"},{"version":"b46acd6a6a627d876898e1c84d3f84902264b445","lessThan":"d313416280d41bea272f02a6034dfa88008692a0","versionType":"git","status":"affected"},{"version":"b46acd6a6a627d876898e1c84d3f84902264b445","lessThan":"9611f644302c07d21bc8af97e3e06a3d30064253","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["fs/ntfs3/fslog.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"5.15","status":"affected"},{"version":"0","lessThan":"5.15","versionType":"semver","status":"unaffected"},{"version":"5.15.212","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.178","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.97","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/0fad25687d4d3fa1fdd313d31b9cb5817c425029","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/29b86dbe88cbbef53bb9aaec2e279359f8c450f8","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/7972df425687daa70d971fe6ed415e78683133dd","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/7ac4c86915c24c208a0f0611b71d9676686fe756","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/8128bec895075253c779d67afdc90ae513265fca","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/9611f644302c07d21bc8af97e3e06a3d30064253","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/d313416280d41bea272f02a6034dfa88008692a0","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-72194","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:21:37.943","lastModified":"2026-08-15T06:21:37.943","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nfs/ntfs3: add depth limit to indx_find_buffer to prevent stack overflow\n\nindx_find_buffer() recursively descends the B+ tree index with no depth\nlimit.  A crafted NTFS image with circular index node references causes\nunbounded recursion, overflowing the kernel stack and panicking the\nsystem.\n\nThis is reachable by mounting a malicious NTFS filesystem (e.g. from a\nUSB drive via desktop automount) and deleting a file whose index entry\ntriggers the rebalancing fallback path in indx_delete_entry().\n\nAdd a depth parameter and bail out with -EINVAL when it reaches the\nfnd->nodes array bound, matching the constraint already enforced by\nfnd_push() in indx_find().\n\nThe related function indx_find() was previously patched for a similar\ninfinite-loop issue (commit 1732053c8a6b), but indx_find_buffer() was\nmissed."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["fs/ntfs3/index.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"82cae269cfa953032fbb8980a7d554d60fb00b17","lessThan":"99031d4f63c785d2a985b6a4c64c4256f7117052","versionType":"git","status":"affected"},{"version":"82cae269cfa953032fbb8980a7d554d60fb00b17","lessThan":"65357a81f64cb3fbe13b4b937586755e4b3a072f","versionType":"git","status":"affected"},{"version":"82cae269cfa953032fbb8980a7d554d60fb00b17","lessThan":"96fb64f9da86fd2dbd78fbe9d9e41ae27e12ce34","versionType":"git","status":"affected"},{"version":"82cae269cfa953032fbb8980a7d554d60fb00b17","lessThan":"78612f478f9fadcec4f9b3b089970da67ffb47e9","versionType":"git","status":"affected"},{"version":"82cae269cfa953032fbb8980a7d554d60fb00b17","lessThan":"908c9243ba309997b73cbda3e4c563d0fb345ee9","versionType":"git","status":"affected"},{"version":"82cae269cfa953032fbb8980a7d554d60fb00b17","lessThan":"fdf50c788e0991e42a187ff75479a0df7fb752f1","versionType":"git","status":"affected"},{"version":"82cae269cfa953032fbb8980a7d554d60fb00b17","lessThan":"1ebd684b8f627f75bc3e03f8b2ad8400fd1f02cd","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["fs/ntfs3/index.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"5.15","status":"affected"},{"version":"0","lessThan":"5.15","versionType":"semver","status":"unaffected"},{"version":"5.15.212","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.178","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.97","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/1ebd684b8f627f75bc3e03f8b2ad8400fd1f02cd","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/65357a81f64cb3fbe13b4b937586755e4b3a072f","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/78612f478f9fadcec4f9b3b089970da67ffb47e9","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/908c9243ba309997b73cbda3e4c563d0fb345ee9","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/96fb64f9da86fd2dbd78fbe9d9e41ae27e12ce34","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/99031d4f63c785d2a985b6a4c64c4256f7117052","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/fdf50c788e0991e42a187ff75479a0df7fb752f1","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-72195","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:21:38.077","lastModified":"2026-08-15T06:21:38.077","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nfs/ntfs3: bound attr_off in UpdateResidentValue against data_off\n\nIn do_action()'s UpdateResidentValue case (fslog.c:3307),\nlrh->attr_off and lrh->redo_len come from the on-disk LRH.\nWhen they satisfy aoff + dlen < attr->res.data_off, the\nassignment\n\n\tattr->res.data_size = cpu_to_le32(aoff + dlen - data_off);\n\nunderflows to ~4 GiB (e.g. 0xFFFFFFF9 when aoff=0x10, dlen=1,\ndata_off=0x18).  Subsequent code that reads attr->res.data_size\nto walk the resident attribute payload would then read up to\n4 GiB past the 1024-byte MFT record allocation.\n\nThe existing mi_enum_attr() defense in fs/ntfs3/record.c:287\ncatches the corrupted data_size on the next attribute walk\nand fails the mount, but only on the path that walks all\nattributes.  A read site that picks an attribute by name and\nreads its data_size without re-validating is not covered.\nValidate aoff against data_off and asize at the source.\n\nReproduced under UML+KASAN on mainline 8d90b09e6741 via\npr_warn-only probe: with aoff=0x10 and data_off=0x18, the\npost-assignment data_size is 0xfffffff9 (mount then fails\nat -22 from mi_enum_attr).\n\n[almaz.alexandrovich@paragon-software.com: clang-formatted the changes]"}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["fs/ntfs3/fslog.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"b46acd6a6a627d876898e1c84d3f84902264b445","lessThan":"ab8761676d638c5be170aaf91b7ffdd451236616","versionType":"git","status":"affected"},{"version":"b46acd6a6a627d876898e1c84d3f84902264b445","lessThan":"53c12f178f584dc5f836ffe2782138a6e9348ed9","versionType":"git","status":"affected"},{"version":"b46acd6a6a627d876898e1c84d3f84902264b445","lessThan":"546518468e6c9ea469669eef78f8cc380ad6e2ca","versionType":"git","status":"affected"},{"version":"b46acd6a6a627d876898e1c84d3f84902264b445","lessThan":"97758fd9756b5f09e9ddc6a5f6a569041acc8421","versionType":"git","status":"affected"},{"version":"b46acd6a6a627d876898e1c84d3f84902264b445","lessThan":"50b5e83384e7fed3d11d18b79ff350e9d6d89861","versionType":"git","status":"affected"},{"version":"b46acd6a6a627d876898e1c84d3f84902264b445","lessThan":"a89c66674283a0293c0f266dc57087a6114371a3","versionType":"git","status":"affected"},{"version":"b46acd6a6a627d876898e1c84d3f84902264b445","lessThan":"d1570c48f49a693974d000251030370ee2e83539","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["fs/ntfs3/fslog.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"5.15","status":"affected"},{"version":"0","lessThan":"5.15","versionType":"semver","status":"unaffected"},{"version":"5.15.212","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.178","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.97","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/50b5e83384e7fed3d11d18b79ff350e9d6d89861","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/53c12f178f584dc5f836ffe2782138a6e9348ed9","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/546518468e6c9ea469669eef78f8cc380ad6e2ca","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/97758fd9756b5f09e9ddc6a5f6a569041acc8421","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/a89c66674283a0293c0f266dc57087a6114371a3","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/ab8761676d638c5be170aaf91b7ffdd451236616","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/d1570c48f49a693974d000251030370ee2e83539","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-72196","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:21:38.200","lastModified":"2026-08-15T06:21:38.200","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nfs/ntfs3: bound copy_lcns dp->page_lcns[] index in analysis pass\n\nIn log_replay()'s analysis pass, after find_dp() returns a\nvalid DIR_PAGE_ENTRY for the (target_attr, target_vcn) tuple,\nthe copy_lcns block walks lrh->lcns_follow further entries:\n\n\tt16 = le16_to_cpu(lrh->lcns_follow);\n\tfor (i = 0; i < t16; i++) {\n\t    size_t j = (size_t)(le64_to_cpu(lrh->target_vcn) -\n\t                        le64_to_cpu(dp->vcn));\n\t    dp->page_lcns[j + i] = lrh->page_lcns[i];\n\t}\n\nfind_dp() only validates that target_vcn falls within\n[dp->vcn, dp->vcn + dp->lcns_follow), i.e., that the FIRST\ncluster is covered.  The walk through the further entries is\nnot bounded against dp->lcns_follow.  For a malformed LRH\nwhere target_vcn = dp->vcn + dp->lcns_follow - 1 and\nlrh->lcns_follow > 1, the i > 0 writes overflow the dp's\nallocated page_lcns[] array.\n\nAdd the missing j + lrh->lcns_follow <= dp->lcns_follow guard.\n\nReproduced under UML+KASAN on mainline 8d90b09e6741 as a\nslab-out-of-bounds write of size 8 from log_replay+0x68d4 on\nthe mount path.\n\nThis is distinct from Pavitra Jha's 2026-05-02 patch\n(\"fs/ntfs3: validate lcns_follow in log_replay conversion\",\n<20260502154252.164586-1-jhapavitra98@gmail.com>) which\naddresses the separate version-0 dirty-page-table conversion\npath's memmove(&dp->vcn, ...) call.  The two fixes are\ncomplementary; both should land.\n\n[almaz.alexandrovich@paragon-software.com: clang-formatted the changes,\nfixed conflicts]"}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["fs/ntfs3/fslog.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"b46acd6a6a627d876898e1c84d3f84902264b445","lessThan":"9b3d8cc9d54fcded4de51b2b1026ae7182512077","versionType":"git","status":"affected"},{"version":"b46acd6a6a627d876898e1c84d3f84902264b445","lessThan":"9b7c28d8c61bdb041936222a09a708531a1c2921","versionType":"git","status":"affected"},{"version":"b46acd6a6a627d876898e1c84d3f84902264b445","lessThan":"0f13e823bf86bd1800168ea0bb5bca8b8500a81c","versionType":"git","status":"affected"},{"version":"b46acd6a6a627d876898e1c84d3f84902264b445","lessThan":"d240cd98f5f7b65c90f6b2b6abe3232ccdc405ab","versionType":"git","status":"affected"},{"version":"b46acd6a6a627d876898e1c84d3f84902264b445","lessThan":"49c86dae0c0ccb8d98ddcdc46987259389c816dd","versionType":"git","status":"affected"},{"version":"b46acd6a6a627d876898e1c84d3f84902264b445","lessThan":"5e7b598660cfa8e5af172cf4c65cffc126333307","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["fs/ntfs3/fslog.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"5.15","status":"affected"},{"version":"0","lessThan":"5.15","versionType":"semver","status":"unaffected"},{"version":"6.1.178","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.97","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/0f13e823bf86bd1800168ea0bb5bca8b8500a81c","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/49c86dae0c0ccb8d98ddcdc46987259389c816dd","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/5e7b598660cfa8e5af172cf4c65cffc126333307","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/9b3d8cc9d54fcded4de51b2b1026ae7182512077","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/9b7c28d8c61bdb041936222a09a708531a1c2921","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/d240cd98f5f7b65c90f6b2b6abe3232ccdc405ab","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-72197","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:21:38.323","lastModified":"2026-08-15T06:21:38.323","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nfs/ntfs3: bound DeleteIndexEntryAllocation memmove length\n\nIn do_action()'s DeleteIndexEntryAllocation case, e->size comes\nfrom an on-disk INDEX_BUFFER entry.  When e->size makes\ne + e->size point past hdr + hdr->used,\nPtrOffset(e1, Add2Ptr(hdr, used)) returns a negative ptrdiff_t\nthat is silently cast to a quasi-infinite size_t when passed\nto memmove().  The memmove then walks past the destination\nbuffer.\n\nThe sibling DeleteIndexEntryRoot case at fslog.c:3540-3543\nalready carries the corresponding guard:\n\n\tif (PtrOffset(e1, Add2Ptr(hdr, used)) < esize ||\n\t    Add2Ptr(e, esize) > Add2Ptr(lrh, rec_len) ||\n\t    used + esize > le32_to_cpu(hdr->total)) {\n\t\tgoto dirty_vol;\n\t}\n\nApply the same shape to the allocation-path case.  Also reject\nesize == 0: memmove(e, e, ...) is a no-op and leaves\nhdr->used unchanged, hiding a malformed entry from the\nexisting check_index_header() walk.\n\nReproduced under UML+KASAN on mainline 8d90b09e6741 by\nmounting a crafted NTFS image: the unguarded memmove takes a\nlength of 0xffffffffffffff00 and the kernel oopses in\nmemmove+0x81/0x1a0 on the do_action+0x36a2 frame.\n\n[almaz.alexandrovich@paragon-software.com: clang-formatted the changes]"}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["fs/ntfs3/fslog.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"b46acd6a6a627d876898e1c84d3f84902264b445","lessThan":"c38ed2ab62fab75fd6d0fdc2bee540fbebc7b959","versionType":"git","status":"affected"},{"version":"b46acd6a6a627d876898e1c84d3f84902264b445","lessThan":"b509b9613f20dc5b653d54bf78fab00d79cc43c8","versionType":"git","status":"affected"},{"version":"b46acd6a6a627d876898e1c84d3f84902264b445","lessThan":"4c8aac931c1cd70347961ba5157aa916448c6a25","versionType":"git","status":"affected"},{"version":"b46acd6a6a627d876898e1c84d3f84902264b445","lessThan":"f383aae59ec3994c14804f4191c59038b206be81","versionType":"git","status":"affected"},{"version":"b46acd6a6a627d876898e1c84d3f84902264b445","lessThan":"09fddd52c1b0cef2c086d61be8f3d5dc92e36565","versionType":"git","status":"affected"},{"version":"b46acd6a6a627d876898e1c84d3f84902264b445","lessThan":"554700c65d398276cb00a8ef95f1d5e00b9eff93","versionType":"git","status":"affected"},{"version":"b46acd6a6a627d876898e1c84d3f84902264b445","lessThan":"fc4626bb3656362de8b0ecd56605d47a19ec3518","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["fs/ntfs3/fslog.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"5.15","status":"affected"},{"version":"0","lessThan":"5.15","versionType":"semver","status":"unaffected"},{"version":"5.15.212","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.178","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.97","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/09fddd52c1b0cef2c086d61be8f3d5dc92e36565","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/4c8aac931c1cd70347961ba5157aa916448c6a25","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/554700c65d398276cb00a8ef95f1d5e00b9eff93","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/b509b9613f20dc5b653d54bf78fab00d79cc43c8","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/c38ed2ab62fab75fd6d0fdc2bee540fbebc7b959","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/f383aae59ec3994c14804f4191c59038b206be81","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/fc4626bb3656362de8b0ecd56605d47a19ec3518","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-72198","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:21:38.440","lastModified":"2026-08-15T06:21:38.440","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nntfs: reject non-resident records for resident-only attributes\n\nThe shared lookup-time attribute validator rejects non-resident\n$FILE_NAME and $VOLUME_NAME records because their formats require\nresident values and callers handle returned records as resident\nattributes. Other resident-only attribute types still pass through the\ngeneric non-resident mapping-pairs checks.\n\nThat leaves real resident/non-resident union confusion paths. Inode load\nlooks up $STANDARD_INFORMATION and then reads data.resident.value_offset\nwithout checking a->non_resident. ntfs_inode_sync_standard_information()\ndoes the same when updating the standard information value.\nntfs_write_volume_flags() also looks up $VOLUME_INFORMATION and reads\ndata.resident.value_offset directly. $INDEX_ROOT callers in dir.c and\nindex.c depend on the same lookup contract before consuming the resident\nindex root value.\n\nReject non-resident records for all resident-only attribute types in the\nshared validator. Keep the existing $FILE_NAME and $VOLUME_NAME behavior,\nbut factor it through a helper and extend it to\n$STANDARD_INFORMATION, $OBJECT_ID, $VOLUME_INFORMATION, $INDEX_ROOT, and\n$EA_INFORMATION. For $OBJECT_ID and $EA_INFORMATION this is contract\nhardening for resident-only formats; this patch only rejects the\nnon-resident form and does not add new resident value validation for\nthose types."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["fs/ntfs/attrib.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"b54c9beb90e570bae17a9c18442aeeaf17165ccb","versionType":"git","status":"affected"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"097cdfd0a55df5af82c9753833f39a8bfadbcfcb","versionType":"git","status":"affected"},{"version":"0","lessThan":"7.1.5","versionType":"semver","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["fs/ntfs/attrib.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/097cdfd0a55df5af82c9753833f39a8bfadbcfcb","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/b54c9beb90e570bae17a9c18442aeeaf17165ccb","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-72199","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:21:38.533","lastModified":"2026-08-15T06:21:38.533","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nntfs: validate resident index root values on lookup\n\nResident $INDEX_ROOT values carry index header fields that callers\nconsume after lookup. Some callers already validate parts of the layout\nbefore walking entries, but those checks are scattered and do not cover\nall root header invariants, such as entries_offset alignment and lower\nbound, index_length, and allocated_size consistency.\n\nThe resident root resize paths now keep these header fields consistent\nwhile the value size changes: ntfs_ir_truncate() lowers\nindex.allocated_size before shrinking the resident value, and\nntfs_ir_reparent() grows the resident value before publishing a larger\nroot header. Lookup-time validation can therefore cover these invariants\nwithout tripping over the driver's own resize paths.\n\nAdd $INDEX_ROOT to the minimum resident value size table and validate the\nresident index header fields before returning the attribute from lookup.\nRequire 8-byte aligned index header fields, a sane entries_offset, an\nindex_length within allocated_size, allocated_size within the resident\nvalue, and enough entry space for at least an index entry header.\n\nThe shared validator already rejects non-resident records for\nresident-only attribute types, including $INDEX_ROOT."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["fs/ntfs/attrib.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"bfb01dd319b6b4c3e79756de7b75ccf0b9a0a247","versionType":"git","status":"affected"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"fcf5bf0e8570798970e3ae8c95d04765ba2c5b97","versionType":"git","status":"affected"},{"version":"0","lessThan":"7.1.5","versionType":"semver","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["fs/ntfs/attrib.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/bfb01dd319b6b4c3e79756de7b75ccf0b9a0a247","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/fcf5bf0e8570798970e3ae8c95d04765ba2c5b97","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-72200","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:21:38.640","lastModified":"2026-08-15T06:21:38.640","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nntfs: detect mapping-pairs LCN accumulator overflow\n\nThe NTFS mapping-pairs parser accumulates relative LCN deltas in a\nsigned integer.  A corrupted attribute can drive that addition past\nthe representable range.\n\nOne corrupt runlist shape sets the accumulated LCN to S64_MAX and\nthen adds a delta of 1 in the next mapping-pairs entry.\n\nSigned overflow is undefined and can turn an invalid runlist into a\ndifferent set of physical clusters.\n\nCheck the LCN addition for overflow before storing the next run."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["fs/ntfs/runlist.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"7fb64788812d137b37f6d8724e1e41c624c1e814","versionType":"git","status":"affected"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"ec4f061f2219e0f0c6465d56d0380bf749235a53","versionType":"git","status":"affected"},{"version":"0","lessThan":"7.1.5","versionType":"semver","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["fs/ntfs/runlist.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/7fb64788812d137b37f6d8724e1e41c624c1e814","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/ec4f061f2219e0f0c6465d56d0380bf749235a53","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-72201","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:21:38.747","lastModified":"2026-08-15T06:21:38.747","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nntfs: validate index entries on reading\n\nValidate index entries immediately after reading an index root or index\nblock from disk. This eliminates repeated checks in lookup and readdir,\nand reduce the risk of missing checks in those paths."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["fs/ntfs/dir.c","fs/ntfs/index.c","fs/ntfs/index.h","fs/ntfs/inode.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"e2b95d3adb558ddd5685f9e072ec8661d57ee3a9","versionType":"git","status":"affected"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"2221b691d7b2e17f08153f95848dacaa5d87e21d","versionType":"git","status":"affected"},{"version":"0","lessThan":"7.1.5","versionType":"semver","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["fs/ntfs/dir.c","fs/ntfs/index.c","fs/ntfs/index.h","fs/ntfs/inode.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/2221b691d7b2e17f08153f95848dacaa5d87e21d","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/e2b95d3adb558ddd5685f9e072ec8661d57ee3a9","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-72202","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:21:38.860","lastModified":"2026-08-15T06:21:38.860","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nntfs: avoid heap allocation for free-cluster readahead state\n\nget_nr_free_clusters() allocates a temporary file_ra_state before it\npublishes the precomputed free cluster count, sets NVolFreeClusterKnown(),\nand wakes vol->free_waitq. If that allocation fails, the worker returns\nwithout setting the flag or waking waiters, so callers waiting for the free\ncount can block indefinitely.\n\nThe readahead state is only used synchronously while scanning the bitmap.\nKeep it on the stack and pass it by address to the readahead helper. This\neliminates the early allocation failure path instead of adding a special\ncase that publishes a conservative count and wakes the waitqueue.\nZero-initialize the on-stack state because file_ra_state_init() only sets\nra_pages and prev_pos.\n\nApply the same treatment to __get_nr_free_mft_records(), which scans the\nMFT bitmap with the same short-lived readahead state."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["fs/ntfs/super.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"40ee64e633e5e413f2255bb48c063977d8c86f34","versionType":"git","status":"affected"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"c05132077df57a384919f61d7f8a8e76d748a6d4","versionType":"git","status":"affected"},{"version":"0","lessThan":"7.1.5","versionType":"semver","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["fs/ntfs/super.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/40ee64e633e5e413f2255bb48c063977d8c86f34","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/c05132077df57a384919f61d7f8a8e76d748a6d4","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-72203","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:21:38.970","lastModified":"2026-08-15T06:21:38.970","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nntfs: skip extent mft records in writeback to prevent deadlock\n\nThis patch fixes the ABBA deadlock between extent_lock and extent\nmrec_lock triggered by xfstests generic/113, that occurs since the commit\n6994acf33bae (\"ntfs: use base mft_no when looking up base inode for\n\t\textent record\").\n\nPath A (inode writeback):\n  VFS writeback\n    -> ntfs_write_inode()\n      -> __ntfs_write_inode()\n        -> mutex_lock(&ni->extent_lock)\n        -> mutex_lock(&tni->mrec_lock)\n\nPath B (MFT folio writeback):\n  VFS writeback of $MFT dirty folios\n    -> ntfs_mft_writepages()\n      -> ntfs_write_mft_block()\n        -> ntfs_may_write_mft_record()\n          -> holds one extent mrec_lock from a previous iteration\n          -> tries to acquire another base inode extent_lock\n\nBy removing all extent_lock and extent mrec_lock acquisition from the MFT\nfolio writeback path, the ABBA lock ordering is eliminated:\n\nPath A: __ntfs_write_inode(): extent_lock -> mrec_lock\nPath B (removed): ntfs_write_mft_block(): mrec_lock -> extent_lock\n\nPath B is always redundant for extent records because:\n\n1. mark_mft_record_dirty(ext_ni) does NOT dirty the MFT folio.\n   It only sets NInoDirty(ext_ni) and marks the base VFS inode dirty\n   via __mark_inode_dirty(I_DIRTY_DATASYNC), which triggers Path A.\n   Therefore, normal extent modifications never create a situation where\n   the MFT folio is dirty and Path B is not scheduled.\n\n2. The MFT folio only gets dirtied via ntfs_mft_mark_dirty() inside\n   ntfs_mft_record_alloc(). But all identified callers in attrib.c\n   (ntfs_attr_add, ntfs_attr_record_move_away,\n   ntfs_attr_make_non_resident, ntfs_attr_record_resize) follow through\n   with mark_mft_record_dirty(), which triggers Path A to write the\n   complete record.\n\n3. ntfs_evict_big_inode() calls ntfs_commit_inode() before freeing extent\n   inodes, ensuring all dirty extents are flushed via Path A before the\n   base inode leaves the icache."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["fs/ntfs/mft.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"f831ab09d521898bf1dd99bf5adfd630ea1428e3","versionType":"git","status":"affected"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"76bc14c7097ff678b2b5dbfd4fa33b46897d87ce","versionType":"git","status":"affected"},{"version":"0","lessThan":"7.1.5","versionType":"semver","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["fs/ntfs/mft.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/76bc14c7097ff678b2b5dbfd4fa33b46897d87ce","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/f831ab09d521898bf1dd99bf5adfd630ea1428e3","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-72204","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:21:39.090","lastModified":"2026-08-15T06:21:39.090","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nntfs: centalize $INDEX_ROOT header validation\n\nAdd a dedicated helper to perform stricter validation of $INDEX_ROOT and\nuse it for both directory inodes and named index inodes. This keeps the\nroot size and header geometry checks consistent across both read paths."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["fs/ntfs/index.c","fs/ntfs/index.h","fs/ntfs/inode.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"b06730c6af58d3569883f8dd7c36a90aba5ecc0a","versionType":"git","status":"affected"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"8b97b302f553a480fb76d2afd53cd6c0635a9dcd","versionType":"git","status":"affected"},{"version":"0","lessThan":"7.1.5","versionType":"semver","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["fs/ntfs/index.c","fs/ntfs/index.h","fs/ntfs/inode.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/8b97b302f553a480fb76d2afd53cd6c0635a9dcd","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/b06730c6af58d3569883f8dd7c36a90aba5ecc0a","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-72205","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:21:39.190","lastModified":"2026-08-15T06:21:39.190","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nntfs: free volume-wide resources on fill_super failure\n\nntfs_fill_super()'s err_out_now path frees only the volume struct via\nkfree(vol), leaving several vol-owned allocations behind on every mount\nfailure:\n\n  - vol->nls_map, loaded by ntfs_init_fs_context() via\n    load_nls_default() (or replaced by an explicit nls= option in\n    ntfs_parse_param()), is never unload_nls()'d.\n\n  - vol->volume_label, allocated by load_system_files() through\n    ntfs_ucstonls() once the $Volume name attribute has been parsed, is\n    not released by load_system_files()'s own error labels nor by the\n    fill_super() inline cleanup that only runs on d_make_root()\n    failure.  Any later failure inside load_system_files() leaks it.\n\n  - vol->lcn_empty_bits_per_page was kvfree()'d in\n    unl_upcase_iput_tmp_ino_err_out_now without clearing the pointer,\n    so it could not be folded into a single common cleanup.\n\nBecause the failure paths never call ntfs_volume_free() and never reach\nthe d_make_root() inline cleanup block (it sits above the label and is\njumped over by the load_system_files() / kvmalloc failure gotos), these\nresources accumulate per failed mount attempt with no chance of\nrecovery short of unloading the module.  This is a silent leak: the\ninodes loaded prior to failure remain hashed but generic_shutdown_super()\nskips evict_inodes() when sb->s_root is unset, so no CHECK_DATA_CORRUPTION\nwarning is emitted either.\n\nMove the per-volume frees down to err_out_now and drop the\nlcn_empty_bits_per_page kvfree() from the upper label so the cleanup is\nperformed exactly once on every failure path.  Using unconditional\nkvfree() / kfree() / unload_nls() is safe because they all accept NULL\nand the upper labels that previously freed nls_map (the d_make_root()\ninline cleanup) already clear the pointer."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["fs/ntfs/super.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"aca3d383a23cb7f3a2849c09fda3974f1838d941","versionType":"git","status":"affected"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"a9523a7d3b24b3a6b25ec1eb668ee6618cacf05e","versionType":"git","status":"affected"},{"version":"0","lessThan":"7.1.5","versionType":"semver","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["fs/ntfs/super.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/a9523a7d3b24b3a6b25ec1eb668ee6618cacf05e","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/aca3d383a23cb7f3a2849c09fda3974f1838d941","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-72206","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:21:39.307","lastModified":"2026-08-15T06:21:39.307","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nntfs: validate index block header more strictly\n\nModify ntfs_index_block_inconsisent() to perform stricter validation of\nINDEX_HEADER geometry in INDX blocks, and update\nntfs_lookup_inode_by_name() to use that function to validate INDX\nblocks."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["fs/ntfs/dir.c","fs/ntfs/index.c","fs/ntfs/index.h"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"34a49b3e94a50f45b62c6e6f574f676a079ba23e","versionType":"git","status":"affected"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"14bc34fe948523dc2b0174691f9af9e74eb4f3fd","versionType":"git","status":"affected"},{"version":"0","lessThan":"7.1.5","versionType":"semver","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["fs/ntfs/dir.c","fs/ntfs/index.c","fs/ntfs/index.h"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/14bc34fe948523dc2b0174691f9af9e74eb4f3fd","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/34a49b3e94a50f45b62c6e6f574f676a079ba23e","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-72207","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:21:39.417","lastModified":"2026-08-15T06:21:39.417","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nntfs: not change 0-byte $DATA attribute to non-resident\n\nWhen ntfs_resident_attr_resize() cannot grow a resident attribute in\nplace, it retries after converting other resident attributes to\nnon-resident to free space in the MFT recrord.\n\nDo not select zero-length resident $DATA attributes for this conversion.\nfsck treats 0-byte non-resident $DATA attribute as corruptions."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["fs/ntfs/attrib.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"ceb49c37250125d418410988f2376ed4d57a6706","versionType":"git","status":"affected"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"0aad21570197973af4a1b25b3fb8ed3aeb9e7670","versionType":"git","status":"affected"},{"version":"0","lessThan":"7.1.5","versionType":"semver","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["fs/ntfs/attrib.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/0aad21570197973af4a1b25b3fb8ed3aeb9e7670","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/ceb49c37250125d418410988f2376ed4d57a6706","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-72208","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:21:39.510","lastModified":"2026-08-15T06:21:39.510","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nntfs: add bounds check before accessing EA entries\n\nin ntfs_ea_lookup and ntfs_listxattr, this verifies that there is enough\nspace in the EA entry before accessing the next_entry_offset field of\nthe EA entry."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["fs/ntfs/ea.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"d9d9925de1d8f233cc60d3dc356e12f232f97c15","versionType":"git","status":"affected"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"937282f7d15b593d0be765fa2ced164130ec87f7","versionType":"git","status":"affected"},{"version":"0","lessThan":"7.1.5","versionType":"semver","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["fs/ntfs/ea.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/937282f7d15b593d0be765fa2ced164130ec87f7","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/d9d9925de1d8f233cc60d3dc356e12f232f97c15","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-72209","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:21:39.607","lastModified":"2026-08-15T06:21:39.607","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nntfs: validate attribute values on lookup\n\nntfs_attr_find() and ntfs_external_attr_find() check that generic\nresident attribute values fit in their attribute records and that\nfixed-size resident values are large enough. For variable-length resident\nformats, however, the fixed part is not enough: embedded length fields\ncan still point callers past the resident value.\n\nA crafted image can set a small resident $FILE_NAME value_length while\nleaving file_name_length large. Callers then trust file_name_length and\nread past the resident value when converting or comparing the name. This\nwas reproduced with a crafted image under KASAN as a slab-out-of-bounds\nread from the kmalloc-1k MFT record copy. The stack included\nntfs_lookup(), ntfs_iget(), ntfs_read_locked_inode(), ntfs_attr_name_get(),\nntfs_ucstonls(), and utf16s_to_utf8s().\n\nAdd a shared attribute value validator and use it before a lookup path\ncan return an attribute, including the AT_UNUSED enumeration case where\ncallers inspect returned attributes directly. The helper validates\nresident value bounds, minimum resident value sizes, variable-length\n$FILE_NAME fields, and non-resident mapping-pairs metadata that was\npreviously checked separately in both lookup paths.\n\nThis also preserves the intended resident @val matching semantics in the\nexternal attribute lookup path. The old duplicated validation block\noverwrote the actual resident value length with the type-specific minimum\nlength before comparing @val, so variable-length resident values could\nfail to match even when the bytes were identical. Keep the comparison on\nthe actual value length, and make ntfs_attrlist_entry_add() compare\nresident attributes with lowest_vcn zero instead of reading the\nnon-resident union member after a successful resident match.\n\nReject non-resident $FILE_NAME records too: the format requires\n$FILE_NAME to be resident and callers treat returned records as resident."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["fs/ntfs/attrib.c","fs/ntfs/attrlist.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6ceb4cc81ef3409ff79dcb959771f9110787397a","lessThan":"e4c36dfac57a7261e9aeb0f3a7f30944a8aefb56","versionType":"git","status":"affected"},{"version":"6ceb4cc81ef3409ff79dcb959771f9110787397a","lessThan":"d5803e3345dae9c6470bb61869885236276b9a35","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["fs/ntfs/attrib.c","fs/ntfs/attrlist.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"7.1","status":"affected"},{"version":"0","lessThan":"7.1","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/d5803e3345dae9c6470bb61869885236276b9a35","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/e4c36dfac57a7261e9aeb0f3a7f30944a8aefb56","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-72210","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:21:39.713","lastModified":"2026-08-15T06:21:39.713","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nntfs: fix off-by-one in mapping pairs decoding bounds checks\n\nIn ntfs_mapping_pairs_decompress(), attr_end points one byte past the\nend of the attribute record:\n\n    attr_end = (u8 *)attr + le32_to_cpu(attr->length);\n\nThe two bounds checks validating that mapping pair data bytes fit within\nthe attribute use strict greater-than (>), which allows a one-byte\nout-of-bounds read when the data extends exactly to attr_end:\n\n  b = *buf & 0xf;\n  if (b) {\n      if (unlikely(buf + b > attr_end))   // off-by-one\n          goto io_error;\n      for (deltaxcn = (s8)buf[b--]; b; b--)\n          deltaxcn = (deltaxcn << 8) + buf[b];\n  }\n\nWhen buf + b == attr_end, the check evaluates to false and buf[b] reads\none byte past the valid attribute boundary. The same pattern appears in\nthe LCN delta bytes check.\n\nFix both checks to use >= so that buf[b] at exactly attr_end is\ncorrectly rejected as out of bounds."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["fs/ntfs/runlist.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"bfe835e535fe0aa5767fdd8116f62e835ba50b55","versionType":"git","status":"affected"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"18760a74ef7c28df93726445b5595162e62ed341","versionType":"git","status":"affected"},{"version":"0","lessThan":"7.1.5","versionType":"semver","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["fs/ntfs/runlist.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/18760a74ef7c28df93726445b5595162e62ed341","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/bfe835e535fe0aa5767fdd8116f62e835ba50b55","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-72211","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:21:39.803","lastModified":"2026-08-15T06:21:39.803","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nntfs: grow index root value before reparent header update\n\nntfs_ir_reparent() moves the resident index root entries into an index\nblock and leaves a small root stub containing the child VCN. That root\nstub can be larger than the existing resident value. For example, an\nempty root with value_length 48 has an index area of 32 bytes, while the\nlarge-index root stub needs index_length and allocated_size of 40 bytes.\n\nThe current code publishes the larger index.index_length and\nindex.allocated_size before resizing the resident value. If the resize\nreturns -ENOSPC, the recovery path can call ntfs_inode_add_attrlist(),\nwhich looks attributes up again while the root header says\nallocated_size 40 but the resident value still only provides 32 bytes of\nindex area. Lookup-time $INDEX_ROOT validation then correctly rejects\nthat transient layout as corrupt.\n\nThis reproduces as a generic/013 failure under qemu. In the failing run,\nthe transient root had value_len=48, index_size=32, index_length=40, and\nallocated_size=40, and ntfsprogs-plus ntfsck reported \"Corrupt index\nroot in MFT record 1177\".\n\nWhen the root stub grows, resize the resident value before publishing the\nlarger root header. If the resize fails, the old root remains valid for\nrecovery lookups. Keep the existing header-before-resize ordering for\nshrink or same-size cases so the resident value never temporarily\nexposes an allocated_size beyond its bounds."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["fs/ntfs/index.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"38d444271604afc6381ddb5a181e391915c35fae","versionType":"git","status":"affected"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"0bb508fb3b97e4802ec727fd2af4d608f65dd190","versionType":"git","status":"affected"},{"version":"0","lessThan":"7.1.5","versionType":"semver","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["fs/ntfs/index.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/0bb508fb3b97e4802ec727fd2af4d608f65dd190","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/38d444271604afc6381ddb5a181e391915c35fae","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-72212","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:21:39.913","lastModified":"2026-08-15T06:21:39.913","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nmm/memory_hotplug: fix incorrect altmap passing in error path\n\nIn create_altmaps_and_memory_blocks(), when arch_add_memory() succeeds\nwith memmap_on_memory enabled, the vmemmap pages are allocated from\nparams.altmap.  If create_memory_block_devices() subsequently fails, the\nerror path calls arch_remove_memory() with a NULL altmap instead of\nparams.altmap.\n\nThis is a bug that could lead to memory corruption.  Since altmap is NULL,\nvmemmap_free() falls back to freeing the vmemmap pages into the system\nbuddy allocator via free_pages() instead of the altmap. \narch_remove_memory() then immediately destroys the physical linear mapping\nfor this memory.  This injects unowned pages into the buddy allocator,\ncausing machine checks or memory corruption if the system later attempts\nto allocate and use those freed pages.\n\nFix this by passing params.altmap to arch_remove_memory() in the error\npath."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["mm/memory_hotplug.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6b8f0798b85aa529011570369db985a788f3003f","lessThan":"3833e6abdbbfb59ec8203a84a84206cb7ffb41ac","versionType":"git","status":"affected"},{"version":"6b8f0798b85aa529011570369db985a788f3003f","lessThan":"722e6c54bde6391fb95f0357f555aca887c7b18c","versionType":"git","status":"affected"},{"version":"6b8f0798b85aa529011570369db985a788f3003f","lessThan":"2f9e3ec17c3d2093c664c00a027588a446c39894","versionType":"git","status":"affected"},{"version":"6b8f0798b85aa529011570369db985a788f3003f","lessThan":"2fac4afa0e2e68841334c78c1821e49f74fbc66a","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["mm/memory_hotplug.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.8","status":"affected"},{"version":"0","lessThan":"6.8","versionType":"semver","status":"unaffected"},{"version":"6.12.97","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/2f9e3ec17c3d2093c664c00a027588a446c39894","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/2fac4afa0e2e68841334c78c1821e49f74fbc66a","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/3833e6abdbbfb59ec8203a84a84206cb7ffb41ac","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/722e6c54bde6391fb95f0357f555aca887c7b18c","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-72213","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:21:40.013","lastModified":"2026-08-15T06:21:40.013","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nmm/hugetlb: fix hugetlb cgroup rsvd charge/uncharge mismatch\n\nIn alloc_hugetlb_folio(), a single h_cg pointer is used for both the rsvd\nand non-rsvd hugetlb cgroup charges.  When map_chg is set,\nhugetlb_cgroup_charge_cgroup_rsvd() stores the charged cgroup in h_cg, but\nthe immediately following hugetlb_cgroup_charge_cgroup() overwrites h_cg\nwith the non-rsvd cgroup pointer.\n\nAs a result, hugetlb_cgroup_commit_charge_rsvd() stores the wrong\n(non-rsvd) cgroup pointer into the folio's rsvd slot.\n\nWhen the folio is later freed, free_huge_folio() unconditionally calls\nboth hugetlb_cgroup_uncharge_folio() and\nhugetlb_cgroup_uncharge_folio_rsvd().  The rsvd uncharge reads back the\nwrong cgroup from the folio and decrements a counter that was never\ncharged for that cgroup, causing a page_counter underflow:\n\n  page_counter underflow: -512 nr_pages=512\n  WARNING: mm/page_counter.c:61 at page_counter_cancel\n\nFix this by introducing a separate h_cg_rsvd pointer exclusively for the\nrsvd charge path, keeping the rsvd and non-rsvd charges fully independent\nthrough their charge, commit, and error uncharge paths."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["mm/hugetlb.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"08cf9faf7558020aed6a0da5810b824b07139dfa","lessThan":"5c32ae4a91fb5f4941328e0c1720a7fa4189c3bd","versionType":"git","status":"affected"},{"version":"08cf9faf7558020aed6a0da5810b824b07139dfa","lessThan":"1697d253f51cf5e3825a3423ff49e128a3502ab2","versionType":"git","status":"affected"},{"version":"08cf9faf7558020aed6a0da5810b824b07139dfa","lessThan":"b785f2bd9496facedc0a031be09cddcd1d3c84d3","versionType":"git","status":"affected"},{"version":"08cf9faf7558020aed6a0da5810b824b07139dfa","lessThan":"15807d0ddde37407af72859426b654f3d1972b00","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["mm/hugetlb.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"5.7","status":"affected"},{"version":"0","lessThan":"5.7","versionType":"semver","status":"unaffected"},{"version":"6.12.101","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/15807d0ddde37407af72859426b654f3d1972b00","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/1697d253f51cf5e3825a3423ff49e128a3502ab2","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/5c32ae4a91fb5f4941328e0c1720a7fa4189c3bd","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/b785f2bd9496facedc0a031be09cddcd1d3c84d3","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-72214","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:21:40.130","lastModified":"2026-08-15T06:21:40.130","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\npower: supply: cpcap-battery: Fix missing nvmem_device_put() causing reference leak\n\nIn cpcap_battery_detect_battery_type(), the reference to an nvmem\ndevice obtained via nvmem_device_find() is not released with\nnvmem_device_put() on the success or read-failure paths, causing a\npermanent reference leak. The driver’s retry logic on subsequent\nbattery property reads can compound this leak, preventing the nvmem\ndevice from ever being freed.\n\nFound by code review."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/power/supply/cpcap-battery.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"fd46821e85de90fb5b7356251164af4815b6e3f6","lessThan":"fc65520fe0781a1ff46631f111e07b4a1c677b96","versionType":"git","status":"affected"},{"version":"fd46821e85de90fb5b7356251164af4815b6e3f6","lessThan":"700c225d829a1256b59053c34a1a9d1a6ab70b09","versionType":"git","status":"affected"},{"version":"fd46821e85de90fb5b7356251164af4815b6e3f6","lessThan":"deaf6b3f8187231ad8f7770b10ed0be2cd47e9b2","versionType":"git","status":"affected"},{"version":"fd46821e85de90fb5b7356251164af4815b6e3f6","lessThan":"a3d81de441233a92ec21469cd0c4eb3c26b95cd8","versionType":"git","status":"affected"},{"version":"fd46821e85de90fb5b7356251164af4815b6e3f6","lessThan":"b56a5cbf8f1f1a5740f1137c89b14d0373309d8d","versionType":"git","status":"affected"},{"version":"fd46821e85de90fb5b7356251164af4815b6e3f6","lessThan":"a2c14ff63e0e02e3c832385e523e9cc81301171c","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/power/supply/cpcap-battery.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"5.18","status":"affected"},{"version":"0","lessThan":"5.18","versionType":"semver","status":"unaffected"},{"version":"6.1.178","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.97","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/700c225d829a1256b59053c34a1a9d1a6ab70b09","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/a2c14ff63e0e02e3c832385e523e9cc81301171c","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/a3d81de441233a92ec21469cd0c4eb3c26b95cd8","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/b56a5cbf8f1f1a5740f1137c89b14d0373309d8d","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/deaf6b3f8187231ad8f7770b10ed0be2cd47e9b2","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/fc65520fe0781a1ff46631f111e07b4a1c677b96","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-72215","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:21:40.233","lastModified":"2026-08-15T06:21:40.233","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nMIPS: DEC: Ensure 32-bit stack location for o32 prom_printf()\n\nIn 64-bit configurations calling any firmware entry points from a kernel\nthread other than the initial one will result in a situation where the\nstack has been placed in the XKPHYS 64-bit memory segment.\n\nConsequently the stack pointer is no longer a 32-bit value and when the\n32-bit firmware code called uses 32-bit ALU operations to manipulate the\nstack pointer, the calculated result is incorrect (in fact in the 64-bit\nMIPS ISA almost all 32-bit ALU operations will produce an unpredictable\nresult when executed on 64-bit data) and control goes astray.\n\nThis may happen when no final console driver has been enabled in the\nconfiguration and consequently the initial console continues being used\nlate into bootstrap, or with an upcoming change that will switch the zs\ndriver to use a platform device, which in turn will make the console\nhandover happen only after other kernel threads have already been\nstarted, and the kernel will hang at:\n\n  pid_max: default: 32768 minimum: 301\n\nor somewhat later, but always before:\n\n  cblist_init_generic: Setting adjustable number of callback queues.\n\nhas been printed.\n\nIt seems that only the prom_printf() entry point is affected.  Of all\nthe other entry points wired only rex_slot_address() and rex_gettcinfo()\nare called from a kernel thread other than the initial one, specifically\nkernel_init(), and they are leaf functions that do no business with the\nstack, having worked with no issue ever since 64-bit support was added\nfor the platform back in 2002.\n\nTo address this issue then, arrange for the stack to be switched in the\no32 wrapper as required for prom_printf() only, by supplying call_o32()\nwith a pointer to a chunk of initdata space, which is placed in the\nCKSEG0 32-bit compatibility segment, observing that prom_printf() is\nonly called from console output handler and therefore with the console\nlock held, implying no need for this code to be reentrant.\n\nOther firmware entry points may be called with interrupts enabled and no\nlock held, and may therefore require that call_o32() be reentrant.  They\ntrigger no issue at this point and \"if it ain't broke, don't fix it,\" so\njust leave them alone."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["arch/mips/dec/prom/init.c","arch/mips/include/asm/dec/prom.h"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"9cd4a8ed12d2a6313592e43c14cca5eca6717bee","versionType":"git","status":"affected"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"3394757c5d3970ab36d2aafa6dd40952b43f0d16","versionType":"git","status":"affected"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"1ed18b5c3be9657fe288fa4dae0bef2470598683","versionType":"git","status":"affected"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"27857db30c98583e12dd8d939ba2370bce08a5be","versionType":"git","status":"affected"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"d828bca84311e278093e60b2864a54f4bbb0c2ad","versionType":"git","status":"affected"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"d3fd2d358df0ca712183509cbbed6a16bde1d17e","versionType":"git","status":"affected"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"3ae86630b94f72bf4012c6322f81f622dc4fdf24","versionType":"git","status":"affected"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"5ff79e8bdc75db51e30298a75939e2308e7658e0","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["arch/mips/dec/prom/init.c","arch/mips/include/asm/dec/prom.h"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"2.6.12","status":"affected"},{"version":"0","lessThan":"2.6.12","versionType":"semver","status":"unaffected"},{"version":"5.10.261","lessThanOrEqual":"5.10.*","versionType":"semver","status":"unaffected"},{"version":"5.15.212","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.178","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.97","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/1ed18b5c3be9657fe288fa4dae0bef2470598683","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/27857db30c98583e12dd8d939ba2370bce08a5be","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/3394757c5d3970ab36d2aafa6dd40952b43f0d16","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/3ae86630b94f72bf4012c6322f81f622dc4fdf24","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/5ff79e8bdc75db51e30298a75939e2308e7658e0","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/9cd4a8ed12d2a6313592e43c14cca5eca6717bee","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/d3fd2d358df0ca712183509cbbed6a16bde1d17e","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/d828bca84311e278093e60b2864a54f4bbb0c2ad","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-72216","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:21:40.383","lastModified":"2026-08-15T06:21:40.383","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nremoteproc: qcom: Fix leak when custom dump_segments addition fails\n\nFree allocated minidump_region 'name' in qcom_add_minidump_segments()\nwhen failing before adding the region to 'dump_segments'. Otherwise,\nthe 'name' is not tracked and is never freed by qcom_minidump_cleanup().\n\nReturn error when adding to 'dump_segments' fails."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/remoteproc/qcom_common.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"8ed8485c4f056d488d17a2b56581c86aeb42955d","lessThan":"65104d6eb43f066dcf73ca9ade6478824b17d867","versionType":"git","status":"affected"},{"version":"8ed8485c4f056d488d17a2b56581c86aeb42955d","lessThan":"381c8a7a59da06293951c343857f4a2465b2c655","versionType":"git","status":"affected"},{"version":"8ed8485c4f056d488d17a2b56581c86aeb42955d","lessThan":"51aad3d89a2dd2bd34713785b0f2fd5177eb33b6","versionType":"git","status":"affected"},{"version":"8ed8485c4f056d488d17a2b56581c86aeb42955d","lessThan":"e5b1aaa74118e91f0c0f18b22b6f853199873db4","versionType":"git","status":"affected"},{"version":"8ed8485c4f056d488d17a2b56581c86aeb42955d","lessThan":"ecf9fc18e62c58eae1ceb65dab2bccb8a724de2d","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/remoteproc/qcom_common.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"5.11","status":"affected"},{"version":"0","lessThan":"5.11","versionType":"semver","status":"unaffected"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.97","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/381c8a7a59da06293951c343857f4a2465b2c655","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/51aad3d89a2dd2bd34713785b0f2fd5177eb33b6","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/65104d6eb43f066dcf73ca9ade6478824b17d867","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/e5b1aaa74118e91f0c0f18b22b6f853199873db4","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/ecf9fc18e62c58eae1ceb65dab2bccb8a724de2d","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-72217","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:21:40.493","lastModified":"2026-08-15T06:21:40.493","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nSUNRPC: Bound-check xdr_buf_to_bvec() stores before writing\n\nxdr_buf_to_bvec() writes a bio_vec into the caller's array before\ntesting whether that slot is in range, and the head branch performs\nthe store with no check at all. When the caller's budget is exactly\nused up, the next store lands one element past the end of the array.\nThe overflow label returns count - 1, which masks the surplus store\nbut cannot undo it.\n\nrq_bvec, the array passed by nfsd_vfs_write(), is allocated to\nexactly rq_maxpages entries with no slack. The OOB store can land in\nadjacent slab memory; the bv_len and bv_offset fields written there\nare derived from client-supplied RPC payload sizes.\n\nMove the in-range check ahead of the store in the head, page-loop,\nand tail branches. With the check at the top of each sequence, count\nis incremented only after a successful store, so the overflow label\ncan return count directly."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["net/sunrpc/xdr.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"2eb2b93581813b74c7174961126f6ec38eadb5a7","lessThan":"4a1148f2739d5089c3ca8ae2e9d1053e219ab5df","versionType":"git","status":"affected"},{"version":"2eb2b93581813b74c7174961126f6ec38eadb5a7","lessThan":"6029e711a818bf34d6c4b90cafee24f3afffa110","versionType":"git","status":"affected"},{"version":"2eb2b93581813b74c7174961126f6ec38eadb5a7","lessThan":"69e18135e2a004a79505451dbef07314ea16e1eb","versionType":"git","status":"affected"},{"version":"2eb2b93581813b74c7174961126f6ec38eadb5a7","lessThan":"98414b42530af65cb984ffc12685096a3b5e179a","versionType":"git","status":"affected"},{"version":"2eb2b93581813b74c7174961126f6ec38eadb5a7","lessThan":"42f5b80dda6b86e424054baf1475df686c403d5c","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["net/sunrpc/xdr.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.6","status":"affected"},{"version":"0","lessThan":"6.6","versionType":"semver","status":"unaffected"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.97","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/42f5b80dda6b86e424054baf1475df686c403d5c","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/4a1148f2739d5089c3ca8ae2e9d1053e219ab5df","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/6029e711a818bf34d6c4b90cafee24f3afffa110","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/69e18135e2a004a79505451dbef07314ea16e1eb","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/98414b42530af65cb984ffc12685096a3b5e179a","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-72218","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:21:40.613","lastModified":"2026-08-15T06:21:40.613","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nlockd: Plug nlm_file refcount leak on cached nlm_do_fopen() failure\n\nThe cached-file path in nlm_lookup_file() reaches the found: label\nunconditionally, even when nlm_do_fopen() fails. At that label\n*result and file->f_count are updated before the error is returned.\nThe wrappers nlm3svc_lookup_file() and nlm4svc_lookup_file() then\nbail out of their switch without copying *result back to their\ncaller, so the proc handler's local nlm_file pointer remains NULL\nand the cleanup path skips nlm_release_file(). The f_count\nincrement is never released, and nlm_traverse_files() can no\nlonger reap the file because its refcount never returns to zero\nbetween requests.\n\nShort-circuit the cached path so neither *result nor f_count is\ntouched when nlm_do_fopen() fails on a hashed nlm_file."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["fs/lockd/svcsubs.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"e580323ac0b51ad10ec2e181d1f777479b7983e7","lessThan":"6cd84cefd8b73e85b9eda17b319bd40a670f3a38","versionType":"git","status":"affected"},{"version":"7f024fcd5c97dc70bb9121c80407cf3cf9be7159","lessThan":"fe3b45b56b6c3d4b6b341de27fa291005287a21c","versionType":"git","status":"affected"},{"version":"7f024fcd5c97dc70bb9121c80407cf3cf9be7159","lessThan":"cb3420c047957e565101585bb4f15e1a6e3de6b0","versionType":"git","status":"affected"},{"version":"7f024fcd5c97dc70bb9121c80407cf3cf9be7159","lessThan":"7ce4c23e783e766507b2cef27bbf97e9ca944f1a","versionType":"git","status":"affected"},{"version":"7f024fcd5c97dc70bb9121c80407cf3cf9be7159","lessThan":"84008bf1860e0ef8059a7583a1163f36b704d08a","versionType":"git","status":"affected"},{"version":"7f024fcd5c97dc70bb9121c80407cf3cf9be7159","lessThan":"46d59ff421824b6483549d87f14efffbbbd1f6cb","versionType":"git","status":"affected"},{"version":"7f024fcd5c97dc70bb9121c80407cf3cf9be7159","lessThan":"3a5c55a19cad62f2973be25fe96a1a9e7f618e8a","versionType":"git","status":"affected"},{"version":"7f024fcd5c97dc70bb9121c80407cf3cf9be7159","lessThan":"70a38f87bed7f0694fd07988b47b2db1e10d8df3","versionType":"git","status":"affected"},{"version":"5.10.220","lessThan":"5.10.261","versionType":"semver","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["fs/lockd/svcsubs.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"5.15","status":"affected"},{"version":"0","lessThan":"5.15","versionType":"semver","status":"unaffected"},{"version":"5.10.261","lessThanOrEqual":"5.10.*","versionType":"semver","status":"unaffected"},{"version":"5.15.212","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.178","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.97","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/3a5c55a19cad62f2973be25fe96a1a9e7f618e8a","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/46d59ff421824b6483549d87f14efffbbbd1f6cb","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/6cd84cefd8b73e85b9eda17b319bd40a670f3a38","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/70a38f87bed7f0694fd07988b47b2db1e10d8df3","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/7ce4c23e783e766507b2cef27bbf97e9ca944f1a","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/84008bf1860e0ef8059a7583a1163f36b704d08a","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/cb3420c047957e565101585bb4f15e1a6e3de6b0","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/fe3b45b56b6c3d4b6b341de27fa291005287a21c","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-72219","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:21:40.747","lastModified":"2026-08-15T06:21:40.747","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nlockd: Plug nlm_file leak when nlm_do_fopen() fails\n\nA client can repeatedly drive nlm_do_fopen() failures by presenting\nfile handles that the underlying export rejects. After kzalloc_obj()\nsucceeds in nlm_lookup_file(), the freshly allocated nlm_file is not\nyet inserted into nlm_files[]. The nlm_do_fopen() failure path jumps\nto out_unlock, which releases nlm_file_mutex and returns without\nfreeing the allocation, so each failure leaks one nlm_file.\n\nRoute the failure through out_free so kfree() runs before the\nfunction returns."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["fs/lockd/svcsubs.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"e580323ac0b51ad10ec2e181d1f777479b7983e7","lessThan":"bca74fff138429f3d5802865f38fc883d53a4f1a","versionType":"git","status":"affected"},{"version":"7f024fcd5c97dc70bb9121c80407cf3cf9be7159","lessThan":"d7c677feb3aa1f42b1026d75a8ea61338b51e4fb","versionType":"git","status":"affected"},{"version":"7f024fcd5c97dc70bb9121c80407cf3cf9be7159","lessThan":"39f59bf67231ed2eb0cdf6337194360e964b609a","versionType":"git","status":"affected"},{"version":"7f024fcd5c97dc70bb9121c80407cf3cf9be7159","lessThan":"ddfbd816273b4e9c9b836f5b8773664c6f40f807","versionType":"git","status":"affected"},{"version":"7f024fcd5c97dc70bb9121c80407cf3cf9be7159","lessThan":"1403f1221a35a6caf959bb7bf005741f17263c66","versionType":"git","status":"affected"},{"version":"7f024fcd5c97dc70bb9121c80407cf3cf9be7159","lessThan":"1161c4b5bd0048c8148e919f818a33cff3623ef0","versionType":"git","status":"affected"},{"version":"7f024fcd5c97dc70bb9121c80407cf3cf9be7159","lessThan":"3f2dc01b9cb516d4727a3b9263ee58c71ca00ba9","versionType":"git","status":"affected"},{"version":"7f024fcd5c97dc70bb9121c80407cf3cf9be7159","lessThan":"f16a1513452edb532fec81e591c64c320866719c","versionType":"git","status":"affected"},{"version":"5.10.220","lessThan":"5.10.261","versionType":"semver","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["fs/lockd/svcsubs.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"5.15","status":"affected"},{"version":"0","lessThan":"5.15","versionType":"semver","status":"unaffected"},{"version":"5.10.261","lessThanOrEqual":"5.10.*","versionType":"semver","status":"unaffected"},{"version":"5.15.212","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.178","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.97","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/1161c4b5bd0048c8148e919f818a33cff3623ef0","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/1403f1221a35a6caf959bb7bf005741f17263c66","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/39f59bf67231ed2eb0cdf6337194360e964b609a","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/3f2dc01b9cb516d4727a3b9263ee58c71ca00ba9","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/bca74fff138429f3d5802865f38fc883d53a4f1a","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/d7c677feb3aa1f42b1026d75a8ea61338b51e4fb","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/ddfbd816273b4e9c9b836f5b8773664c6f40f807","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/f16a1513452edb532fec81e591c64c320866719c","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-72220","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:21:40.883","lastModified":"2026-08-15T06:21:40.883","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nsunrpc: harden rq_procinfo lifecycle to prevent double-free\n\nThe svc_release_rqst() function executes the callback inside\nrqstp->rq_procinfo->pc_release. However, if a worker thread begins\nprocessing a new request and encounters an early error path (e.g.,\nunsupported protocol, short frame, or bad auth) before a valid\nrq_procinfo is installed, a stale release hook can be re-triggered\nagainst reused state from the previous RPC, resulting in a double-free\nor use-after-free vulnerability.\n\nHarden the lifecycle of rq_procinfo by:\n1. Ensuring svc_release_rqst() always clears rq_procinfo after the\n   optional pc_release() call, regardless of whether the hook exists.\n2. Explicitly clearing rq_procinfo at request entry in svc_process()\n   before any early decode or drop paths.\n3. Ensuring svc_process_bc() does the same at backchannel entry.\n\nThis guarantees that error flows will not encounter a non-NULL stale\nrq_procinfo pointer when there is nothing to release."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["net/sunrpc/svc.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"d9adbb6e10bf7d4223d3d521ede1b2052903bc5e","lessThan":"66014ab165cb01bfef5836939412a8ef98d5d5ff","versionType":"git","status":"affected"},{"version":"d9adbb6e10bf7d4223d3d521ede1b2052903bc5e","lessThan":"31ba490c02d476a5e4f90b8845932ac9db8aa71b","versionType":"git","status":"affected"},{"version":"d9adbb6e10bf7d4223d3d521ede1b2052903bc5e","lessThan":"18d216788bef06332ff8901670ecf1ed8f6eb614","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["net/sunrpc/svc.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.18","status":"affected"},{"version":"0","lessThan":"6.18","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/18d216788bef06332ff8901670ecf1ed8f6eb614","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/31ba490c02d476a5e4f90b8845932ac9db8aa71b","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/66014ab165cb01bfef5836939412a8ef98d5d5ff","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-72221","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:21:40.990","lastModified":"2026-08-15T06:21:40.990","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nsunrpc: wait for in-flight TLS handshake callback when cancel loses race\n\nWhen wait_for_completion_interruptible_timeout() in\nsvc_tcp_handshake() returns 0 (timeout) or -ERESTARTSYS (signal) and\ntls_handshake_cancel() then returns false, handshake_complete() has\nwon the cancellation race: it has set HANDSHAKE_F_REQ_COMPLETED and\nis about to invoke svc_tcp_handshake_done(), but the callback's\nside effects on xpt_flags and on svsk->sk_handshake_done have not\nyet committed.\n\nThe current code reads xpt_flags immediately to decide whether the\nsession succeeded. Two races result.\n\nIf the callback has executed set_bit(XPT_TLS_SESSION) but not yet\nclear_bit(XPT_HANDSHAKE), svc_tcp_handshake() sees a session,\nenqueues the transport, and returns. svc_xprt_received() then\nclears XPT_BUSY, a worker thread picks the transport up, the\ndispatcher in svc_handle_xprt() observes XPT_HANDSHAKE still set,\nand xpo_handshake is invoked a second time. That svc_tcp_handshake()\ncalls init_completion(&svsk->sk_handshake_done) while the original\ncallback concurrently calls complete_all() on it, corrupting the\nembedded swait_queue.\n\nIf the callback has set HANDSHAKE_F_REQ_COMPLETED but not yet\nentered svc_tcp_handshake_done(), svc_tcp_handshake() reads\nXPT_TLS_SESSION as clear and tears the connection down even though\nthe handshake is about to succeed.\n\nWait for the callback to commit before inspecting xpt_flags. The\ncompletion is guaranteed to fire because handshake_complete()\ninvokes svc_tcp_handshake_done() unconditionally once it has set\nHANDSHAKE_F_REQ_COMPLETED."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["net/sunrpc/svcsock.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"b3cbf98e2fdf3cb147a95161560cd25987284330","lessThan":"0d8ceb39884148dc7a2fdf71e1cac5961ed1d2b9","versionType":"git","status":"affected"},{"version":"b3cbf98e2fdf3cb147a95161560cd25987284330","lessThan":"e0f4691d42a54d359d8b64509fd9ab938d4f2a33","versionType":"git","status":"affected"},{"version":"b3cbf98e2fdf3cb147a95161560cd25987284330","lessThan":"65b23bec1fca6e9ebdc3e6041ebf8c6ab074141b","versionType":"git","status":"affected"},{"version":"b3cbf98e2fdf3cb147a95161560cd25987284330","lessThan":"a4f878e8ecd729ccf2e50993444e217583adeace","versionType":"git","status":"affected"},{"version":"b3cbf98e2fdf3cb147a95161560cd25987284330","lessThan":"d00e32f84ca1a77cb67a3fbf59f58dada95f5a21","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["net/sunrpc/svcsock.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.4","status":"affected"},{"version":"0","lessThan":"6.4","versionType":"semver","status":"unaffected"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.97","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/0d8ceb39884148dc7a2fdf71e1cac5961ed1d2b9","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/65b23bec1fca6e9ebdc3e6041ebf8c6ab074141b","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/a4f878e8ecd729ccf2e50993444e217583adeace","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/d00e32f84ca1a77cb67a3fbf59f58dada95f5a21","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/e0f4691d42a54d359d8b64509fd9ab938d4f2a33","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-72222","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:21:41.120","lastModified":"2026-08-15T06:21:41.120","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nsunrpc: pin svc_xprt across the asynchronous TLS handshake callback\n\nsvc_tcp_handshake() stores the raw svc_xprt pointer in\ntls_handshake_args.ta_data and submits the request through\ntls_server_hello_x509(). The handshake core takes only\nsock_hold(req->hr_sk); nothing references the embedding struct\nsvc_sock that svc_tcp_handshake_done() reaches via container_of().\n\nTwo close races leave the in-flight callback writing through a freed\nsvc_sock. svc_sock_free() calls tls_handshake_cancel() and discards\nits return value: a false return means handshake_complete() has\nalready set HANDSHAKE_F_REQ_COMPLETED but hp_done() may not have\nfinished, yet svc_sock_free() proceeds to kfree(svsk). The\ncancel-loser fall-through inside svc_tcp_handshake() itself produces\nthe same window: when wait_for_completion_interruptible_timeout()\nreturns <= 0 (timeout or signal) and tls_handshake_cancel() returns\nfalse, the function does not drain, returns, and svc_handle_xprt()\ncalls svc_xprt_received(), which clears XPT_BUSY and can drop the\nlast reference. A concurrent close then runs svc_sock_free() while\nsvc_tcp_handshake_done() is still updating xpt_flags and walking\nsvsk->sk_handshake_done.\n\nThe corruption surfaces as set_bit/clear_bit RMW into the freed\nxpt_flags slab slot and as complete_all() walking and writing the\nfreed wait_queue_head_t list embedded in sk_handshake_done -- a\nslab-corruption primitive, not a benign read. The path is reachable\non any TLS-enabled NFS server whenever a connection close overlaps\nthe tlshd downcall delivery window; the interruptible wait means\nsignal delivery suffices, not just SVC_HANDSHAKE_TO expiry.\n\nTake svc_xprt_get(xprt) immediately before tls_server_hello_x509()\nso the in-flight callback owns its own reference. Release it on the\ntwo edges where the callback is guaranteed not to fire -- submission\nfailure from tls_server_hello_x509() and a successful\ntls_handshake_cancel() -- and at the tail of\nsvc_tcp_handshake_done() after complete_all().\n\n[cel: rewrote commit message to describe the actual change]"}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["net/sunrpc/svcsock.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"b3cbf98e2fdf3cb147a95161560cd25987284330","lessThan":"f3b55945dd99f29d83e1965d0141040a35262346","versionType":"git","status":"affected"},{"version":"b3cbf98e2fdf3cb147a95161560cd25987284330","lessThan":"2d4f97d13fff91e0bc539216be88b884b544d49f","versionType":"git","status":"affected"},{"version":"b3cbf98e2fdf3cb147a95161560cd25987284330","lessThan":"3f9ee75a97a769be258784c22b89657acb5ed9bd","versionType":"git","status":"affected"},{"version":"b3cbf98e2fdf3cb147a95161560cd25987284330","lessThan":"083e9c2ec7e8bb13b79c9fd7b337abdd758ecc5f","versionType":"git","status":"affected"},{"version":"b3cbf98e2fdf3cb147a95161560cd25987284330","lessThan":"4f988f3a2808fb659f3880c282041ff067acad78","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["net/sunrpc/svcsock.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.4","status":"affected"},{"version":"0","lessThan":"6.4","versionType":"semver","status":"unaffected"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.97","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/083e9c2ec7e8bb13b79c9fd7b337abdd758ecc5f","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/2d4f97d13fff91e0bc539216be88b884b544d49f","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/3f9ee75a97a769be258784c22b89657acb5ed9bd","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/4f988f3a2808fb659f3880c282041ff067acad78","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/f3b55945dd99f29d83e1965d0141040a35262346","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-72223","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:21:41.233","lastModified":"2026-08-15T06:21:41.233","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nnvdimm/btt: Free arena sub-allocations on discover_arenas() error path\n\nMemory allocated by btt_freelist_init(), btt_rtt_init(), and\nbtt_maplocks_init() is not freed on some discover_arenas() error\npaths. This leaks memory when arena discovery fails.\n\nAdd the missing kfree() calls to release the allocations before\nreturning an error.\n\n[ as: commit message and log edits ]"}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/nvdimm/btt.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"5212e11fde4d40fa627668b4f2222d20db488f71","lessThan":"2d0364937550a7b3e2592629c2a68753ac020b28","versionType":"git","status":"affected"},{"version":"5212e11fde4d40fa627668b4f2222d20db488f71","lessThan":"eeb95774bc79268e2b78ebf01d8781560b5bd671","versionType":"git","status":"affected"},{"version":"5212e11fde4d40fa627668b4f2222d20db488f71","lessThan":"7563f69caa9143a491d5f26e563255c734751545","versionType":"git","status":"affected"},{"version":"5212e11fde4d40fa627668b4f2222d20db488f71","lessThan":"0b0d9404951aacc9717aa61e77af4a6e9e8f8249","versionType":"git","status":"affected"},{"version":"5212e11fde4d40fa627668b4f2222d20db488f71","lessThan":"873ced7f345e99f7ee16f9ff226515580332ecc4","versionType":"git","status":"affected"},{"version":"5212e11fde4d40fa627668b4f2222d20db488f71","lessThan":"30d490bb2c4cd220e7dedf862ab6a09eb5dcbad5","versionType":"git","status":"affected"},{"version":"5212e11fde4d40fa627668b4f2222d20db488f71","lessThan":"ba59b96d8d21dc8729fca44a022ca5919c1848c9","versionType":"git","status":"affected"},{"version":"5212e11fde4d40fa627668b4f2222d20db488f71","lessThan":"13fe4cd9ddd0aacb7777812328be525a11ea3fea","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/nvdimm/btt.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"4.2","status":"affected"},{"version":"0","lessThan":"4.2","versionType":"semver","status":"unaffected"},{"version":"5.10.261","lessThanOrEqual":"5.10.*","versionType":"semver","status":"unaffected"},{"version":"5.15.212","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.178","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.97","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/0b0d9404951aacc9717aa61e77af4a6e9e8f8249","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/13fe4cd9ddd0aacb7777812328be525a11ea3fea","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/2d0364937550a7b3e2592629c2a68753ac020b28","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/30d490bb2c4cd220e7dedf862ab6a09eb5dcbad5","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/7563f69caa9143a491d5f26e563255c734751545","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/873ced7f345e99f7ee16f9ff226515580332ecc4","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/ba59b96d8d21dc8729fca44a022ca5919c1848c9","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/eeb95774bc79268e2b78ebf01d8781560b5bd671","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-72224","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:21:41.370","lastModified":"2026-08-15T06:21:41.370","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nnvdimm/btt: Free arenas on btt_init() error paths\n\nThe arenas allocated by discover_arenas() or create_arenas() are not\nfreed on some error paths in btt_init(). This leaks memory when BTT\ninitialization fails.\n\nCall free_arenas() from the affected error paths to release the\nallocations.\n\n[ as: commit message and log edits ]"}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/nvdimm/btt.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"5212e11fde4d40fa627668b4f2222d20db488f71","lessThan":"9ab5293d9ac3f2c4232220e563d04701f5f44607","versionType":"git","status":"affected"},{"version":"5212e11fde4d40fa627668b4f2222d20db488f71","lessThan":"68c967e105d50f885e02b0dbdc9211fd5f84bdcd","versionType":"git","status":"affected"},{"version":"5212e11fde4d40fa627668b4f2222d20db488f71","lessThan":"0b63788093ff6ccfffe6e87de9e08aeeb406599c","versionType":"git","status":"affected"},{"version":"5212e11fde4d40fa627668b4f2222d20db488f71","lessThan":"5804e6a6912b5a1e47c821777d69191d69a3fe64","versionType":"git","status":"affected"},{"version":"5212e11fde4d40fa627668b4f2222d20db488f71","lessThan":"52a7e7ece79c4b0f406149e19cd2b4b11a6c19e4","versionType":"git","status":"affected"},{"version":"5212e11fde4d40fa627668b4f2222d20db488f71","lessThan":"f4ca396bdd60b4e0a665b2589bfc4ddbea9bda2b","versionType":"git","status":"affected"},{"version":"5212e11fde4d40fa627668b4f2222d20db488f71","lessThan":"7e49684d90faa34ff6d5586be658e986d9d475ac","versionType":"git","status":"affected"},{"version":"5212e11fde4d40fa627668b4f2222d20db488f71","lessThan":"1a6b6442a982d0ca5fb6a1a39b6f6dfd760eda57","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/nvdimm/btt.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"4.2","status":"affected"},{"version":"0","lessThan":"4.2","versionType":"semver","status":"unaffected"},{"version":"5.10.261","lessThanOrEqual":"5.10.*","versionType":"semver","status":"unaffected"},{"version":"5.15.212","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.178","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.97","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/0b63788093ff6ccfffe6e87de9e08aeeb406599c","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/1a6b6442a982d0ca5fb6a1a39b6f6dfd760eda57","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/52a7e7ece79c4b0f406149e19cd2b4b11a6c19e4","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/5804e6a6912b5a1e47c821777d69191d69a3fe64","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/68c967e105d50f885e02b0dbdc9211fd5f84bdcd","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/7e49684d90faa34ff6d5586be658e986d9d475ac","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/9ab5293d9ac3f2c4232220e563d04701f5f44607","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/f4ca396bdd60b4e0a665b2589bfc4ddbea9bda2b","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-72225","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:21:41.487","lastModified":"2026-08-15T06:21:41.487","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\njbd2: fix integer underflow in jbd2_journal_initialize_fast_commit()\n\njbd2_journal_initialize_fast_commit() validates journal capacity by\nchecking (journal->j_last - num_fc_blks < JBD2_MIN_JOURNAL_BLOCKS).\nBoth j_last and num_fc_blks are unsigned, so when num_fc_blks exceeds\nj_last the subtraction wraps to a large value, bypassing the bounds\ncheck.\n\nThe resulting underflow corrupts j_last, j_fc_first, and j_free,\nleading to journal abort.\n\nFix by checking num_fc_blks against j_last before the subtraction,\nreturning -EFSCORRUPTED."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["fs/jbd2/journal.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6866d7b3f2bb4f011041ba54c98b1584497fe2fd","lessThan":"e144ad0250f77e23e28949587b8b57e40dc3b512","versionType":"git","status":"affected"},{"version":"6866d7b3f2bb4f011041ba54c98b1584497fe2fd","lessThan":"4b48dcb88bb9117e3d3f051175a9a8b7cff7f8b6","versionType":"git","status":"affected"},{"version":"6866d7b3f2bb4f011041ba54c98b1584497fe2fd","lessThan":"fb9b49618ed7296ebfad62a3835da8945f727001","versionType":"git","status":"affected"},{"version":"6866d7b3f2bb4f011041ba54c98b1584497fe2fd","lessThan":"4450dcaadf7d4aae8b6e4223b5d6ee4eb77097a9","versionType":"git","status":"affected"},{"version":"6866d7b3f2bb4f011041ba54c98b1584497fe2fd","lessThan":"78955fdce8ff654e6d33a2fa90882a1e7eb26330","versionType":"git","status":"affected"},{"version":"6866d7b3f2bb4f011041ba54c98b1584497fe2fd","lessThan":"a58fc10adf503969fec2007b5afe8987258046c4","versionType":"git","status":"affected"},{"version":"6866d7b3f2bb4f011041ba54c98b1584497fe2fd","lessThan":"289a2ca0c9b7eae74f93fc213b0b971669b8683d","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["fs/jbd2/journal.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"5.10","status":"affected"},{"version":"0","lessThan":"5.10","versionType":"semver","status":"unaffected"},{"version":"5.15.212","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.178","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.97","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/289a2ca0c9b7eae74f93fc213b0b971669b8683d","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/4450dcaadf7d4aae8b6e4223b5d6ee4eb77097a9","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/4b48dcb88bb9117e3d3f051175a9a8b7cff7f8b6","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/78955fdce8ff654e6d33a2fa90882a1e7eb26330","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/a58fc10adf503969fec2007b5afe8987258046c4","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/e144ad0250f77e23e28949587b8b57e40dc3b512","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/fb9b49618ed7296ebfad62a3835da8945f727001","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-72226","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:21:49.383","lastModified":"2026-08-15T06:21:49.383","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nbatman-adv: tt: prevent TVLV OOB check overflow\n\nA TT unicast TVLV contains the number of VLANs stored in it. This number is\nan u16 and gets multiplied by the size of the struct\nbatadv_tvlv_tt_vlan_data (8 bytes). The size can therefore overflow the u16\nused to store the tt_vlan_len. All additional safety checks to prevent\nout-of-bounds access of the TVLV buffer are invalid due to this overflow.\n\nUsing size_t prevents this overflow and ensures that the safety checks\ncompare against the actual buffer requirements."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["net/batman-adv/translation-table.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"7ea7b4a142758deaf46c1af0ca9ceca6dd55138b","lessThan":"0de12a4c4847f571d82a9cd96bc633eded41d7c6","versionType":"git","status":"affected"},{"version":"7ea7b4a142758deaf46c1af0ca9ceca6dd55138b","lessThan":"d6ff4764ff784ede25f5c83a6f5883a74c93a5ea","versionType":"git","status":"affected"},{"version":"7ea7b4a142758deaf46c1af0ca9ceca6dd55138b","lessThan":"1898273c5dc8148267ef9f97cd2517a2822350e7","versionType":"git","status":"affected"},{"version":"7ea7b4a142758deaf46c1af0ca9ceca6dd55138b","lessThan":"604bd5042fbcd1ab9f7cd98fd847ec017aeede8a","versionType":"git","status":"affected"},{"version":"7ea7b4a142758deaf46c1af0ca9ceca6dd55138b","lessThan":"7319c0794f91be2734aac695794e7203606b49f8","versionType":"git","status":"affected"},{"version":"7ea7b4a142758deaf46c1af0ca9ceca6dd55138b","lessThan":"3256c05d5a9db34346eaf20f52dddde984852d77","versionType":"git","status":"affected"},{"version":"7ea7b4a142758deaf46c1af0ca9ceca6dd55138b","lessThan":"6222b443686525cb5a9b6a9cecf23b2e2ab23e2a","versionType":"git","status":"affected"},{"version":"7ea7b4a142758deaf46c1af0ca9ceca6dd55138b","lessThan":"7a581d9aaba8c82bd6177fa36b2588eea77f6e2b","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["net/batman-adv/translation-table.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"3.13","status":"affected"},{"version":"0","lessThan":"3.13","versionType":"semver","status":"unaffected"},{"version":"5.10.261","lessThanOrEqual":"5.10.*","versionType":"semver","status":"unaffected"},{"version":"5.15.212","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.178","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.97","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc3","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/0de12a4c4847f571d82a9cd96bc633eded41d7c6","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/1898273c5dc8148267ef9f97cd2517a2822350e7","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/3256c05d5a9db34346eaf20f52dddde984852d77","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/604bd5042fbcd1ab9f7cd98fd847ec017aeede8a","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/6222b443686525cb5a9b6a9cecf23b2e2ab23e2a","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/7319c0794f91be2734aac695794e7203606b49f8","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/7a581d9aaba8c82bd6177fa36b2588eea77f6e2b","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/d6ff4764ff784ede25f5c83a6f5883a74c93a5ea","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-72227","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:21:49.510","lastModified":"2026-08-15T06:21:49.510","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nbatman-adv: mcast: avoid OOB read of num_dests header\n\nBefore the access to struct batadv_tvlv_mcast_tracker's num_dests, it is\nattempted to check whether enough space is actually in the network header.\nBut instead of using offsetofend() to check for the whole size (2) which\nmust be accessible, offsetof() of is called. The latter is always returning\n0. The comparison with the network header length will always return that\nenough data is available - even when only 1 or 0 bytes are accessible.\n\nInstead of using offsetofend(), use the more common check for the whole\nheader."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["net/batman-adv/multicast_forw.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"07afe1ba288c04280622fa002ed385f1ac0b6fe6","lessThan":"80f62893d135f415e7a374dd47b468ec298f7aed","versionType":"git","status":"affected"},{"version":"07afe1ba288c04280622fa002ed385f1ac0b6fe6","lessThan":"d2b657c9653fcebca828a2ead13f444e0da68817","versionType":"git","status":"affected"},{"version":"07afe1ba288c04280622fa002ed385f1ac0b6fe6","lessThan":"7d1a877670bc2e901241073f022ca8d1b2f85f1c","versionType":"git","status":"affected"},{"version":"07afe1ba288c04280622fa002ed385f1ac0b6fe6","lessThan":"38eaed28e250895d56f4b7989bd65479a511c5c3","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["net/batman-adv/multicast_forw.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.8","status":"affected"},{"version":"0","lessThan":"6.8","versionType":"semver","status":"unaffected"},{"version":"6.12.97","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc3","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/38eaed28e250895d56f4b7989bd65479a511c5c3","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/7d1a877670bc2e901241073f022ca8d1b2f85f1c","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/80f62893d135f415e7a374dd47b468ec298f7aed","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/d2b657c9653fcebca828a2ead13f444e0da68817","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-72228","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:21:49.617","lastModified":"2026-08-15T06:21:49.617","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nbatman-adv: frag: fix primary_if leak on failed linearization\n\nIf the skb has a frag_list, it must be linearized before it can be split\nusing skb_split(). But when this step failed, it must not only free the skb\nbut also take care of the reference to the already found primary_if."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["net/batman-adv/fragmentation.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"a6a73781b460c4fe2cf2c40400ac91dfddb353fa","lessThan":"e59b1960f71521ce4eb4397c4e82f5285601ab57","versionType":"git","status":"affected"},{"version":"8f37aad74f46dd5d8b95fac17804b75f77931fa9","lessThan":"c1b28432fd6345e0d2308f39c507ed5750c265d2","versionType":"git","status":"affected"},{"version":"a063f2fba3fa633a599253b62561051ac185fa99","lessThan":"4f3bf293f7662500142234ae6f23725953690bc9","versionType":"git","status":"affected"},{"version":"a063f2fba3fa633a599253b62561051ac185fa99","lessThan":"d2148aeee93197ccf821114489775132f28eebf5","versionType":"git","status":"affected"},{"version":"a063f2fba3fa633a599253b62561051ac185fa99","lessThan":"db3c700826e8126fbdaa83468a9c4ee4ee65319f","versionType":"git","status":"affected"},{"version":"a063f2fba3fa633a599253b62561051ac185fa99","lessThan":"a90f4fff9025371bce5371daa610af957de8dd6a","versionType":"git","status":"affected"},{"version":"a063f2fba3fa633a599253b62561051ac185fa99","lessThan":"777a88256d6f70672116e53400659cc417e1feaa","versionType":"git","status":"affected"},{"version":"a063f2fba3fa633a599253b62561051ac185fa99","lessThan":"353d2c1d5492e53ae34f490a84494124dc3d3531","versionType":"git","status":"affected"},{"version":"5ed837a7e05bcba72bdcd86b12547ea5b796cc01","versionType":"git","status":"affected"},{"version":"5853618b022b8ed287a278540303e1b283d6f247","versionType":"git","status":"affected"},{"version":"3915341a935f3397f65a01580dc3bfc4cdf53d14","versionType":"git","status":"affected"},{"version":"bea410635595f8efbec90c948da04c3613ef87ea","versionType":"git","status":"affected"},{"version":"5.10.117","lessThan":"5.10.261","versionType":"semver","status":"affected"},{"version":"5.15.41","lessThan":"5.15.212","versionType":"semver","status":"affected"},{"version":"4.14.280","lessThan":"4.15","versionType":"semver","status":"affected"},{"version":"4.19.244","lessThan":"4.20","versionType":"semver","status":"affected"},{"version":"5.4.195","lessThan":"5.5","versionType":"semver","status":"affected"},{"version":"5.17.9","lessThan":"5.18","versionType":"semver","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["net/batman-adv/fragmentation.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"5.18","status":"affected"},{"version":"0","lessThan":"5.18","versionType":"semver","status":"unaffected"},{"version":"5.10.261","lessThanOrEqual":"5.10.*","versionType":"semver","status":"unaffected"},{"version":"5.15.212","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.178","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.97","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc3","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/353d2c1d5492e53ae34f490a84494124dc3d3531","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/4f3bf293f7662500142234ae6f23725953690bc9","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/777a88256d6f70672116e53400659cc417e1feaa","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/a90f4fff9025371bce5371daa610af957de8dd6a","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/c1b28432fd6345e0d2308f39c507ed5750c265d2","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/d2148aeee93197ccf821114489775132f28eebf5","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/db3c700826e8126fbdaa83468a9c4ee4ee65319f","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/e59b1960f71521ce4eb4397c4e82f5285601ab57","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-72229","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:21:49.750","lastModified":"2026-08-15T06:21:49.750","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nbatman-adv: clean untagged VLAN on netdev registration failure\n\nWhen an mesh interface is registered, it creates an untagged struct\nbatadv_meshif_vlan on top of it via the NETDEV_REGISTER notifier. But in\nthis process, another receiver of this notification can veto the\nregistration. The netdev registration will be aborted because of this veto.\n\nThe register_netdevice() call will try to clean up the net_device using\nunregister_netdevice_queue() - which only uses the .priv_destructor to\nfree private resources. In this situation, .dellink will not be called.\n\nThe cleanup of the untagged batadv_meshif_vlan must thefore be done in the\ndestructor to avoid a leak of this object."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["net/batman-adv/main.c","net/batman-adv/mesh-interface.c","net/batman-adv/mesh-interface.h"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"5d2c05b213377694a2aa8ce1ed9b23f7c39b0569","lessThan":"86e32dfb6a6fe29898f4a562b7b6e38e480bba4d","versionType":"git","status":"affected"},{"version":"5d2c05b213377694a2aa8ce1ed9b23f7c39b0569","lessThan":"06ae245168268b705a204f93c318b30107d10e92","versionType":"git","status":"affected"},{"version":"5d2c05b213377694a2aa8ce1ed9b23f7c39b0569","lessThan":"dbca15fcbeed5276af440a53aed3901590fa7fc9","versionType":"git","status":"affected"},{"version":"5d2c05b213377694a2aa8ce1ed9b23f7c39b0569","lessThan":"f2423da55976ea249f73029e468aefda4b94acba","versionType":"git","status":"affected"},{"version":"5d2c05b213377694a2aa8ce1ed9b23f7c39b0569","lessThan":"f15ca6250591cfe78408114a54eaa8d58da51bfa","versionType":"git","status":"affected"},{"version":"5d2c05b213377694a2aa8ce1ed9b23f7c39b0569","lessThan":"c945f6007e7851e74706c72f98763023699bcd97","versionType":"git","status":"affected"},{"version":"5d2c05b213377694a2aa8ce1ed9b23f7c39b0569","lessThan":"5a82c558098889cc8bfff85cc62f563833205d91","versionType":"git","status":"affected"},{"version":"5d2c05b213377694a2aa8ce1ed9b23f7c39b0569","lessThan":"8669a550c752d86baebc5fdc83b8ff35c4372c0e","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["net/batman-adv/main.c","net/batman-adv/mesh-interface.c","net/batman-adv/mesh-interface.h"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"3.13","status":"affected"},{"version":"0","lessThan":"3.13","versionType":"semver","status":"unaffected"},{"version":"5.10.261","lessThanOrEqual":"5.10.*","versionType":"semver","status":"unaffected"},{"version":"5.15.212","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.178","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.97","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc3","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/06ae245168268b705a204f93c318b30107d10e92","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/5a82c558098889cc8bfff85cc62f563833205d91","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/8669a550c752d86baebc5fdc83b8ff35c4372c0e","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/86e32dfb6a6fe29898f4a562b7b6e38e480bba4d","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/c945f6007e7851e74706c72f98763023699bcd97","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/dbca15fcbeed5276af440a53aed3901590fa7fc9","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/f15ca6250591cfe78408114a54eaa8d58da51bfa","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/f2423da55976ea249f73029e468aefda4b94acba","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-72230","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:21:49.870","lastModified":"2026-08-15T06:21:49.870","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nbatman-adv: frag: free unfragmentable packet\n\nThe caller of batadv_frag_send_packet() assume that the skb provided to the\nfunction are always consumed. But the pre-check for an empty payload or the\nzero fragment size returned an error without any further actions.\n\nA failed pre-check must use the same error handling code as the rest of the\nfunction."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["net/batman-adv/fragmentation.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"ee75ed88879af88558818a5c6609d85f60ff0df4","lessThan":"a5155aeeae8ead3c6081f7f197608033e4dcfe75","versionType":"git","status":"affected"},{"version":"ee75ed88879af88558818a5c6609d85f60ff0df4","lessThan":"04ccbed8179e7d4d0906d00939300ddc5b48ce7e","versionType":"git","status":"affected"},{"version":"ee75ed88879af88558818a5c6609d85f60ff0df4","lessThan":"601dff01a03ecced59938cdd69eeb2c66e4158f2","versionType":"git","status":"affected"},{"version":"ee75ed88879af88558818a5c6609d85f60ff0df4","lessThan":"740542f11bf8c86411c429fbd7f84fc6bee80e76","versionType":"git","status":"affected"},{"version":"ee75ed88879af88558818a5c6609d85f60ff0df4","lessThan":"59e1da1ab354d1f2b7bab8d44f846262f990ad9d","versionType":"git","status":"affected"},{"version":"ee75ed88879af88558818a5c6609d85f60ff0df4","lessThan":"8f54162e07d3eea1e4ff21464cf2a815d79b6510","versionType":"git","status":"affected"},{"version":"ee75ed88879af88558818a5c6609d85f60ff0df4","lessThan":"08047838817561cef33ada9774a2a4663d499ecb","versionType":"git","status":"affected"},{"version":"ee75ed88879af88558818a5c6609d85f60ff0df4","lessThan":"6b628425aed49a1c7a4ffc997583840fc582d32b","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["net/batman-adv/fragmentation.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"3.13","status":"affected"},{"version":"0","lessThan":"3.13","versionType":"semver","status":"unaffected"},{"version":"5.10.261","lessThanOrEqual":"5.10.*","versionType":"semver","status":"unaffected"},{"version":"5.15.212","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.178","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.97","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc3","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/04ccbed8179e7d4d0906d00939300ddc5b48ce7e","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/08047838817561cef33ada9774a2a4663d499ecb","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/59e1da1ab354d1f2b7bab8d44f846262f990ad9d","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/601dff01a03ecced59938cdd69eeb2c66e4158f2","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/6b628425aed49a1c7a4ffc997583840fc582d32b","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/740542f11bf8c86411c429fbd7f84fc6bee80e76","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/8f54162e07d3eea1e4ff21464cf2a815d79b6510","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/a5155aeeae8ead3c6081f7f197608033e4dcfe75","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-72231","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:21:50.000","lastModified":"2026-08-15T06:21:50.000","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nbatman-adv: tt: avoid request storms during pending request\n\nbatadv_send_tt_request() allocates a tt_req_node when none exists for the\ndestination originator node. This should prevent that a multiple TT\nrequests are send at the same time to an originator.\n\nBut if allocation of the send buffer failed, this request must be cleaned\nup again. But indicator for such a failure is \"ret == false\". But the\nactual implementation is checking for \"ret == true\".\n\nThe check must be inverted to not loose the information about the TT\nrequest directly after it was attempted to be sent out. This should avoid\npotential request storms."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["net/batman-adv/translation-table.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"335fbe0f5d2501b7dd815806aef6fd9bad784eb1","lessThan":"6055695ea40c64a47e00742c12c99b1a33b4daed","versionType":"git","status":"affected"},{"version":"335fbe0f5d2501b7dd815806aef6fd9bad784eb1","lessThan":"21c44a6895f41df811d1c91d10eea194dda2b345","versionType":"git","status":"affected"},{"version":"335fbe0f5d2501b7dd815806aef6fd9bad784eb1","lessThan":"5e46c76d9a5062212c4c5f642a5549fd9c057f8a","versionType":"git","status":"affected"},{"version":"335fbe0f5d2501b7dd815806aef6fd9bad784eb1","lessThan":"067e413eec2e63c2996909ef55214b3a0eda0be7","versionType":"git","status":"affected"},{"version":"335fbe0f5d2501b7dd815806aef6fd9bad784eb1","lessThan":"716f434eb35869e130424331584a91fbb729b9bd","versionType":"git","status":"affected"},{"version":"335fbe0f5d2501b7dd815806aef6fd9bad784eb1","lessThan":"6a65ac8a81e903bb4b555c1d13532f5cb0167a4a","versionType":"git","status":"affected"},{"version":"335fbe0f5d2501b7dd815806aef6fd9bad784eb1","lessThan":"aba1cf21954e64c36afb966b754adad2b0b8aa48","versionType":"git","status":"affected"},{"version":"335fbe0f5d2501b7dd815806aef6fd9bad784eb1","lessThan":"27c7d40008231ae4140d35501b60087a9de2d2c3","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["net/batman-adv/translation-table.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"3.13","status":"affected"},{"version":"0","lessThan":"3.13","versionType":"semver","status":"unaffected"},{"version":"5.10.261","lessThanOrEqual":"5.10.*","versionType":"semver","status":"unaffected"},{"version":"5.15.212","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.178","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.97","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc3","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/067e413eec2e63c2996909ef55214b3a0eda0be7","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/21c44a6895f41df811d1c91d10eea194dda2b345","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/27c7d40008231ae4140d35501b60087a9de2d2c3","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/5e46c76d9a5062212c4c5f642a5549fd9c057f8a","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/6055695ea40c64a47e00742c12c99b1a33b4daed","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/6a65ac8a81e903bb4b555c1d13532f5cb0167a4a","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/716f434eb35869e130424331584a91fbb729b9bd","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/aba1cf21954e64c36afb966b754adad2b0b8aa48","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-72232","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:21:50.137","lastModified":"2026-08-15T06:21:50.137","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nbatman-adv: ensure minimal ethernet header on TX\n\nAs documented in commit 8bd67ebb50c0 (\"net: bridge: xmit: make sure we have\nat least eth header len bytes\"), it is possible by for a local user with\neBPF TC hook access to attach a tc filter which truncates the packet and\nredirects to an batadv interface. But the code assumes that at least\nETH_HLEN bytes are available and thus might read outside of the available\nbuffer.\n\nThe batadv_interface_tx() must therefore always check itself if enough data\nis available for the ethernet header and don't rely on min_header_len."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["net/batman-adv/mesh-interface.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"c6c8fea29769d998d94fcec9b9f14d4b52b349d3","lessThan":"58799078afebd5115e052bf69ad6697f9759dd6f","versionType":"git","status":"affected"},{"version":"c6c8fea29769d998d94fcec9b9f14d4b52b349d3","lessThan":"38cd10b0aeec755d89f78722a2b83f4088ff0cb0","versionType":"git","status":"affected"},{"version":"c6c8fea29769d998d94fcec9b9f14d4b52b349d3","lessThan":"811fea37620f2097955d95ce81cfdba03fd30f1b","versionType":"git","status":"affected"},{"version":"c6c8fea29769d998d94fcec9b9f14d4b52b349d3","lessThan":"e6640923afee619d9fa82b07394dc9498e202304","versionType":"git","status":"affected"},{"version":"c6c8fea29769d998d94fcec9b9f14d4b52b349d3","lessThan":"6b4f521e01257387906f8b969ad3450d8208d4e2","versionType":"git","status":"affected"},{"version":"c6c8fea29769d998d94fcec9b9f14d4b52b349d3","lessThan":"9e16b6751a8206de0b865d99bb02771e6751d12d","versionType":"git","status":"affected"},{"version":"c6c8fea29769d998d94fcec9b9f14d4b52b349d3","lessThan":"dbeb4145d9778f922f459935da9a027750765a69","versionType":"git","status":"affected"},{"version":"c6c8fea29769d998d94fcec9b9f14d4b52b349d3","lessThan":"49df66b7993c80b80c7eb9a84ba5b3410c8296a0","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["net/batman-adv/mesh-interface.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"2.6.38","status":"affected"},{"version":"0","lessThan":"2.6.38","versionType":"semver","status":"unaffected"},{"version":"5.10.261","lessThanOrEqual":"5.10.*","versionType":"semver","status":"unaffected"},{"version":"5.15.212","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.178","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.97","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc3","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/38cd10b0aeec755d89f78722a2b83f4088ff0cb0","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/49df66b7993c80b80c7eb9a84ba5b3410c8296a0","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/58799078afebd5115e052bf69ad6697f9759dd6f","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/6b4f521e01257387906f8b969ad3450d8208d4e2","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/811fea37620f2097955d95ce81cfdba03fd30f1b","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/9e16b6751a8206de0b865d99bb02771e6751d12d","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/dbeb4145d9778f922f459935da9a027750765a69","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/e6640923afee619d9fa82b07394dc9498e202304","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-72233","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:21:50.253","lastModified":"2026-08-15T06:21:50.253","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nbatman-adv: bla: reacquire gw address after skb realloc\n\nThe pskb_may_pull() called by batadv_bla_is_backbone_gw() could reallocate\nthe buffer behind the skb. Variables which were pointing to the old buffer\nneed to be reassigned to avoid an use-after-free."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["net/batman-adv/routing.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"9e794b6bf4a2c65d698d7433ddfabc54a5d53a88","lessThan":"41819c5467b6eb8ab4567f0ac98702ce9b6abbb1","versionType":"git","status":"affected"},{"version":"9e794b6bf4a2c65d698d7433ddfabc54a5d53a88","lessThan":"a9ab19fbca86b32e9a9ae9e1a63e70a7eab3400f","versionType":"git","status":"affected"},{"version":"9e794b6bf4a2c65d698d7433ddfabc54a5d53a88","lessThan":"4a6673c55752a7aa41e28f51660eb981504ca088","versionType":"git","status":"affected"},{"version":"9e794b6bf4a2c65d698d7433ddfabc54a5d53a88","lessThan":"ab2bac47a02637df1128a151e81d3ec14767f4bb","versionType":"git","status":"affected"},{"version":"9e794b6bf4a2c65d698d7433ddfabc54a5d53a88","lessThan":"dc16bbf53cede1baf564bf0c8a861114b64e18b3","versionType":"git","status":"affected"},{"version":"9e794b6bf4a2c65d698d7433ddfabc54a5d53a88","lessThan":"e5e18886aadd3870e2d84e32a9678317fab1dd9e","versionType":"git","status":"affected"},{"version":"9e794b6bf4a2c65d698d7433ddfabc54a5d53a88","lessThan":"f4fb97ecf677cd9c3aa4f3bfc6fbf5b0e4bdbbbf","versionType":"git","status":"affected"},{"version":"9e794b6bf4a2c65d698d7433ddfabc54a5d53a88","lessThan":"cdf3b5af2bc4431e58629e8ad2086b1e9185c761","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["net/batman-adv/routing.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"4.12","status":"affected"},{"version":"0","lessThan":"4.12","versionType":"semver","status":"unaffected"},{"version":"5.10.261","lessThanOrEqual":"5.10.*","versionType":"semver","status":"unaffected"},{"version":"5.15.212","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.178","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.97","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc2","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/41819c5467b6eb8ab4567f0ac98702ce9b6abbb1","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/4a6673c55752a7aa41e28f51660eb981504ca088","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/a9ab19fbca86b32e9a9ae9e1a63e70a7eab3400f","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/ab2bac47a02637df1128a151e81d3ec14767f4bb","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/cdf3b5af2bc4431e58629e8ad2086b1e9185c761","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/dc16bbf53cede1baf564bf0c8a861114b64e18b3","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/e5e18886aadd3870e2d84e32a9678317fab1dd9e","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/f4fb97ecf677cd9c3aa4f3bfc6fbf5b0e4bdbbbf","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-72234","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:21:50.390","lastModified":"2026-08-15T06:21:50.390","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nbatman-adv: access unicast_ttvn skb->data only after skb realloc\n\nThe pskb_may_pull() called by batadv_get_vid() could reallocate the buffer\nbehind the skb. Variables which were pointing to the old buffer need to be\nreassigned to avoid an use-after-free.\n\nThis was done correctly for the ethernet header but missed for the\nunicast_packet pointer."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["net/batman-adv/routing.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"c018ad3de61a1dc4194879a53e5559e094aa7b1a","lessThan":"aa9558af859934f24717d4bab97d61004f91a736","versionType":"git","status":"affected"},{"version":"c018ad3de61a1dc4194879a53e5559e094aa7b1a","lessThan":"9c2c05629e46c1fd43931506d41c56a885a98eb4","versionType":"git","status":"affected"},{"version":"c018ad3de61a1dc4194879a53e5559e094aa7b1a","lessThan":"7b162b36de750565404cd3b98315706622c6974f","versionType":"git","status":"affected"},{"version":"c018ad3de61a1dc4194879a53e5559e094aa7b1a","lessThan":"ed90eb5c68420cdfe67ec1f773324198d2ef6f50","versionType":"git","status":"affected"},{"version":"c018ad3de61a1dc4194879a53e5559e094aa7b1a","lessThan":"979175834a699ccc3c4c0b0ba60ecae0f135a587","versionType":"git","status":"affected"},{"version":"c018ad3de61a1dc4194879a53e5559e094aa7b1a","lessThan":"b8afcf799b2cc92c41beebd029e53ed18960184a","versionType":"git","status":"affected"},{"version":"c018ad3de61a1dc4194879a53e5559e094aa7b1a","lessThan":"9a7b7248798123efbd5fafe58461d57c7cc718af","versionType":"git","status":"affected"},{"version":"c018ad3de61a1dc4194879a53e5559e094aa7b1a","lessThan":"7141990add3f75436f2933cb310654cad3b1e3e9","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["net/batman-adv/routing.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"3.13","status":"affected"},{"version":"0","lessThan":"3.13","versionType":"semver","status":"unaffected"},{"version":"5.10.261","lessThanOrEqual":"5.10.*","versionType":"semver","status":"unaffected"},{"version":"5.15.212","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.178","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.97","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc2","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/7141990add3f75436f2933cb310654cad3b1e3e9","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/7b162b36de750565404cd3b98315706622c6974f","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/979175834a699ccc3c4c0b0ba60ecae0f135a587","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/9a7b7248798123efbd5fafe58461d57c7cc718af","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/9c2c05629e46c1fd43931506d41c56a885a98eb4","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/aa9558af859934f24717d4bab97d61004f91a736","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/b8afcf799b2cc92c41beebd029e53ed18960184a","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/ed90eb5c68420cdfe67ec1f773324198d2ef6f50","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-72235","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:21:50.510","lastModified":"2026-08-15T06:21:50.510","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nbatman-adv: retrieve ethhdr after potential skb realloc on RX\n\npskb_may_pull() in batadv_interface_rx() could reallocate the buffer behind\nthe skb. Variables which were pointing to the old buffer need to be\nreassigned to avoid an use-after-free.\n\nThis was done correctly for the VLAN header but missed for the ethernet\nheader which is later used for the TT and AP isolation handling."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["net/batman-adv/mesh-interface.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"c6c8fea29769d998d94fcec9b9f14d4b52b349d3","lessThan":"6e189f14d1ea28db212b9d70a02131a7ce518012","versionType":"git","status":"affected"},{"version":"c6c8fea29769d998d94fcec9b9f14d4b52b349d3","lessThan":"a1820344b180cb55af748f102bc536b5c93164db","versionType":"git","status":"affected"},{"version":"c6c8fea29769d998d94fcec9b9f14d4b52b349d3","lessThan":"6abf73589bed3f27ee240c08108feb72bed0b9c6","versionType":"git","status":"affected"},{"version":"c6c8fea29769d998d94fcec9b9f14d4b52b349d3","lessThan":"f19259395b44af67f3c274e34237c295b526b859","versionType":"git","status":"affected"},{"version":"c6c8fea29769d998d94fcec9b9f14d4b52b349d3","lessThan":"2cefa5141cab8ec1e4b24cf585958b13f2e3049d","versionType":"git","status":"affected"},{"version":"c6c8fea29769d998d94fcec9b9f14d4b52b349d3","lessThan":"85a71a81854e0e191ad0e533eabb4eff54866feb","versionType":"git","status":"affected"},{"version":"c6c8fea29769d998d94fcec9b9f14d4b52b349d3","lessThan":"b031fc97e1993d29d6c3a0e86a99140528cf31e8","versionType":"git","status":"affected"},{"version":"c6c8fea29769d998d94fcec9b9f14d4b52b349d3","lessThan":"035e1fed892d3d06002a73ff73668f618a514644","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["net/batman-adv/mesh-interface.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"2.6.38","status":"affected"},{"version":"0","lessThan":"2.6.38","versionType":"semver","status":"unaffected"},{"version":"5.10.261","lessThanOrEqual":"5.10.*","versionType":"semver","status":"unaffected"},{"version":"5.15.212","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.178","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.97","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc2","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/035e1fed892d3d06002a73ff73668f618a514644","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/2cefa5141cab8ec1e4b24cf585958b13f2e3049d","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/6abf73589bed3f27ee240c08108feb72bed0b9c6","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/6e189f14d1ea28db212b9d70a02131a7ce518012","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/85a71a81854e0e191ad0e533eabb4eff54866feb","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/a1820344b180cb55af748f102bc536b5c93164db","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/b031fc97e1993d29d6c3a0e86a99140528cf31e8","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/f19259395b44af67f3c274e34237c295b526b859","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-72236","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:21:50.633","lastModified":"2026-08-15T06:21:50.633","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\ns390/perf_cpum_cf: Add missing array_index_nospec() to __hw_perf_event_init()\n\nev variable is userspace controlled via event->attr.config and used\nas an array index after bounds checking, but without speculation\nbarriers.\n\nAdd the missing array_index_nospec() call to prevent speculative\nexecution."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["arch/s390/kernel/perf_cpum_cf.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"212188a596d17d519842ef2173150315735b54e1","lessThan":"27206bb57c47bdbe33bccc78fa7f7e2a719a06b9","versionType":"git","status":"affected"},{"version":"212188a596d17d519842ef2173150315735b54e1","lessThan":"a21f3615c88421df81060b6ff89220fd34094c4d","versionType":"git","status":"affected"},{"version":"212188a596d17d519842ef2173150315735b54e1","lessThan":"fa1ebae4206e6afc8caa642e9eb1bbe39a9a724f","versionType":"git","status":"affected"},{"version":"212188a596d17d519842ef2173150315735b54e1","lessThan":"f79dff8c721bbb1f3fc312ea55e0551c2cc28801","versionType":"git","status":"affected"},{"version":"212188a596d17d519842ef2173150315735b54e1","lessThan":"49145bce539117db4b6e9e83c0e5ef528e361050","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["arch/s390/kernel/perf_cpum_cf.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"3.4","status":"affected"},{"version":"0","lessThan":"3.4","versionType":"semver","status":"unaffected"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.97","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc4","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/27206bb57c47bdbe33bccc78fa7f7e2a719a06b9","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/49145bce539117db4b6e9e83c0e5ef528e361050","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/a21f3615c88421df81060b6ff89220fd34094c4d","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/f79dff8c721bbb1f3fc312ea55e0551c2cc28801","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/fa1ebae4206e6afc8caa642e9eb1bbe39a9a724f","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-72237","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:21:50.733","lastModified":"2026-08-15T06:21:50.733","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nperf/x86/amd/brs: Fix kernel address leakage\n\nA user-only branch stack can contain branches that originate from\nthe kernel. As a result, kernel addresses are exposed to user space\neven when PERF_SAMPLE_BRANCH_USER is requested. On AMD processors\nsupporting X86_FEATURE_BRS (Zen 3 only), perf can still report entries\nsuch as SYSRET/interrupt returns for which the branch-from addresses\nare in the kernel.\n\nE.g.\n\n  $ perf record -j any,u -c 4000 -e branch-brs -o - -- \\\n        perf bench syscall basic --loop 1000 | \\\n        perf script -i - -F brstack|tr ' ' '\\n'| \\\n        grep -E '0x[89a-f][0-9a-f]{15}'\n\n  ...\n  0xffffffff810001c4/0x72e2e32955eb/-/-/-/0//-\n  0xffffffff810001c4/0x72e2d94a9821/-/-/-/0//-\n  0xffffffff810001c4/0x72e2d94ffa1b/-/-/-/0//-\n  ...\n\nBRS provides no hardware branch filtering, so privilege level\nfiltering is performed entirely in software. However, amd_brs_match_plm()\nonly validates the branch-to address against the requested privilege\nlevels. For branches from the kernel to user space, the branch-from\naddress is left unchecked and is leaked. Extend the software filter to\nalso validate the branch-from address, so that any branch record whose\nbranch-from address is in the kernel is dropped when\nPERF_SAMPLE_BRANCH_USER is requested."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["arch/x86/events/amd/brs.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"8910075d61a37e5b0d82e6c83ed9a0a31fe9ea08","lessThan":"ac44b4a3d6137489f8fa2e794b12e849c6b22eaa","versionType":"git","status":"affected"},{"version":"8910075d61a37e5b0d82e6c83ed9a0a31fe9ea08","lessThan":"90843d00dbc61220b66408ea0d8775cae9e51f70","versionType":"git","status":"affected"},{"version":"8910075d61a37e5b0d82e6c83ed9a0a31fe9ea08","lessThan":"046f6244da9b68e463a849b21446b9424e531491","versionType":"git","status":"affected"},{"version":"8910075d61a37e5b0d82e6c83ed9a0a31fe9ea08","lessThan":"2e706be56f418718bb3ae66c0aa94f9b61150e6d","versionType":"git","status":"affected"},{"version":"8910075d61a37e5b0d82e6c83ed9a0a31fe9ea08","lessThan":"47915e855fb38b42133e31ba917d99565f862154","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["arch/x86/events/amd/brs.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"5.19","status":"affected"},{"version":"0","lessThan":"5.19","versionType":"semver","status":"unaffected"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.97","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc3","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/046f6244da9b68e463a849b21446b9424e531491","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/2e706be56f418718bb3ae66c0aa94f9b61150e6d","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/47915e855fb38b42133e31ba917d99565f862154","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/90843d00dbc61220b66408ea0d8775cae9e51f70","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/ac44b4a3d6137489f8fa2e794b12e849c6b22eaa","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-72238","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:21:50.850","lastModified":"2026-08-15T06:21:50.850","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nx86/boot: Validate console=uart8250 baud rate to fix early boot hang\n\nWhen the baud rate is empty, 0, invalid, or overflows to 0 when stored\nas an int, the system will hang during early boot because of a division\nby zero in early_serial_init().\n\nFall back to DEFAULT_BAUD when the resulting baud rate is 0 to prevent\nan early system hang."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["arch/x86/boot/early_serial_console.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"ce0aa5dd20e44372f9617dd67c984f41fcdbed88","lessThan":"c1a276a731d02cbb728d0530f327a68728f2d8b0","versionType":"git","status":"affected"},{"version":"ce0aa5dd20e44372f9617dd67c984f41fcdbed88","lessThan":"24fbed0a2a45f5f379ef2b53bd2abe58be1142ad","versionType":"git","status":"affected"},{"version":"ce0aa5dd20e44372f9617dd67c984f41fcdbed88","lessThan":"efa96a22613b86e05cd81229ce0be411c1a4a79a","versionType":"git","status":"affected"},{"version":"ce0aa5dd20e44372f9617dd67c984f41fcdbed88","lessThan":"9a77a7639dfdc3eca417cd37620ce64da79c80c4","versionType":"git","status":"affected"},{"version":"ce0aa5dd20e44372f9617dd67c984f41fcdbed88","lessThan":"b4d05032e9af7137eab8f3af2855073f896ca843","versionType":"git","status":"affected"},{"version":"ce0aa5dd20e44372f9617dd67c984f41fcdbed88","lessThan":"f7c67c97b37c11f2a95c204092fb8159f2779e8f","versionType":"git","status":"affected"},{"version":"ce0aa5dd20e44372f9617dd67c984f41fcdbed88","lessThan":"4dad7e870c7e5178f71b5e1e4f67934b9e8cc207","versionType":"git","status":"affected"},{"version":"ce0aa5dd20e44372f9617dd67c984f41fcdbed88","lessThan":"ffa0aa5b625fe0bed7463ac613f8b06676ff4542","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["arch/x86/boot/early_serial_console.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"2.6.36","status":"affected"},{"version":"0","lessThan":"2.6.36","versionType":"semver","status":"unaffected"},{"version":"5.10.261","lessThanOrEqual":"5.10.*","versionType":"semver","status":"unaffected"},{"version":"5.15.212","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.178","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.97","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc4","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/24fbed0a2a45f5f379ef2b53bd2abe58be1142ad","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/4dad7e870c7e5178f71b5e1e4f67934b9e8cc207","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/9a77a7639dfdc3eca417cd37620ce64da79c80c4","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/b4d05032e9af7137eab8f3af2855073f896ca843","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/c1a276a731d02cbb728d0530f327a68728f2d8b0","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/efa96a22613b86e05cd81229ce0be411c1a4a79a","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/f7c67c97b37c11f2a95c204092fb8159f2779e8f","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/ffa0aa5b625fe0bed7463ac613f8b06676ff4542","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-72239","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:21:50.970","lastModified":"2026-08-15T06:21:50.970","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nx86/virt/sev: Revert \"Drop WBINVD before setting MSR_AMD64_SYSCFG_SNP_EN\"\n\nRevert\n\n  99cf1fb58e68 (\"x86/virt/sev: Drop WBINVD before setting MSR_AMD64_SYSCFG_SNP_EN\").\n\nSection 8.8 of the SNP spec says:\n\n  Before invoking SNP_INIT_EX with INIT_RMP set to 1, software must ensure\n  that no CPUs contain dirty cache lines for the memory containing the RMP.\n\nCachelines can be moved from cache to cache in a dirty state. The\nwbinvd_on_all_cpus() before SNP_INIT_EX flushes the caches for each CPU, but\nif the IPIs for WBINVD race with this dirty cacheline movement, it is possible\nthat they may not get flushed, violating the firmware requirement.\n\nDoing wbinvd_on_all_cpus() before setting SNPEn is safer since the RMP\ntable is not yet in use.\n\n  [ Heroically bisected by Srikanth. ]\n  [ bp: Massage commit message. ]"}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["arch/x86/virt/svm/sev.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"99cf1fb58e68291d408b4c4484181cf88f081857","lessThan":"e5158ff53fdff9c229bf13aa5f75eb17cdcfcd2d","versionType":"git","status":"affected"},{"version":"99cf1fb58e68291d408b4c4484181cf88f081857","lessThan":"4c2509f3b79756679a02bea649c6a7501b58f52c","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["arch/x86/virt/svm/sev.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"7.1","status":"affected"},{"version":"0","lessThan":"7.1","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc3","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/4c2509f3b79756679a02bea649c6a7501b58f52c","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/e5158ff53fdff9c229bf13aa5f75eb17cdcfcd2d","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-72240","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:21:51.063","lastModified":"2026-08-15T06:21:51.063","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nmfd: sm501: Fix reference leak on failed device registration\n\nWhen platform_device_register() fails in sm501_register_device(), the\nembedded struct device in pdev has already been initialized by\ndevice_initialize(), but the failure path only reports the error and\nreturns without dropping the device reference for the current platform\ndevice:\n\n  sm501_register_device()\n    -> platform_device_register(pdev)\n       -> device_initialize(&pdev->dev)\n       -> setup_pdev_dma_masks(pdev)\n       -> platform_device_add(pdev)\n\nThis leads to a reference leak when platform_device_register() fails.\nFix this by calling platform_device_put() before returning the error.\n\nThe issue was identified by a static analysis tool I developed and\nconfirmed by manual review."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/mfd/sm501.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"b6d6454fdb66f3829af8b92ab06825b6060fdf7e","lessThan":"bbb1ecaed4ed7680e63d3a0f143f03de32de5d6e","versionType":"git","status":"affected"},{"version":"b6d6454fdb66f3829af8b92ab06825b6060fdf7e","lessThan":"e2dac91380a10e9e8d5883fb73ce9d9b390a629c","versionType":"git","status":"affected"},{"version":"b6d6454fdb66f3829af8b92ab06825b6060fdf7e","lessThan":"0baf9d43a7b7b43df2900bd8656e75b725028b6e","versionType":"git","status":"affected"},{"version":"b6d6454fdb66f3829af8b92ab06825b6060fdf7e","lessThan":"a3e340d506c1036a747fb0972aebf1063f7ef30e","versionType":"git","status":"affected"},{"version":"b6d6454fdb66f3829af8b92ab06825b6060fdf7e","lessThan":"760a1029692f1d788dc11aa636a3bf432e58b240","versionType":"git","status":"affected"},{"version":"b6d6454fdb66f3829af8b92ab06825b6060fdf7e","lessThan":"16a42c88c4667fa0bd944e438a667e059551f1f1","versionType":"git","status":"affected"},{"version":"b6d6454fdb66f3829af8b92ab06825b6060fdf7e","lessThan":"2ff8156fd500d54c61430b6834137fd0a07047ce","versionType":"git","status":"affected"},{"version":"b6d6454fdb66f3829af8b92ab06825b6060fdf7e","lessThan":"8c2f0b42fc252e1bf1c7746447091a468e784ca1","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/mfd/sm501.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"2.6.21","status":"affected"},{"version":"0","lessThan":"2.6.21","versionType":"semver","status":"unaffected"},{"version":"5.10.261","lessThanOrEqual":"5.10.*","versionType":"semver","status":"unaffected"},{"version":"5.15.212","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.178","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.97","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/0baf9d43a7b7b43df2900bd8656e75b725028b6e","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/16a42c88c4667fa0bd944e438a667e059551f1f1","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/2ff8156fd500d54c61430b6834137fd0a07047ce","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/760a1029692f1d788dc11aa636a3bf432e58b240","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/8c2f0b42fc252e1bf1c7746447091a468e784ca1","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/a3e340d506c1036a747fb0972aebf1063f7ef30e","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/bbb1ecaed4ed7680e63d3a0f143f03de32de5d6e","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/e2dac91380a10e9e8d5883fb73ce9d9b390a629c","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-72241","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:21:51.183","lastModified":"2026-08-15T06:21:51.183","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nleds: uleds: Fix potential buffer overread\n\nThe name string supplied by userspace is not guaranteed to be\nnull-terminated, so using strchr() on it might result in a buffer\noverread. The same thing will happen when said string is used by\nthe LED class device.\n\nFix this by using strnchr() instead and explicitly check that\nthe name string is properly null-terminated."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/leds/uleds.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"e381322b0190c1253d347de3f28b5c37756fb651","lessThan":"a84c59121dfdc7b324f72dc5012aa8fe5e7d2d7b","versionType":"git","status":"affected"},{"version":"e381322b0190c1253d347de3f28b5c37756fb651","lessThan":"5bb89e23729f3a59592d699a437bb001f24b8f67","versionType":"git","status":"affected"},{"version":"e381322b0190c1253d347de3f28b5c37756fb651","lessThan":"5ad6f6c9209e5777b896def9876708853ae26d0d","versionType":"git","status":"affected"},{"version":"e381322b0190c1253d347de3f28b5c37756fb651","lessThan":"8bf529571cca60fb8af65d6d034bdbbc99a9127c","versionType":"git","status":"affected"},{"version":"e381322b0190c1253d347de3f28b5c37756fb651","lessThan":"a91ac9fdac7385cbc98aeae55b4e5302125497a2","versionType":"git","status":"affected"},{"version":"e381322b0190c1253d347de3f28b5c37756fb651","lessThan":"6dd51d84a9502553e58beade72823258871b8111","versionType":"git","status":"affected"},{"version":"e381322b0190c1253d347de3f28b5c37756fb651","lessThan":"263ccdd627caeda6e980ed3c6e32bb4fd6b380b1","versionType":"git","status":"affected"},{"version":"e381322b0190c1253d347de3f28b5c37756fb651","lessThan":"c19fe864f667afc49d1391d764e20b66555bcf7a","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/leds/uleds.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"4.10","status":"affected"},{"version":"0","lessThan":"4.10","versionType":"semver","status":"unaffected"},{"version":"5.10.261","lessThanOrEqual":"5.10.*","versionType":"semver","status":"unaffected"},{"version":"5.15.212","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.178","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.97","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/263ccdd627caeda6e980ed3c6e32bb4fd6b380b1","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/5ad6f6c9209e5777b896def9876708853ae26d0d","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/5bb89e23729f3a59592d699a437bb001f24b8f67","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/6dd51d84a9502553e58beade72823258871b8111","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/8bf529571cca60fb8af65d6d034bdbbc99a9127c","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/a84c59121dfdc7b324f72dc5012aa8fe5e7d2d7b","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/a91ac9fdac7385cbc98aeae55b4e5302125497a2","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/c19fe864f667afc49d1391d764e20b66555bcf7a","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-72242","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:21:51.317","lastModified":"2026-08-15T06:21:51.317","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nselinux: avoid sk_socket dereference in selinux_sctp_bind_connect()\n\nselinux_sctp_bind_connect() dereferences sk->sk_socket to pass a\nstruct socket * to selinux_socket_bind() and\nselinux_socket_connect_helper().  However, when the hook is invoked\nfrom the ASCONF softirq path (sctp_process_asconf), there is no file\nreference guaranteeing that sk->sk_socket is non-NULL.  The setsockopt\ncallers (bindx, connectx, set_primary, sendmsg connect) hold a file\nreference and are not affected.\n\nBoth selinux_socket_bind() and selinux_socket_connect_helper()\nimmediately resolve sock->sk, never using the struct socket * for\nanything else.  Refactor the inner logic into helpers that take a\nstruct sock * directly so that selinux_sctp_bind_connect() never needs\nto touch sk->sk_socket at all."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["security/selinux/hooks.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"d452930fd3b9031e59abfeddb2fa383f1403d61a","lessThan":"5d4d93f9bfbc997ffbb03cd6107e8f6979dbb9b4","versionType":"git","status":"affected"},{"version":"d452930fd3b9031e59abfeddb2fa383f1403d61a","lessThan":"cc8bd47b35eca82393cbad08b1cc86f02e034439","versionType":"git","status":"affected"},{"version":"d452930fd3b9031e59abfeddb2fa383f1403d61a","lessThan":"d61a80b17254be7230bc5544f8e62ddf21ab38e2","versionType":"git","status":"affected"},{"version":"d452930fd3b9031e59abfeddb2fa383f1403d61a","lessThan":"37d642b37ccdc31e1947c2ebc8dc38f03d4a0ceb","versionType":"git","status":"affected"},{"version":"d452930fd3b9031e59abfeddb2fa383f1403d61a","lessThan":"56acfeb10019e200ab6787d01f8d7cbe0f01526f","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["security/selinux/hooks.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"4.17","status":"affected"},{"version":"0","lessThan":"4.17","versionType":"semver","status":"unaffected"},{"version":"6.6.148","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.97","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc3","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/37d642b37ccdc31e1947c2ebc8dc38f03d4a0ceb","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/56acfeb10019e200ab6787d01f8d7cbe0f01526f","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/5d4d93f9bfbc997ffbb03cd6107e8f6979dbb9b4","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/cc8bd47b35eca82393cbad08b1cc86f02e034439","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/d61a80b17254be7230bc5544f8e62ddf21ab38e2","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-72243","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:21:51.443","lastModified":"2026-08-15T06:21:51.443","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nselinux: check connect-related permissions on TCP Fast Open\n\nSimilar to Landlock, SELinux was not updated when TCP Fast Open\nsupport was introduced to ensure connect-related permissions are\nchecked when using TCP Fast Open. Update its socket_sendmsg() hook to\ncall selinux_socket_connect() when MSG_FASTOPEN is passed."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["security/selinux/hooks.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"11406d0d7e11b4e525bb2ace2c70107031d058da","versionType":"git","status":"affected"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"e507633bf76bccf1a6af27771fb0d6e2862b7eac","versionType":"git","status":"affected"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"d028bc080a0dcd6a7f8e1ae1bd32dda696505ba3","versionType":"git","status":"affected"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"fc633a598206d4f23af782db7c0b5f3a82751d2c","versionType":"git","status":"affected"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"646ebbc5f2ff9147d084e1213143f091026a611c","versionType":"git","status":"affected"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"44c74d27d1b9aaa99fa8a83640c1223575262b80","versionType":"git","status":"affected"},{"version":"0","lessThan":"6.1.178","versionType":"semver","status":"affected"},{"version":"0","lessThan":"6.6.145","versionType":"semver","status":"affected"},{"version":"0","lessThan":"6.12.97","versionType":"semver","status":"affected"},{"version":"0","lessThan":"6.18.40","versionType":"semver","status":"affected"},{"version":"0","lessThan":"7.1.5","versionType":"semver","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["security/selinux/hooks.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.1.178","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.97","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc3","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/11406d0d7e11b4e525bb2ace2c70107031d058da","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/44c74d27d1b9aaa99fa8a83640c1223575262b80","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/646ebbc5f2ff9147d084e1213143f091026a611c","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/d028bc080a0dcd6a7f8e1ae1bd32dda696505ba3","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/e507633bf76bccf1a6af27771fb0d6e2862b7eac","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/fc633a598206d4f23af782db7c0b5f3a82751d2c","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-72244","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:21:51.557","lastModified":"2026-08-15T06:21:51.557","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\ngpu/buddy: bail out of try_harder when alignment cannot be honoured\n\nThe try_harder contiguous fallback could return a range whose start\noffset did not match the caller's min_block_size. When a candidate's\nstart is misaligned, realign it: free the misaligned run and reallocate\nexactly @size at the next lower min_block_size boundary. This keeps the\nreturned size unchanged with no surplus to trim, and rejects the request\nonly when no aligned candidate fits.\n\nv2: align misaligned candidates down to min_block_size instead of\n    bailing out, for both the RHS and LHS paths (Matthew)."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/gpu/buddy.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"0a1844bf0b532d84324453374ad6845f64066c28","lessThan":"4289531106ee175a6eb45db7d4f2734d1dae9887","versionType":"git","status":"affected"},{"version":"0a1844bf0b532d84324453374ad6845f64066c28","lessThan":"7185c5262435b93e5eeffa647008992256b9c51a","versionType":"git","status":"affected"},{"version":"0a1844bf0b532d84324453374ad6845f64066c28","lessThan":"419d7d9306491f3e0e417cf794844c73cabee090","versionType":"git","status":"affected"},{"version":"0a1844bf0b532d84324453374ad6845f64066c28","lessThan":"56bc6384314fb9ae98975fb2af8b143097ede3dc","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/gpu/buddy.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.7","status":"affected"},{"version":"0","lessThan":"6.7","versionType":"semver","status":"unaffected"},{"version":"6.12.101","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.42","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc3","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/419d7d9306491f3e0e417cf794844c73cabee090","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/4289531106ee175a6eb45db7d4f2734d1dae9887","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/56bc6384314fb9ae98975fb2af8b143097ede3dc","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/7185c5262435b93e5eeffa647008992256b9c51a","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-72245","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:21:51.657","lastModified":"2026-08-15T06:21:51.657","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\ngpu: host1x: Fix device reference leak in host1x_device_parse_dt() error path\n\nAfter device_initialize(), the embedded struct device in struct\nhost1x_device should be released through the device core with\nput_device().\n\nIn host1x_device_add(), if host1x_device_parse_dt() fails, the current\nerror path frees the object directly with kfree(device). That bypasses\nthe normal device lifetime handling and leaks the reference held on the\nembedded struct device.\n\nThe issue was identified by a static analysis tool I developed and\nconfirmed by manual review.\n\nFix this by using put_device() in the host1x_device_parse_dt() failure\npath."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/gpu/host1x/bus.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"f4c5cf88fbd50e4779042268947b2e2f90c20484","lessThan":"a408d89e20d38d78f540e1951dc4c6056ad662e1","versionType":"git","status":"affected"},{"version":"f4c5cf88fbd50e4779042268947b2e2f90c20484","lessThan":"4ee41361c637eafa80f5d88b46d0016e6cdb24db","versionType":"git","status":"affected"},{"version":"f4c5cf88fbd50e4779042268947b2e2f90c20484","lessThan":"3642d0a45214e3b4cf61bf5e75b04b490d0b3519","versionType":"git","status":"affected"},{"version":"f4c5cf88fbd50e4779042268947b2e2f90c20484","lessThan":"edc7267b59a465c6ae7c5ffac2171c30962bd325","versionType":"git","status":"affected"},{"version":"f4c5cf88fbd50e4779042268947b2e2f90c20484","lessThan":"4454caa204a2edb19c62754ddb96e5dbca0d2f49","versionType":"git","status":"affected"},{"version":"f4c5cf88fbd50e4779042268947b2e2f90c20484","lessThan":"c4d6442ac3ed00041fe4e1df715717ed78a7d37f","versionType":"git","status":"affected"},{"version":"f4c5cf88fbd50e4779042268947b2e2f90c20484","lessThan":"8559b1501f77a5b5d003790bec170ca449e0c674","versionType":"git","status":"affected"},{"version":"f4c5cf88fbd50e4779042268947b2e2f90c20484","lessThan":"e75717f9aec04355777be41070890c6a815c76df","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/gpu/host1x/bus.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"4.0","status":"affected"},{"version":"0","lessThan":"4.0","versionType":"semver","status":"unaffected"},{"version":"5.10.261","lessThanOrEqual":"5.10.*","versionType":"semver","status":"unaffected"},{"version":"5.15.212","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.178","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.97","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/3642d0a45214e3b4cf61bf5e75b04b490d0b3519","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/4454caa204a2edb19c62754ddb96e5dbca0d2f49","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/4ee41361c637eafa80f5d88b46d0016e6cdb24db","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/8559b1501f77a5b5d003790bec170ca449e0c674","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/a408d89e20d38d78f540e1951dc4c6056ad662e1","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/c4d6442ac3ed00041fe4e1df715717ed78a7d37f","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/e75717f9aec04355777be41070890c6a815c76df","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/edc7267b59a465c6ae7c5ffac2171c30962bd325","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-72246","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:21:51.783","lastModified":"2026-08-15T06:21:51.783","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nnetfilter: flowtable: use correct direction to set up tunnel route\n\nThe layer 2 encapsulation and layer 3 tunnel information in the xmit\npath is taken from the other tuple, because the tunnel information that\nis included in the tuple for hashtable lookups is also used to perform\nthe egress encapsulation in the transmit path.\n\nThis patch uses the correct direction when setting up the tunnel, the\noriginal proposed patch to address this fix uses the reversed direction.\n\nWhile at it, remove the redundant check to call dst_release() to drop\nthe reference on the dst that was obtained from the forward path, which\nis not useful in the direct xmit path unless tunneling is performed."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["net/netfilter/nf_flow_table_core.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"0880c4ed122d0cddc9f29a2b28f055d1f24f0fca","lessThan":"392d033fd372268015bc5a54ba7c593ba44940d1","versionType":"git","status":"affected"},{"version":"fa7395c02d95e51bad2952325d2d6503bfbad437","lessThan":"90941d9c925d66a482c9121919ec3546a6988c16","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["net/netfilter/nf_flow_table_core.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"7.2-rc3","status":"affected"},{"version":"0","lessThan":"7.2-rc3","versionType":"semver","status":"unaffected"},{"version":"7.2-rc4","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/392d033fd372268015bc5a54ba7c593ba44940d1","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/90941d9c925d66a482c9121919ec3546a6988c16","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-72247","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:21:51.887","lastModified":"2026-08-15T06:21:51.887","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nnetfilter: nf_conncount: fix zone comparison in tuple dedup\n\nThe \"already exists\" dedup logic in __nf_conncount_add() decides\nwhether a connection has already been counted and can be skipped instead\nof incrementing the connlimit count.  It compares the conntrack zone of a\nlist entry with the zone of the connection being added using\nnf_ct_zone_id() and nf_ct_zone_equal(), passing conn->zone.dir or\nzone->dir as the direction argument.\n\nThose helpers take enum ip_conntrack_dir values: IP_CT_DIR_ORIGINAL is 0\nand IP_CT_DIR_REPLY is 1.  However, zone->dir is a u8 bitmask:\nNF_CT_ZONE_DIR_ORIG is 1, NF_CT_ZONE_DIR_REPL is 2 and\nNF_CT_DEFAULT_ZONE_DIR is 3.  Passing that bitmask as the enum direction\nshifts the meaning of every non-zero value.  An ORIG-only zone passes 1\nand is tested as REPLY, while REPL-only and default zones pass 2 or 3 and\ntest bits beyond the valid direction range.  In those cases\nnf_ct_zone_id() can fall back to NF_CT_DEFAULT_ZONE_ID instead of using\nthe real zone id, so different zones can be treated as equal and dedup\ncollapses to tuple equality alone.\n\nnf_conncount stores and compares the original-direction tuple for a\nconnection.  If an skb already has an attached conntrack entry,\nget_ct_or_tuple_from_skb() explicitly copies\nct->tuplehash[IP_CT_DIR_ORIGINAL].tuple, regardless of the packet's\nctinfo.  Therefore the zone comparison in the tuple dedup path must use\nIP_CT_DIR_ORIGINAL as well; the zone direction bitmask describes where a\nzone id applies, not which direction this conncount tuple represents.\n\nFix the two dedup comparisons by passing IP_CT_DIR_ORIGINAL directly.\nDo not special-case NF_CT_DEFAULT_ZONE_DIR and do not compare raw zone\nids: using the existing helpers with IP_CT_DIR_ORIGINAL preserves the\ndirection-aware NF_CT_DEFAULT_ZONE_ID fallback.  A default bidirectional\nzone contains the ORIG bit, so it naturally returns the real zone id;\nreply-only zones continue to fall back for original-direction tuple\ncomparisons."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["net/netfilter/nf_conncount.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"21ba8847f857028dc83a0f341e16ecc616e34740","lessThan":"82fc35e0da9a91db9a034f8311f18f77a599ae3f","versionType":"git","status":"affected"},{"version":"21ba8847f857028dc83a0f341e16ecc616e34740","lessThan":"78b5d6dbc860776161f9e9206b06ff8a01f531ab","versionType":"git","status":"affected"},{"version":"21ba8847f857028dc83a0f341e16ecc616e34740","lessThan":"4f30a89c0ed2418719a1144881c2635b940b543d","versionType":"git","status":"affected"},{"version":"21ba8847f857028dc83a0f341e16ecc616e34740","lessThan":"7bdc3c0985ecf17b957811fedcc684acdf698acc","versionType":"git","status":"affected"},{"version":"21ba8847f857028dc83a0f341e16ecc616e34740","lessThan":"35a56e2a46b90e6bd4ca816b80e9cb8d20dfc3ce","versionType":"git","status":"affected"},{"version":"21ba8847f857028dc83a0f341e16ecc616e34740","lessThan":"3cd9a5792cbea81139c24320986dd0db69e9b5d0","versionType":"git","status":"affected"},{"version":"21ba8847f857028dc83a0f341e16ecc616e34740","lessThan":"6ff07ac5405bea4d4ead3559fc123f987576424a","versionType":"git","status":"affected"},{"version":"21ba8847f857028dc83a0f341e16ecc616e34740","lessThan":"f62c41b4910e65da396ec9a8c40c1fe7fe82e449","versionType":"git","status":"affected"},{"version":"525e1dffed8711973f77412729621098a95238e5","versionType":"git","status":"affected"},{"version":"75af3d78168e654a5cd8bbc4c774f97be836165f","versionType":"git","status":"affected"},{"version":"4.14.92","lessThan":"4.15","versionType":"semver","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["net/netfilter/nf_conncount.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"4.18","status":"affected"},{"version":"0","lessThan":"4.18","versionType":"semver","status":"unaffected"},{"version":"5.10.261","lessThanOrEqual":"5.10.*","versionType":"semver","status":"unaffected"},{"version":"5.15.212","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.178","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.97","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc4","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/35a56e2a46b90e6bd4ca816b80e9cb8d20dfc3ce","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/3cd9a5792cbea81139c24320986dd0db69e9b5d0","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/4f30a89c0ed2418719a1144881c2635b940b543d","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/6ff07ac5405bea4d4ead3559fc123f987576424a","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/78b5d6dbc860776161f9e9206b06ff8a01f531ab","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/7bdc3c0985ecf17b957811fedcc684acdf698acc","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/82fc35e0da9a91db9a034f8311f18f77a599ae3f","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/f62c41b4910e65da396ec9a8c40c1fe7fe82e449","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-72248","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:21:52.030","lastModified":"2026-08-15T06:21:52.030","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nnetfilter: flowtable: support IPIP tunnel with direct xmit\n\nThe combination of IPIP tunnel with direct xmit, eg. bridge device,\nbreaks because no dst_entry is provided to check the skb headroom and to\nset the iph->frag_off field. This leads to invalid dst usage and can\ntrigger a crash in the tunnel transmit path.\n\nFix this by moving dst_cache and dst_cookie out of the runtime union so\nthat they can be shared by neighbour, xfrm, and direct tunnel flows.\nFor FLOW_OFFLOAD_XMIT_DIRECT tuples carrying tunnel metadata, preserve\nroute state in these shared fields and release it through the common\ndst release path.\n\nSince dst_entry is now available to the three supported xmit modes and\ndst_release() already deals with NULL dst, remove the xmit type check\nin nft_flow_dst_release(). Moreover, skip the check if the dst entry\nis NULL in nf_flow_dst_check() which is now the case for the direct\nxmit case.\n\nBased on patch from Rein Wei <n05ec@lzu.edu.cn>."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["include/net/netfilter/nf_flow_table.h","net/netfilter/nf_flow_table_core.c","net/netfilter/nf_flow_table_ip.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"d30301ba4b07ac92eb38353a111833b009003170","lessThan":"0880c4ed122d0cddc9f29a2b28f055d1f24f0fca","versionType":"git","status":"affected"},{"version":"d30301ba4b07ac92eb38353a111833b009003170","lessThan":"fa7395c02d95e51bad2952325d2d6503bfbad437","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["include/net/netfilter/nf_flow_table.h","net/netfilter/nf_flow_table_core.c","net/netfilter/nf_flow_table_ip.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.19","status":"affected"},{"version":"0","lessThan":"6.19","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc3","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/0880c4ed122d0cddc9f29a2b28f055d1f24f0fca","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/fa7395c02d95e51bad2952325d2d6503bfbad437","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-72249","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:21:52.150","lastModified":"2026-08-15T06:21:52.150","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nnetfilter: flowtable: use dst in this direction when pushing IPIP header\n\nWhen pushing the IPIP header, the route of the other direction is used\nto calculate the headroom, use the route in this direction. Accessing\nthe other tuple to set the IP source and destination is fine because\nthis tuple does not provide such information to avoid storing redundant\ninformation. However, this tuple already provides the dst for this\ndirection, this went unnoticed because this bug affects headroom and\niph->frag_off only at this stage."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["net/netfilter/nf_flow_table_ip.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"d30301ba4b07ac92eb38353a111833b009003170","lessThan":"ecb78fbb03d3f86e2e93767875e273308086a424","versionType":"git","status":"affected"},{"version":"d30301ba4b07ac92eb38353a111833b009003170","lessThan":"c328b90c17fc5fa7786503695152880b2afb9326","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["net/netfilter/nf_flow_table_ip.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.19","status":"affected"},{"version":"0","lessThan":"6.19","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc3","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/c328b90c17fc5fa7786503695152880b2afb9326","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/ecb78fbb03d3f86e2e93767875e273308086a424","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-72250","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:21:52.267","lastModified":"2026-08-15T06:21:52.267","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nnetfilter: nf_conntrack_reasm: guard mac_header adjustment after IPv6 defrag\n\nnf_ct_frag6_reasm() slides the packet head forward to drop the IPv6\nfragment header and then unconditionally advances skb->mac_header:\n\n\tskb->mac_header += sizeof(struct frag_hdr);\n\nOn the NF_INET_LOCAL_OUT defrag path the skb has no link-layer header\nyet, so skb->mac_header is still the \"not set\" sentinel (u16)~0U. Adding\nsizeof(struct frag_hdr) wraps it to a small value (0xffff + 8 == 7),\nafter which skb_mac_header_was_set() wrongly reports a MAC header is\npresent and skb_mac_header() points into the headroom.\n\nThe reassembler has done this unconditional add since it was introduced;\nit was harmless while mac_header was a bare pointer, but wrong once\nmac_header became a u16 offset whose unset state is the ~0U sentinel\ntested by skb_mac_header_was_set(). The sibling net/ipv6/reassembly.c\ndoes the same relocation and does guard the adjustment; mirror the\nguard here."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["net/ipv6/netfilter/nf_conntrack_reasm.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"9fb9cbb1082d6b31fb45aa1a14432449a0df6cf1","lessThan":"6e8cd710ca35c576f5f2e5a396047c9ac61f75e5","versionType":"git","status":"affected"},{"version":"9fb9cbb1082d6b31fb45aa1a14432449a0df6cf1","lessThan":"2a95ec21824a8ad81ad660b12231456fc0ac9830","versionType":"git","status":"affected"},{"version":"9fb9cbb1082d6b31fb45aa1a14432449a0df6cf1","lessThan":"bbcdef2061b170af45702ce6b359c02c12acfc94","versionType":"git","status":"affected"},{"version":"9fb9cbb1082d6b31fb45aa1a14432449a0df6cf1","lessThan":"cd0d7bbc027b4d3329712cdcdeb4e5567ffd0d58","versionType":"git","status":"affected"},{"version":"9fb9cbb1082d6b31fb45aa1a14432449a0df6cf1","lessThan":"53ef70a315420ed31581d38343684b3bf9a3c76d","versionType":"git","status":"affected"},{"version":"9fb9cbb1082d6b31fb45aa1a14432449a0df6cf1","lessThan":"a58230f3a7c4f6c3261786bc1efb72c42e68cd25","versionType":"git","status":"affected"},{"version":"9fb9cbb1082d6b31fb45aa1a14432449a0df6cf1","lessThan":"00bdce2fda7e430d24cfbc96764a1b96deb31f82","versionType":"git","status":"affected"},{"version":"9fb9cbb1082d6b31fb45aa1a14432449a0df6cf1","lessThan":"3b08fed5b7e0d5e3a25d73ef3ba09cd33ade16c9","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["net/ipv6/netfilter/nf_conntrack_reasm.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"2.6.15","status":"affected"},{"version":"0","lessThan":"2.6.15","versionType":"semver","status":"unaffected"},{"version":"5.10.261","lessThanOrEqual":"5.10.*","versionType":"semver","status":"unaffected"},{"version":"5.15.212","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.178","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.97","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc3","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/00bdce2fda7e430d24cfbc96764a1b96deb31f82","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/2a95ec21824a8ad81ad660b12231456fc0ac9830","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/3b08fed5b7e0d5e3a25d73ef3ba09cd33ade16c9","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/53ef70a315420ed31581d38343684b3bf9a3c76d","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/6e8cd710ca35c576f5f2e5a396047c9ac61f75e5","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/a58230f3a7c4f6c3261786bc1efb72c42e68cd25","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/bbcdef2061b170af45702ce6b359c02c12acfc94","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/cd0d7bbc027b4d3329712cdcdeb4e5567ffd0d58","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-72251","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:21:52.393","lastModified":"2026-08-15T06:21:52.393","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nnetfilter: nf_nat_sip: reload possible stale data pointer\n\nquoting sashiko:\n ------------------------------------------------------------------------\n [..] noticed a potential memory bug and header corruption involving the\n SIP NAT helper.\n\n In net/netfilter/nf_nat_sip.c:nf_nat_sip():\n\tif (skb_ensure_writable(skb, skb->len)) {\n\t\tnf_ct_helper_log(skb, ct, \"cannot mangle packet\");\n\t\treturn NF_DROP;\n\t}\n\tuh = (void *)skb->data + protoff;\n\tuh->dest = ct_sip_info->forced_dport;\n\tif (!nf_nat_mangle_udp_packet(skb, ct, ctinfo, protoff,\n\t\t\t\t      0, 0, NULL, 0)) {\n\n If a cloned or fragmented SKB is reallocated by skb_ensure_writable(), the\n old data buffer is freed. However, nf_nat_sip() fails to update *dptr to\n point to the new buffer.\n\n It also appears to use nf_nat_mangle_udp_packet() on what could be a TCP\n packet, which would overwrite the sequence number with a checksum update.\n ------------------------------------------------------------------------\n\nnf_conntrack_sip linerizes skbs, hence no fragmented skb can be seen.\nBut clones are possible, so rebuild dptr.\n\nDisable nf_nat_mangle_udp_packet() branch for TCP streams.\nIt doesn't look like this can ever happen, else we should have received\nbug reports about this, so just check the conntrack is UDP and drop\notherwise.\n\nThe calling conntrack_sip set ->forced_dport for SIP_HDR_VIA_UDP messages,\nso I don't think this is ever expected to be true for a TCP stream."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["net/netfilter/nf_nat_sip.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"7266507d89991fa1e989283e4e032c6d9357fe26","lessThan":"bded21a4bf9bf86a79148be735723a97ca9a7532","versionType":"git","status":"affected"},{"version":"7266507d89991fa1e989283e4e032c6d9357fe26","lessThan":"dc11f26685aa850f237226f0f463647aea58ab7c","versionType":"git","status":"affected"},{"version":"7266507d89991fa1e989283e4e032c6d9357fe26","lessThan":"e38143c9b477f2968024c47c647dd4456a40aff1","versionType":"git","status":"affected"},{"version":"7266507d89991fa1e989283e4e032c6d9357fe26","lessThan":"57e4e29644ec054d7021d296407e7ddd844afea2","versionType":"git","status":"affected"},{"version":"7266507d89991fa1e989283e4e032c6d9357fe26","lessThan":"eae9c6ccb5af69c713a65f8ae219f5c1aa32cd17","versionType":"git","status":"affected"},{"version":"7266507d89991fa1e989283e4e032c6d9357fe26","lessThan":"2bcf2c5052fb5e73e255140ab43f056aef409c27","versionType":"git","status":"affected"},{"version":"7266507d89991fa1e989283e4e032c6d9357fe26","lessThan":"0e76e3e886cc9ee027337d5ad39cb96f57b7bdc7","versionType":"git","status":"affected"},{"version":"7266507d89991fa1e989283e4e032c6d9357fe26","lessThan":"77e43bcb7ec177e293a5c3f1b91a2c5aebfb6c68","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["net/netfilter/nf_nat_sip.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"3.9","status":"affected"},{"version":"0","lessThan":"3.9","versionType":"semver","status":"unaffected"},{"version":"5.10.261","lessThanOrEqual":"5.10.*","versionType":"semver","status":"unaffected"},{"version":"5.15.212","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.178","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.97","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc3","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/0e76e3e886cc9ee027337d5ad39cb96f57b7bdc7","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/2bcf2c5052fb5e73e255140ab43f056aef409c27","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/57e4e29644ec054d7021d296407e7ddd844afea2","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/77e43bcb7ec177e293a5c3f1b91a2c5aebfb6c68","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/bded21a4bf9bf86a79148be735723a97ca9a7532","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/dc11f26685aa850f237226f0f463647aea58ab7c","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/e38143c9b477f2968024c47c647dd4456a40aff1","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/eae9c6ccb5af69c713a65f8ae219f5c1aa32cd17","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-72252","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:21:52.600","lastModified":"2026-08-15T06:21:52.600","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nnetfilter: nft_set_pipapo: don't leak bad clone into future transaction\n\nOn memory allocation failure the cloned nft_pipapo_match can enter a bad\nstate:\n - some fields can have their lookup tables resized while others did\n   not\n - bits might have been toggled\n - scratch map can be undersized which also means m->bsize_max can be\n   lower than what is required\n\nThis means that the next insertion in the same batch can trigger\nout-of-bounds writes.\n\nFurthermore, a failure in the first can result in the bad clone to\nleak into the next transaction because the abort callback is never\nexecuted in this case (the upper layer saw an error and no attempt to\nallocate a transactional request was made).\n\nRecord a state for the nft_pipapo_match structure:\n- NEW (pristine clone)\n- MOD (modified clone with good state)\n- ERR (potentially bogus content)\n\nThen make it so that deletes and insertions fail when the clone\nentered ERR state.\n\nIn case the very first insert attempt results in an error, free the\nclone right away."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["net/netfilter/nft_set_pipapo.c","net/netfilter/nft_set_pipapo.h"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"3c4287f62044a90e73a561aa05fc46e62da173da","lessThan":"047e813324eac2ac60cddfb58bcdbd0144eadb09","versionType":"git","status":"affected"},{"version":"3c4287f62044a90e73a561aa05fc46e62da173da","lessThan":"610e3b73efaec3dd81a95dcda2421ad7d9795bd0","versionType":"git","status":"affected"},{"version":"3c4287f62044a90e73a561aa05fc46e62da173da","lessThan":"02b6b0e892aea582590671796fd6eff5b93ea93f","versionType":"git","status":"affected"},{"version":"3c4287f62044a90e73a561aa05fc46e62da173da","lessThan":"e74f9680e1b64872a51cc7b5bda1edaaa08aa51f","versionType":"git","status":"affected"},{"version":"3c4287f62044a90e73a561aa05fc46e62da173da","lessThan":"47e65eff50691f0a5b79d325e28d83ec1da43bcf","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["net/netfilter/nft_set_pipapo.c","net/netfilter/nft_set_pipapo.h"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"5.6","status":"affected"},{"version":"0","lessThan":"5.6","versionType":"semver","status":"unaffected"},{"version":"6.6.148","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.97","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc2","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/02b6b0e892aea582590671796fd6eff5b93ea93f","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/047e813324eac2ac60cddfb58bcdbd0144eadb09","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/47e65eff50691f0a5b79d325e28d83ec1da43bcf","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/610e3b73efaec3dd81a95dcda2421ad7d9795bd0","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/e74f9680e1b64872a51cc7b5bda1edaaa08aa51f","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-72253","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:21:52.760","lastModified":"2026-08-15T06:21:52.760","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nnetfilter: nf_conntrack_sip: validate skb_dst() before accessing it\n\ntc ingress and openvswitch do not guarantee routing information to be\navailable. These subsystems use the conntrack helper infrastructure, and\nthe SIP helper relies on the skb_dst() to be present if\nsip_external_media is set to 1 (which is disabled by default as a module\nparameter).\n\nThis effectively disables the sip_external_media toggle for these\nsubsystems without resulting in a crash."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["net/netfilter/nf_conntrack_sip.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"cae3a2627520c3795b54533c5328b77af3405dbe","lessThan":"e64a48c50a1ff565a98c6a98d82b5b942868e76e","versionType":"git","status":"affected"},{"version":"cae3a2627520c3795b54533c5328b77af3405dbe","lessThan":"c199ed687c00841daf60e9d131976958583a8c09","versionType":"git","status":"affected"},{"version":"cae3a2627520c3795b54533c5328b77af3405dbe","lessThan":"09755dc62b026076b1d47f83489eb0547c8135e0","versionType":"git","status":"affected"},{"version":"cae3a2627520c3795b54533c5328b77af3405dbe","lessThan":"b843a96252f672332837ea2ecb7c8db0acf68e20","versionType":"git","status":"affected"},{"version":"cae3a2627520c3795b54533c5328b77af3405dbe","lessThan":"e5e24a365a5e024efef63cc49abb345fbd4852c5","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["net/netfilter/nf_conntrack_sip.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"4.3","status":"affected"},{"version":"0","lessThan":"4.3","versionType":"semver","status":"unaffected"},{"version":"6.6.148","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.101","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.42","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc2","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/09755dc62b026076b1d47f83489eb0547c8135e0","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/b843a96252f672332837ea2ecb7c8db0acf68e20","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/c199ed687c00841daf60e9d131976958583a8c09","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/e5e24a365a5e024efef63cc49abb345fbd4852c5","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/e64a48c50a1ff565a98c6a98d82b5b942868e76e","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-72254","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:21:52.910","lastModified":"2026-08-15T06:21:52.910","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nnetfilter: nft_fib: reject fib expression on the netdev egress hook\n\nA fib expression in a netdev egress base chain dereferences nft_in(pkt),\nNULL on the transmit path, causing a NULL pointer dereference at eval.\nnft_fib_validate() masks the hook with NF_INET_* values, but netdev hook\nnumbers are a separate enum that aliases them (NF_NETDEV_EGRESS ==\nNF_INET_LOCAL_IN), so an egress chain passes validation and then faults.\n\nAdd nft_fib_netdev_validate() that limits each result/flag to the netdev\nhook where the device it reads exists: the input-device cases (OIF,\nOIFNAME, ADDRTYPE with F_IIF) to ingress, the output-device case (ADDRTYPE\nwith F_OIF) to egress, ADDRTYPE with no device flag to both. Also restrict\nnft_fib_validate() to NFPROTO_IPV4/IPV6/INET so its NF_INET_* masks are\nnot applied to another family's hooks."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["net/netfilter/nft_fib.c","net/netfilter/nft_fib_netdev.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"42df6e1d221dddc0f2acf2be37e68d553ad65f96","lessThan":"4fee43759b489559a491f7c95f9bfa7a1d0c7a10","versionType":"git","status":"affected"},{"version":"42df6e1d221dddc0f2acf2be37e68d553ad65f96","lessThan":"568931f26af4727a51e8521f72efbc78d3b82410","versionType":"git","status":"affected"},{"version":"42df6e1d221dddc0f2acf2be37e68d553ad65f96","lessThan":"d01c913febead04a01a5f3a6374d1f45504dc523","versionType":"git","status":"affected"},{"version":"42df6e1d221dddc0f2acf2be37e68d553ad65f96","lessThan":"f68305267ebda7e839b5e8f77e8d77535a3d5a0f","versionType":"git","status":"affected"},{"version":"42df6e1d221dddc0f2acf2be37e68d553ad65f96","lessThan":"d07955dd34ecae17d35d8c7d0a273a3fba653a8c","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["net/netfilter/nft_fib.c","net/netfilter/nft_fib_netdev.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"5.16","status":"affected"},{"version":"0","lessThan":"5.16","versionType":"semver","status":"unaffected"},{"version":"6.6.148","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.101","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.42","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc2","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/4fee43759b489559a491f7c95f9bfa7a1d0c7a10","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/568931f26af4727a51e8521f72efbc78d3b82410","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/d01c913febead04a01a5f3a6374d1f45504dc523","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/d07955dd34ecae17d35d8c7d0a273a3fba653a8c","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/f68305267ebda7e839b5e8f77e8d77535a3d5a0f","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-72255","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:21:53.127","lastModified":"2026-08-15T06:21:53.127","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nnetfilter: nf_queue: pin bridge device while NFQUEUE holds fake dst\n\nThe br_netfilter fake rtable is embedded in struct net_bridge and is\nattached to bridged packets with skb_dst_set_noref(). If such a packet is\nqueued to NFQUEUE, __nf_queue() upgrades that fake dst with\nskb_dst_force().\n\nAt that point the queued skb can hold a real dst reference after bridge\nteardown has started. The problem is not that every bridged packet needs\nits own dst reference. The problem is that NFQUEUE can keep the bridge\nprivate fake dst alive after unregister begins.\n\nFix this by keeping the bridge fake dst model unchanged and pinning the\nbridge master device only while the packet sits in NFQUEUE. Record the\nbridge device in nf_queue_entry when the queued skb carries a bridge fake\ndst, take a device reference for the queue lifetime, and drop it when the\nqueue entry is freed.\n\nAlso make sure queued entries are reaped when that bridge device goes\ndown, and drop the redundant nf_bridge_info_exists() test from the fake\ndst detection.\n\nThis keeps netdev_priv(br->dev) alive until verdict completion, so the\nembedded fake rtable and its metrics backing storage cannot be freed out\nfrom under dst_release(). It also avoids the constant refcount bump and\navoids using ipv4-specific dst helpers for IPv6 bridge traffic."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["include/net/netfilter/nf_queue.h","net/netfilter/nf_queue.c","net/netfilter/nfnetlink_queue.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"34666d467cbf1e2e3c7bb15a63eccfb582cdd71f","lessThan":"430521af7fe8a9c08f5a2554224a35f11f51d99e","versionType":"git","status":"affected"},{"version":"34666d467cbf1e2e3c7bb15a63eccfb582cdd71f","lessThan":"3f03a2d225c668283110ad5f9ff159ba4591e2c7","versionType":"git","status":"affected"},{"version":"34666d467cbf1e2e3c7bb15a63eccfb582cdd71f","lessThan":"01ace27af47801dd7f6b839e782b62863af979cc","versionType":"git","status":"affected"},{"version":"34666d467cbf1e2e3c7bb15a63eccfb582cdd71f","lessThan":"0ca505346c5e2905ab7b5313af801fcf38f594a8","versionType":"git","status":"affected"},{"version":"34666d467cbf1e2e3c7bb15a63eccfb582cdd71f","lessThan":"47b3af24de5fbed4bf2952de0f5294ef1a338a26","versionType":"git","status":"affected"},{"version":"34666d467cbf1e2e3c7bb15a63eccfb582cdd71f","lessThan":"c9c9b37f8c5505224e8d206184df3bb668ee00cf","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["include/net/netfilter/nf_queue.h","net/netfilter/nf_queue.c","net/netfilter/nfnetlink_queue.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"3.18","status":"affected"},{"version":"0","lessThan":"3.18","versionType":"semver","status":"unaffected"},{"version":"6.1.178","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.97","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/01ace27af47801dd7f6b839e782b62863af979cc","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/0ca505346c5e2905ab7b5313af801fcf38f594a8","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/3f03a2d225c668283110ad5f9ff159ba4591e2c7","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/430521af7fe8a9c08f5a2554224a35f11f51d99e","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/47b3af24de5fbed4bf2952de0f5294ef1a338a26","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/c9c9b37f8c5505224e8d206184df3bb668ee00cf","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-72256","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:21:53.310","lastModified":"2026-08-15T06:21:53.310","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nnetfilter: xt_cluster: reject template conntracks in hash match\n\nxt_cluster_mt() treats any non-NULL nf_ct_get() result as a fully\ninitialized conntrack and passes it to xt_cluster_hash().\n\nThis causes a state confusion bug when the raw table CT target attaches\na template conntrack to skb->_nfct before normal conntrack processing.\nTemplates carry IPS_TEMPLATE status but do not have a valid tuple for\nhashing yet, so xt_cluster_hash() can hit its WARN_ON() path on the\nzeroed l3num field.\n\nReject template conntracks before hashing them. This matches existing\nnetfilter handling for template objects and avoids hashing incomplete\nconntrack state."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["net/netfilter/xt_cluster.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"0269ea4937343536ec7e85649932bc8c9686ea78","lessThan":"4558bd7b47c7be82dffd837f27be8ea3ecee557d","versionType":"git","status":"affected"},{"version":"0269ea4937343536ec7e85649932bc8c9686ea78","lessThan":"d5f9d050b0b267227c1f02f11021872c7768a9cc","versionType":"git","status":"affected"},{"version":"0269ea4937343536ec7e85649932bc8c9686ea78","lessThan":"4cb8b5f586e41c187942291cc0938006077fa79e","versionType":"git","status":"affected"},{"version":"0269ea4937343536ec7e85649932bc8c9686ea78","lessThan":"fac2fdac3baad9ffd12b3b0bba4374d4b3585d54","versionType":"git","status":"affected"},{"version":"0269ea4937343536ec7e85649932bc8c9686ea78","lessThan":"13ea4f86cf738c74be2146886ac261988a631e62","versionType":"git","status":"affected"},{"version":"0269ea4937343536ec7e85649932bc8c9686ea78","lessThan":"07f9ddbf5e799c24a3a52ec9bd7b729a6f6d69d5","versionType":"git","status":"affected"},{"version":"0269ea4937343536ec7e85649932bc8c9686ea78","lessThan":"5b2d4f0010018a7aa3495aa1dbf1b7a34011e7aa","versionType":"git","status":"affected"},{"version":"0269ea4937343536ec7e85649932bc8c9686ea78","lessThan":"5feba91006ec92da57acc1cc2e34df623b98541e","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["net/netfilter/xt_cluster.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"2.6.30","status":"affected"},{"version":"0","lessThan":"2.6.30","versionType":"semver","status":"unaffected"},{"version":"5.10.261","lessThanOrEqual":"5.10.*","versionType":"semver","status":"unaffected"},{"version":"5.15.212","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.178","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.97","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/07f9ddbf5e799c24a3a52ec9bd7b729a6f6d69d5","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/13ea4f86cf738c74be2146886ac261988a631e62","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/4558bd7b47c7be82dffd837f27be8ea3ecee557d","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/4cb8b5f586e41c187942291cc0938006077fa79e","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/5b2d4f0010018a7aa3495aa1dbf1b7a34011e7aa","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/5feba91006ec92da57acc1cc2e34df623b98541e","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/d5f9d050b0b267227c1f02f11021872c7768a9cc","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/fac2fdac3baad9ffd12b3b0bba4374d4b3585d54","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-72257","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:21:53.527","lastModified":"2026-08-15T06:21:53.527","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nASoC: qcom: q6apm: fix NULL pointer dereference in graph_callback\n\nWhen q6apm_free_fragments() is called it frees rx_data.buf/tx_data.buf\nand sets them to NULL under graph->lock. A late DSP buffer-done response\ncan race with this: graph_callback() passes the !graph->ar_graph guard\n(not yet NULL), acquires the lock, but then dereferences a now-NULL buf\npointer to read buf[token].phys, crashing at virtual address 0x10.\n\nAdd a NULL check for buf inside the mutex-protected section in both the\nwrite-done (DATA_CMD_RSP_WR_SH_MEM_EP_DATA_BUFFER_DONE_V2) and\nread-done (DATA_CMD_RSP_RD_SH_MEM_EP_DATA_BUFFER_V2) handlers and bail\nout cleanly if buffers have already been freed.\n\nThis problem is only shown up recently while apr bus was updated to\nprocess the commands per service rather from single global queue."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["sound/soc/qcom/qdsp6/q6apm.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"5477518b8a0e8a45239646acd80c9bafc4401522","lessThan":"a164e744d8de1c41049bd9a1452a4b6bbf5bd8bc","versionType":"git","status":"affected"},{"version":"5477518b8a0e8a45239646acd80c9bafc4401522","lessThan":"ec369eac0795cfa8f4d3a0cd35a1e8e15f780331","versionType":"git","status":"affected"},{"version":"5477518b8a0e8a45239646acd80c9bafc4401522","lessThan":"2c715f8a1e644ce4c3e8be5b0fd3f1f4704b73b3","versionType":"git","status":"affected"},{"version":"5477518b8a0e8a45239646acd80c9bafc4401522","lessThan":"ca028334343a140efda4b22e53cbce2c5e94a489","versionType":"git","status":"affected"},{"version":"5477518b8a0e8a45239646acd80c9bafc4401522","lessThan":"214af790e3a33ab73587de4c925c60a550eae9c6","versionType":"git","status":"affected"},{"version":"5477518b8a0e8a45239646acd80c9bafc4401522","lessThan":"2e9261761b35f0b67b7487688cd1365f535be0b3","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["sound/soc/qcom/qdsp6/q6apm.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"5.16","status":"affected"},{"version":"0","lessThan":"5.16","versionType":"semver","status":"unaffected"},{"version":"6.1.178","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.97","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/214af790e3a33ab73587de4c925c60a550eae9c6","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/2c715f8a1e644ce4c3e8be5b0fd3f1f4704b73b3","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/2e9261761b35f0b67b7487688cd1365f535be0b3","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/a164e744d8de1c41049bd9a1452a4b6bbf5bd8bc","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/ca028334343a140efda4b22e53cbce2c5e94a489","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/ec369eac0795cfa8f4d3a0cd35a1e8e15f780331","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-72258","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:21:53.747","lastModified":"2026-08-15T06:21:53.747","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nASoC: mediatek: mt8183: Release reserved memory on cleanup\n\nThe MT8183 AFE probe can assign reserved memory with\nof_reserved_mem_device_init(), but the assignment is never released on\ndriver removal or later probe failures.\n\nRegister a devm cleanup action so the reserved memory assignment is\nreleased consistently, matching newer Mediatek AFE drivers."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["sound/soc/mediatek/mt8183/mt8183-afe-pcm.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"aa771d2928fedd7fb10aa373601eeee0ed8ccfae","lessThan":"48b6c39883637b444c2f976e7b8ca964b1889561","versionType":"git","status":"affected"},{"version":"3b13b5a4f29e50bbc3c464823cf8c94b93a16367","lessThan":"e2d05ab62614162797fee28925279d9e8c2f200a","versionType":"git","status":"affected"},{"version":"ec4a10ca4a68ec97f12f4d17d7abb74db34987db","lessThan":"e42d8322b67f21493a832ec338aad1c93bd01ea7","versionType":"git","status":"affected"},{"version":"ec4a10ca4a68ec97f12f4d17d7abb74db34987db","lessThan":"03009465312ca35137f84cf84c95686137608deb","versionType":"git","status":"affected"},{"version":"ec4a10ca4a68ec97f12f4d17d7abb74db34987db","lessThan":"bee65e00c0924ebecf97718d95dcf4a05ee36471","versionType":"git","status":"affected"},{"version":"c2ab521120eb83103bc5927bb7b7aa84043f495f","versionType":"git","status":"affected"},{"version":"40bff79f167ff700cf1f203b1ad54b389d0e7189","versionType":"git","status":"affected"},{"version":"6.6.102","lessThan":"6.6.145","versionType":"semver","status":"affected"},{"version":"6.12.42","lessThan":"6.12.97","versionType":"semver","status":"affected"},{"version":"6.15.10","lessThan":"6.16","versionType":"semver","status":"affected"},{"version":"6.16.1","lessThan":"6.17","versionType":"semver","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["sound/soc/mediatek/mt8183/mt8183-afe-pcm.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.17","status":"affected"},{"version":"0","lessThan":"6.17","versionType":"semver","status":"unaffected"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.97","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/03009465312ca35137f84cf84c95686137608deb","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/48b6c39883637b444c2f976e7b8ca964b1889561","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/bee65e00c0924ebecf97718d95dcf4a05ee36471","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/e2d05ab62614162797fee28925279d9e8c2f200a","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/e42d8322b67f21493a832ec338aad1c93bd01ea7","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-72259","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:21:53.907","lastModified":"2026-08-15T06:21:53.907","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nASoC: mediatek: mt8192: Release reserved memory on cleanup\n\nThe MT8192 AFE probe calls of_reserved_mem_device_init() and falls\nback to preallocated buffers when no reserved memory region is\navailable. When the reserved memory assignment succeeds, however, the\ndriver never releases it.\n\nRegister a devm cleanup action after a successful reserved-memory\nassignment so the assignment is released on probe failure and driver\nunbind."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["sound/soc/mediatek/mt8192/mt8192-afe-pcm.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"aa771d2928fedd7fb10aa373601eeee0ed8ccfae","lessThan":"989cbe8cc86f4639f4e1fbe84ea0339759e92f1f","versionType":"git","status":"affected"},{"version":"3b13b5a4f29e50bbc3c464823cf8c94b93a16367","lessThan":"756cfc0039fe9dc1388ea231821508a78a087afe","versionType":"git","status":"affected"},{"version":"ec4a10ca4a68ec97f12f4d17d7abb74db34987db","lessThan":"51c367230e30ed80b49d5330831c1f2c59405b02","versionType":"git","status":"affected"},{"version":"ec4a10ca4a68ec97f12f4d17d7abb74db34987db","lessThan":"4c9df23e121f1095f02cc7e1531ce3a6d74ff697","versionType":"git","status":"affected"},{"version":"ec4a10ca4a68ec97f12f4d17d7abb74db34987db","lessThan":"965e17ae6751c5d3302430c8ebd650e72d45a85f","versionType":"git","status":"affected"},{"version":"c2ab521120eb83103bc5927bb7b7aa84043f495f","versionType":"git","status":"affected"},{"version":"40bff79f167ff700cf1f203b1ad54b389d0e7189","versionType":"git","status":"affected"},{"version":"6.6.102","lessThan":"6.6.145","versionType":"semver","status":"affected"},{"version":"6.12.42","lessThan":"6.12.97","versionType":"semver","status":"affected"},{"version":"6.15.10","lessThan":"6.16","versionType":"semver","status":"affected"},{"version":"6.16.1","lessThan":"6.17","versionType":"semver","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["sound/soc/mediatek/mt8192/mt8192-afe-pcm.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.17","status":"affected"},{"version":"0","lessThan":"6.17","versionType":"semver","status":"unaffected"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.97","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/4c9df23e121f1095f02cc7e1531ce3a6d74ff697","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/51c367230e30ed80b49d5330831c1f2c59405b02","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/756cfc0039fe9dc1388ea231821508a78a087afe","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/965e17ae6751c5d3302430c8ebd650e72d45a85f","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/989cbe8cc86f4639f4e1fbe84ea0339759e92f1f","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-72260","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:21:54.100","lastModified":"2026-08-15T06:21:54.100","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nASoC: mediatek: mt8192: Check runtime resume during probe\n\nThe MT8192 AFE probe enables runtime PM temporarily while reinitializing\nthe regmap cache from hardware, but it uses pm_runtime_get_sync()\nwithout checking the return value. If runtime resume fails, probe keeps\ngoing without the device necessarily being accessible, and\npm_runtime_get_sync() may leave the PM usage count incremented.\n\nThe regmap_reinit_cache() failure path also returns before dropping the\ntemporary PM reference and before clearing pm_runtime_bypass_reg_ctl.\n\nUse pm_runtime_resume_and_get() so resume failures do not leak a usage\ncount, and clear the temporary bypass flag after dropping the probe PM\nreference on all regmap_reinit_cache() outcomes."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["sound/soc/mediatek/mt8192/mt8192-afe-pcm.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"125ab5d588b0b3b842064c4d53a666ca74521ae8","lessThan":"6e2ee6eacc3ec7b339753abcf33812d27e03efe5","versionType":"git","status":"affected"},{"version":"125ab5d588b0b3b842064c4d53a666ca74521ae8","lessThan":"faa97a1a6cab01cd3e2055deb4db4e57efc43ff2","versionType":"git","status":"affected"},{"version":"125ab5d588b0b3b842064c4d53a666ca74521ae8","lessThan":"e0f276f1918a202e9c3ac72baffd311cecb6b8db","versionType":"git","status":"affected"},{"version":"125ab5d588b0b3b842064c4d53a666ca74521ae8","lessThan":"f6e424835cc05d215c57b6370b2c1e353dd02915","versionType":"git","status":"affected"},{"version":"125ab5d588b0b3b842064c4d53a666ca74521ae8","lessThan":"e24d5dde56a50946020b134fa8448869093db76a","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["sound/soc/mediatek/mt8192/mt8192-afe-pcm.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"5.11","status":"affected"},{"version":"0","lessThan":"5.11","versionType":"semver","status":"unaffected"},{"version":"6.6.148","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.101","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/6e2ee6eacc3ec7b339753abcf33812d27e03efe5","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/e0f276f1918a202e9c3ac72baffd311cecb6b8db","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/e24d5dde56a50946020b134fa8448869093db76a","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/f6e424835cc05d215c57b6370b2c1e353dd02915","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/faa97a1a6cab01cd3e2055deb4db4e57efc43ff2","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-72261","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:21:54.257","lastModified":"2026-08-15T06:21:54.257","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nASoC: SOF: ipc3-control: Validate size in snd_sof_update_control\n\nIn snd_sof_update_control(), firmware-provided cdata->num_elems is\nchecked against local_cdata->data->size but never against the actual\nallocation size. If local_cdata->data->size was previously set to an\ninconsistent value, the memcpy could write past the allocated buffer.\n\nAdd a bounds check to ensure num_elems fits within the available space\nin the ipc_control_data allocation before copying."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["sound/soc/sof/ipc3-control.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"10f461d79c2d1afb22344986cc1b4631169cf25e","lessThan":"1dc25a3e06364f48c4ef06016852f8b82425151a","versionType":"git","status":"affected"},{"version":"10f461d79c2d1afb22344986cc1b4631169cf25e","lessThan":"ee781058cd4d71e4449f41cbe6a3b8c59daa2c51","versionType":"git","status":"affected"},{"version":"10f461d79c2d1afb22344986cc1b4631169cf25e","lessThan":"ecf67f1302f2080b4d241b973364aacda70ad740","versionType":"git","status":"affected"},{"version":"10f461d79c2d1afb22344986cc1b4631169cf25e","lessThan":"d3abaedf6a58469610136d2dace1a85cddf7afcf","versionType":"git","status":"affected"},{"version":"10f461d79c2d1afb22344986cc1b4631169cf25e","lessThan":"2a591bf6fd41fd14bdae689aafac4a9ee702c23c","versionType":"git","status":"affected"},{"version":"10f461d79c2d1afb22344986cc1b4631169cf25e","lessThan":"390aa4c9339bb0ec0bc8d554e830faf93ca9d49e","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["sound/soc/sof/ipc3-control.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"5.18","status":"affected"},{"version":"0","lessThan":"5.18","versionType":"semver","status":"unaffected"},{"version":"6.1.178","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.97","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/1dc25a3e06364f48c4ef06016852f8b82425151a","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/2a591bf6fd41fd14bdae689aafac4a9ee702c23c","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/390aa4c9339bb0ec0bc8d554e830faf93ca9d49e","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/d3abaedf6a58469610136d2dace1a85cddf7afcf","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/ecf67f1302f2080b4d241b973364aacda70ad740","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/ee781058cd4d71e4449f41cbe6a3b8c59daa2c51","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-72262","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:21:54.443","lastModified":"2026-08-15T06:21:54.443","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nASoC: SOF: ipc3-control: Fix heap overflow in bytes_ext put/get\n\nThe ipc_control_data buffer is allocated as kzalloc(max_size), where\nmax_size covers the entire struct sof_ipc_ctrl_data including its\nflexible array payload. However, the bounds checks in bytes_ext_put\nand _bytes_ext_get compared user data lengths against max_size\ndirectly, ignoring that cdata->data sits at an offset of\nsizeof(struct sof_ipc_ctrl_data) bytes into the allocation.\n\nThis allowed writing up to sizeof(struct sof_ipc_ctrl_data) bytes past\nthe end of the heap buffer from unprivileged userspace via the ALSA TLV\nkcontrol interface, and similarly allowed over-reading adjacent heap\ndata on the get path.\n\nFix all bounds checks to subtract sizeof(*cdata) from max_size so they\nreflect the actual space available at the cdata->data offset. Also fix\nthe error-path restore in bytes_ext_put which wrote to cdata->data\ninstead of cdata, causing the same overflow."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["sound/soc/sof/ipc3-control.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"67ec2a091630c28ea8d05db2bd7178a05b04b7e6","lessThan":"1adde1941bba7b0d7104b86ed819d48d81cb0ad9","versionType":"git","status":"affected"},{"version":"67ec2a091630c28ea8d05db2bd7178a05b04b7e6","lessThan":"eaa67e139c9217099e2a7b717aeeb46c65de3494","versionType":"git","status":"affected"},{"version":"67ec2a091630c28ea8d05db2bd7178a05b04b7e6","lessThan":"121577383b5cf221e86581e0f2bcca4c66f17469","versionType":"git","status":"affected"},{"version":"67ec2a091630c28ea8d05db2bd7178a05b04b7e6","lessThan":"f4933e1d11b97b6a0951648b7c3e53850e1b33a9","versionType":"git","status":"affected"},{"version":"67ec2a091630c28ea8d05db2bd7178a05b04b7e6","lessThan":"fd46668d538993218eea19c6925c868ac0f2630c","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["sound/soc/sof/ipc3-control.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"5.18","status":"affected"},{"version":"0","lessThan":"5.18","versionType":"semver","status":"unaffected"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.97","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/121577383b5cf221e86581e0f2bcca4c66f17469","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/1adde1941bba7b0d7104b86ed819d48d81cb0ad9","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/eaa67e139c9217099e2a7b717aeeb46c65de3494","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/f4933e1d11b97b6a0951648b7c3e53850e1b33a9","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/fd46668d538993218eea19c6925c868ac0f2630c","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-72263","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:21:54.613","lastModified":"2026-08-15T06:21:54.613","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nASoC: SOF: topology: fix memory leak in snd_sof_load_topology\n\nWhen the topology filename contains \"dummy\" and tplg_cnt is 0, the\nfunction returns -EINVAL directly without freeing the tplg_files\nallocated by kcalloc() at line 2497. This leaks memory on every\nsuch topology load attempt.\n\nFix this by setting ret = -EINVAL and jumping to the out: label,\nwhich already handles the kfree(tplg_files) cleanup."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["sound/soc/sof/topology.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"99c159279c6dfa2c4867c7f76875f58263f8f43b","lessThan":"6ed7787c43ecf4ae27a3e700cab53a1ed646c7f8","versionType":"git","status":"affected"},{"version":"99c159279c6dfa2c4867c7f76875f58263f8f43b","lessThan":"d46f9f23897261da53ffbeb89d48a13982ba7d28","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["sound/soc/sof/topology.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.19","status":"affected"},{"version":"0","lessThan":"6.19","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/6ed7787c43ecf4ae27a3e700cab53a1ed646c7f8","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/d46f9f23897261da53ffbeb89d48a13982ba7d28","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-72264","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:21:54.743","lastModified":"2026-08-15T06:21:54.743","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nfbdev: tridentfb: fix potential memory leak in trident_pci_probe()\n\nIn trident_pci_probe(), the memory allocated for modelist using\nfb_videomode_to_modelist() is not freed in subsequent error paths.\nFix that by calling fb_destroy_modelist()."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/video/fbdev/tridentfb.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6a5e3bd0c8bc1025bb5092f54d5aea38216c665e","lessThan":"868432039a3fd7c2c0d515e48f33d5e43391666c","versionType":"git","status":"affected"},{"version":"6a5e3bd0c8bc1025bb5092f54d5aea38216c665e","lessThan":"089d149ccd7c3ac3d5e14ac65e558dcd9ec27583","versionType":"git","status":"affected"},{"version":"6a5e3bd0c8bc1025bb5092f54d5aea38216c665e","lessThan":"de9cf16e39c0378716e9764fc0fbb6d4b45a1ee1","versionType":"git","status":"affected"},{"version":"6a5e3bd0c8bc1025bb5092f54d5aea38216c665e","lessThan":"8d16e5bc78478176621cac0f4c381136d3c92c5f","versionType":"git","status":"affected"},{"version":"6a5e3bd0c8bc1025bb5092f54d5aea38216c665e","lessThan":"5bdb6f11ad0398b11a3ae4d9104035f9dc628cdc","versionType":"git","status":"affected"},{"version":"6a5e3bd0c8bc1025bb5092f54d5aea38216c665e","lessThan":"4ebe2c3a7db6332aab3655f8c552ca387c1dc199","versionType":"git","status":"affected"},{"version":"6a5e3bd0c8bc1025bb5092f54d5aea38216c665e","lessThan":"2efd9797331a559b93ab888f451838f87bd6dfa3","versionType":"git","status":"affected"},{"version":"6a5e3bd0c8bc1025bb5092f54d5aea38216c665e","lessThan":"7a35ec619d9af8ee128320975c1252b8ad65f1e8","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/video/fbdev/tridentfb.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"4.4","status":"affected"},{"version":"0","lessThan":"4.4","versionType":"semver","status":"unaffected"},{"version":"5.10.261","lessThanOrEqual":"5.10.*","versionType":"semver","status":"unaffected"},{"version":"5.15.212","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.178","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.97","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/089d149ccd7c3ac3d5e14ac65e558dcd9ec27583","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/2efd9797331a559b93ab888f451838f87bd6dfa3","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/4ebe2c3a7db6332aab3655f8c552ca387c1dc199","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/5bdb6f11ad0398b11a3ae4d9104035f9dc628cdc","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/7a35ec619d9af8ee128320975c1252b8ad65f1e8","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/868432039a3fd7c2c0d515e48f33d5e43391666c","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/8d16e5bc78478176621cac0f4c381136d3c92c5f","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/de9cf16e39c0378716e9764fc0fbb6d4b45a1ee1","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-72265","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:21:54.913","lastModified":"2026-08-15T06:21:54.913","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nfbdev: nvidia: fix potential memory leak in nvidiafb_probe()\n\nIn nvidiafb_probe(), the memory allocated for modelist in\nnvidia_set_fbinfo() is not freed in the subsequent error paths.\nFix that by calling fb_destroy_modelist()."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/video/fbdev/nvidia/nvidia.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"7e747f7b17ccce750502fd4d0b4e866fe4f066a6","versionType":"git","status":"affected"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"2515cd60f6b5ad680ed164aa6bd19b05270af34c","versionType":"git","status":"affected"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"508704de34fb8c0dcbbf13397212363bbf0974de","versionType":"git","status":"affected"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"6ca48f23ce61a26349d7d084fb63b70499137c8e","versionType":"git","status":"affected"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"e8172773e5251f4df2eed74caab6ca3195fed1ea","versionType":"git","status":"affected"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"009a8514745b16c468acc25aa00539abbf38e1b5","versionType":"git","status":"affected"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"ed3b3eb212441fb5f287dfd24ebafe11d634f009","versionType":"git","status":"affected"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"85f5e38c162bdf9dbbe197275d416402712f3707","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/video/fbdev/nvidia/nvidia.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"2.6.12","status":"affected"},{"version":"0","lessThan":"2.6.12","versionType":"semver","status":"unaffected"},{"version":"5.10.261","lessThanOrEqual":"5.10.*","versionType":"semver","status":"unaffected"},{"version":"5.15.212","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.178","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.97","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/009a8514745b16c468acc25aa00539abbf38e1b5","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/2515cd60f6b5ad680ed164aa6bd19b05270af34c","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/508704de34fb8c0dcbbf13397212363bbf0974de","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/6ca48f23ce61a26349d7d084fb63b70499137c8e","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/7e747f7b17ccce750502fd4d0b4e866fe4f066a6","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/85f5e38c162bdf9dbbe197275d416402712f3707","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/e8172773e5251f4df2eed74caab6ca3195fed1ea","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/ed3b3eb212441fb5f287dfd24ebafe11d634f009","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-72266","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:21:55.090","lastModified":"2026-08-15T06:21:55.090","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nfbdev: vesafb: fix memory leak in vesafb_probe()\n\nSince commit 73ce73c30ba9 (\"fbdev: Transfer video= option strings to\ncaller; clarify ownership\") the string returned from fb_get_options()\nis expected to be freed by the caller. But the string is not freed in\nvesafb_probe(). Fix that by freeing the option string after setup."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/video/fbdev/vesafb.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"73ce73c30ba9ae4d90fdfad7ebe9104001d5d851","lessThan":"124df55c7201d011a3fead2205685b6c47eae093","versionType":"git","status":"affected"},{"version":"73ce73c30ba9ae4d90fdfad7ebe9104001d5d851","lessThan":"43af398217ca8940bf30643fd1150b4c655b8a88","versionType":"git","status":"affected"},{"version":"73ce73c30ba9ae4d90fdfad7ebe9104001d5d851","lessThan":"58bc18e03481b62f0ec53fe47f36615d52660a7d","versionType":"git","status":"affected"},{"version":"73ce73c30ba9ae4d90fdfad7ebe9104001d5d851","lessThan":"7b96ce9f8e47538c3c6eebbb217c94d696975cac","versionType":"git","status":"affected"},{"version":"73ce73c30ba9ae4d90fdfad7ebe9104001d5d851","lessThan":"b15d708995c01bbffe7dcd634a31959f6805bed3","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/video/fbdev/vesafb.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.4","status":"affected"},{"version":"0","lessThan":"6.4","versionType":"semver","status":"unaffected"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.97","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/124df55c7201d011a3fead2205685b6c47eae093","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/43af398217ca8940bf30643fd1150b4c655b8a88","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/58bc18e03481b62f0ec53fe47f36615d52660a7d","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/7b96ce9f8e47538c3c6eebbb217c94d696975cac","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/b15d708995c01bbffe7dcd634a31959f6805bed3","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-72267","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:21:55.250","lastModified":"2026-08-15T06:21:55.250","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nfbdev: carminefb: fix potential memory leak in alloc_carmine_fb()\n\nThe memory allocated for modelist in fb_videomode_to_modelist() is not\nfreed in the subsequent error path.\nFix that by calling fb_destroy_modelist()"}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/video/fbdev/carminefb.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"2ece5f43b041b96fa2a05107a10a6b0ea0c03a3b","lessThan":"97b6c3f6e82a526d95dcfbfcf1c42ba44c61c3d6","versionType":"git","status":"affected"},{"version":"2ece5f43b041b96fa2a05107a10a6b0ea0c03a3b","lessThan":"6069044e74b7510bf2f034ccd049bc962fb9c765","versionType":"git","status":"affected"},{"version":"2ece5f43b041b96fa2a05107a10a6b0ea0c03a3b","lessThan":"b51990be8411335c263b51e9f4def1e84bfaa923","versionType":"git","status":"affected"},{"version":"2ece5f43b041b96fa2a05107a10a6b0ea0c03a3b","lessThan":"d21e6747f3f68dcce59b5d2205f98633d28f69eb","versionType":"git","status":"affected"},{"version":"2ece5f43b041b96fa2a05107a10a6b0ea0c03a3b","lessThan":"bcc43b2f7410eddb21f73e9a650499a6432c9383","versionType":"git","status":"affected"},{"version":"2ece5f43b041b96fa2a05107a10a6b0ea0c03a3b","lessThan":"d81860691e4cfa14d596136ea2727f244e9e5950","versionType":"git","status":"affected"},{"version":"2ece5f43b041b96fa2a05107a10a6b0ea0c03a3b","lessThan":"dae8f6ddc35cb1673dba32d2fd8f1f85cd377adf","versionType":"git","status":"affected"},{"version":"2ece5f43b041b96fa2a05107a10a6b0ea0c03a3b","lessThan":"6fcca16a2b19c37f60693c56cbc0c923364ff3ef","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/video/fbdev/carminefb.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"2.6.27","status":"affected"},{"version":"0","lessThan":"2.6.27","versionType":"semver","status":"unaffected"},{"version":"5.10.261","lessThanOrEqual":"5.10.*","versionType":"semver","status":"unaffected"},{"version":"5.15.212","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.178","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.97","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/6069044e74b7510bf2f034ccd049bc962fb9c765","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/6fcca16a2b19c37f60693c56cbc0c923364ff3ef","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/97b6c3f6e82a526d95dcfbfcf1c42ba44c61c3d6","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/b51990be8411335c263b51e9f4def1e84bfaa923","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/bcc43b2f7410eddb21f73e9a650499a6432c9383","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/d21e6747f3f68dcce59b5d2205f98633d28f69eb","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/d81860691e4cfa14d596136ea2727f244e9e5950","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/dae8f6ddc35cb1673dba32d2fd8f1f85cd377adf","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-72268","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:21:55.467","lastModified":"2026-08-15T06:21:55.467","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nfbdev: tdfxfb: fix potential memory leak in tdfxfb_probe()\n\nIn tdfxfb_probe(), the memory allocated for modelist using\nfb_videomode_to_modelist() when CONFIG_FB_3DFX_I2C is defined, is not\nfreed in the subsequent error paths.\nFix that by calling fb_destroy_modelist()."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/video/fbdev/tdfxfb.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"215059d2421f95c30d1fca6ff31357fcae9f67dc","lessThan":"237611edf15172e4dc7fa9b3b71c2445602d3459","versionType":"git","status":"affected"},{"version":"215059d2421f95c30d1fca6ff31357fcae9f67dc","lessThan":"2199d70efc5bea0e9b4462a4f9e4c3d3c21c5d34","versionType":"git","status":"affected"},{"version":"215059d2421f95c30d1fca6ff31357fcae9f67dc","lessThan":"b039e0693df003c5baa1e89630344f92a78afb15","versionType":"git","status":"affected"},{"version":"215059d2421f95c30d1fca6ff31357fcae9f67dc","lessThan":"dfbb1a695d8891774c80c0e2a9192afb66469eb7","versionType":"git","status":"affected"},{"version":"215059d2421f95c30d1fca6ff31357fcae9f67dc","lessThan":"b7b26adc2718ca8f81ca75cd03aee94269d00e8a","versionType":"git","status":"affected"},{"version":"215059d2421f95c30d1fca6ff31357fcae9f67dc","lessThan":"e1ca9b8559e0f5959228626bdeaae530a1ee0337","versionType":"git","status":"affected"},{"version":"215059d2421f95c30d1fca6ff31357fcae9f67dc","lessThan":"2fd16a94bea5e0c3e93791436cf8a800b175762a","versionType":"git","status":"affected"},{"version":"215059d2421f95c30d1fca6ff31357fcae9f67dc","lessThan":"bb019d755366cc3e777a12d4bf457ff289837370","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/video/fbdev/tdfxfb.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"2.6.30","status":"affected"},{"version":"0","lessThan":"2.6.30","versionType":"semver","status":"unaffected"},{"version":"5.10.261","lessThanOrEqual":"5.10.*","versionType":"semver","status":"unaffected"},{"version":"5.15.212","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.178","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.97","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/2199d70efc5bea0e9b4462a4f9e4c3d3c21c5d34","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/237611edf15172e4dc7fa9b3b71c2445602d3459","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/2fd16a94bea5e0c3e93791436cf8a800b175762a","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/b039e0693df003c5baa1e89630344f92a78afb15","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/b7b26adc2718ca8f81ca75cd03aee94269d00e8a","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/bb019d755366cc3e777a12d4bf457ff289837370","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/dfbb1a695d8891774c80c0e2a9192afb66469eb7","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/e1ca9b8559e0f5959228626bdeaae530a1ee0337","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-72269","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:21:55.643","lastModified":"2026-08-15T06:21:55.643","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nfbdev: uvesafb: fix potential memory leak in uvesafb_probe()\n\nDue to an incorrect goto label, memory allocated for modedb and modelist\nin uvesafb_vbe_init() is not freed in some error paths. Fix this by\nupdating the goto label."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/video/fbdev/uvesafb.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"8bdb3a2d7df48b861972c4bfb58490853a228f51","lessThan":"f413512c79c2d0012c6ed486e4025e1489e6d443","versionType":"git","status":"affected"},{"version":"8bdb3a2d7df48b861972c4bfb58490853a228f51","lessThan":"61d46d6f5dc163aa5f3548633b5f392b021620ff","versionType":"git","status":"affected"},{"version":"8bdb3a2d7df48b861972c4bfb58490853a228f51","lessThan":"81985921e14f5b471fc0ffe990826d0bda52c0cf","versionType":"git","status":"affected"},{"version":"8bdb3a2d7df48b861972c4bfb58490853a228f51","lessThan":"c53fdf7ee65af1b9b4566cc437d3754ce7b47118","versionType":"git","status":"affected"},{"version":"8bdb3a2d7df48b861972c4bfb58490853a228f51","lessThan":"c606c28085a3106c91c6d37bbbbf97b451d572ce","versionType":"git","status":"affected"},{"version":"8bdb3a2d7df48b861972c4bfb58490853a228f51","lessThan":"12fe6a56506ed3bf0aaf6130a29102ce1fce62da","versionType":"git","status":"affected"},{"version":"8bdb3a2d7df48b861972c4bfb58490853a228f51","lessThan":"aa387a3e51808f580b51593e3c2f3d4703d91c1a","versionType":"git","status":"affected"},{"version":"8bdb3a2d7df48b861972c4bfb58490853a228f51","lessThan":"033e56fed09047ee63072e9f58789f40c1c7079d","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/video/fbdev/uvesafb.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"2.6.24","status":"affected"},{"version":"0","lessThan":"2.6.24","versionType":"semver","status":"unaffected"},{"version":"5.10.261","lessThanOrEqual":"5.10.*","versionType":"semver","status":"unaffected"},{"version":"5.15.212","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.178","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.97","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/033e56fed09047ee63072e9f58789f40c1c7079d","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/12fe6a56506ed3bf0aaf6130a29102ce1fce62da","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/61d46d6f5dc163aa5f3548633b5f392b021620ff","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/81985921e14f5b471fc0ffe990826d0bda52c0cf","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/aa387a3e51808f580b51593e3c2f3d4703d91c1a","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/c53fdf7ee65af1b9b4566cc437d3754ce7b47118","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/c606c28085a3106c91c6d37bbbbf97b451d572ce","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/f413512c79c2d0012c6ed486e4025e1489e6d443","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-72270","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:21:55.873","lastModified":"2026-08-15T06:21:55.873","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nfbdev: s3fb: fix potential memory leak in s3_pci_probe()\n\nIn s3_pci_probe(), the memory allocated for modelist using\nfb_videomode_to_modelist() is not freed in subsequent error paths.\nFix that by calling fb_destroy_modelist()"}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/video/fbdev/s3fb.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"86c0f043a737dadf034a4e6f29aefb074f4a1146","lessThan":"37f4b8bd9e3835a7d4da26baf80b497e478d3123","versionType":"git","status":"affected"},{"version":"86c0f043a737dadf034a4e6f29aefb074f4a1146","lessThan":"ef6c5e4607483259a0daf6584e9e34ef643a655d","versionType":"git","status":"affected"},{"version":"86c0f043a737dadf034a4e6f29aefb074f4a1146","lessThan":"fc90ec978a3cef6f6d8c6074bee538998c7c9837","versionType":"git","status":"affected"},{"version":"86c0f043a737dadf034a4e6f29aefb074f4a1146","lessThan":"0d0fa8425b29657b3d3e5bb36f50a50e57c8101f","versionType":"git","status":"affected"},{"version":"86c0f043a737dadf034a4e6f29aefb074f4a1146","lessThan":"25b354f74b028a3f91b12e6b446256965744c477","versionType":"git","status":"affected"},{"version":"86c0f043a737dadf034a4e6f29aefb074f4a1146","lessThan":"ad54698255a4b988cae1ad908c158c1d4128887c","versionType":"git","status":"affected"},{"version":"86c0f043a737dadf034a4e6f29aefb074f4a1146","lessThan":"56964e8039150a14462005458b25f19d6cad8f4a","versionType":"git","status":"affected"},{"version":"86c0f043a737dadf034a4e6f29aefb074f4a1146","lessThan":"3b0ed04bc852887a9164e1bbf521652e8ef3eb92","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/video/fbdev/s3fb.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"3.0","status":"affected"},{"version":"0","lessThan":"3.0","versionType":"semver","status":"unaffected"},{"version":"5.10.261","lessThanOrEqual":"5.10.*","versionType":"semver","status":"unaffected"},{"version":"5.15.212","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.178","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.97","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/0d0fa8425b29657b3d3e5bb36f50a50e57c8101f","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/25b354f74b028a3f91b12e6b446256965744c477","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/37f4b8bd9e3835a7d4da26baf80b497e478d3123","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/3b0ed04bc852887a9164e1bbf521652e8ef3eb92","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/56964e8039150a14462005458b25f19d6cad8f4a","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/ad54698255a4b988cae1ad908c158c1d4128887c","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/ef6c5e4607483259a0daf6584e9e34ef643a655d","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/fc90ec978a3cef6f6d8c6074bee538998c7c9837","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-72271","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:21:56.093","lastModified":"2026-08-15T06:21:56.093","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nfbdev: i740fb: fix potential memory leak in i740fb_probe()\n\nIn i740fb_probe(), the memory allocated in fb_videomode_to_modelist()\nfor modelist is not freed in the error paths. Fix that by calling\nfb_destroy_modelist()."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/video/fbdev/i740fb.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"5350c65f4f15bbc111ffa629130d3f32cdd4ccf6","lessThan":"d3776b1bf9c100873c7365bd31a67ed6caacbd82","versionType":"git","status":"affected"},{"version":"5350c65f4f15bbc111ffa629130d3f32cdd4ccf6","lessThan":"ccf073cd4a2f783adc40b04db3805dbddaaf9f31","versionType":"git","status":"affected"},{"version":"5350c65f4f15bbc111ffa629130d3f32cdd4ccf6","lessThan":"aebdbe61b3960cd22b8bb6e70e3d94fb3bbb202c","versionType":"git","status":"affected"},{"version":"5350c65f4f15bbc111ffa629130d3f32cdd4ccf6","lessThan":"e1ecbaeec5fbf0b0e2d5810ec574f762d148771e","versionType":"git","status":"affected"},{"version":"5350c65f4f15bbc111ffa629130d3f32cdd4ccf6","lessThan":"3c0cf89b74e7b8ebc21a1542937c8e912d19f22b","versionType":"git","status":"affected"},{"version":"5350c65f4f15bbc111ffa629130d3f32cdd4ccf6","lessThan":"146b708bc75f1e6cf70df31195632c9946cb70fd","versionType":"git","status":"affected"},{"version":"5350c65f4f15bbc111ffa629130d3f32cdd4ccf6","lessThan":"2ede8fa708235c81ab18de14077f1a458bec7e22","versionType":"git","status":"affected"},{"version":"5350c65f4f15bbc111ffa629130d3f32cdd4ccf6","lessThan":"5936063409af230a2c88b8700c47b89a19fd70b5","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/video/fbdev/i740fb.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"3.4","status":"affected"},{"version":"0","lessThan":"3.4","versionType":"semver","status":"unaffected"},{"version":"5.10.261","lessThanOrEqual":"5.10.*","versionType":"semver","status":"unaffected"},{"version":"5.15.212","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.178","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.97","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/146b708bc75f1e6cf70df31195632c9946cb70fd","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/2ede8fa708235c81ab18de14077f1a458bec7e22","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/3c0cf89b74e7b8ebc21a1542937c8e912d19f22b","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/5936063409af230a2c88b8700c47b89a19fd70b5","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/aebdbe61b3960cd22b8bb6e70e3d94fb3bbb202c","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/ccf073cd4a2f783adc40b04db3805dbddaaf9f31","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/d3776b1bf9c100873c7365bd31a67ed6caacbd82","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/e1ecbaeec5fbf0b0e2d5810ec574f762d148771e","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-72272","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:21:56.550","lastModified":"2026-08-15T06:21:56.550","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nfbdev: radeon: fix potential memory leak in radeonfb_pci_register()\n\nThe function radeonfb_pci_register() allocates memory for modelist\n(by calling radeon_check_modes() which calls fb_add_videomode()).\nThe memory is appended to info->modelist, but is not freed in subsequent\nerror paths. Fix this by calling fb_destroy_modelist()."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/video/fbdev/aty/radeon_base.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"a94a4a0ec2684454934ba104988d6222836a572f","versionType":"git","status":"affected"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"30a2ff955b66b16d4c98dc61f4fe8b3a57c6f7bb","versionType":"git","status":"affected"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"c622a3eed6ad26879b6c0bc208fd6e3ffc4b7de3","versionType":"git","status":"affected"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"f4dacbfd885f34222e67145294de9b8479aa021d","versionType":"git","status":"affected"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"1c5387451176db5def499db809d718765f359a37","versionType":"git","status":"affected"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"c2c795a320e7ef9aa69c7f4bd2c9ac07064eff9a","versionType":"git","status":"affected"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"1b1b43342fbf11eaf2a8926b9ed4805579d772ac","versionType":"git","status":"affected"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"df8c1101c9a08859da612b5d0a08d55d475522c6","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/video/fbdev/aty/radeon_base.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"2.6.12","status":"affected"},{"version":"0","lessThan":"2.6.12","versionType":"semver","status":"unaffected"},{"version":"5.10.261","lessThanOrEqual":"5.10.*","versionType":"semver","status":"unaffected"},{"version":"5.15.212","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.178","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.97","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/1b1b43342fbf11eaf2a8926b9ed4805579d772ac","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/1c5387451176db5def499db809d718765f359a37","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/30a2ff955b66b16d4c98dc61f4fe8b3a57c6f7bb","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/a94a4a0ec2684454934ba104988d6222836a572f","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/c2c795a320e7ef9aa69c7f4bd2c9ac07064eff9a","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/c622a3eed6ad26879b6c0bc208fd6e3ffc4b7de3","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/df8c1101c9a08859da612b5d0a08d55d475522c6","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/f4dacbfd885f34222e67145294de9b8479aa021d","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-72273","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:21:56.887","lastModified":"2026-08-15T06:21:56.887","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nfbdev: efifb: fix memory leak in efifb_probe()\n\nSince commit 73ce73c30ba9 (\"fbdev: Transfer video= option strings to\ncaller; clarify ownership\") the string returned from fb_get_options()\nis expected to be freed by the caller, but the string is not freed in\nefifb_probe(). Fix that by freeing the option string after setup."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/video/fbdev/efifb.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"73ce73c30ba9ae4d90fdfad7ebe9104001d5d851","lessThan":"fafb2e08741b20027cee77918816de29a32d6fd6","versionType":"git","status":"affected"},{"version":"73ce73c30ba9ae4d90fdfad7ebe9104001d5d851","lessThan":"475383daf5f855f5b2c3a9aa801f69b69a81799e","versionType":"git","status":"affected"},{"version":"73ce73c30ba9ae4d90fdfad7ebe9104001d5d851","lessThan":"febb5b4f67ace78d6b6862cc3c853b64710afb6c","versionType":"git","status":"affected"},{"version":"73ce73c30ba9ae4d90fdfad7ebe9104001d5d851","lessThan":"5276e3f75ddb51f980a8903f4b39e73cf42415e5","versionType":"git","status":"affected"},{"version":"73ce73c30ba9ae4d90fdfad7ebe9104001d5d851","lessThan":"9b6eaf101656958397a6012bf43f6e2e42c9e5cb","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/video/fbdev/efifb.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.4","status":"affected"},{"version":"0","lessThan":"6.4","versionType":"semver","status":"unaffected"},{"version":"6.6.148","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.97","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/475383daf5f855f5b2c3a9aa801f69b69a81799e","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/5276e3f75ddb51f980a8903f4b39e73cf42415e5","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/9b6eaf101656958397a6012bf43f6e2e42c9e5cb","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/fafb2e08741b20027cee77918816de29a32d6fd6","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/febb5b4f67ace78d6b6862cc3c853b64710afb6c","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-72274","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:21:57.107","lastModified":"2026-08-15T06:21:57.107","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nfbdev: hecubafb: fix potential memory leak in hecubafb_probe()\n\nThe memory allocated for pagerefs in fb_deferred_io_init() is not freed\non the error path. Fix it by calling fb_deferred_io_cleanup()."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/video/fbdev/hecubafb.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"186b89659c4c67cccead52961eab0ca3b23951dc","lessThan":"3eb2bc1009c2476426ffbaf642d7ac82f4685b4d","versionType":"git","status":"affected"},{"version":"56c134f7f1b58be08bdb0ca8372474a4a5165f31","lessThan":"7de72f7534d961b117e0b051fa8798975036f5f3","versionType":"git","status":"affected"},{"version":"56c134f7f1b58be08bdb0ca8372474a4a5165f31","lessThan":"2952767e399e2796d45644ea50f442988d2bb02d","versionType":"git","status":"affected"},{"version":"56c134f7f1b58be08bdb0ca8372474a4a5165f31","lessThan":"612ea3a8e525580aa82f26ab873e285f5caf9d99","versionType":"git","status":"affected"},{"version":"56c134f7f1b58be08bdb0ca8372474a4a5165f31","lessThan":"d684ce2db92b1093bcca2b42e5160a5fe23eb496","versionType":"git","status":"affected"},{"version":"56c134f7f1b58be08bdb0ca8372474a4a5165f31","lessThan":"9a94b85531852eb86283eca36ab041782c6b3518","versionType":"git","status":"affected"},{"version":"56c134f7f1b58be08bdb0ca8372474a4a5165f31","lessThan":"cbef2a305a8a72969b86f96b7c07b86edde61aff","versionType":"git","status":"affected"},{"version":"5.15.149","lessThan":"5.15.212","versionType":"semver","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/video/fbdev/hecubafb.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"5.19","status":"affected"},{"version":"0","lessThan":"5.19","versionType":"semver","status":"unaffected"},{"version":"5.15.212","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.178","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.97","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/2952767e399e2796d45644ea50f442988d2bb02d","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/3eb2bc1009c2476426ffbaf642d7ac82f4685b4d","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/612ea3a8e525580aa82f26ab873e285f5caf9d99","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/7de72f7534d961b117e0b051fa8798975036f5f3","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/9a94b85531852eb86283eca36ab041782c6b3518","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/cbef2a305a8a72969b86f96b7c07b86edde61aff","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/d684ce2db92b1093bcca2b42e5160a5fe23eb496","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-72275","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:21:57.353","lastModified":"2026-08-15T06:21:57.353","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nfbdev: broadsheetfb: fix potential memory leak in broadsheetfb_probe()\n\nThe memory allocated for pagerefs in fb_deferred_io_init() is not freed\non the error path. Fix it by calling fb_deferred_io_cleanup()."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/video/fbdev/broadsheetfb.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"186b89659c4c67cccead52961eab0ca3b23951dc","lessThan":"edc5a845108337d0c167ab850fe9adfaea442975","versionType":"git","status":"affected"},{"version":"56c134f7f1b58be08bdb0ca8372474a4a5165f31","lessThan":"54a4cd11702d5e8bcefc3b514e338955813993a1","versionType":"git","status":"affected"},{"version":"56c134f7f1b58be08bdb0ca8372474a4a5165f31","lessThan":"4ce94f9e3bfb37866638e4b81e2c3d8f7470a12c","versionType":"git","status":"affected"},{"version":"56c134f7f1b58be08bdb0ca8372474a4a5165f31","lessThan":"07d2f9cb667c2f6331a483227c62d0a4a91ef42f","versionType":"git","status":"affected"},{"version":"56c134f7f1b58be08bdb0ca8372474a4a5165f31","lessThan":"e8c9aae8c950869f65af8b9dd2f71f861ea6e433","versionType":"git","status":"affected"},{"version":"56c134f7f1b58be08bdb0ca8372474a4a5165f31","lessThan":"e818c397548cde68d64c6abf8be0a5f3e3eef7d1","versionType":"git","status":"affected"},{"version":"56c134f7f1b58be08bdb0ca8372474a4a5165f31","lessThan":"9d18a4e4234fd3ee0d0eed8ccbbb50cb76b2232c","versionType":"git","status":"affected"},{"version":"5.15.149","lessThan":"5.15.212","versionType":"semver","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/video/fbdev/broadsheetfb.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"5.19","status":"affected"},{"version":"0","lessThan":"5.19","versionType":"semver","status":"unaffected"},{"version":"5.15.212","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.178","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.97","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/07d2f9cb667c2f6331a483227c62d0a4a91ef42f","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/4ce94f9e3bfb37866638e4b81e2c3d8f7470a12c","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/54a4cd11702d5e8bcefc3b514e338955813993a1","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/9d18a4e4234fd3ee0d0eed8ccbbb50cb76b2232c","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/e818c397548cde68d64c6abf8be0a5f3e3eef7d1","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/e8c9aae8c950869f65af8b9dd2f71f861ea6e433","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/edc5a845108337d0c167ab850fe9adfaea442975","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-72276","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:21:57.590","lastModified":"2026-08-15T06:21:57.590","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nfbdev: metronomefb: fix potential memory leak in metronomefb_probe()\n\nThe memory allocated for pagerefs in fb_deferred_io_init() is not freed\non the error path. Fix it by calling fb_deferred_io_cleanup()."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/video/fbdev/metronomefb.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"186b89659c4c67cccead52961eab0ca3b23951dc","lessThan":"77e26383083c59a67244fcf2e70eecd354451906","versionType":"git","status":"affected"},{"version":"56c134f7f1b58be08bdb0ca8372474a4a5165f31","lessThan":"f779bd494f9521f89bfd4ce23953f3527341e9fd","versionType":"git","status":"affected"},{"version":"56c134f7f1b58be08bdb0ca8372474a4a5165f31","lessThan":"01708cf3dca2f88eca26269521cbcc8e2f054ee4","versionType":"git","status":"affected"},{"version":"56c134f7f1b58be08bdb0ca8372474a4a5165f31","lessThan":"d54bb39cd34f44b32d5c4a8416fff8b01a9e76be","versionType":"git","status":"affected"},{"version":"56c134f7f1b58be08bdb0ca8372474a4a5165f31","lessThan":"6854cf33dddb212bd7c3d69189623876e7334075","versionType":"git","status":"affected"},{"version":"56c134f7f1b58be08bdb0ca8372474a4a5165f31","lessThan":"a889978ec44fe33edb3fb7140dcbbb8e6465c1cb","versionType":"git","status":"affected"},{"version":"56c134f7f1b58be08bdb0ca8372474a4a5165f31","lessThan":"894632b862a39b3fe1cb5de06fbae86225ea64de","versionType":"git","status":"affected"},{"version":"5.15.149","lessThan":"5.15.212","versionType":"semver","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/video/fbdev/metronomefb.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"5.19","status":"affected"},{"version":"0","lessThan":"5.19","versionType":"semver","status":"unaffected"},{"version":"5.15.212","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.178","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.97","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/01708cf3dca2f88eca26269521cbcc8e2f054ee4","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/6854cf33dddb212bd7c3d69189623876e7334075","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/77e26383083c59a67244fcf2e70eecd354451906","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/894632b862a39b3fe1cb5de06fbae86225ea64de","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/a889978ec44fe33edb3fb7140dcbbb8e6465c1cb","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/d54bb39cd34f44b32d5c4a8416fff8b01a9e76be","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/f779bd494f9521f89bfd4ce23953f3527341e9fd","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-72277","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:21:57.750","lastModified":"2026-08-15T06:21:57.750","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nKVM: arm64: nv: Inject SEA if guest VNCR isn't normal memory\n\nWhen constructing an L1 VNCR mapping, KVM unconditionally uses cacheable\nmemory attributes, even if the underlying PFN isn't memory. This gets\nparticularly hairy if the endpoint doesn't support cacheable memory\nattributes, potentially throwing an SError on writeback...\n\nWhile KVM does permit cacheable memory attributes on certain PFNMAP\nVMAs, kvm_translate_vncr() isn't currently grabbing the VMA. So do the\nsimpler thing for now and just reject everything that isn't memory."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["arch/arm64/kvm/nested.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"2a359e072596fcb2e9e85017a865e3618a2fe5b5","lessThan":"d5436e18e4fc2886ac306304d884ea3b92e1edbf","versionType":"git","status":"affected"},{"version":"2a359e072596fcb2e9e85017a865e3618a2fe5b5","lessThan":"bc00e0e376ee3572f5d26c174473abef1e35decc","versionType":"git","status":"affected"},{"version":"2a359e072596fcb2e9e85017a865e3618a2fe5b5","lessThan":"4bd7dbe0b2243e6aa735cae4d5e1ff988b30b2a6","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["arch/arm64/kvm/nested.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.16","status":"affected"},{"version":"0","lessThan":"6.16","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc4","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/4bd7dbe0b2243e6aa735cae4d5e1ff988b30b2a6","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/bc00e0e376ee3572f5d26c174473abef1e35decc","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/d5436e18e4fc2886ac306304d884ea3b92e1edbf","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-72278","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:21:57.927","lastModified":"2026-08-15T06:21:57.927","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nKVM: arm64: nv: Re-translate VNCR before injecting abort\n\nKVM faults in the VNCR page with FOLL_WRITE whenever the guest aborts\nfor a write, similar to how a regular stage-2 mapping is handled. It is\nentirely possible that the guest reads from the VNCR before writing to\nit, in which case the PFN could only be read-only.\n\nInvalidate the VNCR TLB and re-fetch the translation upon taking a VNCR\nabort, allowing the host mapping to be faulted in for write the second\ntime around. Interestingly enough, this also satisfies the ordering\nrequirements of FEAT_ETS2/3 between descriptor updates and MMU faults."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["arch/arm64/kvm/nested.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"2a359e072596fcb2e9e85017a865e3618a2fe5b5","lessThan":"ea7a76d7d614b5f82b4d0785f9af3550e860a71a","versionType":"git","status":"affected"},{"version":"2a359e072596fcb2e9e85017a865e3618a2fe5b5","lessThan":"0a5dd8cf4d58ea28da132c2097cd1c525302ac48","versionType":"git","status":"affected"},{"version":"2a359e072596fcb2e9e85017a865e3618a2fe5b5","lessThan":"bb645aa0a4caeaf7f9cd32e9a948594d434c1a8f","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["arch/arm64/kvm/nested.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.16","status":"affected"},{"version":"0","lessThan":"6.16","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc4","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/0a5dd8cf4d58ea28da132c2097cd1c525302ac48","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/bb645aa0a4caeaf7f9cd32e9a948594d434c1a8f","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/ea7a76d7d614b5f82b4d0785f9af3550e860a71a","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-72279","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:21:58.077","lastModified":"2026-08-15T06:21:58.077","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nKVM: arm64: nv: Respect read-only PFN when mapping L1 VNCR\n\nKVM currently maps the L1 VNCR into the host stage-1 by relying entirely\non the permissions of the guest stage-1. At the same time, it is\nentirely possible that the backing PFN is read-only (e.g. RO memslot),\nmeaning that the L1 VNCR should use at most a read-only mapping.\n\nCache the writability of the PFN in the VNCR TLB and use it to constrain\nthe resulting fixmap permissions. Promote VNCR permission faults to an\nSEA in the case where the guest attempts to write to a read-only\nendpoint. Conveniently, this also plugs a page leak found by Sashiko [*]\nresulting from the early return for a read-only PFN."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["arch/arm64/kvm/nested.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"2a359e072596fcb2e9e85017a865e3618a2fe5b5","lessThan":"5c50db5bcbb9073cb2fd97be51b962de92f429e9","versionType":"git","status":"affected"},{"version":"2a359e072596fcb2e9e85017a865e3618a2fe5b5","lessThan":"d35defbdfcb15296ebe28968ad7452c1a8c11cea","versionType":"git","status":"affected"},{"version":"2a359e072596fcb2e9e85017a865e3618a2fe5b5","lessThan":"2684e02bac41c5220f6c1ab2bdcc957b71812977","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["arch/arm64/kvm/nested.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.16","status":"affected"},{"version":"0","lessThan":"6.16","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc4","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/2684e02bac41c5220f6c1ab2bdcc957b71812977","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/5c50db5bcbb9073cb2fd97be51b962de92f429e9","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/d35defbdfcb15296ebe28968ad7452c1a8c11cea","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-72280","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:21:58.270","lastModified":"2026-08-15T06:21:58.270","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nKVM: arm64: nv: Drop bogus WARN for write to ZCR_EL2\n\nIt is entirely possible for a guest to write to the ZCR_EL2 sysreg alias\nwhile in a nested context, as it is expected if FEAT_NV2 is advertised\nto the L1 hypervisor.\n\nGet rid of the bogus WARN which, since the hyp vectors were installed at\nthis point, has the effect of a hyp_panic..."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["arch/arm64/kvm/hyp/include/hyp/switch.h"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"0cfc85b8f5cf3b77463d61542191c75ba0cc3a5f","lessThan":"6561597dba97e3e8479a9919bda172cf43eb902c","versionType":"git","status":"affected"},{"version":"0cfc85b8f5cf3b77463d61542191c75ba0cc3a5f","lessThan":"5000bcae71c869cba6674c326fec2d8ad659ae3a","versionType":"git","status":"affected"},{"version":"0cfc85b8f5cf3b77463d61542191c75ba0cc3a5f","lessThan":"7deadbc5dab5b8e2316364603bc6281129c8461c","versionType":"git","status":"affected"},{"version":"0cfc85b8f5cf3b77463d61542191c75ba0cc3a5f","lessThan":"9f1667098c6ae7ec81a9a56859cfdacb822aa0d0","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["arch/arm64/kvm/hyp/include/hyp/switch.h"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.11","status":"affected"},{"version":"0","lessThan":"6.11","versionType":"semver","status":"unaffected"},{"version":"6.12.97","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc4","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/5000bcae71c869cba6674c326fec2d8ad659ae3a","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/6561597dba97e3e8479a9919bda172cf43eb902c","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/7deadbc5dab5b8e2316364603bc6281129c8461c","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/9f1667098c6ae7ec81a9a56859cfdacb822aa0d0","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-72281","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:21:58.433","lastModified":"2026-08-15T06:21:58.433","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nKVM: arm64: account pKVM reclaim against the VM mm\n\nProtected guest faults charge long term pins to the VM's mm. Teardown\ncan run later from file release, where current->mm may be unrelated.\n\nDrop the charge from kvm->mm instead."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["arch/arm64/kvm/pkvm.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"4e6e03f9eaddb6be5ca8477dc5642e94ddece47e","lessThan":"34d8d7242c52c174add6b413d56420aa60f8054c","versionType":"git","status":"affected"},{"version":"4e6e03f9eaddb6be5ca8477dc5642e94ddece47e","lessThan":"d098bb75d14fde2f12155f1a95ec0168160867ce","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["arch/arm64/kvm/pkvm.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"7.1","status":"affected"},{"version":"0","lessThan":"7.1","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc4","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/34d8d7242c52c174add6b413d56420aa60f8054c","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/d098bb75d14fde2f12155f1a95ec0168160867ce","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-72282","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:21:58.680","lastModified":"2026-08-15T06:21:58.680","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nKVM: Move kvm_io_bus_get_dev() locking responsibilities to callers\n\nkvm_io_bus_get_dev() returns a device that is only matched by the\naddress, and nothing else. This can cause a lifetime issue if\nthe matched device is not the expected type, as by the time\nthe caller can introspect the object, it might be gone (the srcu\nlock having been dropped).\n\nGiven that there is only a single user of this helper, the simplest\noption is to move the locking responsibility to the caller, which\ncan keep the srcu lock held for as long as it wants.\n\nNote that this aligns with other kvm_io_bus*() helpers, which\nalready require the srcu lock to be held by the callers."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["arch/arm64/kvm/vgic/vgic-its.c","virt/kvm/kvm_main.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"8a39d00670f0792c1186e442e1dd28fe0326f2ee","lessThan":"f398b7d92cd999191249830b9171c9bd787a9a91","versionType":"git","status":"affected"},{"version":"8a39d00670f0792c1186e442e1dd28fe0326f2ee","lessThan":"1b4a3c2f0509e7b0e65667f3c36676a849ee2755","versionType":"git","status":"affected"},{"version":"8a39d00670f0792c1186e442e1dd28fe0326f2ee","lessThan":"cfe107b02a3c3f049e0dc15b6a36625f048eda2a","versionType":"git","status":"affected"},{"version":"8a39d00670f0792c1186e442e1dd28fe0326f2ee","lessThan":"90d35d2b8e47afd68fe2a4dd0eeb60bc71641775","versionType":"git","status":"affected"},{"version":"8a39d00670f0792c1186e442e1dd28fe0326f2ee","lessThan":"e01071ea006c9b952125ed8b0cc90ac7bd356cce","versionType":"git","status":"affected"},{"version":"8a39d00670f0792c1186e442e1dd28fe0326f2ee","lessThan":"7099e7148f81c605bbc319b16ce0131540341560","versionType":"git","status":"affected"},{"version":"8a39d00670f0792c1186e442e1dd28fe0326f2ee","lessThan":"0cbae0e296d27ce4c4cce83e34d40c2bfd8133aa","versionType":"git","status":"affected"},{"version":"8a39d00670f0792c1186e442e1dd28fe0326f2ee","lessThan":"3a07249981629ace483ebbef81ef6b34c2d2afec","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["arch/arm64/kvm/vgic/vgic-its.c","virt/kvm/kvm_main.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"4.8","status":"affected"},{"version":"0","lessThan":"4.8","versionType":"semver","status":"unaffected"},{"version":"5.10.261","lessThanOrEqual":"5.10.*","versionType":"semver","status":"unaffected"},{"version":"5.15.212","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.178","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.97","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc4","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/0cbae0e296d27ce4c4cce83e34d40c2bfd8133aa","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/1b4a3c2f0509e7b0e65667f3c36676a849ee2755","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/3a07249981629ace483ebbef81ef6b34c2d2afec","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/7099e7148f81c605bbc319b16ce0131540341560","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/90d35d2b8e47afd68fe2a4dd0eeb60bc71641775","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/cfe107b02a3c3f049e0dc15b6a36625f048eda2a","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/e01071ea006c9b952125ed8b0cc90ac7bd356cce","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/f398b7d92cd999191249830b9171c9bd787a9a91","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-72283","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:21:59.037","lastModified":"2026-08-15T06:21:59.037","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nKVM: x86: Nullify irqfd->producer if updating IRTE for bypass fails\n\nNullify irqfd->producer if updating the IRTE for bypass fails, as leaving a\ndangling pointer will result in a use-after-free if the irqfd is reachable\nthrough KVM's routing, but the producer is freed separately.  E.g. for VFIO\nPCI, the producer is embedded in struct \"vfio_pci_irq_ctx\" and freed when\nthe vector is disabled, which can happen independent of routing updates.\n\n[sean: drop PPC change, massage changelog]"}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["arch/x86/kvm/irq.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"77e1b8332d1d7aa786f7515e9bd4055def6a1e06","lessThan":"d1379888cc4230bac647ec24ab83306afbd03e88","versionType":"git","status":"affected"},{"version":"77e1b8332d1d7aa786f7515e9bd4055def6a1e06","lessThan":"d5560b6569cd05ba72c6b33427fbabc6ec46b8cf","versionType":"git","status":"affected"},{"version":"77e1b8332d1d7aa786f7515e9bd4055def6a1e06","lessThan":"ed446e8aa894883c08892cfee69782fdf8f6c3ca","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["arch/x86/kvm/irq.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.17","status":"affected"},{"version":"0","lessThan":"6.17","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc4","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/d1379888cc4230bac647ec24ab83306afbd03e88","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/d5560b6569cd05ba72c6b33427fbabc6ec46b8cf","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/ed446e8aa894883c08892cfee69782fdf8f6c3ca","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-72284","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:21:59.240","lastModified":"2026-08-15T06:21:59.240","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nKVM: x86: Ignore pending PV EOI if the vCPU has since disabled PV EOIs\n\nIgnore KVM's internal \"service pending PV EOI\" request if the vCPU has\ndisabled PV EOIs since the request was made.  Asserting that PV EOIs are\nenabled can fail if reading guest memory in pv_eoi_get_user() fails, i.e.\nif pv_eoi_test_and_clr_pending() bails early, *and* the vCPU also disables\nPV EOIs.\n\n  kernel BUG at arch/x86/kvm/lapic.c:3338!\n  Oops: invalid opcode: 0000 [#1] SMP\n  CPU: 4 UID: 1000 PID: 890 Comm: pv_eoi_test Not tainted 7.0.0-d585aa5894d8-vm #337 PREEMPT\n  Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS 0.0.0 02/06/2015\n  RIP: 0010:kvm_lapic_sync_from_vapic+0x12b/0x140 [kvm]\n  Call Trace:\n   <TASK>\n   kvm_arch_vcpu_ioctl_run+0x1075/0x1c30 [kvm]\n   kvm_vcpu_ioctl+0x2d5/0x980 [kvm]\n   __x64_sys_ioctl+0x8a/0xd0\n   do_syscall_64+0xb5/0xb40\n   entry_SYSCALL_64_after_hwframe+0x4b/0x53\n   </TASK>\n  Modules linked in: kvm_intel kvm irqbypass\n  ---[ end trace 0000000000000000 ]---"}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["arch/x86/kvm/lapic.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"ae7a2a3fb6f8b784c2752863f4f1f20c656f76fb","lessThan":"038b9ce6fafda1babd1e33d52cbc6039747a6d87","versionType":"git","status":"affected"},{"version":"ae7a2a3fb6f8b784c2752863f4f1f20c656f76fb","lessThan":"8e9f7a95279bf608cf4c331ed89612e28c04564f","versionType":"git","status":"affected"},{"version":"ae7a2a3fb6f8b784c2752863f4f1f20c656f76fb","lessThan":"ebd7845ca0471d251a1cb48d84eb165aff5b7123","versionType":"git","status":"affected"},{"version":"ae7a2a3fb6f8b784c2752863f4f1f20c656f76fb","lessThan":"97542f15dc4cf6cd3fdc035e482dca54246ddf48","versionType":"git","status":"affected"},{"version":"ae7a2a3fb6f8b784c2752863f4f1f20c656f76fb","lessThan":"32bdca80aa81c2cb906f50a88b220ce1ecdc5e6e","versionType":"git","status":"affected"},{"version":"ae7a2a3fb6f8b784c2752863f4f1f20c656f76fb","lessThan":"9285e4070df2c40585c3d7ec9571faa7a2b97e17","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["arch/x86/kvm/lapic.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"3.6","status":"affected"},{"version":"0","lessThan":"3.6","versionType":"semver","status":"unaffected"},{"version":"6.1.178","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.97","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc4","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/038b9ce6fafda1babd1e33d52cbc6039747a6d87","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/32bdca80aa81c2cb906f50a88b220ce1ecdc5e6e","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/8e9f7a95279bf608cf4c331ed89612e28c04564f","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/9285e4070df2c40585c3d7ec9571faa7a2b97e17","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/97542f15dc4cf6cd3fdc035e482dca54246ddf48","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/ebd7845ca0471d251a1cb48d84eb165aff5b7123","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-72285","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:21:59.700","lastModified":"2026-08-15T06:21:59.700","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nKVM: TDX: Reject concurrent change to CPUID entry count\n\nReject KVM_TDX_INIT_VM if userspace changes cpuid.nent between the\ninitial read and the subsequent copy of the initialization data.\n\ntdx_td_init() first reads user_data->cpuid.nent to size the flexible\nkvm_tdx_init_vm copy.  The copied structure also contains cpuid.nent,\nand that field can differ from the value used to size the allocation if\nuserspace modifies the input concurrently.  setup_tdparams_cpuids() later\npasses init_vm->cpuid.nent to kvm_find_cpuid_entry2(), which uses it as\nthe array bound for the copied entries.\n\nRequire the copied count to match the value used to size the allocation\nso that CPUID parsing cannot access beyond the entries actually copied."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["arch/x86/kvm/vmx/tdx.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"0bd0a4a1428baaf4447e95f0832492d9e3d64961","lessThan":"d6b5aba65e99531c97b146622a406c75653819d5","versionType":"git","status":"affected"},{"version":"0bd0a4a1428baaf4447e95f0832492d9e3d64961","lessThan":"cfbebb55e5127dc162e73fa8956000055a78606c","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["arch/x86/kvm/vmx/tdx.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.19","status":"affected"},{"version":"0","lessThan":"6.19","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc4","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/cfbebb55e5127dc162e73fa8956000055a78606c","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/d6b5aba65e99531c97b146622a406c75653819d5","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-72286","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:21:59.920","lastModified":"2026-08-15T06:21:59.920","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nKVM: SEV: Do not allow intra-host migration/mirroring of SNP VMs\n\nThe intra-host migration/mirroring feature is not fully implemented for\nSEV-SNP VMs. The proper migration requires additional SNP-specific\nstate such as guest_req_mutex, guest_req_buf, and guest_resp_buf to be\ntransferred or initialized on the destination.\n\nThe SNP VM mirroring requires vmsa features to be copied as well otherwise\nASID would be bound to SNP range while VM is detected as a SEV VM.\n\nReject SNP source VMs in migration/mirroring until proper SNP state\ntransfer is implemented.\n\n\n[sean: let lines poke past 80 chars, tag for stable]"}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["arch/x86/kvm/svm/sev.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"1dfe571c12cf99244b933208fb77f29471ded677","lessThan":"b70404b89daad5f9f33f7ac640b1065cba639935","versionType":"git","status":"affected"},{"version":"1dfe571c12cf99244b933208fb77f29471ded677","lessThan":"ba06690b28be950bd46d938d9b919c4024292627","versionType":"git","status":"affected"},{"version":"1dfe571c12cf99244b933208fb77f29471ded677","lessThan":"d2f9df3b615ca0cd45899c090366945528186052","versionType":"git","status":"affected"},{"version":"1dfe571c12cf99244b933208fb77f29471ded677","lessThan":"6ee4140788234a6fabf59e6a50e38cdb936008cd","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["arch/x86/kvm/svm/sev.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.11","status":"affected"},{"version":"0","lessThan":"6.11","versionType":"semver","status":"unaffected"},{"version":"6.12.97","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc4","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/6ee4140788234a6fabf59e6a50e38cdb936008cd","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/b70404b89daad5f9f33f7ac640b1065cba639935","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/ba06690b28be950bd46d938d9b919c4024292627","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/d2f9df3b615ca0cd45899c090366945528186052","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-72287","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:22:00.180","lastModified":"2026-08-15T06:22:00.180","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nKVM: nVMX: Move vTPR vs. TPR Threshold consistency check into \"normal\" checks\n\nMove the off-by-default consistency check for vmcs12.tpr_threshold vs.\nthe virtual APIC vTPR into the \"normal\" controls checks, as waiting until\nKVM has loaded some amount of state is unnecessary and actively dangerous.\nSpecifically, failure to unwind vmcs01.GUEST_CR3 to KVM's value when EPT\nis disabled results in KVM running L1 with an L1-controlled CR3, not with\nKVM's CR3!\n\nAlternatively, KVM could simply reset the MMU to force a reload of\nvmcs01.GUEST_CR3, but the _only_ reason the check was shoved into a \"late\"\nflow was to wait until the vmcs12 pages were retrieved.  Rather than build\nup more crusty code, simply access vTPR using a regular guest memory access\n(performance isn't a concern).  To circumvent the restrictions that led to\nKVM deferring nested_get_vmcs12_pages(), (a) use a VM-scoped API to read\nguest memory so that it always hits non-SMM memslots (for RSM), and (b)\nskip the check (since its off-by-default anyways) when the vCPU doesn't\nwant to run, i.e. when userspace is restoring/stuffing state.\n\nIf reading guest memory fails, simply skip the consistency check, as KVM's\nde facto ABI is that VMX instruction accesses to non-existent memory get\nPCI Bus Error semantics, where reads return 0xFFs.  And if vTPR=0xFF, then\nthe vTPR is guaranteed to be greater than or equal to TPR_THRESHOLD."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["arch/x86/kvm/vmx/nested.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"1100e4910ad207bc00aedc8dfdb228dd1b81f310","lessThan":"7d066368f72e6192af7e21c5817626f6da666991","versionType":"git","status":"affected"},{"version":"1100e4910ad207bc00aedc8dfdb228dd1b81f310","lessThan":"ebdac7554abb347ca4197be241116842161acd9b","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["arch/x86/kvm/vmx/nested.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.19","status":"affected"},{"version":"0","lessThan":"6.19","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc4","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/7d066368f72e6192af7e21c5817626f6da666991","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/ebdac7554abb347ca4197be241116842161acd9b","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-72288","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:22:00.450","lastModified":"2026-08-15T06:22:00.450","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nKVM: arm64: vgic: Handle race between interrupt affinity change and LPI disabling\n\nHyunwoo Kim reports some really bad races should the following\nsituation occur:\n\n- LPI-I is pending in vcpu-B's AP list\n- vcpu-A writes to vcpu-B's RD to disable its LPIs\n- vcpu-C moves I from B to C\n\nIf the last two race nicely enough, vgic_prune_ap_list() can drop\nthe irq and AP list locks, reacquire them, and in the interval\nthe irq has been freed. UAF follows.\n\nThe fix is two-fold:\n\n- Before dropping the irq and ap_list locks, take a reference on\n  the irq\n\n- Do not try to handle migration of the pending bit: there is no\n  expectation that this state is retained, as per the architecture\n\nWith that, we're sure that the interrupt is still around, and we\nsafely remove it from the AP list as it has no target at this\nstage (unless another interrupt fires, but that's another story)."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["arch/arm64/kvm/vgic/vgic.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"5dd4b924e390af426e424d5e52c1b4d1566af817","lessThan":"d19dca8194ebed371e624331c6be2cb73b562caf","versionType":"git","status":"affected"},{"version":"5dd4b924e390af426e424d5e52c1b4d1566af817","lessThan":"b1a89d12d35a8256d2b170ced0b1c86851f3def2","versionType":"git","status":"affected"},{"version":"5dd4b924e390af426e424d5e52c1b4d1566af817","lessThan":"7258770e5814f15e8308ebda82ac9acf6964ba8e","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["arch/arm64/kvm/vgic/vgic.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"4.8","status":"affected"},{"version":"0","lessThan":"4.8","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc4","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/7258770e5814f15e8308ebda82ac9acf6964ba8e","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/b1a89d12d35a8256d2b170ced0b1c86851f3def2","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/d19dca8194ebed371e624331c6be2cb73b562caf","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-72289","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:22:00.630","lastModified":"2026-08-15T06:22:00.630","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nKVM: arm64: vgic: Check the interrupt is still ours before migrating it\n\nvgic_prune_ap_list() drops both ap_list_lock and irq_lock while migrating\nan interrupt to another vCPU. After reacquiring the locks it only checks\nthat the affinity is unchanged (target_vcpu == vgic_target_oracle(irq))\nbefore moving the interrupt, which assumes that an interrupt whose affinity\nis preserved is still queued on this vCPU's ap_list.\n\nThat assumption no longer holds if the interrupt is taken off the ap_list\nwhile the locks are dropped. vgic_flush_pending_lpis() removes the\ninterrupt from the list and sets irq->vcpu to NULL, but leaves\nenabled/pending/target_vcpu untouched. As the interrupt is still enabled\nand pending, vgic_target_oracle() returns the same target_vcpu, so the\naffinity check passes and list_del() is run a second time on an entry that\nhas already been removed.\n\nAlso check that the interrupt is still assigned to this vCPU\n(irq->vcpu == vcpu) before moving it."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["arch/arm64/kvm/vgic/vgic.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"0919e84c0fc1fc73525fdcedefab89ea8460f697","lessThan":"3893e1fcf6f306b327a8358dcd1cbd077989a240","versionType":"git","status":"affected"},{"version":"0919e84c0fc1fc73525fdcedefab89ea8460f697","lessThan":"cb3efe1a354f1638726725c3ecee1ce8d1a7e2dc","versionType":"git","status":"affected"},{"version":"0919e84c0fc1fc73525fdcedefab89ea8460f697","lessThan":"da2d249a39a1881681c303ceea33f38ba1c5bbeb","versionType":"git","status":"affected"},{"version":"0919e84c0fc1fc73525fdcedefab89ea8460f697","lessThan":"654be81c4c637af12709d47c7efc3302cd336513","versionType":"git","status":"affected"},{"version":"0919e84c0fc1fc73525fdcedefab89ea8460f697","lessThan":"e363c0bc0226dc5ea5046a88e9a6864b82c45399","versionType":"git","status":"affected"},{"version":"0919e84c0fc1fc73525fdcedefab89ea8460f697","lessThan":"79fdd2aa774e44847cd9bb7edc811e73e3dc7bfe","versionType":"git","status":"affected"},{"version":"0919e84c0fc1fc73525fdcedefab89ea8460f697","lessThan":"0658b09cba7fe866c6cd70cd2dcdfdcabe80328f","versionType":"git","status":"affected"},{"version":"0919e84c0fc1fc73525fdcedefab89ea8460f697","lessThan":"0074b82cdfcb5fd13710a0ac308ade68ac6f6fbe","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["arch/arm64/kvm/vgic/vgic.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"4.7","status":"affected"},{"version":"0","lessThan":"4.7","versionType":"semver","status":"unaffected"},{"version":"5.10.261","lessThanOrEqual":"5.10.*","versionType":"semver","status":"unaffected"},{"version":"5.15.212","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.178","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.97","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc4","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/0074b82cdfcb5fd13710a0ac308ade68ac6f6fbe","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/0658b09cba7fe866c6cd70cd2dcdfdcabe80328f","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/3893e1fcf6f306b327a8358dcd1cbd077989a240","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/654be81c4c637af12709d47c7efc3302cd336513","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/79fdd2aa774e44847cd9bb7edc811e73e3dc7bfe","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/cb3efe1a354f1638726725c3ecee1ce8d1a7e2dc","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/da2d249a39a1881681c303ceea33f38ba1c5bbeb","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/e363c0bc0226dc5ea5046a88e9a6864b82c45399","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-72290","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:22:00.917","lastModified":"2026-08-15T06:22:00.917","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nKVM: s390: pci: Fix GISC refcount leak on AIF enable failure\n\nkvm_s390_gisc_register() registers the guest ISC before pinning\nthe guest interrupt forwarding pages and allocating the AISB bit.\nIf any of the later setup steps fails, the function unwinds the\npinned pages and other local state, but does not unregister the\nGISC reference. Add the missing kvm_s390_gisc_unregister() to the\nerror unwind path."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["arch/s390/kvm/pci.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"3c5a1b6f0a18520a0edd0600fef6f1a8553b8fdc","lessThan":"3882224b0e714f34de91e5f28307c5d3fccfe8f8","versionType":"git","status":"affected"},{"version":"3c5a1b6f0a18520a0edd0600fef6f1a8553b8fdc","lessThan":"6e69317cd44a2f21f8f7a9d93eb3220e868adfa8","versionType":"git","status":"affected"},{"version":"3c5a1b6f0a18520a0edd0600fef6f1a8553b8fdc","lessThan":"6cd6e1c978784eec9032e2fe94a53e62b674fe3e","versionType":"git","status":"affected"},{"version":"3c5a1b6f0a18520a0edd0600fef6f1a8553b8fdc","lessThan":"5fb75c5272950b3ebe8bdee7abfdafd44f38313b","versionType":"git","status":"affected"},{"version":"3c5a1b6f0a18520a0edd0600fef6f1a8553b8fdc","lessThan":"adce12bb0e0dc82d1d6f0821c9faee3145e62a6f","versionType":"git","status":"affected"},{"version":"3c5a1b6f0a18520a0edd0600fef6f1a8553b8fdc","lessThan":"7b69729046a4c58f4cb457184e5ac4aaa179bff4","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["arch/s390/kvm/pci.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.0","status":"affected"},{"version":"0","lessThan":"6.0","versionType":"semver","status":"unaffected"},{"version":"6.1.178","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.97","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc4","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/3882224b0e714f34de91e5f28307c5d3fccfe8f8","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/5fb75c5272950b3ebe8bdee7abfdafd44f38313b","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/6cd6e1c978784eec9032e2fe94a53e62b674fe3e","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/6e69317cd44a2f21f8f7a9d93eb3220e868adfa8","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/7b69729046a4c58f4cb457184e5ac4aaa179bff4","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/adce12bb0e0dc82d1d6f0821c9faee3145e62a6f","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-72291","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:22:01.130","lastModified":"2026-08-15T06:22:01.130","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nKVM: s390: Fix unlikely race in try_get_locked_pte()\n\nFix an unlikely race in try_get_locked_pte(), which could have happened\nif puds or pmds get unmapped between the p?dp_get() and p?d_offset()\nfunctions."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["arch/s390/mm/gmap_helpers.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"89fa757931dc0bcd64ef22b28d1d5ad00c5d02f4","lessThan":"ce587046baacdeb774b7756ab29b3f594e429004","versionType":"git","status":"affected"},{"version":"89fa757931dc0bcd64ef22b28d1d5ad00c5d02f4","lessThan":"5670b7f927f8d98685f3f5873dbf9f8d7a5a63f3","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["arch/s390/mm/gmap_helpers.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"7.1","status":"affected"},{"version":"0","lessThan":"7.1","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/5670b7f927f8d98685f3f5873dbf9f8d7a5a63f3","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/ce587046baacdeb774b7756ab29b3f594e429004","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-72292","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:22:01.377","lastModified":"2026-08-15T06:22:01.377","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nKVM: s390: Initialize KVM_S390_GET_CMMA_BITS memory\n\nkvm_s390_get_cmma_bits() allocates its output buffer with vmalloc(),\nwhich does not zero the returned pages:\n\n\tvalues = vmalloc(args->count);\n\nIn the non-peek (migration) path, dat_get_cmma() reports a byte count\nspanning from the first to the last dirty page, but __dat_get_cmma_pte()\nwrites values[gfn - start] only for pages whose CMMA dirty bit is set.\nThe walk uses DAT_WALK_IGN_HOLES, so clean and unmapped pages that lie\nbetween two dirty pages within the reported span are visited but never\nstore their byte.  Those gaps (up to KVM_S390_MAX_BIT_DISTANCE pages\neach) stay uninitialized yet fall inside [0, count) and are copied out\nby copy_to_user(), disclosing stale kernel memory to user space.\n\nBefore the switch to the new gmap implementation the buffer was fully\npopulated for every gfn in the span, so no uninitialized bytes were\nexposed; the dirty-only walk introduced the leak.\n\nUse vzalloc() so the gaps read back as zero."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["arch/s390/kvm/kvm-s390.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"e38c884df92119d96f652d51f82661dd2fc0b885","lessThan":"a4a19941ccb2164edc3491faa5ac5df82e94b363","versionType":"git","status":"affected"},{"version":"e38c884df92119d96f652d51f82661dd2fc0b885","lessThan":"c7dda3d0f869dc97223448a06c9a2e5235928e48","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["arch/s390/kvm/kvm-s390.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"7.0","status":"affected"},{"version":"0","lessThan":"7.0","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/a4a19941ccb2164edc3491faa5ac5df82e94b363","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/c7dda3d0f869dc97223448a06c9a2e5235928e48","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-72293","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:22:01.583","lastModified":"2026-08-15T06:22:01.583","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nKVM: s390: vsie: Add missing radix_tree_preload() in _gaccess_shadow_fault()\n\nAdd missing radix_tree_preload() in _gaccess_shadow_fault() to\nguarantee forward progress. The core of _gaccess_shadow_fault() has\nbeen split into ___gaccess_shadow_fault() in order to simplify locking."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["arch/s390/kvm/gaccess.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"e38c884df92119d96f652d51f82661dd2fc0b885","lessThan":"0c3d4ca328e661cb4eda3bb344ea17e4b6a63171","versionType":"git","status":"affected"},{"version":"e38c884df92119d96f652d51f82661dd2fc0b885","lessThan":"668e70cc545e2659f3c4adad20a0883533042473","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["arch/s390/kvm/gaccess.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"7.0","status":"affected"},{"version":"0","lessThan":"7.0","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/0c3d4ca328e661cb4eda3bb344ea17e4b6a63171","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/668e70cc545e2659f3c4adad20a0883533042473","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-72294","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:22:01.783","lastModified":"2026-08-15T06:22:01.783","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nLoongArch: KVM: Check irq validity in kvm_vcpu_ioctl_interrupt()\n\nFunction kvm_vcpu_ioctl_interrupt() can be called from userspace, here\nadd irq validility cheking in kvm_vcpu_ioctl_interrupt()."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["arch/loongarch/kvm/vcpu.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"f45ad5b8aa9335bc6b30331b739e778f2f730b35","lessThan":"15469ba0284c7cc01c38493391e9e73b918833c4","versionType":"git","status":"affected"},{"version":"f45ad5b8aa9335bc6b30331b739e778f2f730b35","lessThan":"efe27b19a15c384cad7c80de399f3107ab070e6d","versionType":"git","status":"affected"},{"version":"f45ad5b8aa9335bc6b30331b739e778f2f730b35","lessThan":"d4574547e04a47ad498149576f65b84475ea6f4c","versionType":"git","status":"affected"},{"version":"f45ad5b8aa9335bc6b30331b739e778f2f730b35","lessThan":"09b318ab77b7a4fc9987fd98d1525fc55ddc2617","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["arch/loongarch/kvm/vcpu.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.7","status":"affected"},{"version":"0","lessThan":"6.7","versionType":"semver","status":"unaffected"},{"version":"6.12.97","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/09b318ab77b7a4fc9987fd98d1525fc55ddc2617","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/15469ba0284c7cc01c38493391e9e73b918833c4","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/d4574547e04a47ad498149576f65b84475ea6f4c","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/efe27b19a15c384cad7c80de399f3107ab070e6d","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-72295","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:22:02.037","lastModified":"2026-08-15T06:22:02.037","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nLoongArch: KVM: Validate irqchip index in irqfd routing\n\nSashiko reported that the irqchip index is not validated for LoongArch.\nAdd validation and reject out-of-range irqchip indexes to avoid indexing\npast the routing table's chip array."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["arch/loongarch/kvm/irqfd.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"1928254c5ccb7bdffd7f0334e1ce250e9ce4de94","lessThan":"199b570d7fca1aa70e596f10a6276997becffb6d","versionType":"git","status":"affected"},{"version":"1928254c5ccb7bdffd7f0334e1ce250e9ce4de94","lessThan":"8b3e188d19e4ffe916780aeb7ddad9d6457b8bcc","versionType":"git","status":"affected"},{"version":"1928254c5ccb7bdffd7f0334e1ce250e9ce4de94","lessThan":"3474037904c20ff915e3ebab0ab5c1e41bbe549e","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["arch/loongarch/kvm/irqfd.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.13","status":"affected"},{"version":"0","lessThan":"6.13","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/199b570d7fca1aa70e596f10a6276997becffb6d","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/3474037904c20ff915e3ebab0ab5c1e41bbe549e","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/8b3e188d19e4ffe916780aeb7ddad9d6457b8bcc","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-72296","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:22:02.160","lastModified":"2026-08-15T06:22:02.160","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nnet: ife: require ETH_HLEN to be pullable in ife_decode()\n\nife decode may return after making only the outer IFE header and\nmetadata pullable. The caller then passes the decapsulated packet to\neth_type_trans(), which expects the inner Ethernet header to be\naccessible from the linear data area.\n\nWith a malformed IFE frame, the inner Ethernet header may still be\nshorter than ETH_HLEN in the linear area, which can lead to a crash in\nthe original code.\n\nFix this by extending the pull check in ife_decode() so that the inner\nEthernet header is also guaranteed to be pullable before returning."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["net/ife/ife.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"ef6980b6becb1afd9d82a4f043749a10ae81bf14","lessThan":"70013f9163bef7fbd9fa62f81cf91b2a7ba66163","versionType":"git","status":"affected"},{"version":"ef6980b6becb1afd9d82a4f043749a10ae81bf14","lessThan":"be272e159dfe1207b67332ad6e17adcf59b4ea4b","versionType":"git","status":"affected"},{"version":"ef6980b6becb1afd9d82a4f043749a10ae81bf14","lessThan":"8c8818e52fddb247ff3214622401a4de6ff8482e","versionType":"git","status":"affected"},{"version":"ef6980b6becb1afd9d82a4f043749a10ae81bf14","lessThan":"9433578bff9c100c466a6354574892e55293cb8f","versionType":"git","status":"affected"},{"version":"ef6980b6becb1afd9d82a4f043749a10ae81bf14","lessThan":"1cb42ec10294a55380e52e674b3df2b962648242","versionType":"git","status":"affected"},{"version":"ef6980b6becb1afd9d82a4f043749a10ae81bf14","lessThan":"5526d1997aea6c9bd865ca4d4894b52e799d735c","versionType":"git","status":"affected"},{"version":"ef6980b6becb1afd9d82a4f043749a10ae81bf14","lessThan":"b69ad768cd4a2ef4e07c18492ae85438ed17c7cb","versionType":"git","status":"affected"},{"version":"ef6980b6becb1afd9d82a4f043749a10ae81bf14","lessThan":"9406f6012b7343661efb516a11c62d4db2b62f75","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["net/ife/ife.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"4.6","status":"affected"},{"version":"0","lessThan":"4.6","versionType":"semver","status":"unaffected"},{"version":"5.10.261","lessThanOrEqual":"5.10.*","versionType":"semver","status":"unaffected"},{"version":"5.15.212","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.178","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.97","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/1cb42ec10294a55380e52e674b3df2b962648242","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/5526d1997aea6c9bd865ca4d4894b52e799d735c","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/70013f9163bef7fbd9fa62f81cf91b2a7ba66163","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/8c8818e52fddb247ff3214622401a4de6ff8482e","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/9406f6012b7343661efb516a11c62d4db2b62f75","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/9433578bff9c100c466a6354574892e55293cb8f","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/b69ad768cd4a2ef4e07c18492ae85438ed17c7cb","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/be272e159dfe1207b67332ad6e17adcf59b4ea4b","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-72297","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:22:02.293","lastModified":"2026-08-15T06:22:02.293","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nnet: atm: reject out-of-range traffic classes in QoS validation\n\nReject ATM traffic classes above ATM_ANYCLASS in check_tp().\nSO_ATMQOS stores the supplied QoS after check_qos() succeeds, so\naccepting larger values leaves invalid traffic_class values in\nvcc->qos.\n\nThat bad state later reaches pvc_info(), which indexes class_name[]\nwith vcc->qos.{rx,tp}.traffic_class. Values above ATM_ANYCLASS cause\nan out-of-bounds read when /proc/net/atm/pvc is read.\n\nTighten the existing QoS validation so invalid traffic_class values\nare rejected at the point where user supplied QoS is accepted."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["net/atm/common.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"1a6dda72455b399ce9c1a12695471dc4d5c61add","versionType":"git","status":"affected"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"2b3e241729e87afed13ac0f666472d5d6ca42e87","versionType":"git","status":"affected"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"367acd288bc6255e247cb1a1efbf5c6567cab423","versionType":"git","status":"affected"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"513f820b3f0cf4462e17d84c39ed3948d061a6ea","versionType":"git","status":"affected"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"15444b57fdc6fc3f3e22a87f791ae5be81e6ecf5","versionType":"git","status":"affected"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"e62adb157c2eaad9ad4867ec6cd9af5b9a51b1c7","versionType":"git","status":"affected"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"806b7b6edc8446e8b94b706807a7090a14d47b5c","versionType":"git","status":"affected"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"cdf19f380e46192e7084be559638aab1f6ed86a2","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["net/atm/common.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"2.6.12","status":"affected"},{"version":"0","lessThan":"2.6.12","versionType":"semver","status":"unaffected"},{"version":"5.10.261","lessThanOrEqual":"5.10.*","versionType":"semver","status":"unaffected"},{"version":"5.15.212","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.178","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.97","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/15444b57fdc6fc3f3e22a87f791ae5be81e6ecf5","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/1a6dda72455b399ce9c1a12695471dc4d5c61add","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/2b3e241729e87afed13ac0f666472d5d6ca42e87","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/367acd288bc6255e247cb1a1efbf5c6567cab423","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/513f820b3f0cf4462e17d84c39ed3948d061a6ea","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/806b7b6edc8446e8b94b706807a7090a14d47b5c","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/cdf19f380e46192e7084be559638aab1f6ed86a2","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/e62adb157c2eaad9ad4867ec6cd9af5b9a51b1c7","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-72298","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:22:02.437","lastModified":"2026-08-15T06:22:02.437","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nnet: qrtr: fix 32-bit integer overflow in qrtr_endpoint_post()\n\nqrtr_endpoint_post() validates an incoming packet with\n\n\tif (!size || len != ALIGN(size, 4) + hdrlen)\n\t\tgoto err;\n\nwhere size comes from the wire. On 32-bit, size_t is 32 bits and\nALIGN(size, 4) wraps to 0 for size >= 0xfffffffd, so the check\npasses and skb_put_data(skb, data + hdrlen, size) writes past the\nhdrlen-sized skb and oopses the kernel. 64-bit is unaffected.\n\nThis is the 32-bit residual of ad9d24c9429e2 (\"net: qrtr: fix OOB\nRead in qrtr_endpoint_post\"), which fixed only the 64-bit case.\n\nReject any size that cannot fit the buffer before the ALIGN."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["net/qrtr/af_qrtr.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"960b08dd36de1e341e3eb43d1c547513e338f4f8","lessThan":"3665e644ea081c4624a1637023b0de3b29f4ae04","versionType":"git","status":"affected"},{"version":"ad9d24c9429e2159d1e279dc3a83191ccb4daf1d","lessThan":"b609f7f46916c6b05585ca82455077198a23770f","versionType":"git","status":"affected"},{"version":"ad9d24c9429e2159d1e279dc3a83191ccb4daf1d","lessThan":"242408b5b763c01288adf3113cbce84378a76e1a","versionType":"git","status":"affected"},{"version":"ad9d24c9429e2159d1e279dc3a83191ccb4daf1d","lessThan":"d0597074e99731fdad5593e4f6d056a3866f2cab","versionType":"git","status":"affected"},{"version":"ad9d24c9429e2159d1e279dc3a83191ccb4daf1d","lessThan":"689b7267f8632b4661879dc323e26ebb60978afb","versionType":"git","status":"affected"},{"version":"ad9d24c9429e2159d1e279dc3a83191ccb4daf1d","lessThan":"22100a8f73d4ae4f17697dae93d4e2e1d283a6ec","versionType":"git","status":"affected"},{"version":"ad9d24c9429e2159d1e279dc3a83191ccb4daf1d","lessThan":"7f72c285f6d3bf63968a0344beee8ab1b370198b","versionType":"git","status":"affected"},{"version":"ad9d24c9429e2159d1e279dc3a83191ccb4daf1d","lessThan":"20054869770c7df060c5ecee3e8bbf9029c47191","versionType":"git","status":"affected"},{"version":"f8111c0d7ed42ede41a3d0d393b104de0730a8a6","versionType":"git","status":"affected"},{"version":"26b8d10703a9be45d6097946b2b4011f7dd2c56f","versionType":"git","status":"affected"},{"version":"19892ab9c9d838e2e5a7744d36e4bb8b7c3292fe","versionType":"git","status":"affected"},{"version":"5.10.46","lessThan":"5.10.261","versionType":"semver","status":"affected"},{"version":"4.19.196","lessThan":"4.20","versionType":"semver","status":"affected"},{"version":"5.4.128","lessThan":"5.5","versionType":"semver","status":"affected"},{"version":"5.12.13","lessThan":"5.13","versionType":"semver","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["net/qrtr/af_qrtr.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"5.13","status":"affected"},{"version":"0","lessThan":"5.13","versionType":"semver","status":"unaffected"},{"version":"5.10.261","lessThanOrEqual":"5.10.*","versionType":"semver","status":"unaffected"},{"version":"5.15.212","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.178","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.97","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/20054869770c7df060c5ecee3e8bbf9029c47191","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/22100a8f73d4ae4f17697dae93d4e2e1d283a6ec","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/242408b5b763c01288adf3113cbce84378a76e1a","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/3665e644ea081c4624a1637023b0de3b29f4ae04","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/689b7267f8632b4661879dc323e26ebb60978afb","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/7f72c285f6d3bf63968a0344beee8ab1b370198b","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/b609f7f46916c6b05585ca82455077198a23770f","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/d0597074e99731fdad5593e4f6d056a3866f2cab","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-72299","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:22:02.567","lastModified":"2026-08-15T06:22:02.567","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\ntipc: restrict socket queue dumps in enqueue tracepoints\n\ntipc_sk_enqueue() runs with sk->sk_lock.slock held while the socket is\nowned by user context. The spinlock protects the backlog queue in this\npath, but it does not serialize against the socket owner consuming or\npurging sk_receive_queue.\n\nKASAN reported:\n\n  CPU: 14 UID: 0 PID: 1050 Comm: tipc3 Not tainted 7.1.0-rc6+ #126 PREEMPT(lazy)\n  Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS 1.15.0-1 04/01/2014\n  Call Trace:\n    <TASK>\n    dump_stack_lvl+0x76/0xa0 lib/dump_stack.c:123\n    print_report+0xce/0x5b0 mm/kasan/report.c:482\n    kasan_report+0xc6/0x100 mm/kasan/report.c:597\n    __asan_report_load4_noabort+0x14/0x30 mm/kasan/report_generic.c:380\n    tipc_skb_dump+0x1327/0x16f0 net/tipc/trace.c:73\n    tipc_list_dump+0x208/0x2e0 net/tipc/trace.c:187\n    tipc_sk_dump+0xaf6/0xd60 net/tipc/socket.c:3996\n    trace_event_raw_event_tipc_sk_class+0x312/0x5a0 net/tipc/trace.h:188\n    tipc_sk_rcv+0xb1d/0x1d50 net/tipc/socket.c:2497\n    tipc_node_xmit+0x1c3/0x1440 net/tipc/node.c:1689\n    __tipc_sendmsg+0x97a/0x1440 net/tipc/socket.c:1512\n    tipc_sendmsg+0x52/0x80 net/tipc/socket.c:1400\n    sock_sendmsg+0x2f6/0x3e0 net/socket.c:825\n    splice_to_socket+0x7f9/0x1010 fs/splice.c:884\n    do_splice+0xe21/0x2330 fs/splice.c:936\n    __do_splice+0x153/0x260 fs/splice.c:1431\n    __x64_sys_splice+0x150/0x230 fs/splice.c:1616\n    x64_sys_call+0xeb5/0x2790 arch/x86/entry/syscall_64.c:41\n    do_syscall_64+0xf3/0x620 arch/x86/entry/syscall_64.c:63\n    entry_SYSCALL_64_after_hwframe+0x76/0x7e arch/x86/entry/entry_64.S:130\n  RIP: 0033:0x71624e8aafe2\n  Code: 08 0f 85 71 3a ff ff 49 89 fb 48 89 f0 48 89 d7 48 89 ce 4c 89 c2 4d 89 ca 4c 8b 44 24 08 4c 8b 4c 24 10 4c 89 5c 24 08 0f 05 <c3> 66 2e 0f 1f 84 00 00 00 00 00 66 2e 0f 1f 84 00 00 00 00 00 66\n  RSP: 002b:0000716157ffed68 EFLAGS: 00000246 ORIG_RAX: 0000000000000113\n  RAX: ffffffffffffffda RBX: 0000716157fff6c0 RCX: 000071624e8aafe2\n  RDX: 000000000000005f RSI: 0000000000000000 RDI: 0000000000000066\n  RBP: 0000716157ffed90 R08: 0000000000008000 R09: 0000000000000001\n  R10: 0000000000000000 R11: 0000000000000246 R12: ffffffffffffff00\n  R13: 0000000000000021 R14: 0000000000000000 R15: 00007fff89799c40\n    </TASK>\n\nThe TIPC_DUMP_ALL tracepoints in tipc_sk_enqueue() also dump\nsk_receive_queue and can therefore dereference skbs that the socket\nowner has already dequeued or freed. Restrict these dumps to\nTIPC_DUMP_SK_BKLGQ, which matches the queue protected by the held\nspinlock.\n\nKeep the change limited to the enqueue path, where the unsafe queue dump\nis reachable while the socket is owned by user context."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["net/tipc/socket.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"01e661ebfbad40e6280fb8ec25f2861d39ba4387","lessThan":"12876864f9de5fa6f611a30c6c17e405a773bf0a","versionType":"git","status":"affected"},{"version":"01e661ebfbad40e6280fb8ec25f2861d39ba4387","lessThan":"b9e100815f4b55e9ccaf6af9a3aba173eb13d381","versionType":"git","status":"affected"},{"version":"01e661ebfbad40e6280fb8ec25f2861d39ba4387","lessThan":"61a55fa24a5d737436018764a647fe5b6cb36371","versionType":"git","status":"affected"},{"version":"01e661ebfbad40e6280fb8ec25f2861d39ba4387","lessThan":"6acbbe54215d5f4251593000cff2bf51d6748713","versionType":"git","status":"affected"},{"version":"01e661ebfbad40e6280fb8ec25f2861d39ba4387","lessThan":"acd7df8d955480a6f6e5bb809da67b1500cc3cf4","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["net/tipc/socket.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"5.0","status":"affected"},{"version":"0","lessThan":"5.0","versionType":"semver","status":"unaffected"},{"version":"6.6.148","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.101","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/12876864f9de5fa6f611a30c6c17e405a773bf0a","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/61a55fa24a5d737436018764a647fe5b6cb36371","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/6acbbe54215d5f4251593000cff2bf51d6748713","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/acd7df8d955480a6f6e5bb809da67b1500cc3cf4","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/b9e100815f4b55e9ccaf6af9a3aba173eb13d381","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-72300","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:22:02.690","lastModified":"2026-08-15T06:22:02.690","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nASoC: SOF: topology: validate vendor array size before parsing\n\nsof_parse_token_sets() reads array->size while iterating over topology\nprivate data. The loop condition only checks that some data remains, so a\nmalformed topology with a truncated trailing vendor array can make the\nparser read the size field before a full vendor-array header is available.\n\nValidate that the remaining private data contains a complete\nsnd_soc_tplg_vendor_array header before reading array->size.\n\nThe declared array size check also needs to remain signed. asize is an int,\nbut sizeof(*array) has type size_t, so comparing them directly promotes\nnegative asize values to unsigned and lets them pass the check,\nas reported in the stable review thread reference below.\n\nCast sizeof(*array) to int when validating the declared array size. This\nrejects negative, zero and otherwise too-small sizes before the parser\ndispatches to the tuple-specific code."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["sound/soc/sof/topology.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"5c37bd025068381f5bdbbf6a5ae3a1da8f6ed928","lessThan":"7c6d2d2baeb1e62dc8c6951d27edc16c5ea6e3aa","versionType":"git","status":"affected"},{"version":"06d4938e41d62af7b5b3f39eb239f58b21f50443","lessThan":"a40e250414b463e953c54cd2a829c9a9a49a78c3","versionType":"git","status":"affected"},{"version":"55024322915539098f7a7dd318351c7a003ff041","lessThan":"d34deef34c99bb4b3ebd2ac51058857827a20e7e","versionType":"git","status":"affected"},{"version":"215e5fe75881a7e2425df04aeeed47a903d5cd5d","lessThan":"201b60c4d15538fcc3c0c2ea9b75dd7d0f58022c","versionType":"git","status":"affected"},{"version":"215e5fe75881a7e2425df04aeeed47a903d5cd5d","lessThan":"8468dd79cfb2ffbdeaf7c353f63d64941cb8ba05","versionType":"git","status":"affected"},{"version":"756c48bdf23050def518e85929be6edea9ae6823","versionType":"git","status":"affected"},{"version":"6.6.136","lessThan":"6.6.145","versionType":"semver","status":"affected"},{"version":"6.12.83","lessThan":"6.12.97","versionType":"semver","status":"affected"},{"version":"6.18.24","lessThan":"6.18.40","versionType":"semver","status":"affected"},{"version":"6.19.14","lessThan":"6.20","versionType":"semver","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["sound/soc/sof/topology.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"7.0","status":"affected"},{"version":"0","lessThan":"7.0","versionType":"semver","status":"unaffected"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.97","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/201b60c4d15538fcc3c0c2ea9b75dd7d0f58022c","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/7c6d2d2baeb1e62dc8c6951d27edc16c5ea6e3aa","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/8468dd79cfb2ffbdeaf7c353f63d64941cb8ba05","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/a40e250414b463e953c54cd2a829c9a9a49a78c3","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/d34deef34c99bb4b3ebd2ac51058857827a20e7e","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-72301","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:22:02.807","lastModified":"2026-08-15T06:22:02.807","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nASoC: SOF: ipc3-control: Fix TOCTOU in bytes_put and bytes_get\n\nIn sof_ipc3_bytes_put(), the size used for the memcpy is derived from\nthe old data->size already in the buffer, not the incoming new data's\nsize field. If the new data has a different size, the copy length is\nwrong: it may truncate valid data or copy stale bytes.\n\nSimilarly, sof_ipc3_bytes_get() checks data->size against max_size\nwithout accounting for the sizeof(struct sof_ipc_ctrl_data) offset\nof the flex array within the allocation.\n\nFix bytes_put to validate and use the incoming data's sof_abi_hdr.size\nfrom ucontrol before copying. Fix bytes_get to subtract sizeof(*cdata)\nfrom the bounds check to match the actual available space."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["sound/soc/sof/ipc3-control.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"544ac8858f249950b4d99c68e538cdc07300528f","lessThan":"8bd715a9d882fe1993bb2aec5eff89fffa946592","versionType":"git","status":"affected"},{"version":"544ac8858f249950b4d99c68e538cdc07300528f","lessThan":"0dce240145f47545d2e4b18c6d58033b83e1fd0e","versionType":"git","status":"affected"},{"version":"544ac8858f249950b4d99c68e538cdc07300528f","lessThan":"ed4f758f34be4c32e02933ac4fa044589d9c1c16","versionType":"git","status":"affected"},{"version":"544ac8858f249950b4d99c68e538cdc07300528f","lessThan":"0c4fbdaca225b97122b61b68c5353caa33a253c3","versionType":"git","status":"affected"},{"version":"544ac8858f249950b4d99c68e538cdc07300528f","lessThan":"92f90917413bdd6078fefff6f6c83a07bf870b04","versionType":"git","status":"affected"},{"version":"544ac8858f249950b4d99c68e538cdc07300528f","lessThan":"1f97760417b5faa60e9642fd0ed61eb17d0b1b39","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["sound/soc/sof/ipc3-control.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"5.18","status":"affected"},{"version":"0","lessThan":"5.18","versionType":"semver","status":"unaffected"},{"version":"6.1.178","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.97","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/0c4fbdaca225b97122b61b68c5353caa33a253c3","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/0dce240145f47545d2e4b18c6d58033b83e1fd0e","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/1f97760417b5faa60e9642fd0ed61eb17d0b1b39","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/8bd715a9d882fe1993bb2aec5eff89fffa946592","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/92f90917413bdd6078fefff6f6c83a07bf870b04","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/ed4f758f34be4c32e02933ac4fa044589d9c1c16","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-72302","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:22:02.917","lastModified":"2026-08-15T06:22:02.917","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nASoC: SOF: ipc3-control: Use overflow checks in control_update size calc\n\nIn sof_ipc3_control_update(), the expected_size calculation uses\nfirmware-provided cdata->num_elems in arithmetic that could overflow\non 32-bit platforms, wrapping to a small value. This would allow the\ncdata->rhdr.hdr.size comparison to pass with mismatched sizes,\npotentially leading to out-of-bounds access in snd_sof_update_control.\n\nUse check_mul_overflow() and check_add_overflow() to detect and reject\noverflowed size calculations."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["sound/soc/sof/ipc3-control.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"10f461d79c2d1afb22344986cc1b4631169cf25e","lessThan":"6856b3c23b0995eefad5a6142b4365ef70e1fe4a","versionType":"git","status":"affected"},{"version":"10f461d79c2d1afb22344986cc1b4631169cf25e","lessThan":"89a2309a9eec80d4c19e3aed62c4f923594d1911","versionType":"git","status":"affected"},{"version":"10f461d79c2d1afb22344986cc1b4631169cf25e","lessThan":"ffd79e77f2fbacd7a5d40ad1d4c7f3f089a8f2f3","versionType":"git","status":"affected"},{"version":"10f461d79c2d1afb22344986cc1b4631169cf25e","lessThan":"711d912b18763af62a63aa8f2419a774eb63bba4","versionType":"git","status":"affected"},{"version":"10f461d79c2d1afb22344986cc1b4631169cf25e","lessThan":"312c7d2ebe696da3f885eee77d52297664e57c53","versionType":"git","status":"affected"},{"version":"10f461d79c2d1afb22344986cc1b4631169cf25e","lessThan":"8791977d7289f6e9d2b014f60a5455f053a7bc04","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["sound/soc/sof/ipc3-control.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"5.18","status":"affected"},{"version":"0","lessThan":"5.18","versionType":"semver","status":"unaffected"},{"version":"6.1.178","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.97","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/312c7d2ebe696da3f885eee77d52297664e57c53","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/6856b3c23b0995eefad5a6142b4365ef70e1fe4a","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/711d912b18763af62a63aa8f2419a774eb63bba4","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/8791977d7289f6e9d2b014f60a5455f053a7bc04","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/89a2309a9eec80d4c19e3aed62c4f923594d1911","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/ffd79e77f2fbacd7a5d40ad1d4c7f3f089a8f2f3","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-72303","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:22:03.023","lastModified":"2026-08-15T06:22:03.023","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nASoC: SOF: ipc4-control: Validate notification payload size\n\nValidate MODULE_NOTIFICATION payload length before reading\nbytes/channel data in control update handling."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["sound/soc/sof/ipc4-control.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"2a28b5240f2b328495c6565d277f438dbc583d61","lessThan":"c29f5b4498894aebb2f87b1a29bb320e2f9348f9","versionType":"git","status":"affected"},{"version":"2a28b5240f2b328495c6565d277f438dbc583d61","lessThan":"5bdfeccb7fbf6e000fc783cd8412732e67c1ad0c","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["sound/soc/sof/ipc4-control.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"7.0","status":"affected"},{"version":"0","lessThan":"7.0","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/5bdfeccb7fbf6e000fc783cd8412732e67c1ad0c","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/c29f5b4498894aebb2f87b1a29bb320e2f9348f9","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-72304","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:22:03.120","lastModified":"2026-08-15T06:22:03.120","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nASoC: SOF: ipc4-control: Fix TOCTOU in sof_ipc4_bytes_put\n\nIn sof_ipc4_bytes_put(), the copy size is derived from the old\ndata->size in the buffer rather than the incoming new data's size\nfield from ucontrol. If the new data has a different size, the copy\nuses the wrong length: it may truncate valid data or copy stale bytes.\n\nFix by validating and using the incoming data's sof_abi_hdr.size from\nucontrol before copying."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["sound/soc/sof/ipc4-control.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"a062c8899fede2ab5660a817e9b602d3fa280a99","lessThan":"266f936db83aee6ca6473bbb06259bda52bf4fc3","versionType":"git","status":"affected"},{"version":"a062c8899fede2ab5660a817e9b602d3fa280a99","lessThan":"4cf6a7ebbf8787393b158b2cc341723e5bebc4a8","versionType":"git","status":"affected"},{"version":"a062c8899fede2ab5660a817e9b602d3fa280a99","lessThan":"fb4293173db2d474d8fbc0e5ecf4943e6df2b40e","versionType":"git","status":"affected"},{"version":"a062c8899fede2ab5660a817e9b602d3fa280a99","lessThan":"038406abde0d0883419ec89425ea941ec8bbef95","versionType":"git","status":"affected"},{"version":"a062c8899fede2ab5660a817e9b602d3fa280a99","lessThan":"3ad673e7139cf214afd24321a829aad6575f4163","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["sound/soc/sof/ipc4-control.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.4","status":"affected"},{"version":"0","lessThan":"6.4","versionType":"semver","status":"unaffected"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.97","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/038406abde0d0883419ec89425ea941ec8bbef95","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/266f936db83aee6ca6473bbb06259bda52bf4fc3","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/3ad673e7139cf214afd24321a829aad6575f4163","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/4cf6a7ebbf8787393b158b2cc341723e5bebc4a8","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/fb4293173db2d474d8fbc0e5ecf4943e6df2b40e","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-72305","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:22:03.217","lastModified":"2026-08-15T06:22:03.217","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nVDUSE: avoid leaking information to userspace\n\nThe bounceing is not necessarily page aligned, so current VDUSE can\nleak kernel information through mapping bounce pages to\nuserspace. Allocate bounce pages with __GFP_ZERO to avoid leaking\ninformation to userspace."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/vdpa/vdpa_user/iova_domain.c","drivers/vdpa/vdpa_user/vduse_dev.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"8c773d53fb7b64267b0f55c1d3517cb8c5e29b3c","lessThan":"fde25641cbddd0c084e3320d08f755e7e6acfae5","versionType":"git","status":"affected"},{"version":"8c773d53fb7b64267b0f55c1d3517cb8c5e29b3c","lessThan":"5e88c1bc3a41d9a260dd42bae8ad18fd4f35bbe1","versionType":"git","status":"affected"},{"version":"8c773d53fb7b64267b0f55c1d3517cb8c5e29b3c","lessThan":"690fb82c4122f8c2656fa4f842275132771b68b9","versionType":"git","status":"affected"},{"version":"8c773d53fb7b64267b0f55c1d3517cb8c5e29b3c","lessThan":"00335df9da2011e095f846d645cc2e9fd2907659","versionType":"git","status":"affected"},{"version":"8c773d53fb7b64267b0f55c1d3517cb8c5e29b3c","lessThan":"9c1523803445ee0348f62b77793266dd981596e0","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/vdpa/vdpa_user/iova_domain.c","drivers/vdpa/vdpa_user/vduse_dev.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"5.15","status":"affected"},{"version":"0","lessThan":"5.15","versionType":"semver","status":"unaffected"},{"version":"6.6.148","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.101","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.42","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/00335df9da2011e095f846d645cc2e9fd2907659","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/5e88c1bc3a41d9a260dd42bae8ad18fd4f35bbe1","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/690fb82c4122f8c2656fa4f842275132771b68b9","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/9c1523803445ee0348f62b77793266dd981596e0","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/fde25641cbddd0c084e3320d08f755e7e6acfae5","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-72306","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:22:03.330","lastModified":"2026-08-15T06:22:03.330","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nvduse: Fix race in vduse_dev_msg_sync and vduse_dev_read_iter\n\nThere is one race case in vduse_dev_msg_sync and vduse_dev_read_iter:\n\nvduse_dev_read_iter():\n    lock(msg_lock);\n    dequeue_msg(send_list);\n    unlock(msg_lock);\nvduse_dev_msg_sync():\n    wait_timeout() finish\n    lock(msg_lock);\n    check msg->complete is false\n        list_del(msg);   <- double list_del() crash!\n\nTo fix this case, we shall ensure vduse_msg is on send_list or recv_list\noutside the msg_lock critical section."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/vdpa/vdpa_user/vduse_dev.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"c8a6153b6c59d95c0e091f053f6f180952ade91e","lessThan":"c83ad3dfa6d9953d5ce6839416bf5a1bfc50285a","versionType":"git","status":"affected"},{"version":"c8a6153b6c59d95c0e091f053f6f180952ade91e","lessThan":"09723f26ed801c083e914cec4cc0e1af4b933dc7","versionType":"git","status":"affected"},{"version":"c8a6153b6c59d95c0e091f053f6f180952ade91e","lessThan":"d7e7c813834c6c05c26033456ab7169e2f9c99eb","versionType":"git","status":"affected"},{"version":"c8a6153b6c59d95c0e091f053f6f180952ade91e","lessThan":"3755965adbb617f4283ac6ccd351ed0676843cba","versionType":"git","status":"affected"},{"version":"c8a6153b6c59d95c0e091f053f6f180952ade91e","lessThan":"d8715b5a8fdb23fef576700e71d0c253dbeddad4","versionType":"git","status":"affected"},{"version":"c8a6153b6c59d95c0e091f053f6f180952ade91e","lessThan":"8062ff9d366c4bc4ae775e14eac9a769f20c60dd","versionType":"git","status":"affected"},{"version":"c8a6153b6c59d95c0e091f053f6f180952ade91e","lessThan":"ae9c13b6fd79087cc5a216ee1649b6f012c2a238","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/vdpa/vdpa_user/vduse_dev.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"5.15","status":"affected"},{"version":"0","lessThan":"5.15","versionType":"semver","status":"unaffected"},{"version":"5.15.212","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.178","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.97","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/09723f26ed801c083e914cec4cc0e1af4b933dc7","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/3755965adbb617f4283ac6ccd351ed0676843cba","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/8062ff9d366c4bc4ae775e14eac9a769f20c60dd","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/ae9c13b6fd79087cc5a216ee1649b6f012c2a238","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/c83ad3dfa6d9953d5ce6839416bf5a1bfc50285a","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/d7e7c813834c6c05c26033456ab7169e2f9c99eb","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/d8715b5a8fdb23fef576700e71d0c253dbeddad4","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-72307","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:22:03.440","lastModified":"2026-08-15T06:22:03.440","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nmlxsw: fix refcount leak in mlxsw_sp_vrs_lpm_tree_replace()\n\nWhen mlxsw_sp_vrs_lpm_tree_replace() fails after replacing some VRs,\nthe error rollback loop does not correctly revert the preceding\nreplacements. The loop decrements the index but fails to update the\nvr pointer, which still points to the VR that caused the failure. As\na result, the condition and the rollback call always operate on the\nsame VR, potentially calling mlxsw_sp_vr_lpm_tree_replace() multiple\ntimes on it while never rolling back the earlier VRs. Those VRs\ncontinue to hold a reference to new_tree acquired via\nmlxsw_sp_lpm_tree_hold(), leaking the reference count of new_tree.\n\nFix by reinitializing vr inside the error loop with the updated index:\n\n\tvr = &mlxsw_sp->router->vrs[i];\n\nso that the loop correctly iterates over all VRs that were actually\nreplaced."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/net/ethernet/mellanox/mlxsw/spectrum_router.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"fc922bb0dd9406dd9897fd47df958789891c380e","lessThan":"c2c75c45b54f3b12eafb28a4eb47f8821512c1aa","versionType":"git","status":"affected"},{"version":"fc922bb0dd9406dd9897fd47df958789891c380e","lessThan":"7203ac71d3895fa5948b319dd724f0e1cffbc4a1","versionType":"git","status":"affected"},{"version":"fc922bb0dd9406dd9897fd47df958789891c380e","lessThan":"f6454a5fbf2224ad30ec70e686a6c592561da1f2","versionType":"git","status":"affected"},{"version":"fc922bb0dd9406dd9897fd47df958789891c380e","lessThan":"220d41bdce41fe5a39a7f419faab1e907b4093c2","versionType":"git","status":"affected"},{"version":"fc922bb0dd9406dd9897fd47df958789891c380e","lessThan":"9e4a6185679922305ea1df68403f00ccc512656b","versionType":"git","status":"affected"},{"version":"fc922bb0dd9406dd9897fd47df958789891c380e","lessThan":"3a2b47d1b4b3de54d030a7fdb6a322c970513ee3","versionType":"git","status":"affected"},{"version":"fc922bb0dd9406dd9897fd47df958789891c380e","lessThan":"8adebf07b46df79a0e49a6d4ae384f0db7c91db6","versionType":"git","status":"affected"},{"version":"fc922bb0dd9406dd9897fd47df958789891c380e","lessThan":"21cf8dc478a49e8de039c2739b1646a774cb1944","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/net/ethernet/mellanox/mlxsw/spectrum_router.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"4.14","status":"affected"},{"version":"0","lessThan":"4.14","versionType":"semver","status":"unaffected"},{"version":"5.10.261","lessThanOrEqual":"5.10.*","versionType":"semver","status":"unaffected"},{"version":"5.15.212","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.178","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.97","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/21cf8dc478a49e8de039c2739b1646a774cb1944","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/220d41bdce41fe5a39a7f419faab1e907b4093c2","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/3a2b47d1b4b3de54d030a7fdb6a322c970513ee3","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/7203ac71d3895fa5948b319dd724f0e1cffbc4a1","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/8adebf07b46df79a0e49a6d4ae384f0db7c91db6","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/9e4a6185679922305ea1df68403f00ccc512656b","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/c2c75c45b54f3b12eafb28a4eb47f8821512c1aa","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/f6454a5fbf2224ad30ec70e686a6c592561da1f2","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-72308","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:22:03.570","lastModified":"2026-08-15T06:22:03.570","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nmlxsw: fix refcount leak in mlxsw_sp_port_lag_join()\n\nWhen mlxsw_sp_port_lag_index_get() fails, mlxsw_sp_port_lag_join()\nreturns an error without releasing the lag reference obtained by\nthe earlier mlxsw_sp_lag_get().  All other error paths in the\nfunction jump to the cleanup label that ends with\nmlxsw_sp_lag_put(), so this is a single missed release.\n\nFix the leak by replacing the bare 'return err' with a goto to the\nexisting error cleanup label, which will drop the reference safely."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/net/ethernet/mellanox/mlxsw/spectrum.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"0d65fc13042fce6a2d6de58ff0dc9531e8523c07","lessThan":"8b3350eacd9df0597bfe36a594df7b9def0b3edf","versionType":"git","status":"affected"},{"version":"0d65fc13042fce6a2d6de58ff0dc9531e8523c07","lessThan":"1cf8a1af42b1f12a30b7abd34fe4fc23b3170e7e","versionType":"git","status":"affected"},{"version":"0d65fc13042fce6a2d6de58ff0dc9531e8523c07","lessThan":"2d8b3c3e129973a51ae924bdcf6993a76b828814","versionType":"git","status":"affected"},{"version":"0d65fc13042fce6a2d6de58ff0dc9531e8523c07","lessThan":"cab468c3c03f4bcd7530ce2783a4140da14efb7b","versionType":"git","status":"affected"},{"version":"0d65fc13042fce6a2d6de58ff0dc9531e8523c07","lessThan":"41c8c1d65b32beacd8d916a22457b4f6e47f45af","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/net/ethernet/mellanox/mlxsw/spectrum.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"4.5","status":"affected"},{"version":"0","lessThan":"4.5","versionType":"semver","status":"unaffected"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.97","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/1cf8a1af42b1f12a30b7abd34fe4fc23b3170e7e","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/2d8b3c3e129973a51ae924bdcf6993a76b828814","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/41c8c1d65b32beacd8d916a22457b4f6e47f45af","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/8b3350eacd9df0597bfe36a594df7b9def0b3edf","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/cab468c3c03f4bcd7530ce2783a4140da14efb7b","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-72309","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:22:03.673","lastModified":"2026-08-15T06:22:03.673","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\ntracing/remotes: Fix leak in trace_remote_alloc_buffer() error path\n\nIf page allocation fails in trace_remote_alloc_buffer(), desc->nr_cpus\nis not yet incremented for the current CPU. As a consequence, on error,\nhalf-allocated rb_desc will not be freed in trace_remote_free_buffer().\n\nIncrement desc->nr_cpus as soon as the first allocation for the current\nCPU has succeeded."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["kernel/trace/trace_remote.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"96e43537af5461b26f50904c6055046ba65d742f","lessThan":"81a7b7ddb07efdd8cf30eac6def18b9289b8de1e","versionType":"git","status":"affected"},{"version":"96e43537af5461b26f50904c6055046ba65d742f","lessThan":"ec082d0b978b5fb4c11205ccce63587ac94c74e1","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["kernel/trace/trace_remote.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"7.1","status":"affected"},{"version":"0","lessThan":"7.1","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc3","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/81a7b7ddb07efdd8cf30eac6def18b9289b8de1e","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/ec082d0b978b5fb4c11205ccce63587ac94c74e1","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-72310","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:22:03.777","lastModified":"2026-08-15T06:22:03.777","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nsmb: client: fix overflow in passthrough ioctl bounds check\n\nsmb2_ioctl_query_info() validates the PASSTHRU_FSCTL response payload\nbefore copying it to userspace.\n\nThe payload offset and length both come from 32-bit fields. The bounds\ncheck currently adds OutputOffset and qi.input_buffer_length directly, so\nthe addition can wrap in 32-bit arithmetic before the result is compared\nagainst the response buffer length.\n\nA malicious server can use a large OutputOffset and a small OutputCount\nto make the wrapped sum pass the bounds check. The later copy_to_user()\nthen reads from io_rsp + OutputOffset, outside the response buffer.\n\nUse size_add() for the offset plus length check so overflow is treated as\nout of bounds."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["fs/smb/client/smb2ops.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"2b1116bbe898aefdf584838448c6869f69851e0f","lessThan":"175357ee0c596cb82054650dfa32fda51ad35aaa","versionType":"git","status":"affected"},{"version":"2b1116bbe898aefdf584838448c6869f69851e0f","lessThan":"dbd126539c098dba3159ce7d34b10b2daddcbd0f","versionType":"git","status":"affected"},{"version":"2b1116bbe898aefdf584838448c6869f69851e0f","lessThan":"63feb687e89a3a52a31e6e01764117cc500f1974","versionType":"git","status":"affected"},{"version":"2b1116bbe898aefdf584838448c6869f69851e0f","lessThan":"160045fc943f6c46b227644261252c8a22b8a87a","versionType":"git","status":"affected"},{"version":"2b1116bbe898aefdf584838448c6869f69851e0f","lessThan":"b30771b69eafae750afb7385fbcc3d77ed3f3670","versionType":"git","status":"affected"},{"version":"2b1116bbe898aefdf584838448c6869f69851e0f","lessThan":"1627e7d5c9b09721a141d07cedb178882f1ded67","versionType":"git","status":"affected"},{"version":"2b1116bbe898aefdf584838448c6869f69851e0f","lessThan":"1a638c55f2db6cb2296e5e3138015dd8fd9d4aa9","versionType":"git","status":"affected"},{"version":"2b1116bbe898aefdf584838448c6869f69851e0f","lessThan":"a4f27ad055392fa164f5649e89a3637b033c5fcc","versionType":"git","status":"affected"},{"version":"2005c32ec99ee2490e8131b3953f3f212009ffea","versionType":"git","status":"affected"},{"version":"5.4.69","lessThan":"5.5","versionType":"semver","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["fs/smb/client/smb2ops.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"5.5","status":"affected"},{"version":"0","lessThan":"5.5","versionType":"semver","status":"unaffected"},{"version":"5.10.261","lessThanOrEqual":"5.10.*","versionType":"semver","status":"unaffected"},{"version":"5.15.212","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.178","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.97","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc3","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/160045fc943f6c46b227644261252c8a22b8a87a","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/1627e7d5c9b09721a141d07cedb178882f1ded67","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/175357ee0c596cb82054650dfa32fda51ad35aaa","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/1a638c55f2db6cb2296e5e3138015dd8fd9d4aa9","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/63feb687e89a3a52a31e6e01764117cc500f1974","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/a4f27ad055392fa164f5649e89a3637b033c5fcc","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/b30771b69eafae750afb7385fbcc3d77ed3f3670","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/dbd126539c098dba3159ce7d34b10b2daddcbd0f","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-72311","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:22:03.913","lastModified":"2026-08-15T06:22:03.913","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/xe: free madvise VMA array on L2 flush failure\n\nxe_vm_madvise_ioctl() allocates madvise_range.vmas in get_vmas().\nAfter get_vmas() succeeds with at least one VMA, error paths must go\nthrough free_vmas so the array is released before the madvise details are\ndestroyed.\n\nThe L2 flush validation path added for PAT madvise rejects some\nSVM/userptr ranges after get_vmas() has succeeded, but jumps directly to\nmadv_fini. This skips kfree(madvise_range.vmas), leaking the VMA array on\neach failed ioctl.\n\nJump to free_vmas instead, matching the other validation failure paths\nafter get_vmas() has succeeded.\n\n(cherry picked from commit c3a1c3579b1250060da73507a4acef712974c78a)"}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/gpu/drm/xe/xe_vm_madvise.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"4f39a194d41e6b8cb61a91a7bb01b17be59a7d73","lessThan":"bf126747e7bff55e5ba0b1ec10fc5fce99feaed9","versionType":"git","status":"affected"},{"version":"4f39a194d41e6b8cb61a91a7bb01b17be59a7d73","lessThan":"14abbed336a2d1bbd726c25d148d2ec0ff928073","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/gpu/drm/xe/xe_vm_madvise.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"7.1","status":"affected"},{"version":"0","lessThan":"7.1","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc3","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/14abbed336a2d1bbd726c25d148d2ec0ff928073","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/bf126747e7bff55e5ba0b1ec10fc5fce99feaed9","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-72312","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:22:04.013","lastModified":"2026-08-15T06:22:04.013","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nocteontx2-af: fix VF bringup affecting PF promiscuous state\n\nMbox handling of nix_set_rx_mode for a VF with promiscuous and\nall_multi flags set to false causes deletion of the PF's promiscuous\nand allmulti MCAM rules. This occurs because the APIs that\nenable/disable these rules operate only on the PF, even when the\nmbox request is made via a VF interface.\n\nGuard both rvu_npc_enable_allmulti_entry() and\nrvu_npc_enable_promisc_entry() disable paths with an is_vf() check so\nthat a VF bringing up or tearing down its interface cannot inadvertently\nclear the PF's MCAM rules."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/net/ethernet/marvell/octeontx2/af/rvu_nix.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"967db3529ecac305d230aa4e60abddf6ab63543a","lessThan":"daa2451640a3e0727fd598f5c2ccb8bb4d5a8b9c","versionType":"git","status":"affected"},{"version":"967db3529ecac305d230aa4e60abddf6ab63543a","lessThan":"212c59e5e416859579272288fd325148fc316109","versionType":"git","status":"affected"},{"version":"967db3529ecac305d230aa4e60abddf6ab63543a","lessThan":"53e17d9ed779ad25870abb9c31bc294c71a2278c","versionType":"git","status":"affected"},{"version":"967db3529ecac305d230aa4e60abddf6ab63543a","lessThan":"3de77d2f34c2bc2acaedabc2c5e0a561b85c283a","versionType":"git","status":"affected"},{"version":"967db3529ecac305d230aa4e60abddf6ab63543a","lessThan":"3cf83432e0561aef6d7ec2664909d12d0ff0ffc1","versionType":"git","status":"affected"},{"version":"967db3529ecac305d230aa4e60abddf6ab63543a","lessThan":"fabb881df322da25442f98d23f5fa371e3c78ec4","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/net/ethernet/marvell/octeontx2/af/rvu_nix.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"5.14","status":"affected"},{"version":"0","lessThan":"5.14","versionType":"semver","status":"unaffected"},{"version":"6.1.178","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.97","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc3","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/212c59e5e416859579272288fd325148fc316109","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/3cf83432e0561aef6d7ec2664909d12d0ff0ffc1","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/3de77d2f34c2bc2acaedabc2c5e0a561b85c283a","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/53e17d9ed779ad25870abb9c31bc294c71a2278c","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/daa2451640a3e0727fd598f5c2ccb8bb4d5a8b9c","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/fabb881df322da25442f98d23f5fa371e3c78ec4","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-72313","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:22:04.123","lastModified":"2026-08-15T06:22:04.123","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/fb-helper: Only consider active CRTCs for vblank sync\n\nOnly synchronize fbdev output to the vblank of an active CRTC. Go over\nthe list of CRTCs and pick the first that matches. Fixes warnings as\nthe one shown below\n\n[   77.201354] WARNING: drivers/gpu/drm/drm_vblank.c:1320 at drm_crtc_wait_one_vblank+0x194/0x1cc [drm], CPU#1: kworker/1:7/1867\n[   77.201354] omapdrm omapdrm.0: [drm] vblank wait timed out on crtc 0\n\nThis currently happens if the fbdev output is not on CRTC 0.\n\nAtomic and non-atomic drivers require distinct code paths. As for other\nfbdev operations, implement both and select the correct one at runtime.\n\nNot finding an active CRTC is not a bug. Do not wait in this case, but\nflush the display update as before.\n\nv4:\n- avoid possible deadlocks with locking context (Sashiko)\nv3:\n- drop excessive state validation (Jani)\n- acquire plane and CRTC mutices (Sashiko)\nv2:\n- move look-up code into separate helper\n- support drivers with legacy modesetting\nv1:\n- see https://lore.kernel.org/dri-devel/1c9e0e24-9c4a-4259-8700-cf9e5fd60ca3@suse.de/"}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/gpu/drm/drm_fb_helper.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"d8c4bddcd8bcb41885d3db2ba18c840c411564c2","lessThan":"7d84acf641afb68aa8efe40815ef43779ddb12fd","versionType":"git","status":"affected"},{"version":"d8c4bddcd8bcb41885d3db2ba18c840c411564c2","lessThan":"06c2b8d7ea2bcb014dd974fc3bc6d128d65d7477","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/gpu/drm/drm_fb_helper.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.19","status":"affected"},{"version":"0","lessThan":"6.19","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc3","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/06c2b8d7ea2bcb014dd974fc3bc6d128d65d7477","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/7d84acf641afb68aa8efe40815ef43779ddb12fd","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-72314","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:22:04.223","lastModified":"2026-08-15T06:22:04.223","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nregulator: core: regulator_lock_two() should test for EDEADLK not EDEADLOCK\n\nCompare against -EDEADLK, which is what ww_mutex_lock() actually\nreturns and what every other deadlock check in this file already uses.\n\nFunction regulator_lock_two() acquires two regulators via\nregulator_lock_nested() -> ww_mutex_lock().  On contention,\nww_mutex_lock() returns -EDEADLK, which is the caller's signal to drop\nthe lock it holds and retry the acquisition in the canonical order.\n\nHowever, regulator_lock_two() tests the return value against -EDEADLOCK\nrather than -EDEADLK.  On most architectures, EDEADLK and EDEADLOCK are\nthe same value, so the comparison happens to be correct and the bug is\ninvisible.  But on MIPS, SPARC, and PowerPC, those two errors have\ndifferent values.  The test is wrong: a genuine -EDEADLK backoff no\nlonger matches -EDEADLOCK, so instead of unlocking and retrying, the\ncode falls into WARN_ON(ret) and returns with only one of the two\nregulators locked.\n\nIn practice, this is a bug only on MIPS, because the regulator core is\nnot built or used on the other two platforms.\n\nIn general, EDEADLK is preferred over EDEADLOCK for new code."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/regulator/core.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"06140d6dfe720d80566f792b4e28a9cd60a67970","lessThan":"dc804f390fddd9c389edf0976356942e16878d8f","versionType":"git","status":"affected"},{"version":"1e3056b8067c2e9b7741c4e588f0acacbe4bdafc","lessThan":"8e39aa63798ea0a797fd9341419f12ef91df3238","versionType":"git","status":"affected"},{"version":"849ab4cf182b38e562ffcc1b494d510e948822dd","lessThan":"0c305eac40470a224671858a215963b070f9b2a9","versionType":"git","status":"affected"},{"version":"cba6cfdc7c3f1516f0d08ddfb24e689af0932573","lessThan":"29a7953e9adea6c7f9e64947745b79158e7cea7f","versionType":"git","status":"affected"},{"version":"cba6cfdc7c3f1516f0d08ddfb24e689af0932573","lessThan":"e2063307ea3b6da74585129ba7b588e8243e2ef0","versionType":"git","status":"affected"},{"version":"cba6cfdc7c3f1516f0d08ddfb24e689af0932573","lessThan":"346e2d666a29ae7233c56b356a0487eb1d42589b","versionType":"git","status":"affected"},{"version":"cba6cfdc7c3f1516f0d08ddfb24e689af0932573","lessThan":"153d1b8b5bc30847eb70ad535f62f289aa9217e6","versionType":"git","status":"affected"},{"version":"cba6cfdc7c3f1516f0d08ddfb24e689af0932573","lessThan":"d38f8bd771c4999b797d7074b348cf201414bd34","versionType":"git","status":"affected"},{"version":"5224ea575196db11c0a909a78ea426ccdb92f064","versionType":"git","status":"affected"},{"version":"435c65af581a61ca249bd8f717c3a147dc119f11","versionType":"git","status":"affected"},{"version":"cdc042430ea9e07f77ce05a9d29e227dbdecc733","versionType":"git","status":"affected"},{"version":"5.10.180","lessThan":"5.10.261","versionType":"semver","status":"affected"},{"version":"5.15.111","lessThan":"5.15.212","versionType":"semver","status":"affected"},{"version":"6.1.28","lessThan":"6.1.178","versionType":"semver","status":"affected"},{"version":"5.4.243","lessThan":"5.5","versionType":"semver","status":"affected"},{"version":"6.2.15","lessThan":"6.3","versionType":"semver","status":"affected"},{"version":"6.3.2","lessThan":"6.4","versionType":"semver","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/regulator/core.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.4","status":"affected"},{"version":"0","lessThan":"6.4","versionType":"semver","status":"unaffected"},{"version":"5.10.261","lessThanOrEqual":"5.10.*","versionType":"semver","status":"unaffected"},{"version":"5.15.212","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.178","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.97","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc3","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/0c305eac40470a224671858a215963b070f9b2a9","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/153d1b8b5bc30847eb70ad535f62f289aa9217e6","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/29a7953e9adea6c7f9e64947745b79158e7cea7f","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/346e2d666a29ae7233c56b356a0487eb1d42589b","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/8e39aa63798ea0a797fd9341419f12ef91df3238","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/d38f8bd771c4999b797d7074b348cf201414bd34","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/dc804f390fddd9c389edf0976356942e16878d8f","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/e2063307ea3b6da74585129ba7b588e8243e2ef0","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-72315","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:22:04.367","lastModified":"2026-08-15T06:22:04.367","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nsmb: client: fix busy dentry warning on unmount after DIO\n\nCommit c68337442f03 (\"cifs: Fix busy dentry used after unmounting\") fixed\nthe issue in cifs where deferred close of a file led to a dentry reference\ncount not being released in umount, by flushing deferredclose_wq in\ncifs_kill_sb() to solve it.\n\nHowever, the cifs DIO path suffers from the same busy-dentry problem caused\nby a delayed dentry reference-count release:\n\n\t[dio]\t\t\t[cifsd]\t\t\t[close + umount]\nnetfs_unbuffered_write_iter_locked\n...\n\t\t\t\tcifs_demultiplex_thread\n netfs_unbuffered_write\n  cifs_issue_write\n  netfs_wait_for_in_progress_stream [1]\n\t\t\t\t...\n\t\t\t\t netfs_write_subrequest_terminated\n\t\t\t\t  netfs_subreq_clear_in_progress\n\t\t\t\t   netfs_wake_collector // wake [1]\n\t\t\t\t  netfs_put_subrequest\n netfs_put_request\n  queue_work(system_dfl_wq, xxx) [2]\n // dio write return\t\t\t\t\tcifs_close\n\t\t\t\t\t\t\t _cifsFileInfo_put\n\t\t\t\t\t\t\t  // cfile->count 2->1\n\t\t\t\t\t\t\t  --cfile->count [3]\n\n\t\t\t\t\t\t\t// umount\n\t\t\t\t\t\t\tcifs_kill_sb\n\t\t\t\t\t\t\t kill_anon_super\n\t\t\t\t\t\t\t  // warning triggered!\n\t\t\t\t\t\t\t  shrink_dcache_for_umount [4]\n[system_dfl_wq] [5]\nnetfs_free_request\n ...\n _cifsFileInfo_put\n  // cfile->count 1->0\n  --cfile->count\n  queue_work(fileinfo_put_wq, xxx)\n\n[fileinfo_put_wq] [6]\ncifsFileInfo_put_work\n cifsFileInfo_put_final\n  dput\n\nIf the umount path is triggered before [5], it results warning:\nBUG: Dentry 00000000eab1f070{i=9a917b66ae404fec,n=test}  still in use (1)\n[unmount of cifs cifs]\n\nThe existing per-inode ictx->io_count wait in cifs_evict_inode() does not\nhelp: it lives in the inode eviction path, which runs after\nshrink_dcache_for_umount() has already warned about the busy dentries.\n\nFix it by adding a per-superblock outstanding-rreq counter that is\nincremented in cifs_init_request() and decremented in cifs_free_request().\nIn cifs_kill_sb(), before kill_anon_super(), wait for this counter to reach\n0 - which guarantees that all cleanup_work for this sb have run and thus\nall relevant cfile puts are queued on fileinfo_put_wq or serverclose_wq.\nThen drain the workqueue so the dentry refs are dropped.\n\nThis is a targeted wait, not a flush of the system-wide system_dfl_wq."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["fs/smb/client/cifs_fs_sb.h","fs/smb/client/cifsfs.c","fs/smb/client/connect.c","fs/smb/client/file.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"340cea84f691c5206561bb2e0147158fe02070be","lessThan":"f0eac9c3c3711f24efc2aaf12b8ec3e54a38c214","versionType":"git","status":"affected"},{"version":"340cea84f691c5206561bb2e0147158fe02070be","lessThan":"75f5c412fa867efa0bf9b646bffe0d912109e84a","versionType":"git","status":"affected"},{"version":"708c276f516d27beaded7f372ac8111cee43926c","versionType":"git","status":"affected"},{"version":"0629a1a187e424373364d681b42b101894bdb548","versionType":"git","status":"affected"},{"version":"0e4b8faaaebe3137bec5723ef2b3cb0437fb38fd","versionType":"git","status":"affected"},{"version":"f655467a9973f964b267871e5fef533ad5014494","versionType":"git","status":"affected"},{"version":"30afc6ea72cc6cf7c8d579e79b64232801c38d08","versionType":"git","status":"affected"},{"version":"6.1.167","lessThan":"6.2","versionType":"semver","status":"affected"},{"version":"6.6.130","lessThan":"6.7","versionType":"semver","status":"affected"},{"version":"6.12.78","lessThan":"6.13","versionType":"semver","status":"affected"},{"version":"6.18.20","lessThan":"6.19","versionType":"semver","status":"affected"},{"version":"6.19.10","lessThan":"6.20","versionType":"semver","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["fs/smb/client/cifs_fs_sb.h","fs/smb/client/cifsfs.c","fs/smb/client/connect.c","fs/smb/client/file.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"7.0","status":"affected"},{"version":"0","lessThan":"7.0","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc3","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/75f5c412fa867efa0bf9b646bffe0d912109e84a","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/f0eac9c3c3711f24efc2aaf12b8ec3e54a38c214","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-72316","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:22:04.503","lastModified":"2026-08-15T06:22:04.503","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\ndm era: fix NULL pointer dereference in metadata_open()\n\nmetadata_open() returns NULL when kzalloc_obj() fails, but the\ncaller era_ctr() only checks IS_ERR(md).  Since IS_ERR(NULL)\nreturns false, the NULL pointer is treated as a valid result\nand later assigned to era->md, leading to a NULL pointer\ndereference when the metadata is accessed.\n\nFix this by returning ERR_PTR(-ENOMEM) on allocation failure,\nconsistent with dm-cache-metadata.c, dm-thin-metadata.c, and\ndm-clone-metadata.c which all use ERR_PTR(-ENOMEM) for the\nsame pattern."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/md/dm-era-target.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"eec40579d84873dfb7021eb24c50360f073237c5","lessThan":"a705e056c2f3dd067fb2ff414f0537530baa090b","versionType":"git","status":"affected"},{"version":"eec40579d84873dfb7021eb24c50360f073237c5","lessThan":"bd5a80128bdfc93b1cae935a70da000b8c483e6e","versionType":"git","status":"affected"},{"version":"eec40579d84873dfb7021eb24c50360f073237c5","lessThan":"17eb2ab13edd0b06ce6f996c5fd450d7efabb2e8","versionType":"git","status":"affected"},{"version":"eec40579d84873dfb7021eb24c50360f073237c5","lessThan":"889374b8e4a60d13fe4a5a8ae3a311ca93d1a2c3","versionType":"git","status":"affected"},{"version":"eec40579d84873dfb7021eb24c50360f073237c5","lessThan":"01c49eae7c6256f2d8cc08210a2bac3ee070e43a","versionType":"git","status":"affected"},{"version":"eec40579d84873dfb7021eb24c50360f073237c5","lessThan":"14e03ecd3b1b5fc03c082b27a2f8889f8290c30e","versionType":"git","status":"affected"},{"version":"eec40579d84873dfb7021eb24c50360f073237c5","lessThan":"b69ea153d30ce19ca8997eeeca1e2219fae5a29b","versionType":"git","status":"affected"},{"version":"eec40579d84873dfb7021eb24c50360f073237c5","lessThan":"9ae672606c17891d90b282e3490b817620549599","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/md/dm-era-target.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"3.15","status":"affected"},{"version":"0","lessThan":"3.15","versionType":"semver","status":"unaffected"},{"version":"5.10.261","lessThanOrEqual":"5.10.*","versionType":"semver","status":"unaffected"},{"version":"5.15.212","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.178","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.97","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc3","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/01c49eae7c6256f2d8cc08210a2bac3ee070e43a","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/14e03ecd3b1b5fc03c082b27a2f8889f8290c30e","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/17eb2ab13edd0b06ce6f996c5fd450d7efabb2e8","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/889374b8e4a60d13fe4a5a8ae3a311ca93d1a2c3","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/9ae672606c17891d90b282e3490b817620549599","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/a705e056c2f3dd067fb2ff414f0537530baa090b","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/b69ea153d30ce19ca8997eeeca1e2219fae5a29b","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/bd5a80128bdfc93b1cae935a70da000b8c483e6e","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-72317","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:22:04.620","lastModified":"2026-08-15T06:22:04.620","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nSUNRPC: pin upper rpc_clnt across the TLS connect_worker\n\nThe TLS connect path has a use-after-free: nothing pins the\nupper rpc_clnt across the delayed connect_worker. xs_connect()\nstores task->tk_client in sock_xprt::clnt as a raw pointer\nand queues the worker; for TLS-secured transports that worker\nis xs_tcp_tls_setup_socket(), which reads several fields out\nof the saved pointer (cl_timeout, cl_program, cl_prog,\ncl_vers, cl_cred, cl_stats) to construct the args for the\ninner handshake rpc_clnt.\n\nThe xprt does not reference the rpc_clnt; the rpc_clnt\nreferences the xprt. xs_destroy() does cancel the\nconnect_worker, but it runs only when the xprt's refcount\ndrops to zero, which cannot happen until the rpc_clnt\nreleases its cl_xprt reference in rpc_free_client_work().\nWhen a TLS handshake fails fatally (for example, an mTLS\nmount whose client cert does not match the server), the\nconnecting task is woken with -EACCES and exits, the mount\ncaller invokes rpc_shutdown_client(), and the upper rpc_clnt\nis freed before the queued connect_worker fires.\nxs_tcp_tls_setup_socket() then dereferences the freed clnt,\nproducing the refcount_t underflow Michael Nemanov reported.\n\nTake a reference on the upper rpc_clnt in xs_connect() for\nTLS transports via a new rpc_hold_client() helper, and drop\nit in the connect_worker's exit path with rpc_release_client().\nThe xprt_lock_connect() / xprt_unlock_connect() pairing\nalready serialises xs_connect() with xs_tcp_tls_setup_socket(),\nso the take and release are balanced one-for-one.\n\nThe non-TLS connect worker (xs_tcp_setup_socket) never reads\nsock_xprt::clnt, so leave that path alone and avoid the\nclnt-holds-xprt-holds-clnt cycle that would otherwise prevent\nxprt destruction."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["include/linux/sunrpc/clnt.h","net/sunrpc/clnt.c","net/sunrpc/xprtsock.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"75eb6af7acdf566c68d61e98e67ee2f235201c02","lessThan":"79cd550f8c884523b604fbfa43eb02def74d6224","versionType":"git","status":"affected"},{"version":"75eb6af7acdf566c68d61e98e67ee2f235201c02","lessThan":"7a65b41b657b71d5a77861f47dd13eb4bc8e10d0","versionType":"git","status":"affected"},{"version":"75eb6af7acdf566c68d61e98e67ee2f235201c02","lessThan":"5b0427ba582d143a364301f825f4e32272f06d2d","versionType":"git","status":"affected"},{"version":"75eb6af7acdf566c68d61e98e67ee2f235201c02","lessThan":"d49f6d098ed48775b9d27a9f9c5c220fdf76f102","versionType":"git","status":"affected"},{"version":"75eb6af7acdf566c68d61e98e67ee2f235201c02","lessThan":"46bc86c833956219bbfd246c1ffd832a479c5199","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["include/linux/sunrpc/clnt.h","net/sunrpc/clnt.c","net/sunrpc/xprtsock.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.5","status":"affected"},{"version":"0","lessThan":"6.5","versionType":"semver","status":"unaffected"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.97","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc3","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/46bc86c833956219bbfd246c1ffd832a479c5199","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/5b0427ba582d143a364301f825f4e32272f06d2d","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/79cd550f8c884523b604fbfa43eb02def74d6224","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/7a65b41b657b71d5a77861f47dd13eb4bc8e10d0","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/d49f6d098ed48775b9d27a9f9c5c220fdf76f102","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-72318","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:22:04.737","lastModified":"2026-08-15T06:22:04.737","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\ncifs: validate DFS referral string offsets\n\nparse_dfs_referrals() validates that the response header and referral\narray fit in the received buffer, but each referral also contains string\noffsets supplied by the server.\n\nThose offsets are used to compute the DfsPath and NetworkAddress string\npointers without checking whether they still point inside the response\nbuffer. A malformed referral can therefore make the computed pointer\nexceed the end of the buffer. The resulting negative max_len is then\npassed to cifs_strndup_from_utf16(), and the non-Unicode path forwards it\nto kstrndup() as a size_t, allowing strnlen() to read out of bounds.\n\nValidate each string offset before deriving the string pointer."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["fs/smb/client/misc.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"4ecce920e13ace16a5ba45efe8909946c28fb2ad","lessThan":"76c607b9353d377b1d1b11db50e743eee0ccf658","versionType":"git","status":"affected"},{"version":"4ecce920e13ace16a5ba45efe8909946c28fb2ad","lessThan":"d64b6be5740ce230aca184d8d224c75d9866045d","versionType":"git","status":"affected"},{"version":"4ecce920e13ace16a5ba45efe8909946c28fb2ad","lessThan":"929a85932d14190988f1eafd6ee8cc68d66ace0b","versionType":"git","status":"affected"},{"version":"4ecce920e13ace16a5ba45efe8909946c28fb2ad","lessThan":"b784cd1c24d89bf71be2efe1e948ff7c03371e57","versionType":"git","status":"affected"},{"version":"4ecce920e13ace16a5ba45efe8909946c28fb2ad","lessThan":"c37abc99bb3de3d3219ecef253d649f74117fd83","versionType":"git","status":"affected"},{"version":"4ecce920e13ace16a5ba45efe8909946c28fb2ad","lessThan":"027a84ac6b50c12ef767c15abfc58aa865820e9e","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["fs/smb/client/misc.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"4.11","status":"affected"},{"version":"0","lessThan":"4.11","versionType":"semver","status":"unaffected"},{"version":"6.1.178","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.97","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc3","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/027a84ac6b50c12ef767c15abfc58aa865820e9e","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/76c607b9353d377b1d1b11db50e743eee0ccf658","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/929a85932d14190988f1eafd6ee8cc68d66ace0b","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/b784cd1c24d89bf71be2efe1e948ff7c03371e57","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/c37abc99bb3de3d3219ecef253d649f74117fd83","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/d64b6be5740ce230aca184d8d224c75d9866045d","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-72319","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:22:04.857","lastModified":"2026-08-15T06:22:04.857","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nipvs: ensure inner headers in ICMP errors are in headroom\n\nSashiko points out that after stripping the outer headers\nwith pskb_pull() we should ensure the inner IP headers\nin ICMP errors from tunnels are present in the skb headroom\nfor functions like ipv4_update_pmtu(), icmp_send() and\nIP_VS_DBG().\n\nAlso, add more checks for the length of the inner headers."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["net/netfilter/ipvs/ip_vs_core.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"f2edb9f7706dcb2c0d9a362b2ba849efe3a97f5e","lessThan":"19657b3a17b774ae4e2f2635b5ae8638c9344a40","versionType":"git","status":"affected"},{"version":"f2edb9f7706dcb2c0d9a362b2ba849efe3a97f5e","lessThan":"dac813101914c21219ac221a60a31a11bc90e7ec","versionType":"git","status":"affected"},{"version":"f2edb9f7706dcb2c0d9a362b2ba849efe3a97f5e","lessThan":"dd22f74a09e25ca298ced0a3763ef353242cb78d","versionType":"git","status":"affected"},{"version":"f2edb9f7706dcb2c0d9a362b2ba849efe3a97f5e","lessThan":"9bc9b95aee2b2e3f1301a16a67ee504960402875","versionType":"git","status":"affected"},{"version":"f2edb9f7706dcb2c0d9a362b2ba849efe3a97f5e","lessThan":"a735f9964a3d9ed97daf9b08507f8b5bcafe6326","versionType":"git","status":"affected"},{"version":"f2edb9f7706dcb2c0d9a362b2ba849efe3a97f5e","lessThan":"8f48cfe657409fb5c7ba0521b14da6d47546d9cf","versionType":"git","status":"affected"},{"version":"f2edb9f7706dcb2c0d9a362b2ba849efe3a97f5e","lessThan":"92185d6f7819bc558939ae83de7b1abe90e3b5c2","versionType":"git","status":"affected"},{"version":"f2edb9f7706dcb2c0d9a362b2ba849efe3a97f5e","lessThan":"3f7a535ff0fa627a0132803e4c2f903ceffcbc1c","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["net/netfilter/ipvs/ip_vs_core.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"3.7","status":"affected"},{"version":"0","lessThan":"3.7","versionType":"semver","status":"unaffected"},{"version":"5.10.261","lessThanOrEqual":"5.10.*","versionType":"semver","status":"unaffected"},{"version":"5.15.212","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.178","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.97","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc3","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/19657b3a17b774ae4e2f2635b5ae8638c9344a40","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/3f7a535ff0fa627a0132803e4c2f903ceffcbc1c","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/8f48cfe657409fb5c7ba0521b14da6d47546d9cf","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/92185d6f7819bc558939ae83de7b1abe90e3b5c2","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/9bc9b95aee2b2e3f1301a16a67ee504960402875","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/a735f9964a3d9ed97daf9b08507f8b5bcafe6326","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/dac813101914c21219ac221a60a31a11bc90e7ec","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/dd22f74a09e25ca298ced0a3763ef353242cb78d","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-72320","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:22:04.993","lastModified":"2026-08-15T06:22:04.993","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nnetfilter: nft_lookup: fix catchall element handling with inverted lookups\n\nnft_lookup_eval() decides whether a lookup matched (`found`) from the\ndirect set lookup and priv->invert before falling back to the\ncatchall element used by interval sets (e.g. nft_set_rbtree) for the\nopen-ended default range. Since `found` is never recomputed after\n`ext` is replaced by the catchall lookup, inverted lookups\n(NFT_LOOKUP_F_INV, \"!= @set\") can wrongly match or wrongly skip the\ncatchall element, producing the wrong verdict. Fold the catchall\nlookup into `ext` before computing `found`, matching the order\nalready used by nft_objref_map_eval()."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["net/netfilter/nft_lookup.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"aaa31047a6d25da0fa101da1ed544e1247949b40","lessThan":"0ab8880865f9678eb6174e72c1fc4712e44c745c","versionType":"git","status":"affected"},{"version":"aaa31047a6d25da0fa101da1ed544e1247949b40","lessThan":"238c612357b5a25f03eacf356f95034f8551f218","versionType":"git","status":"affected"},{"version":"aaa31047a6d25da0fa101da1ed544e1247949b40","lessThan":"ef0c7d4b04a0e6ad175323c24bc84e11470dd79d","versionType":"git","status":"affected"},{"version":"aaa31047a6d25da0fa101da1ed544e1247949b40","lessThan":"e6107a4c74b54cb33e3bce162a63048ae5a6b198","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["net/netfilter/nft_lookup.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"5.13","status":"affected"},{"version":"0","lessThan":"5.13","versionType":"semver","status":"unaffected"},{"version":"6.12.97","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc3","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/0ab8880865f9678eb6174e72c1fc4712e44c745c","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/238c612357b5a25f03eacf356f95034f8551f218","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/e6107a4c74b54cb33e3bce162a63048ae5a6b198","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/ef0c7d4b04a0e6ad175323c24bc84e11470dd79d","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-72321","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:22:05.103","lastModified":"2026-08-15T06:22:05.103","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nipv4: igmp: Fix potential memory leaks in igmp_mod_timer() and igmp_stop_timer()\n\nWhen a timer is deleted and not re-armed in igmp_mod_timer(), or stopped\nin igmp_stop_timer(), the code currently decrements the reference counter\nof the multicast list entry @im using refcount_dec(&im->refcnt).\n\nHowever, both functions can be called from the RCU reader path:\n- igmp_mod_timer() via igmp_heard_query() -> for_each_pmc_rcu()\n- igmp_stop_timer() via igmp_rcv() -> igmp_heard_report()\n\nIf the group im was concurrently removed from the list by ip_mc_dec_group(),\nits reference count might have already been decremented to 1.\n\nIn this case, timer_delete() succeeds, and refcount_dec() decrements\nthe refcount from 1 to 0. Since refcount_dec() does not free the object\nwhen it hits 0 (unlike ip_ma_put()), the im structure is leaked.\n\nFix this by using ip_ma_put(im) instead of refcount_dec(&im->refcnt),\nand deferring the put until after the spinlock is released."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["net/ipv4/igmp.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"f60ec3058a85447008b88b762c859d336163acb3","versionType":"git","status":"affected"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"95128dc74425ec19ed4f2077ccc651e791ff4b75","versionType":"git","status":"affected"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"3546deaa0c30a14c7cdb5dc8f2432cb428f0cd36","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["net/ipv4/igmp.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"2.6.12","status":"affected"},{"version":"0","lessThan":"2.6.12","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc3","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/3546deaa0c30a14c7cdb5dc8f2432cb428f0cd36","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/95128dc74425ec19ed4f2077ccc651e791ff4b75","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/f60ec3058a85447008b88b762c859d336163acb3","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-72322","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:22:05.207","lastModified":"2026-08-15T06:22:05.207","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nipv6: mcast: Fix potential UAF in MLD delayed work\n\nA race condition exists between device teardown and incoming MLD query\nprocessing, leading to a Use-After-Free in the MLD delayed work.\n\nDuring device destruction, the primary reference to inet6_dev is dropped,\nwhich can drop its refcount to 0. The actual freeing of inet6_dev memory\nis deferred via RCU.\n\nConcurrently, the packet receive path runs under RCU read lock and obtains\nthe inet6_dev pointer. Because the memory is RCU-protected, CPU-0 can\nsafely dereference inet6_dev even if its refcount has hit 0.\n\nHowever, if CPU-0 calls igmp6_event_query() and schedules delayed work, it\nattempts to acquire a reference using in6_dev_hold(). This increments the\nrefcount from 0 to 1, triggering a \"refcount_t: addition on 0\" warning.\nSince the inet6_dev memory is still scheduled to be freed after the RCU\ngrace period, the device is freed while the work is still scheduled.\nWhen the work runs, it accesses the freed memory, causing a kernel panic.\n\nFix this by using refcount_inc_not_zero() (via a new helper\nin6_dev_hold_safe()) to prevent acquiring a reference if the device is\nalready being destroyed. If the refcount is 0, we do not schedule the work."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["include/net/addrconf.h","net/ipv6/mcast.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"f12b63ef26a035c5a29b3ef56401e38199010d4a","versionType":"git","status":"affected"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"0401d6cf7877c9be36652385dfcbf7f891b8b590","versionType":"git","status":"affected"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"f03b0a45535d49bdab7e502efaacee205b2a7865","versionType":"git","status":"affected"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"9815e834f5ff8b39e0ea9f0dbd532f4a3b8f0785","versionType":"git","status":"affected"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"ebbebf6cee950d7f1c81990256c0eae9e62572ae","versionType":"git","status":"affected"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"9ce741c22df4fd9546e30306317ac7df3607e48f","versionType":"git","status":"affected"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"0458ba1cda830ba4ccfcd9e19c0891438bcdbe4e","versionType":"git","status":"affected"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"9b26518b6896a16b809b1e42986f4ebac7bccc1e","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["include/net/addrconf.h","net/ipv6/mcast.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"2.6.12","status":"affected"},{"version":"0","lessThan":"2.6.12","versionType":"semver","status":"unaffected"},{"version":"5.10.261","lessThanOrEqual":"5.10.*","versionType":"semver","status":"unaffected"},{"version":"5.15.212","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.178","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.97","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc3","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/0401d6cf7877c9be36652385dfcbf7f891b8b590","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/0458ba1cda830ba4ccfcd9e19c0891438bcdbe4e","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/9815e834f5ff8b39e0ea9f0dbd532f4a3b8f0785","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/9b26518b6896a16b809b1e42986f4ebac7bccc1e","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/9ce741c22df4fd9546e30306317ac7df3607e48f","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/ebbebf6cee950d7f1c81990256c0eae9e62572ae","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/f03b0a45535d49bdab7e502efaacee205b2a7865","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/f12b63ef26a035c5a29b3ef56401e38199010d4a","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-72323","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:22:05.333","lastModified":"2026-08-15T06:22:05.333","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nipv4: igmp: Fix potential UAF in igmp_gq_start_timer()\n\nA race condition exists between device teardown (inetdev_destroy) and\nincoming IGMP query processing (igmp_rcv), leading to a Use-After-Free\nin the IGMP timer callback.\n\nDuring device destruction, inetdev_destroy() drops the primary reference\nto in_device, which can drop its refcount to 0. The actual freeing of\nin_device memory is deferred via RCU (using call_rcu()).\n\nConcurrently, igmp_rcv() runs under RCU read lock and obtains the\nin_device pointer. Because the memory is RCU-protected, CPU-0 can safely\ndereference in_device even if its refcount has hit 0.\n\nHowever, if CPU-0 calls igmp_gq_start_timer() and re-arms the timer, it\nattempts to acquire a reference using in_dev_hold(). This increments the\nrefcount from 0 to 1, triggering a \"refcount_t: addition on 0\" warning.\nSince the in_device memory is still scheduled to be freed after the RCU\ngrace period (as the free callback does not check the refcount again),\nthe device is freed while the timer is still armed. When the timer\nexpires, it accesses the freed memory, causing a kernel panic.\n\nFix this by using refcount_inc_not_zero() (via a new helper\nin_dev_hold_safe()) to prevent acquiring a reference if the device is\nalready being destroyed. If the refcount is 0, we do not arm the timer.\n\nA similar issue in IPv6 MLD is fixed in a subsequent patch."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["include/linux/inetdevice.h","net/ipv4/igmp.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"40a1e998cb266ed4cb529a0bb4fee2b0ba732702","versionType":"git","status":"affected"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"165258303357e54b75fc19b341ae2a2b7c9e3910","versionType":"git","status":"affected"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"75e984fe0cb9e7fbde0c8ee838c61ce8573d3ea3","versionType":"git","status":"affected"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"8d4394ffa40508e0de72f464af351f6ca6a6cdc3","versionType":"git","status":"affected"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"7b19c0f81ed1fdaec6bc522569be367199a9edf3","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["include/linux/inetdevice.h","net/ipv4/igmp.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"2.6.12","status":"affected"},{"version":"0","lessThan":"2.6.12","versionType":"semver","status":"unaffected"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.97","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc3","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/165258303357e54b75fc19b341ae2a2b7c9e3910","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/40a1e998cb266ed4cb529a0bb4fee2b0ba732702","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/75e984fe0cb9e7fbde0c8ee838c61ce8573d3ea3","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/7b19c0f81ed1fdaec6bc522569be367199a9edf3","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/8d4394ffa40508e0de72f464af351f6ca6a6cdc3","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-72324","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:22:05.447","lastModified":"2026-08-15T06:22:05.447","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\ngpio: mvebu: free generic chips on unbind\n\nirq_alloc_domain_generic_chips() allocates generic chip data that must\nbe freed via irq_domain_remove_generic_chips(). The devres action\nmvebu_gpio_remove_irq_domain() only called irq_domain_remove(), which\nonly frees the generic chips if IRQ_DOMAIN_FLAG_DESTROY_GC is set.\nCall irq_domain_remove_generic_chips() explicitly before\nirq_domain_remove() instead."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/gpio/gpio-mvebu.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"812d47889a8e418d7bea9bec383581a34c19183e","lessThan":"3649b04f86b95243fa0c845695051455fa2ba40b","versionType":"git","status":"affected"},{"version":"812d47889a8e418d7bea9bec383581a34c19183e","lessThan":"3bfcce441c552133adeeb99c294d0ce8a62612ef","versionType":"git","status":"affected"},{"version":"812d47889a8e418d7bea9bec383581a34c19183e","lessThan":"d73e4d790db611da7439e78a6ab6cb32e7885ab8","versionType":"git","status":"affected"},{"version":"812d47889a8e418d7bea9bec383581a34c19183e","lessThan":"b11c513ad943f35cf5e8007d3a56279c79b7ed4b","versionType":"git","status":"affected"},{"version":"f0cde54863da281cec1ed85497b4ec58d29c1460","versionType":"git","status":"affected"},{"version":"7a9239fd04802ee6ddf82d211cff3ee7df9c473a","versionType":"git","status":"affected"},{"version":"3.16.40","lessThan":"3.17","versionType":"semver","status":"affected"},{"version":"4.8.9","lessThan":"4.9","versionType":"semver","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/gpio/gpio-mvebu.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"4.9","status":"affected"},{"version":"0","lessThan":"4.9","versionType":"semver","status":"unaffected"},{"version":"6.12.97","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc3","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/3649b04f86b95243fa0c845695051455fa2ba40b","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/3bfcce441c552133adeeb99c294d0ce8a62612ef","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/b11c513ad943f35cf5e8007d3a56279c79b7ed4b","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/d73e4d790db611da7439e78a6ab6cb32e7885ab8","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-72325","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:22:05.547","lastModified":"2026-08-15T06:22:05.547","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nperf/x86/amd/core: Avoid enabling BRS from the SVM reload path\n\nBranch Sampling (BRS) and Last Branch Record (LBR) are mutually\nexclusive hardware features, and users of both are tracked via\ncpuc->lbr_users.\n\nWhen SVM is toggled on a CPU, the host perf events are reprogrammed to\nupdate the HostOnly filter bit (set when virtualization is enabled,\ncleared when it is disabled). On PerfMonV2-capable processors, this\nreprogramming is performed by calling amd_pmu_enable_all() to rewrite\nthe event selectors. However, amd_pmu_enable_all() also calls\namd_brs_enable_all(), which enables BRS whenever cpuc->lbr_users > 0.\nHaving active LBR events satisfies this gating on processors that have\nLBR but not BRS. The kernel then tries to set the BRS enable bit in\nDebugExtnCfg (MSR 0xc000010f). Since that bit is deprecated on such\nhardware, the write results in a #GP:\n\n  Call Trace:\n   <IRQ>\n   amd_pmu_enable_all+0x1d/0x90\n   amd_pmu_disable_virt+0x62/0xb0\n   kvm_arch_disable_virtualization_cpu+0xa/0x40 [kvm]\n   hardware_disable_nolock+0x1a/0x30 [kvm]\n   __flush_smp_call_function_queue+0x9b/0x410\n   __sysvec_call_function+0x18/0xc0\n   sysvec_call_function+0x69/0x90\n   </IRQ>\n   <TASK>\n   asm_sysvec_call_function+0x16/0x20\n  RIP: 0010:cpuidle_enter_state+0xc4/0x450\n   ? cpuidle_enter_state+0xb7/0x450\n   cpuidle_enter+0x29/0x40\n   cpuidle_idle_call+0xf5/0x160\n   do_idle+0x7b/0xe0\n   cpu_startup_entry+0x26/0x30\n   start_secondary+0x115/0x140\n   secondary_startup_64_no_verify+0x194/0x19b\n   </TASK>\n\nFix this by ensuring that BRS is not enabled from the event selector\nreprogramming path even when cpuc->lbr_users > 0."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["arch/x86/events/amd/core.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"bae19fdd7e9e759580ac4693d2df3bc23ab415d7","lessThan":"e9b1a7411a667539c2f55e720bbb5f623b526a32","versionType":"git","status":"affected"},{"version":"bae19fdd7e9e759580ac4693d2df3bc23ab415d7","lessThan":"7cc438c99bba324a0562b1bafa747b10f7e251df","versionType":"git","status":"affected"},{"version":"bae19fdd7e9e759580ac4693d2df3bc23ab415d7","lessThan":"46d0fd8535edce31f15e48d2de1bdee39a4850e5","versionType":"git","status":"affected"},{"version":"bae19fdd7e9e759580ac4693d2df3bc23ab415d7","lessThan":"07c60dda9c059c09f83d42a3ebda2e7cc1cf3bc2","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["arch/x86/events/amd/core.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"5.19","status":"affected"},{"version":"0","lessThan":"5.19","versionType":"semver","status":"unaffected"},{"version":"6.12.97","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc3","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/07c60dda9c059c09f83d42a3ebda2e7cc1cf3bc2","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/46d0fd8535edce31f15e48d2de1bdee39a4850e5","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/7cc438c99bba324a0562b1bafa747b10f7e251df","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/e9b1a7411a667539c2f55e720bbb5f623b526a32","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-72326","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:22:05.660","lastModified":"2026-08-15T06:22:05.660","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nnet/sched: cake: reject overhead values that underflow length\n\nCAKE accepts signed overhead values and stores them in an s16, but the\nadjusted packet length calculation uses unsigned arithmetic.  A negative\neffective length can therefore wrap to a large value.\n\nSuch configurations make rate accounting depend on integer wraparound\nrather than on the packet size userspace intended to model.  A static\nnetlink lower bound is not enough because packets reaching CAKE can be\nsmaller than any reasonable manual-overhead allowance.\n\nFold the signed overhead adjustment into the existing datapath MPU clamp\nso negative adjusted lengths are clamped before link-layer framing\nadjustments."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["net/sched/sch_cake.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"a729b7f0bd5bf4919306556aed614438f5174537","lessThan":"f511dd7bf6077aa7afbe72914520553fedaacbb4","versionType":"git","status":"affected"},{"version":"a729b7f0bd5bf4919306556aed614438f5174537","lessThan":"e1df6cff03aad8c96e55a8b2a991e505c7a3ff6f","versionType":"git","status":"affected"},{"version":"a729b7f0bd5bf4919306556aed614438f5174537","lessThan":"297f459865360b46a887667cbf3aac6a6f013841","versionType":"git","status":"affected"},{"version":"a729b7f0bd5bf4919306556aed614438f5174537","lessThan":"336c1e414fc0e9844d445174e8ada2a7dd8d1c4b","versionType":"git","status":"affected"},{"version":"a729b7f0bd5bf4919306556aed614438f5174537","lessThan":"bcdf3a3664f7d2c4e37e155f30f72ef33f041804","versionType":"git","status":"affected"},{"version":"a729b7f0bd5bf4919306556aed614438f5174537","lessThan":"7aa0e64fea778a9e3df73e64da95367ff8ad2ea5","versionType":"git","status":"affected"},{"version":"a729b7f0bd5bf4919306556aed614438f5174537","lessThan":"f1e7807df5bf2d42a40266430e9f82f37633cdcf","versionType":"git","status":"affected"},{"version":"a729b7f0bd5bf4919306556aed614438f5174537","lessThan":"b7f97cae7ec1b6c3c32843c42be218690d310467","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["net/sched/sch_cake.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"4.19","status":"affected"},{"version":"0","lessThan":"4.19","versionType":"semver","status":"unaffected"},{"version":"5.10.261","lessThanOrEqual":"5.10.*","versionType":"semver","status":"unaffected"},{"version":"5.15.212","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.178","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.97","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc3","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/297f459865360b46a887667cbf3aac6a6f013841","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/336c1e414fc0e9844d445174e8ada2a7dd8d1c4b","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/7aa0e64fea778a9e3df73e64da95367ff8ad2ea5","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/b7f97cae7ec1b6c3c32843c42be218690d310467","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/bcdf3a3664f7d2c4e37e155f30f72ef33f041804","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/e1df6cff03aad8c96e55a8b2a991e505c7a3ff6f","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/f1e7807df5bf2d42a40266430e9f82f37633cdcf","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/f511dd7bf6077aa7afbe72914520553fedaacbb4","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-72327","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:22:05.780","lastModified":"2026-08-15T06:22:05.780","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/v3d: Reject invalid indirect BO handle in indirect CSD setup\n\nv3d_get_cpu_indirect_csd_params() looks up the indirect buffer object\nfrom a userspace-supplied handle but never checks the result. A bogus\nor stale handle makes drm_gem_object_lookup() return NULL, which is\nthen stored in info->indirect and only dereferenced later when the\nindirect CSD job runs, turning a userspace mistake into a NULL pointer\ndereference in the kernel.\n\nBail out with -ENOENT as soon as the lookup fails, so the bad handle is\nrejected at submission time."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/gpu/drm/v3d/v3d_submit.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"18b8413b25b7070fa2e55858a2c808e6909581d0","lessThan":"7c27f630dc78b673e136cab7d410399a1c52146a","versionType":"git","status":"affected"},{"version":"18b8413b25b7070fa2e55858a2c808e6909581d0","lessThan":"762116dfa72865c82151970960f7cf34f44b21c8","versionType":"git","status":"affected"},{"version":"18b8413b25b7070fa2e55858a2c808e6909581d0","lessThan":"5d65dade4d84913d1879f3db6a12ac007e08314b","versionType":"git","status":"affected"},{"version":"18b8413b25b7070fa2e55858a2c808e6909581d0","lessThan":"2f8b8593c7832fad655290cef9e99af05b1b52b3","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/gpu/drm/v3d/v3d_submit.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.8","status":"affected"},{"version":"0","lessThan":"6.8","versionType":"semver","status":"unaffected"},{"version":"6.12.97","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc3","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/2f8b8593c7832fad655290cef9e99af05b1b52b3","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/5d65dade4d84913d1879f3db6a12ac007e08314b","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/762116dfa72865c82151970960f7cf34f44b21c8","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/7c27f630dc78b673e136cab7d410399a1c52146a","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-72328","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:22:05.873","lastModified":"2026-08-15T06:22:05.873","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\naccel/amdxdna: Fix potential amdxdna_umap lifetime race\n\namdxdna_umap_release() calls the blocking mmu_interval_notifier_remove()\nbefore removing the object from abo->mem.umap_list. If\naie2_populate_range() runs concurrently, it may obtain a reference to an\namdxdna_umap that is being released, leading to a potential use-after-free.\n\nUse kref_get_unless_zero() in aie2_populate_range() when acquiring a\nreference. If the reference count has already dropped to zero, release\nis in progress and the entry is skipped."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/accel/amdxdna/aie2_ctx.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"e486147c912f653ef4b60a6c7dbd4168a4c56a9f","lessThan":"267809e2c56fbea486f7250c8a4acddcc3c54dc5","versionType":"git","status":"affected"},{"version":"e486147c912f653ef4b60a6c7dbd4168a4c56a9f","lessThan":"91e8109ecffb925b6202d2737384df285b195bfb","versionType":"git","status":"affected"},{"version":"e486147c912f653ef4b60a6c7dbd4168a4c56a9f","lessThan":"14f172eff9c19f8043a9858845f33cd034f3a41e","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/accel/amdxdna/aie2_ctx.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.16","status":"affected"},{"version":"0","lessThan":"6.16","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc3","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/14f172eff9c19f8043a9858845f33cd034f3a41e","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/267809e2c56fbea486f7250c8a4acddcc3c54dc5","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/91e8109ecffb925b6202d2737384df285b195bfb","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-72329","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:22:05.980","lastModified":"2026-08-15T06:22:05.980","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nnet/liquidio: drop cached VF pci_dev LUT\n\nThe PF SR-IOV enable path caches VF pci_dev pointers in\ndpiring_to_vfpcidev_lut[] by iterating with pci_get_device(). Those\nentries do not own a reference, because the iterator drops the previous\ndevice reference on each step. The cached pointer is then dereferenced\nlater when handling OCTEON_VF_FLR_REQUEST.\n\nReplace the cached VF mapping with runtime lookup on the mailbox DPI\nring: derive the VF index from q_no, resolve the VF via exported PCI\nIOV helpers, validate it with the PF pointer and VF ID, then issue\npcie_flr() and drop the reference with pci_dev_put(). Remove the\nunused VF lookup table initialization and cleanup."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/net/ethernet/cavium/liquidio/lio_main.c","drivers/net/ethernet/cavium/liquidio/octeon_device.h","drivers/net/ethernet/cavium/liquidio/octeon_mailbox.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"ca6139ffc67ee6ef0459f81e37894ed411083855","lessThan":"81acef3a247fd523513a2e9f71de1c167bc0f882","versionType":"git","status":"affected"},{"version":"ca6139ffc67ee6ef0459f81e37894ed411083855","lessThan":"5c0e3ba4f500fd4314ceb42f07f16bc445156431","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/net/ethernet/cavium/liquidio/lio_main.c","drivers/net/ethernet/cavium/liquidio/octeon_device.h","drivers/net/ethernet/cavium/liquidio/octeon_mailbox.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"4.10","status":"affected"},{"version":"0","lessThan":"4.10","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc3","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/5c0e3ba4f500fd4314ceb42f07f16bc445156431","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/81acef3a247fd523513a2e9f71de1c167bc0f882","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-72330","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:22:06.080","lastModified":"2026-08-15T06:22:06.080","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nnet/tls: Consume empty data records in tls_sw_read_sock()\n\nA peer may send a zero-length TLS application_data record; TLS 1.3\nexplicitly permits these as a traffic-analysis countermeasure (RFC\n8446, Section 5.1). After decryption such a record has full_len ==\n0. tls_sw_read_sock() hands it to the read_actor, which has no\npayload to consume and returns zero. The loop treats a zero return\nas backpressure (used <= 0), requeues the skb at the head of\nrx_list, and stops. rx_list is serviced head-first on the next\ncall, so the empty record is dequeued, fails the same way, and is\nrequeued again; every later record on the connection is blocked\nbehind it.\n\ntls_sw_recvmsg() does not stall on this: a zero-length data record\ncopies nothing and falls through to consume_skb(). Mirror that in\nthe read_sock() path by recognizing an empty data record before\nthe actor runs, consuming it, and continuing."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["net/tls/tls_sw.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"662fbcec32f4af6bdcf5b4006b792ebe9543d945","lessThan":"0867b0f2513ebc1c475af9898c97f4772a68d964","versionType":"git","status":"affected"},{"version":"662fbcec32f4af6bdcf5b4006b792ebe9543d945","lessThan":"c6b440cf766a557b08d25f1b571b3d57d039686e","versionType":"git","status":"affected"},{"version":"662fbcec32f4af6bdcf5b4006b792ebe9543d945","lessThan":"e8a4c9fc437b16aef38f86ce3275677e36924259","versionType":"git","status":"affected"},{"version":"662fbcec32f4af6bdcf5b4006b792ebe9543d945","lessThan":"ebc295ce343600c2d60c1e1e0c5d192080217457","versionType":"git","status":"affected"},{"version":"662fbcec32f4af6bdcf5b4006b792ebe9543d945","lessThan":"3be28e2c9cd0230cb51fd4967df095273afd3848","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["net/tls/tls_sw.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.6","status":"affected"},{"version":"0","lessThan":"6.6","versionType":"semver","status":"unaffected"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.97","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc3","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/0867b0f2513ebc1c475af9898c97f4772a68d964","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/3be28e2c9cd0230cb51fd4967df095273afd3848","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/c6b440cf766a557b08d25f1b571b3d57d039686e","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/e8a4c9fc437b16aef38f86ce3275677e36924259","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/ebc295ce343600c2d60c1e1e0c5d192080217457","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-72331","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:22:06.200","lastModified":"2026-08-15T06:22:06.200","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\naccel/amdxdna: Fix VMA access race\n\naie2_populate_range() and amdxdna_umap_release() access a saved VMA\npointer that may have already been freed, leading to a potential\nuse-after-free.\n\nRemove the VMA accesses from these functions to avoid the race."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/accel/amdxdna/aie2_ctx.c","drivers/accel/amdxdna/amdxdna_gem.c","drivers/accel/amdxdna/amdxdna_gem.h"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"e486147c912f653ef4b60a6c7dbd4168a4c56a9f","lessThan":"bea20225c67fed9be3e98619c77af6ee3f43fe07","versionType":"git","status":"affected"},{"version":"e486147c912f653ef4b60a6c7dbd4168a4c56a9f","lessThan":"1ba02717e821cf14ece642273958647e79698d3d","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/accel/amdxdna/aie2_ctx.c","drivers/accel/amdxdna/amdxdna_gem.c","drivers/accel/amdxdna/amdxdna_gem.h"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.16","status":"affected"},{"version":"0","lessThan":"6.16","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc3","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/1ba02717e821cf14ece642273958647e79698d3d","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/bea20225c67fed9be3e98619c77af6ee3f43fe07","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-72332","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:22:06.310","lastModified":"2026-08-15T06:22:06.310","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\naccel/amdxdna: Prevent PM resume deadlock in hwctx_sync_debug_bo()\n\namdxdna_hwctx_sync_debug_bo() invokes the hardware hwctx_sync_debug_bo()\ncallback while holding xdna->dev_lock.\n\nThe callback may call amdxdna_cmd_submit(), which in turn calls\namdxdna_pm_resume_get(). If the device is suspended,\namdxdna_pm_resume_get() may synchronously execute amdxdna_pm_resume(),\nwhich also acquires xdna->dev_lock, resulting in a deadlock.\n\nAvoid the deadlock by calling amdxdna_pm_resume_get() before holding\nxdna->dev_lock in both amdxdna_hwctx_sync_debug_bo() and\namdxdna_drm_config_hwctx_ioctl()"}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/accel/amdxdna/aie2_ctx.c","drivers/accel/amdxdna/amdxdna_ctx.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"7ea0468380216c10b73633b976d33efa8c12d375","lessThan":"2d8eeb0578ae3aadf112fd3e1997e58178f75979","versionType":"git","status":"affected"},{"version":"7ea0468380216c10b73633b976d33efa8c12d375","lessThan":"e35c9cf5512814fb04f369f2eada64f0a7164609","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/accel/amdxdna/aie2_ctx.c","drivers/accel/amdxdna/amdxdna_ctx.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.19","status":"affected"},{"version":"0","lessThan":"6.19","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc3","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/2d8eeb0578ae3aadf112fd3e1997e58178f75979","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/e35c9cf5512814fb04f369f2eada64f0a7164609","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-72333","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:22:06.433","lastModified":"2026-08-15T06:22:06.433","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nBluetooth: L2CAP: fix tx ident leak for commands without a response\n\nCommit 6c3ea155e5ee (\"Bluetooth: L2CAP: Fix not tracking outstanding\nTX ident\") changed ident allocation to use an IDA, releasing idents in\nl2cap_put_ident() when the matching response command is received.\n\nBut identifiers allocated for commands that have no response defined\nare never released. In particular L2CAP_LE_CREDITS is sent repeatedly for\nthe lifetime of an LE CoC channel, so a peer streaming data to the\nhost exhausts the 1-255 ident range after 254 credit packets. From\nthen on l2cap_get_ident() fails:\n\n    kernel: Bluetooth: Unable to allocate ident: -28\n\nand every subsequent L2CAP_LE_CREDITS packet is sent with ident 0,\nwhich is invalid (Core Spec, Vol 3, Part A, Section 4: \"Signaling\nidentifier 0x00 is an invalid identifier and shall never be used in\nany command\"). Remote stacks that validate the ident drop these\ncommands, never receive new credits, and the channel stalls\npermanently. With default socket buffers this happens after roughly 0.5 MB\nof received data (the exact amount depends on the socket receive buffer):\n\n  < ACL Data TX: Handle 2048 flags 0x00 dlen 12\n        LE L2CAP: LE Flow Control Credit (0x16) ident 0 len 4\n          Source CID: 64\n          Credits: 1\n\nRelease the ident immediately after sending L2CAP_LE_CREDITS since no\nresponse will ever release it. Use a local variable instead of\nchan->ident so that an ident that an EXT_FLOWCTL channel may be waiting on\n(e.g. a pending reconfigure) is not overwritten by a credit packet.\n\nAlso add the missing L2CAP_LE_CONN_RSP case to l2cap_put_ident() so\nidents allocated for outgoing L2CAP_LE_CONN_REQ commands are released\nwhen the response arrives."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["net/bluetooth/l2cap_core.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"e86554c37d3d2b4b24608e0313f882cae28b8adb","lessThan":"b8a32a5fc915b024c60f18d51b6cffd2bd64d4a6","versionType":"git","status":"affected"},{"version":"9b24ad4787cad46a3917620799f8455c6533b8df","lessThan":"bd1e01170341291292fd4c46b5f6949da282ca6c","versionType":"git","status":"affected"},{"version":"ea6cf86167b3972caa68972d2a1ad43ecbbb8331","lessThan":"0c602cb8f148a36bfb39c25ade400bdadc023c4f","versionType":"git","status":"affected"},{"version":"6c3ea155e5ee3e56606233acde8309afda66d483","lessThan":"d0a2b0c81f112540a337cde1c20251bf05ddf1da","versionType":"git","status":"affected"},{"version":"6c3ea155e5ee3e56606233acde8309afda66d483","lessThan":"6e1930ece855a4c256f1c7e6632d634cfb9888b5","versionType":"git","status":"affected"},{"version":"ed97bb2cf96684ee646be6f37e4c4835f9d30caa","versionType":"git","status":"affected"},{"version":"84bc3197f7d87c5b89c156e853d0561a9154eceb","versionType":"git","status":"affected"},{"version":"8c1cdbc1bacc0cf9c27c3ebda11a81c3dcd01630","versionType":"git","status":"affected"},{"version":"6.18.21","lessThan":"6.18.40","versionType":"semver","status":"affected"},{"version":"5.10.261","lessThan":"5.11","versionType":"semver","status":"affected"},{"version":"5.15.212","lessThan":"5.16","versionType":"semver","status":"affected"},{"version":"6.19.11","lessThan":"6.20","versionType":"semver","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["net/bluetooth/l2cap_core.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"7.0","status":"affected"},{"version":"0","lessThan":"7.0","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc3","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/0c602cb8f148a36bfb39c25ade400bdadc023c4f","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/6e1930ece855a4c256f1c7e6632d634cfb9888b5","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/b8a32a5fc915b024c60f18d51b6cffd2bd64d4a6","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/bd1e01170341291292fd4c46b5f6949da282ca6c","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/d0a2b0c81f112540a337cde1c20251bf05ddf1da","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-72334","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:22:06.580","lastModified":"2026-08-15T06:22:06.580","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nBluetooth: ISO: fix malformed ISO_END/CONT handling\n\nCore specification (Part C vol 4 sec 5.4.5) does not exclude empty\nISO_CONT, ISO_END packets.  We currently reject them if they are last.\n\nIf controller sends malformed sequence\n\n    ISO_START -> rx_len = 4, ISO_CONT skb->len 4, ISO_START\n\nthat ends payload in ISO_CONT, we leak conn->rx_skb. If controller sends\ntoo long ISO_END, we panic on skb_put. If controller sends too short\nISO_END we accept it.\n\nFix by marking unfinished ISO_START via conn->rx_skb != NULL.  Check\nskb->len properly before skb_put.  Combine the ISO_CONT/END code paths\nas they require the same initial checks. Reject too short ISO_END\npackets."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["net/bluetooth/iso.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"ccf74f2390d60a2f9a75ef496d2564abb478f46a","lessThan":"990e65eb9387c4ddfa7f68782b6644c2c35d489f","versionType":"git","status":"affected"},{"version":"ccf74f2390d60a2f9a75ef496d2564abb478f46a","lessThan":"e054c1a6ae7310d2815778fddb87da616e11c255","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["net/bluetooth/iso.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.0","status":"affected"},{"version":"0","lessThan":"6.0","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc3","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/990e65eb9387c4ddfa7f68782b6644c2c35d489f","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/e054c1a6ae7310d2815778fddb87da616e11c255","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-72335","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:22:06.677","lastModified":"2026-08-15T06:22:06.677","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nBluetooth: MGMT: Fix adv monitor add failure cleanup\n\nhci_add_adv_monitor() publishes a new adv_monitor in\nhdev->adv_monitors_idr before the powered MSFT setup step. The MSFT\noffload add path can then fail either locally before the controller add\ncommand completes, or in the MSFT add callback. In the current queued\nmanagement add flow, hci_cmd_sync_work() still invokes\nmgmt_add_adv_patterns_monitor_complete() with the original pending command\nafter msft_add_monitor_pattern() returns.\n\nThe buggy scenario involves two paths, with each column showing the order\nwithin that path:\n\nMSFT add handling                  MGMT completion\n1. insert monitor and handle       1. receive sync error\n2. send MSFT add command           2. call add-monitor completion\n3. callback sees bad response      3. load cmd->user_data\n4. callback frees monitor          4. read monitor->handle\n\nLocal MSFT setup failures have the other half of the same ownership bug:\nthey return an error after the IDR insertion, but no later code removes the\nfailed monitor from the IDR.\n\nKeep ownership with the pending management command until its completion.\nFor normal management adds, the MSFT add callback now records successful\ncontroller state and returns errors to its caller. The management\ncompletion frees the monitor on non-success after copying the response\nhandle, while resume/reregister callback-error cleanup remains in the\nMSFT callback. The success path keeps the existing bookkeeping.\n\nValidation reproduced this kernel report:\nBUG: KASAN: slab-use-after-free in mgmt_add_adv_patterns_monitor_complete+0xfb/0x260 [bluetooth]\n\nCall Trace:\n <TASK>\n dump_stack_lvl+0x66/0xa0\n print_report+0xce/0x5f0\n ? mgmt_add_adv_patterns_monitor_complete+0xfb/0x260 [bluetooth]\n ? srso_alias_return_thunk+0x5/0xfbef5\n ? __virt_addr_valid+0x19f/0x330\n ? mgmt_add_adv_patterns_monitor_complete+0xfb/0x260 [bluetooth]\n kasan_report+0xe0/0x110\n ? mgmt_add_adv_patterns_monitor_complete+0xfb/0x260 [bluetooth]\n mgmt_add_adv_patterns_monitor_complete+0xfb/0x260 [bluetooth]\n ? srso_alias_return_thunk+0x5/0xfbef5\n ? 0xffffffffc00d00da\n ? __pfx_mgmt_add_adv_patterns_monitor_complete+0x10/0x10 [bluetooth]\n ? __pfx_mgmt_add_adv_patterns_monitor_complete+0x10/0x10 [bluetooth]\n ? hci_cmd_sync_work+0x1ab/0x210 [bluetooth]\n hci_cmd_sync_work+0x1c0/0x210 [bluetooth]\n ? __pfx_mgmt_add_adv_patterns_monitor_complete+0x10/0x10 [bluetooth]\n process_one_work+0x4fd/0xbc0\n ? __pfx_process_one_work+0x10/0x10\n ? srso_alias_return_thunk+0x5/0xfbef5\n ? srso_alias_return_thunk+0x5/0xfbef5\n ? __list_add_valid_or_report+0x37/0xf0\n ? __pfx_hci_cmd_sync_work+0x10/0x10 [bluetooth]\n ? srso_alias_return_thunk+0x5/0xfbef5\n worker_thread+0x2d8/0x570\n ? __pfx_worker_thread+0x10/0x10\n kthread+0x1ad/0x1f0\n ? __pfx_kthread+0x10/0x10\n ret_from_fork+0x3c9/0x540\n ? __pfx_ret_from_fork+0x10/0x10\n ? srso_alias_return_thunk+0x5/0xfbef5\n ? __switch_to+0x2e9/0x730\n ? __pfx_kthread+0x10/0x10\n ret_from_fork_asm+0x1a/0x30\n </TASK>\n\nAllocated by task 471 on cpu 3 at 285.205389s:\n kasan_save_stack+0x33/0x60\n kasan_save_track+0x17/0x60\n __kasan_kmalloc+0xaa/0xb0\n add_adv_patterns_monitor_rssi+0xd5/0x230 [bluetooth]\n hci_sock_sendmsg+0x96b/0xf80 [bluetooth]\n __sys_sendto+0x2bc/0x2d0\n __x64_sys_sendto+0x76/0x90\n do_syscall_64+0x115/0x6a0\n entry_SYSCALL_64_after_hwframe+0x77/0x7f\n\nFreed by task 454 on cpu 2 at 285.217112s:\n kasan_save_stack+0x33/0x60\n kasan_save_track+0x17/0x60\n kasan_save_free_info+0x3b/0x60\n __kasan_slab_free+0x5f/0x80\n kfree+0x313/0x590\n msft_add_monitor_sync+0x54a/0x570 [bluetooth]\n hci_add_adv_monitor+0x133/0x180 [bluetooth]\n hci_cmd_sync_work+0x187/0x210 [bluetooth]\n process_one_work+0x4fd/0xbc0\n worker_thread+0x2d8/0x570\n kthread+0x1ad/0x1f0\n ret_from_fork+0x3c9/0x540\n ret_from_fork_asm+0x1a/0x30"}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["net/bluetooth/mgmt.c","net/bluetooth/msft.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"a2a4dedf88ab2f807a7ca90947d686816b430f97","lessThan":"b1a719b3c4359ef731646fb7c7844e53dddbda72","versionType":"git","status":"affected"},{"version":"a2a4dedf88ab2f807a7ca90947d686816b430f97","lessThan":"5aabbd01ac315a72bcdfd42985ede712c4744689","versionType":"git","status":"affected"},{"version":"a2a4dedf88ab2f807a7ca90947d686816b430f97","lessThan":"fb256d07395ebbc950f42e439d3896ec3a25c845","versionType":"git","status":"affected"},{"version":"a2a4dedf88ab2f807a7ca90947d686816b430f97","lessThan":"dfc8373893b1876bb367700eac9d776316dabd96","versionType":"git","status":"affected"},{"version":"a2a4dedf88ab2f807a7ca90947d686816b430f97","lessThan":"dbd935a9e056545721bc4e9ce518c775d787b21e","versionType":"git","status":"affected"},{"version":"a2a4dedf88ab2f807a7ca90947d686816b430f97","lessThan":"384a4b2fef9ffe5e270ee5558975c0504881c5fb","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["net/bluetooth/mgmt.c","net/bluetooth/msft.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"5.12","status":"affected"},{"version":"0","lessThan":"5.12","versionType":"semver","status":"unaffected"},{"version":"6.1.178","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.97","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc3","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/384a4b2fef9ffe5e270ee5558975c0504881c5fb","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/5aabbd01ac315a72bcdfd42985ede712c4744689","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/b1a719b3c4359ef731646fb7c7844e53dddbda72","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/dbd935a9e056545721bc4e9ce518c775d787b21e","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/dfc8373893b1876bb367700eac9d776316dabd96","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/fb256d07395ebbc950f42e439d3896ec3a25c845","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-72336","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:22:06.817","lastModified":"2026-08-15T06:22:06.817","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nBluetooth: 6lowpan: hold L2CAP conn across debugfs control\n\nget_l2cap_conn() looks up an LE hci_conn under hdev protection, but\nthen drops that protection before reading hcon->l2cap_data and before\nlowpan_control_write() later dereferences conn->hcon.  A disconnect or\ndevice close can tear down the same L2CAP connection in that window.\n\nThe buggy scenario involves two paths, with each column showing the order\nwithin that path:\n\n6LoWPAN control write:              HCI disconnect/device close:\n  1. get_l2cap_conn() finds hcon      1. hci_disconn_cfm() dispatches\n     and hcon->l2cap_data.               the L2CAP disconnect callback.\n  2. get_l2cap_conn() drops hdev      2. l2cap_conn_del() clears\n     protection and returns conn.        hcon->l2cap_data and drops the\n                                         L2CAP connection reference.\n  3. lowpan_control_write() reads     3. hci_conn_del() removes and drops\n     conn->hcon.                         the HCI connection.\n\nTake a reference to the L2CAP connection with\nl2cap_conn_hold_unless_zero() while hdev is still locked, and drop that\nreference after the debugfs command's last use of conn.  This mirrors the\nexisting L2CAP ACL receive-side handoff and keeps the connection\ndereferenceable after leaving hdev protection.  Export the existing helper\nso the bluetooth_6lowpan module can use the same lifetime primitive.\n\nValidation reproduced this kernel report:\nBUG: KASAN: slab-use-after-free in lowpan_control_write+0x374/0x520\nThe buggy address belongs to the object at ffff888111b9d000 which belongs\nto the cache kmalloc-1k of size 1024\nThe buggy address is located 0 bytes inside of freed 1024-byte region\n[ffff888111b9d000, ffff888111b9d400)\nRead of size 8\nCall trace:\n  dump_stack_lvl+0x66/0xa0\n  print_report+0xce/0x5f0\n  lowpan_control_write+0x374/0x520 (net/bluetooth/6lowpan.c:1131)\n  srso_alias_return_thunk+0x5/0xfbef5\n  __virt_addr_valid+0x19f/0x330\n  kasan_report+0xe0/0x110\n  __debugfs_file_get+0xf7/0x400\n  full_proxy_write+0x9e/0xd0\n  vfs_write+0x1b0/0x810\n  ksys_write+0xd2/0x170\n  dnotify_flush+0x32/0x220\n  do_syscall_64+0x115/0x6a0 (arch/x86/entry/syscall_64.c:87)\n  entry_SYSCALL_64_after_hwframe+0x77/0x7f\nAllocated by task stack:\n  kasan_save_stack+0x33/0x60\n  kasan_save_track+0x17/0x60\n  __kasan_kmalloc+0xaa/0xb0\n  l2cap_conn_add+0x45/0x520\n  l2cap_chan_connect+0xac6/0xd90\n  l2cap_sock_connect+0x216/0x350\n  __sys_connect+0x101/0x130\n  __x64_sys_connect+0x40/0x50\n  do_syscall_64+0x115/0x6a0 (arch/x86/entry/syscall_64.c:87)\n  entry_SYSCALL_64_after_hwframe+0x77/0x7f\nFreed by task stack:\n  kasan_save_stack+0x33/0x60\n  kasan_save_track+0x17/0x60\n  kasan_save_free_info+0x3b/0x60\n  __kasan_slab_free+0x5f/0x80\n  kfree+0x313/0x590\n  hci_conn_hash_flush+0xc0/0x140\n  hci_dev_close_sync+0x41a/0xb00\n  hci_dev_close+0x12f/0x160\n  hci_sock_ioctl+0x157/0x570\n  sock_do_ioctl+0xf7/0x210\n  sock_ioctl+0x32f/0x490\n  __x64_sys_ioctl+0xc7/0x110\n  do_syscall_64+0x115/0x6a0 (arch/x86/entry/syscall_64.c:87)\n  entry_SYSCALL_64_after_hwframe+0x77/0x7f\n  kasan_record_aux_stack+0xa7/0xc0\n  insert_work+0x32/0x100\n  __queue_work+0x262/0xa60\n  queue_work_on+0xad/0xb0\n  l2cap_connect_cfm+0x4ef/0x670\n  hci_le_remote_feat_complete_evt+0x247/0x430\n  hci_event_packet+0x360/0x6f0\n  hci_rx_work+0x2ae/0x7a0\n  process_one_work+0x4fd/0xbc0\n  worker_thread+0x2d8/0x570\n  kthread+0x1ad/0x1f0\n  ret_from_fork+0x3c9/0x540\n  ret_from_fork_asm+0x1a/0x30"}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["net/bluetooth/6lowpan.c","net/bluetooth/l2cap_core.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6b8d4a6a03144c5996f98db7f8256267b0d72a3a","lessThan":"ba1f1ef6522e63aa5dd29805b4390ea2ccadf05e","versionType":"git","status":"affected"},{"version":"6b8d4a6a03144c5996f98db7f8256267b0d72a3a","lessThan":"d2a8dc1f619c9e0e4126bee795c39ebddd2ec8ff","versionType":"git","status":"affected"},{"version":"6b8d4a6a03144c5996f98db7f8256267b0d72a3a","lessThan":"23a83bac3356e7b211bcdcf581a31f7b536a2c24","versionType":"git","status":"affected"},{"version":"6b8d4a6a03144c5996f98db7f8256267b0d72a3a","lessThan":"32c48c7f6cc8c7888e46a8c81622154ccafda5d2","versionType":"git","status":"affected"},{"version":"6b8d4a6a03144c5996f98db7f8256267b0d72a3a","lessThan":"518aa9505fa10ea5662349e5d2efd8c9e32a820b","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["net/bluetooth/6lowpan.c","net/bluetooth/l2cap_core.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"3.17","status":"affected"},{"version":"0","lessThan":"3.17","versionType":"semver","status":"unaffected"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.97","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc3","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/23a83bac3356e7b211bcdcf581a31f7b536a2c24","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/32c48c7f6cc8c7888e46a8c81622154ccafda5d2","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/518aa9505fa10ea5662349e5d2efd8c9e32a820b","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/ba1f1ef6522e63aa5dd29805b4390ea2ccadf05e","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/d2a8dc1f619c9e0e4126bee795c39ebddd2ec8ff","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-72337","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:22:06.953","lastModified":"2026-08-15T06:22:06.953","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nBluetooth: 6lowpan: avoid untracked enable work\n\nlowpan_enable_set() allocates a temporary work item and schedules\ndo_enable_set() on system_wq, then returns to debugfs. The debugfs active\noperation has ended at that point, but the worker still executes module\ntext and manipulates enable_6lowpan and listen_chan.\n\nbt_6lowpan_exit() removes the debugfs files and immediately closes and\nputs listen_chan. It has no pointer to the queued work item, so it cannot\ncancel or flush it before tearing down the state that the worker uses.\n\nThe buggy scenario involves two paths, with each column showing the order\nwithin that path:\n\ndebugfs enable write              module exit\n1. lowpan_enable_set() allocates  1. bt_6lowpan_exit() removes\n   set_enable work                   the debugfs file\n2. schedule_work() queues         2. bt_6lowpan_exit() closes\n   do_enable_set()                   and puts listen_chan\n3. the write operation returns    3. module teardown can continue\n4. do_enable_set() later runs\n   against stale state\n\nRun the enable state transition synchronously in lowpan_enable_set()\ninstead. The simple debugfs setter can sleep, and this file already handles\nthe 6LoWPAN control write synchronously under the same set_lock. Once the\nsetter returns, debugfs removal covers the whole operation and exit can no\nlonger race with an untracked work item.\n\nValidation reproduced this kernel report:\nBUG: KASAN: slab-use-after-free in do_enable_set+0x113/0x2e0\nWorkqueue: events do_enable_set [bluetooth_6lowpan]\nThe buggy address belongs to the object at ffff888109cb8000"}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["net/bluetooth/6lowpan.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"90305829635d90a5053ec99a261035b4ce0a2649","lessThan":"feb3fc2c38ed52003142f31e04109719b200c049","versionType":"git","status":"affected"},{"version":"90305829635d90a5053ec99a261035b4ce0a2649","lessThan":"352a59dc1f4a41314b6f827c17e16af7ca88271a","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["net/bluetooth/6lowpan.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"3.19","status":"affected"},{"version":"0","lessThan":"3.19","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc3","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/352a59dc1f4a41314b6f827c17e16af7ca88271a","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/feb3fc2c38ed52003142f31e04109719b200c049","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-72338","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:22:07.043","lastModified":"2026-08-15T06:22:07.043","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nnet/sched: act_pedit: fix TOCTOU heap OOB write in tc offload\n\nThere is a TOCTOU race condition in flower lockless approach between sizing\na flow_rule buffer and filling it.\nzdi-disclosures@trendmicro.com reports:\nThe cls_flower classifier operates with TCF_PROTO_OPS_DOIT_UNLOCKED\n(fl_change runs without RTNL), while RTM_NEWACTION holds RTNL, so the\nindependent locking domains make the race reachable in practice.  KASAN\nconfirms:\n  BUG: KASAN: slab-out-of-bounds in tcf_pedit_offload_act_setup+0x81b/0x930\n  Write of size 4 at addr ffff888001f27520 by task poc-toctou/312\n  The buggy address is located 0 bytes to the right of\n   allocated 288-byte region [ffff888001f27400, ffff888001f27520)\n   (cache kmalloc-512)\n\nNote: The result is a heap OOB write attacker-controlled content into the\nadjacent slab object (requires CAP_NET_ADMIN).\n\nThe fix introduces reading tcfp_nkeys under act->tcfa_lock in all places\nusing a new tcf_pedit_nkeys_locked() which replaces the old tcf_pedit_nkeys().\nAdditionally we close the remaining TOCTOU window between the sizing read and\nthe fill reads by more careful accounting.\nRather than silently truncating the key count, which leads to incorrect\naction semantics offloaded to hardware and secondary OOB writes if\nthe remaining capacity is zero or consumed by prior actions, we enforce\nremaining capacity checks and return -ENOSPC if the required space exceeds\nthe remaining capacity."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["include/net/tc_act/tc_pedit.h","net/sched/act_api.c","net/sched/act_pedit.c","net/sched/cls_api.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"71d0ed7079dffbc5cd0941d77d9b84e04109c9bb","lessThan":"0d8532a5e972a5351cf4ee4a435e0d65cbba8f23","versionType":"git","status":"affected"},{"version":"71d0ed7079dffbc5cd0941d77d9b84e04109c9bb","lessThan":"27488e1a7f19757e6146edca9458ed4ffc545557","versionType":"git","status":"affected"},{"version":"71d0ed7079dffbc5cd0941d77d9b84e04109c9bb","lessThan":"6f9b23eb92a894ae1118893996943990ee0b860e","versionType":"git","status":"affected"},{"version":"71d0ed7079dffbc5cd0941d77d9b84e04109c9bb","lessThan":"8e49cd891bda447c68122d672510a604a8bb6b24","versionType":"git","status":"affected"},{"version":"71d0ed7079dffbc5cd0941d77d9b84e04109c9bb","lessThan":"8b519cbcabe836a441369fbec1a8a6518a709251","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["include/net/tc_act/tc_pedit.h","net/sched/act_api.c","net/sched/act_pedit.c","net/sched/cls_api.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"4.11","status":"affected"},{"version":"0","lessThan":"4.11","versionType":"semver","status":"unaffected"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.97","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc3","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/0d8532a5e972a5351cf4ee4a435e0d65cbba8f23","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/27488e1a7f19757e6146edca9458ed4ffc545557","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/6f9b23eb92a894ae1118893996943990ee0b860e","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/8b519cbcabe836a441369fbec1a8a6518a709251","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/8e49cd891bda447c68122d672510a604a8bb6b24","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-72339","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:22:07.150","lastModified":"2026-08-15T06:22:07.150","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nqede: fix off-by-one in BD ring consumption on build_skb failure\n\nqede_rx_build_skb() and qede_tpa_rx_build_skb() do not check for a\nNULL return from qede_build_skb(). When it returns NULL under memory\npressure, the functions still consume a BD from the ring before\nreturning NULL. The callers then recycle additional BDs, resulting in\none extra BD being consumed (off-by-one). This desynchronizes the BD\nring, which can corrupt DMA page reference counts and lead to SLUB\nfreelist corruption.\n\nCommit 4e910dbe3650 (\"qede: confirm skb is allocated before using\")\nadded a NULL check inside qede_build_skb() to prevent a NULL pointer\ndereference, but did not address the missing NULL checks in the\ncallers, making this off-by-one reachable.\n\nFix this by adding NULL checks for the return value of\nqede_build_skb() in both qede_rx_build_skb() and\nqede_tpa_rx_build_skb(), returning NULL immediately before any BD ring\nmanipulation."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/net/ethernet/qlogic/qede/qede_fp.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"8a8633978b842c88fbcfe00d4e5dde96048f630e","lessThan":"ecc05d4b20220a09c9c69584fc46ca55248a374a","versionType":"git","status":"affected"},{"version":"8a8633978b842c88fbcfe00d4e5dde96048f630e","lessThan":"07be8b8adf91b7ada4c3dacce064d572a6066421","versionType":"git","status":"affected"},{"version":"8a8633978b842c88fbcfe00d4e5dde96048f630e","lessThan":"1624aa100c0b218181aa74e3696a389b509298cb","versionType":"git","status":"affected"},{"version":"8a8633978b842c88fbcfe00d4e5dde96048f630e","lessThan":"0bf78df2d3ecb1f4964ff42a7327d25845955153","versionType":"git","status":"affected"},{"version":"8a8633978b842c88fbcfe00d4e5dde96048f630e","lessThan":"814a5edac8c9fc04051808d5faaa93768e989281","versionType":"git","status":"affected"},{"version":"8a8633978b842c88fbcfe00d4e5dde96048f630e","lessThan":"b066420e57f3402a52c998678b4678252ac9bb63","versionType":"git","status":"affected"},{"version":"8a8633978b842c88fbcfe00d4e5dde96048f630e","lessThan":"982d6d6bc059c5dff37a2201c2f08c14bcfcbd20","versionType":"git","status":"affected"},{"version":"8a8633978b842c88fbcfe00d4e5dde96048f630e","lessThan":"a0a558ca7e75b49e71f8c545c30e8c005e6e4e2f","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/net/ethernet/qlogic/qede/qede_fp.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"4.18","status":"affected"},{"version":"0","lessThan":"4.18","versionType":"semver","status":"unaffected"},{"version":"5.10.261","lessThanOrEqual":"5.10.*","versionType":"semver","status":"unaffected"},{"version":"5.15.212","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.178","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.97","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc3","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/07be8b8adf91b7ada4c3dacce064d572a6066421","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/0bf78df2d3ecb1f4964ff42a7327d25845955153","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/1624aa100c0b218181aa74e3696a389b509298cb","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/814a5edac8c9fc04051808d5faaa93768e989281","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/982d6d6bc059c5dff37a2201c2f08c14bcfcbd20","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/a0a558ca7e75b49e71f8c545c30e8c005e6e4e2f","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/b066420e57f3402a52c998678b4678252ac9bb63","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/ecc05d4b20220a09c9c69584fc46ca55248a374a","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-72340","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:22:07.280","lastModified":"2026-08-15T06:22:07.280","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nnet: microchip: vcap: fix races on the shared Super VCAP block\n\nThe VCAP instances on a chip are not independent, yet they are locked\nindependently. On sparx5 and lan969x the IS0 and IS2 instances are\nbacked by the same Super VCAP hardware block and share its cache and\ncommand registers: every access drives the shared VCAP_SUPER_CTRL\nregister and moves data through the shared cache registers.\n\nAccessing one instance therefore races with accessing another. The\nper-instance admin->lock cannot prevent this, as each instance takes a\ndifferent lock.\n\nThe locking issue is mostly disguised by the fact that the core usage of\nthe vcap api runs under rtnl. However, the full rule dump in debugfs\ndecodes rules straight from hardware (a READ command followed by a cache\nread) and runs outside rtnl, so it races a concurrent tc-flower rule\nwrite to another Super VCAP instance.\n\nBesides corrupting the dump, the read repopulates the shared cache\nbetween the writers cache fill and its write command, so the writer\ncommits the wrong data and corrupts the hardware entry.\n\nIntroduce vcap_lock() and vcap_unlock() helpers and route every rule\nlock site in the VCAP API and its debugfs code through them. Replace the\nper-instance admin->lock with a single mutex in struct vcap_control that\nserializes access to all instances. The helpers reach it through a new\nadmin->vctrl back-pointer, and the clients initialise and destroy the\ncontrol lock instead of a per-instance one.\n\nNo path holds more than one instance lock, so collapsing them onto a\nsingle mutex cannot self-deadlock."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/net/ethernet/microchip/lan966x/lan966x_vcap_impl.c","drivers/net/ethernet/microchip/sparx5/sparx5_vcap_impl.c","drivers/net/ethernet/microchip/vcap/vcap_api.c","drivers/net/ethernet/microchip/vcap/vcap_api.h","drivers/net/ethernet/microchip/vcap/vcap_api_debugfs.c","drivers/net/ethernet/microchip/vcap/vcap_api_debugfs_kunit.c","drivers/net/ethernet/microchip/vcap/vcap_api_kunit.c","drivers/net/ethernet/microchip/vcap/vcap_api_private.h"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"71c9de995260222e739020104d477af4775a6d26","lessThan":"786456d0a244bbd405dfc60e4de51f8b348b9cb1","versionType":"git","status":"affected"},{"version":"71c9de995260222e739020104d477af4775a6d26","lessThan":"49806bef9572a2e012610517bc14ed0a4db0d1fc","versionType":"git","status":"affected"},{"version":"71c9de995260222e739020104d477af4775a6d26","lessThan":"1e71a40d101547380590db582213c1f1dce1f041","versionType":"git","status":"affected"},{"version":"71c9de995260222e739020104d477af4775a6d26","lessThan":"952928564cc5fdb06f92d7e25c6cd2e1d816362b","versionType":"git","status":"affected"},{"version":"71c9de995260222e739020104d477af4775a6d26","lessThan":"d7a8d500d7e42837bd8dce40cb52c97c6e8706a9","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/net/ethernet/microchip/lan966x/lan966x_vcap_impl.c","drivers/net/ethernet/microchip/sparx5/sparx5_vcap_impl.c","drivers/net/ethernet/microchip/vcap/vcap_api.c","drivers/net/ethernet/microchip/vcap/vcap_api.h","drivers/net/ethernet/microchip/vcap/vcap_api_debugfs.c","drivers/net/ethernet/microchip/vcap/vcap_api_debugfs_kunit.c","drivers/net/ethernet/microchip/vcap/vcap_api_kunit.c","drivers/net/ethernet/microchip/vcap/vcap_api_private.h"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.2","status":"affected"},{"version":"0","lessThan":"6.2","versionType":"semver","status":"unaffected"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.97","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc3","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/1e71a40d101547380590db582213c1f1dce1f041","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/49806bef9572a2e012610517bc14ed0a4db0d1fc","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/786456d0a244bbd405dfc60e4de51f8b348b9cb1","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/952928564cc5fdb06f92d7e25c6cd2e1d816362b","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/d7a8d500d7e42837bd8dce40cb52c97c6e8706a9","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-72341","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:22:07.403","lastModified":"2026-08-15T06:22:07.403","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nnet/mlx5e: Fix publication race for priv->channel_stats[]\n\nmlx5e_channel_stats_alloc() publishes a new entry to\npriv->channel_stats[] and then increments priv->stats_nch as a\npublication token, but neither store carries any memory barrier:\n\n\tpriv->channel_stats[ix] = kvzalloc_node(...);\n\tif (!priv->channel_stats[ix])\n\t\treturn -ENOMEM;\n\tpriv->stats_nch++;\n\nConcurrent readers compute the loop bound from priv->stats_nch and\nthen dereference priv->channel_stats[i] using plain accesses, e.g.\n\n\tfor (i = 0; i < priv->stats_nch; i++) {\n\t\tstruct mlx5e_channel_stats *cs = priv->channel_stats[i];\n\t\t... cs->rq.packets ...\n\t}\n\nOn weakly-ordered architectures (ARM, PowerPC, RISC-V) the writes to\nchannel_stats[ix] and stats_nch may become visible to other CPUs out\nof program order. A reader can observe stats_nch == N while still\nseeing channel_stats[N-1] == NULL, leading to a NULL pointer\ndereference in the channel_stats loop.\n\nThis has been observed in production on BlueField-3 DPUs (arm64),\nwhere ovs-vswitchd queries netdev statistics over netlink during NIC\nbringup, racing mlx5e_open_channel() -> mlx5e_channel_stats_alloc()\non another CPU:\n\n  Unable to handle kernel NULL pointer dereference at virtual address 0x840\n  Hardware name: BlueField-3 DPU\n  pc : mlx5e_fold_sw_stats64+0x30/0x180 [mlx5_core]\n  Call trace:\n   mlx5e_fold_sw_stats64+0x30/0x180 [mlx5_core]\n   dev_get_stats+0x50/0xc0\n   ovs_vport_get_stats+0x38/0xac [openvswitch]\n   ovs_vport_cmd_fill_info+0x194/0x290 [openvswitch]\n   ovs_vport_cmd_get+0xbc/0x10c [openvswitch]\n   genl_family_rcv_msg_doit+0xd0/0x160\n   genl_rcv_msg+0xec/0x1f0\n   netlink_rcv_skb+0x64/0x130\n   genl_rcv+0x40/0x60\n   netlink_unicast+0x2fc/0x370\n   netlink_sendmsg+0x1dc/0x454\n   ...\n   __arm64_sys_sendmsg+0x2c/0x40\n\nAdd mlx5e_stats_nch_write() and mlx5e_stats_nch_read() helpers in en.h\nthat wrap the smp_store_release()/smp_load_acquire() pair on stats_nch.\nThe release/acquire pair establishes the contract:\n\n  stats_nch == N  =>  channel_stats[0..N-1] are visible and non-NULL.\n\nPublish the stats_nch increment via mlx5e_stats_nch_write() in the\nwriter (mlx5e_channel_stats_alloc()), and read stats_nch via\nmlx5e_stats_nch_read() in all readers: mlx5e RX/TX queue stats,\nmlx5e_get_base_stats(), ethtool channels stats, IPoIB stats, the\nsw_stats fold and the HV VHCA stats agent."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/net/ethernet/mellanox/mlx5/core/en.h","drivers/net/ethernet/mellanox/mlx5/core/en/hv_vhca_stats.c","drivers/net/ethernet/mellanox/mlx5/core/en_main.c","drivers/net/ethernet/mellanox/mlx5/core/en_stats.c","drivers/net/ethernet/mellanox/mlx5/core/ipoib/ipoib.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"fa691d0c9c0812b9045f3a9420862e47b3b92518","lessThan":"5c7e3755abf663f033de24f917b77685e9543045","versionType":"git","status":"affected"},{"version":"fa691d0c9c0812b9045f3a9420862e47b3b92518","lessThan":"815515ec68f527ca755cb1e2c1ff9148f6b3ea56","versionType":"git","status":"affected"},{"version":"fa691d0c9c0812b9045f3a9420862e47b3b92518","lessThan":"5a799714e8ca0bce9ea40694f49914cf1adbbaa9","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/net/ethernet/mellanox/mlx5/core/en.h","drivers/net/ethernet/mellanox/mlx5/core/en/hv_vhca_stats.c","drivers/net/ethernet/mellanox/mlx5/core/en_main.c","drivers/net/ethernet/mellanox/mlx5/core/en_stats.c","drivers/net/ethernet/mellanox/mlx5/core/ipoib/ipoib.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"5.17","status":"affected"},{"version":"0","lessThan":"5.17","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc3","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/5a799714e8ca0bce9ea40694f49914cf1adbbaa9","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/5c7e3755abf663f033de24f917b77685e9543045","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/815515ec68f527ca755cb1e2c1ff9148f6b3ea56","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-72342","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:22:07.520","lastModified":"2026-08-15T06:22:07.520","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nnet/mlx5e: Fix HV VHCA stats agent registration race\n\nmlx5e_hv_vhca_stats_create() registers the stats agent through\nmlx5_hv_vhca_agent_create(). The helper publishes the agent in\nhv_vhca->agents[type] under agents_lock and immediately schedules an\nasynchronous control invalidation on the HV VHCA workqueue before\nreturning to mlx5e.\n\nThe asynchronous invalidation invokes the control agent's invalidate\ncallback, which reads the hypervisor control block and forwards the\ncommand to mlx5e_hv_vhca_stats_control(). That callback may either:\n\n  - call cancel_delayed_work_sync(&priv->stats_agent.work), or\n  - call queue_delayed_work(priv->wq, &sagent->work, sagent->delay).\n\nHowever, the delayed_work and priv->stats_agent.agent are only\ninitialized after mlx5_hv_vhca_agent_create() returns to mlx5e:\n\n    agent = mlx5_hv_vhca_agent_create(...);   /* publish + invalidate */\n    ...\n    priv->stats_agent.agent = agent;          /* too late */\n    INIT_DELAYED_WORK(&priv->stats_agent.work, ...); /* too late */\n\nIf the asynchronous control path runs before the two assignments\nabove, it can:\n\n  - Operate on an uninitialized delayed_work whose timer.function is\n    NULL. queue_delayed_work() calls add_timer() unconditionally, so\n    when the timer expires the timer softirq invokes a NULL function\n    pointer.\n  - Re-initialize the timer later through INIT_DELAYED_WORK() while\n    the timer is already enqueued in the timer wheel, corrupting the\n    hlist (entry.pprev cleared while the previous bucket node still\n    points at this entry).\n  - When the worker eventually runs, mlx5e_hv_vhca_stats_work() reads\n    sagent->agent (NULL) and dereferences it inside\n    mlx5_hv_vhca_agent_write().\n\nFix this by:\n\n  - Initializing priv->stats_agent.work before invoking\n    mlx5_hv_vhca_agent_create(), so the work is always in a valid\n    state when the control callback observes it.\n  - Adding a struct mlx5_hv_vhca_agent **ctx_update out-parameter\n    to mlx5_hv_vhca_agent_create(). The helper writes the agent\n    pointer to *ctx_update before publishing into hv_vhca->agents[]\n    and triggering the agents_update flow, so any callback\n    subsequently invoked from that flow already sees a valid\n    priv->stats_agent.agent. This avoids having the control\n    callback participate in agent initialization.\n\nWhile at it, access priv->stats_agent.agent with\nREAD_ONCE()/WRITE_ONCE() for the cross-CPU access with the worker, and\nclear priv->stats_agent.buf on the agent_create() failure path."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/net/ethernet/mellanox/mlx5/core/en/hv_vhca_stats.c","drivers/net/ethernet/mellanox/mlx5/core/lib/hv_vhca.c","drivers/net/ethernet/mellanox/mlx5/core/lib/hv_vhca.h"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"cef35af34d6dc3792333075115c7deb7062b6e18","lessThan":"b0fd6d3bb06182f19f3b59a53f57b5098b99048a","versionType":"git","status":"affected"},{"version":"cef35af34d6dc3792333075115c7deb7062b6e18","lessThan":"24c77044cdfcf5b8b2e9f3b620d8b9aa392d9add","versionType":"git","status":"affected"},{"version":"cef35af34d6dc3792333075115c7deb7062b6e18","lessThan":"e8fc3304cb67fb1d7d11ff9ef9abd5fb64e7e1d5","versionType":"git","status":"affected"},{"version":"cef35af34d6dc3792333075115c7deb7062b6e18","lessThan":"60fddda7207d81fea71463abd403f0b10f74f2e1","versionType":"git","status":"affected"},{"version":"cef35af34d6dc3792333075115c7deb7062b6e18","lessThan":"f5677797b094c3ec5fb350eb8ea7710b88a3d018","versionType":"git","status":"affected"},{"version":"cef35af34d6dc3792333075115c7deb7062b6e18","lessThan":"89b25b5f46f488ea3b29b3444864c76944c9075b","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/net/ethernet/mellanox/mlx5/core/en/hv_vhca_stats.c","drivers/net/ethernet/mellanox/mlx5/core/lib/hv_vhca.c","drivers/net/ethernet/mellanox/mlx5/core/lib/hv_vhca.h"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"5.4","status":"affected"},{"version":"0","lessThan":"5.4","versionType":"semver","status":"unaffected"},{"version":"6.1.178","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.97","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc3","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/24c77044cdfcf5b8b2e9f3b620d8b9aa392d9add","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/60fddda7207d81fea71463abd403f0b10f74f2e1","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/89b25b5f46f488ea3b29b3444864c76944c9075b","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/b0fd6d3bb06182f19f3b59a53f57b5098b99048a","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/e8fc3304cb67fb1d7d11ff9ef9abd5fb64e7e1d5","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/f5677797b094c3ec5fb350eb8ea7710b88a3d018","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-72343","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:22:07.650","lastModified":"2026-08-15T06:22:07.650","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nnet/mlx5e: Fix HV VHCA stats zero-sized buffer allocation\n\nmlx5e_hv_vhca_stats_create() is called from mlx5e_nic_enable(),\nbefore mlx5e_open(). At that point priv->stats_nch is still zero,\nbecause it is only ever incremented in mlx5e_channel_stats_alloc(),\nwhich is reached only from mlx5e_open_channel().\n\nmlx5e_hv_vhca_stats_buf_size() therefore returns 0, and\nkvzalloc(0, GFP_KERNEL) returns ZERO_SIZE_PTR ((void *)16) rather\nthan NULL. The \"if (!buf)\" guard does not catch this, and\nmlx5e_hv_vhca_stats_create() completes \"successfully\" with\npriv->stats_agent.buf set to ZERO_SIZE_PTR.\n\nOnce channels are opened (priv->stats_nch > 0) and the hypervisor\nenables stats reporting, mlx5e_hv_vhca_stats_work() recomputes\nbuf_len using the new non-zero stats_nch and calls\nmemset(buf, 0, buf_len) on ZERO_SIZE_PTR, faulting at address 0x10.\n\nAllocate the buffer based on priv->max_nch, which is set in\nmlx5e_priv_init() and is the upper bound on stats_nch:\n\n  - Add a separate helper mlx5e_hv_vhca_stats_buf_max_size() that\n    returns sizeof(per_ring_stats) * max(max_nch, stats_nch), and\n    use it for the kvzalloc() in mlx5e_hv_vhca_stats_create().\n  - Keep mlx5e_hv_vhca_stats_buf_size() (which returns based on\n    stats_nch) for the worker's active payload size, so the wire\n    format (block->rings = stats_nch) and the amount of data filled\n    by mlx5e_hv_vhca_fill_stats() are unchanged.\n\nThe max(max_nch, stats_nch) guard handles the rare case where\nmlx5e_attach_netdev() recomputes max_nch downward across a\ndetach/resume cycle while priv->stats_nch persists (mlx5e_detach_netdev\ndoes not call mlx5e_priv_cleanup, so stats_nch is only reset when\nthe netdev is destroyed). Without the guard, the worker could compute\nbuf_len from stats_nch and overrun the smaller buffer allocated based\non the reduced max_nch.\n\nAllocating a non-zero buffer also makes the kvzalloc() failure path in\nmlx5e_hv_vhca_stats_create() reachable for the first time: it returns\nearly without (re)creating the agent. Clear\npriv->stats_agent.{agent,buf} in mlx5e_hv_vhca_stats_destroy() after\nfreeing them, so that if a later create() bails out on this path, a\nsubsequent teardown does not double-free the stale agent/buffer left\nfrom a previous enable/disable cycle.\n\nThis mirrors the existing mlx5e pattern of preallocating arrays of\nsize max_nch (e.g. priv->channel_stats) and lazily populating\nentries up to stats_nch on demand."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/net/ethernet/mellanox/mlx5/core/en/hv_vhca_stats.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"fa691d0c9c0812b9045f3a9420862e47b3b92518","lessThan":"3b3a552cf88e10bb7bda88b29cf1fd8267043d50","versionType":"git","status":"affected"},{"version":"fa691d0c9c0812b9045f3a9420862e47b3b92518","lessThan":"5b927dcec5f1087942bf123a82e64a3f66475f01","versionType":"git","status":"affected"},{"version":"fa691d0c9c0812b9045f3a9420862e47b3b92518","lessThan":"22c1d5ecccf92c849bdca1556179aafc95794baf","versionType":"git","status":"affected"},{"version":"fa691d0c9c0812b9045f3a9420862e47b3b92518","lessThan":"420aabb32da4381d8d7cdcaa6a77fad9eaceb0a4","versionType":"git","status":"affected"},{"version":"fa691d0c9c0812b9045f3a9420862e47b3b92518","lessThan":"abc4c56427f144c96b2827a4db3b90eb5b7349a2","versionType":"git","status":"affected"},{"version":"fa691d0c9c0812b9045f3a9420862e47b3b92518","lessThan":"25f6b929c7e379cbea7cb8caa67b49b2d1efae17","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/net/ethernet/mellanox/mlx5/core/en/hv_vhca_stats.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"5.17","status":"affected"},{"version":"0","lessThan":"5.17","versionType":"semver","status":"unaffected"},{"version":"6.1.178","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.97","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc3","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/22c1d5ecccf92c849bdca1556179aafc95794baf","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/25f6b929c7e379cbea7cb8caa67b49b2d1efae17","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/3b3a552cf88e10bb7bda88b29cf1fd8267043d50","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/420aabb32da4381d8d7cdcaa6a77fad9eaceb0a4","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/5b927dcec5f1087942bf123a82e64a3f66475f01","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/abc4c56427f144c96b2827a4db3b90eb5b7349a2","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-72344","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:22:07.773","lastModified":"2026-08-15T06:22:07.773","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nnet/mlx5e: TC, skip peer flow cleanup when LAG seq is unavailable\n\nmlx5_lag_get_dev_seq() will return error when the peer isn't in the LAG\nor when no device is marked as master. Result bad memory access and kernel\ncrash[1].\n\nHence, skip the peer when lookup fails.\n\nNote: In case there are peer flows, they are cleaned before LAG cleared\nthe master mark.\n\n[1]\nRIP: 0010:mlx5e_tc_del_fdb_peers_flow+0x3d/0x350 [mlx5_core]\nCall Trace:\n <TASK>\n mlx5e_tc_clean_fdb_peer_flows+0xc1/0x130 [mlx5_core]\n mlx5_esw_offloads_unpair+0x3a/0x400 [mlx5_core]\n mlx5_esw_offloads_devcom_event+0xee/0x360 [mlx5_core]\n mlx5_devcom_send_event+0x7a/0x140 [mlx5_core]\n mlx5_esw_offloads_devcom_cleanup+0x2f/0x90 [mlx5_core]\n mlx5e_tc_esw_cleanup+0x28/0xf0 [mlx5_core]\n mlx5e_rep_tc_cleanup+0x19/0x30 [mlx5_core]\n mlx5e_cleanup_uplink_rep_tx+0x36/0x40 [mlx5_core]\n mlx5e_cleanup_rep_tx+0x55/0x60 [mlx5_core]\n mlx5e_detach_netdev+0x96/0xf0 [mlx5_core]\n mlx5e_netdev_change_profile+0x5b/0x120 [mlx5_core]\n mlx5e_netdev_attach_nic_profile+0x1b/0x30 [mlx5_core]\n mlx5e_vport_rep_unload+0xdd/0x110 [mlx5_core]\n __esw_offloads_unload_rep+0x81/0xb0 [mlx5_core]\n mlx5_eswitch_unregister_vport_reps+0x1d7/0x220 [mlx5_core]\n mlx5e_rep_remove+0x22/0x30 [mlx5_core]\n device_release_driver_internal+0x194/0x1f0\n bus_remove_device+0xe8/0x1b0\n device_del+0x159/0x3c0\n mlx5_rescan_drivers_locked+0xbc/0x2d0 [mlx5_core]\n mlx5_unregister_device+0x54/0x80 [mlx5_core]\n mlx5_uninit_one+0x73/0x130 [mlx5_core]\n remove_one+0x78/0xe0 [mlx5_core]\n pci_device_remove+0x39/0xa0"}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/net/ethernet/mellanox/mlx5/core/en_tc.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"971b28accc09436fe6a6d5afd667dcbfb3ed7e03","lessThan":"5a95aa0198af75047d98fb72950642c89dab770f","versionType":"git","status":"affected"},{"version":"971b28accc09436fe6a6d5afd667dcbfb3ed7e03","lessThan":"7bed4af0ced82948d660205efecd551ef8bc3912","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/net/ethernet/mellanox/mlx5/core/en_tc.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"7.1","status":"affected"},{"version":"0","lessThan":"7.1","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc3","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/5a95aa0198af75047d98fb72950642c89dab770f","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/7bed4af0ced82948d660205efecd551ef8bc3912","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-72345","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:22:07.870","lastModified":"2026-08-15T06:22:07.870","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nnet/mlx5: LAG, Fix off-by-one in single-FDB error rollback\n\nOn failure at index i, the reverse cleanup loop in\nmlx5_lag_create_single_fdb() starts from i, so the failed index\nitself is rolled back. That can operate on uninitialized state or\ndouble-tear-down a rule the add_one path already self-rolled-back.\n\nStart the rollback from i - 1 so only successfully-installed entries\nare undone."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/net/ethernet/mellanox/mlx5/core/lag/shared_fdb.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"ddbb5ddc43ad000a984149db5af1133433938404","lessThan":"40cc06bf71476932e5d139fa326dcd0372766e16","versionType":"git","status":"affected"},{"version":"ddbb5ddc43ad000a984149db5af1133433938404","lessThan":"0f0e4ae6975c773f7854fc48932a267f6c79088f","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/net/ethernet/mellanox/mlx5/core/lag/shared_fdb.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.14","status":"affected"},{"version":"0","lessThan":"6.14","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc3","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/0f0e4ae6975c773f7854fc48932a267f6c79088f","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/40cc06bf71476932e5d139fa326dcd0372766e16","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-72346","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:22:07.963","lastModified":"2026-08-15T06:22:07.963","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nplatform/x86: bitland-mifs-wmi: Fix NULL pointer dereference during suspend/resume\n\nThe driver registers two distinct WMI devices: a control device\n(BITLAND_WMI_CONTROL) and an event device (BITLAND_WMI_EVENT). During\nthe probe phase, the event device handling path returns early before\ninitializing the platform profile device (data->pp_dev), leaving it\nNULL.\n\nHowever, the PM sleep operations are registered globally for the WMI\ndriver and are triggered for both devices. When entering suspend, the\nevent device invokes bitland_mifs_wmi_suspend(), which passes the\nuninitialized data->pp_dev (NULL) into laptop_profile_get(). This leads\nto a NULL pointer dereference inside dev_get_drvdata(), causing a\nkernel Oops and halting the suspend sequence.\n\nFix this by adding a validity check for data->pp_dev in both the suspend\nand resume callbacks, safely skipping profile operations for the event\ndevice."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/platform/x86/bitland-mifs-wmi.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"dc1ec4fa86b2b8bba2b6122f2b4420217b5bae9e","lessThan":"6f2cb20d8e286218d51754f06ee219d8ce754b18","versionType":"git","status":"affected"},{"version":"dc1ec4fa86b2b8bba2b6122f2b4420217b5bae9e","lessThan":"d3666875c75eb1bc8090343fa0d6fc8fb7924356","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/platform/x86/bitland-mifs-wmi.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"7.1","status":"affected"},{"version":"0","lessThan":"7.1","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc3","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/6f2cb20d8e286218d51754f06ee219d8ce754b18","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/d3666875c75eb1bc8090343fa0d6fc8fb7924356","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-72347","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:22:08.070","lastModified":"2026-08-15T06:22:08.070","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nnetfilter: xt_connmark: reject invalid shift parameters\n\nRevision 2 of the CONNMARK target accepts user-controlled shift\nparameters and applies them to 32-bit mark values in\nconnmark_tg_shift().\n\nA shift_bits value of 32 or more triggers an undefined-shift bug when\nthe rule is evaluated. Invalid shift_dir values are also accepted and\nsilently fall back to the left-shift path.\n\nReject invalid revision-2 shift parameters in connmark_tg_check() so\nmalformed rules fail at installation time, before they can reach the\npacket path."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["net/netfilter/xt_connmark.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"472a73e00757b971d613d796374d2727b2e4954d","lessThan":"d8ce63d928b457fba7ed1e302492dfd32293671c","versionType":"git","status":"affected"},{"version":"472a73e00757b971d613d796374d2727b2e4954d","lessThan":"9657bb11a6376ab0a79f05d433713d6944111e9d","versionType":"git","status":"affected"},{"version":"472a73e00757b971d613d796374d2727b2e4954d","lessThan":"8ace320ac4416f5e5fbcd065309fb2dfcce787b0","versionType":"git","status":"affected"},{"version":"472a73e00757b971d613d796374d2727b2e4954d","lessThan":"c3fa852d117b3fda72265e4230e3967db4a74fcf","versionType":"git","status":"affected"},{"version":"472a73e00757b971d613d796374d2727b2e4954d","lessThan":"4eef84b09a3836919360c4232b0f16651a155eec","versionType":"git","status":"affected"},{"version":"472a73e00757b971d613d796374d2727b2e4954d","lessThan":"230173cc6105bdfb2696d37e6e56687b003fbe63","versionType":"git","status":"affected"},{"version":"472a73e00757b971d613d796374d2727b2e4954d","lessThan":"1b47026fb4b35bac850ad6e8a4ad7fc018e09ebc","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["net/netfilter/xt_connmark.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"4.17","status":"affected"},{"version":"0","lessThan":"4.17","versionType":"semver","status":"unaffected"},{"version":"5.15.212","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.178","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.97","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc3","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/1b47026fb4b35bac850ad6e8a4ad7fc018e09ebc","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/230173cc6105bdfb2696d37e6e56687b003fbe63","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/4eef84b09a3836919360c4232b0f16651a155eec","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/8ace320ac4416f5e5fbcd065309fb2dfcce787b0","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/9657bb11a6376ab0a79f05d433713d6944111e9d","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/c3fa852d117b3fda72265e4230e3967db4a74fcf","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/d8ce63d928b457fba7ed1e302492dfd32293671c","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-72348","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:22:08.177","lastModified":"2026-08-15T06:22:08.177","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nnetfilter: ip6tables: mark malformed IPv6 extension headers for hotdrop\n\nThe ah, hbh and rt matches check that the fixed extension header is\npresent, then use the header length field to derive the advertised\nextension header length for matching.\n\nFor the ah match, add the missing advertised-length check. For hbh\nand rt, update the existing advertised-length checks. In all three\ncases, set hotdrop to true before returning false when the advertised\nextension header length exceeds the available skb data.\n\nReturning false treats the packet as a rule mismatch. Set hotdrop to\ntrue and drop malformed packets so they cannot bypass rules intended\nto drop packets with these IPv6 extension headers."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["net/ipv6/netfilter/ip6t_ah.c","net/ipv6/netfilter/ip6t_hbh.c","net/ipv6/netfilter/ip6t_rt.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"f16d856b6af5fd0e7cb0b0212f70825b599ef72e","versionType":"git","status":"affected"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"fc416870100cf16d5b9495199355a679c3a02d48","versionType":"git","status":"affected"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"f775fcf384b06f35b612f78fa5601fee99eb6513","versionType":"git","status":"affected"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"2fd89a50a9783eed8ed23866b11c8b3d8779a7a8","versionType":"git","status":"affected"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"3578b6d92a5b1e603ae6e8c8f5538a709f03aba4","versionType":"git","status":"affected"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"3d441be2b1c5e98167302fa1c7b61960a067b112","versionType":"git","status":"affected"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"d5e39e5eb6b30bc4a3bb7aba54c293cf36a806c7","versionType":"git","status":"affected"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"43ccc20b5a733226417832cf16ef45322e594990","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["net/ipv6/netfilter/ip6t_ah.c","net/ipv6/netfilter/ip6t_hbh.c","net/ipv6/netfilter/ip6t_rt.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"2.6.12","status":"affected"},{"version":"0","lessThan":"2.6.12","versionType":"semver","status":"unaffected"},{"version":"5.10.261","lessThanOrEqual":"5.10.*","versionType":"semver","status":"unaffected"},{"version":"5.15.212","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.178","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.97","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc3","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/2fd89a50a9783eed8ed23866b11c8b3d8779a7a8","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/3578b6d92a5b1e603ae6e8c8f5538a709f03aba4","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/3d441be2b1c5e98167302fa1c7b61960a067b112","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/43ccc20b5a733226417832cf16ef45322e594990","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/d5e39e5eb6b30bc4a3bb7aba54c293cf36a806c7","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/f16d856b6af5fd0e7cb0b0212f70825b599ef72e","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/f775fcf384b06f35b612f78fa5601fee99eb6513","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/fc416870100cf16d5b9495199355a679c3a02d48","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-72349","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:22:08.297","lastModified":"2026-08-15T06:22:08.297","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nnetfilter: xt_rateest: fix u64 truncation in xt_rateest_mt()\n\nOn links faster than ~34 Gbps, where byte rate may exceed 2^32-1\n(~ 4.3 GBps), the comparison result becomes incorrect because the\ntruncated value no longer reflects the actual estimator rate.\n\nFix by changing the local variables to u64."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["net/netfilter/xt_rateest.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"1c0d32fde5bdf1184bc274f864c09799278a1114","lessThan":"77e9ba358d63fe2eb03c90d29ea85651d95cf2e6","versionType":"git","status":"affected"},{"version":"1c0d32fde5bdf1184bc274f864c09799278a1114","lessThan":"a3ba938f45cb00f6bf49d3aa3647df9b017f5f08","versionType":"git","status":"affected"},{"version":"1c0d32fde5bdf1184bc274f864c09799278a1114","lessThan":"bab305dd769d78074adca73505cc2509e1206bf2","versionType":"git","status":"affected"},{"version":"1c0d32fde5bdf1184bc274f864c09799278a1114","lessThan":"5da915fc159c6b4091669447588e520183969cca","versionType":"git","status":"affected"},{"version":"1c0d32fde5bdf1184bc274f864c09799278a1114","lessThan":"d5cc4c12a4b90bf099199c3c49ecda7e694f2a2b","versionType":"git","status":"affected"},{"version":"1c0d32fde5bdf1184bc274f864c09799278a1114","lessThan":"e702f6dd5d21e331f55fd9168c0210542008546d","versionType":"git","status":"affected"},{"version":"1c0d32fde5bdf1184bc274f864c09799278a1114","lessThan":"905a927b2e6fec7b174e9e5644d271047b61378f","versionType":"git","status":"affected"},{"version":"1c0d32fde5bdf1184bc274f864c09799278a1114","lessThan":"444853cd438201007da5359821adcc2995655ab1","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["net/netfilter/xt_rateest.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"4.10","status":"affected"},{"version":"0","lessThan":"4.10","versionType":"semver","status":"unaffected"},{"version":"5.10.261","lessThanOrEqual":"5.10.*","versionType":"semver","status":"unaffected"},{"version":"5.15.212","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.178","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.97","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc3","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/444853cd438201007da5359821adcc2995655ab1","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/5da915fc159c6b4091669447588e520183969cca","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/77e9ba358d63fe2eb03c90d29ea85651d95cf2e6","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/905a927b2e6fec7b174e9e5644d271047b61378f","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/a3ba938f45cb00f6bf49d3aa3647df9b017f5f08","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/bab305dd769d78074adca73505cc2509e1206bf2","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/d5cc4c12a4b90bf099199c3c49ecda7e694f2a2b","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/e702f6dd5d21e331f55fd9168c0210542008546d","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-72350","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:22:08.407","lastModified":"2026-08-15T06:22:08.407","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nnetfilter: xt_u32: reject invalid shift counts\n\nu32_match_it() executes rule-supplied shift operands on a 32-bit\nvalue. A malformed u32 rule can provide a shift count of 32 or more,\ntriggering an undefined shift out-of-bounds during packet evaluation.\n\nValidate XT_U32_LEFTSH and XT_U32_RIGHTSH operands in\nu32_mt_checkentry() and reject malformed rules before they reach the\npacket path."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["net/netfilter/xt_u32.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"1b50b8a371e90a5e110f466e4ac02cf6b5f681de","lessThan":"ca7c92d9701249e6daf132087756a88cbf2bb2a3","versionType":"git","status":"affected"},{"version":"1b50b8a371e90a5e110f466e4ac02cf6b5f681de","lessThan":"b33b44250d57ab0e5a1e2571b5285fb0d0a7f382","versionType":"git","status":"affected"},{"version":"1b50b8a371e90a5e110f466e4ac02cf6b5f681de","lessThan":"728f479dc0447ae7eaef87926ff49142e415a811","versionType":"git","status":"affected"},{"version":"1b50b8a371e90a5e110f466e4ac02cf6b5f681de","lessThan":"0a8b7a6d763775709c601f584e709ae48bcc000a","versionType":"git","status":"affected"},{"version":"1b50b8a371e90a5e110f466e4ac02cf6b5f681de","lessThan":"cce42014415cecd98aa49b3950e7b02ee7c81268","versionType":"git","status":"affected"},{"version":"1b50b8a371e90a5e110f466e4ac02cf6b5f681de","lessThan":"a597a722fb71a534138c20359b655726622b5f17","versionType":"git","status":"affected"},{"version":"1b50b8a371e90a5e110f466e4ac02cf6b5f681de","lessThan":"00d034fe8230dfc5832fe011ff2d81c1a2cc7a29","versionType":"git","status":"affected"},{"version":"1b50b8a371e90a5e110f466e4ac02cf6b5f681de","lessThan":"64cdf7d30ac18e43df6c48004435febb965809a8","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["net/netfilter/xt_u32.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"2.6.23","status":"affected"},{"version":"0","lessThan":"2.6.23","versionType":"semver","status":"unaffected"},{"version":"5.10.261","lessThanOrEqual":"5.10.*","versionType":"semver","status":"unaffected"},{"version":"5.15.212","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.178","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.97","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc3","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/00d034fe8230dfc5832fe011ff2d81c1a2cc7a29","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/0a8b7a6d763775709c601f584e709ae48bcc000a","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/64cdf7d30ac18e43df6c48004435febb965809a8","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/728f479dc0447ae7eaef87926ff49142e415a811","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/a597a722fb71a534138c20359b655726622b5f17","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/b33b44250d57ab0e5a1e2571b5285fb0d0a7f382","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/ca7c92d9701249e6daf132087756a88cbf2bb2a3","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/cce42014415cecd98aa49b3950e7b02ee7c81268","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-72351","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:22:08.520","lastModified":"2026-08-15T06:22:08.520","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\ngue: validate REMCSUM private option length\n\nGUE private flags can indicate that remote checksum offload metadata is\npresent. The private flags field itself is accounted for by\nguehdr_flags_len(), but guehdr_priv_flags_len() currently returns 0 even\nwhen GUE_PFLAG_REMCSUM is set.\n\nThis lets a packet with only the private flags field pass\nvalidate_gue_flags(), after which gue_remcsum() and gue_gro_remcsum()\nread the missing REMCSUM start/offset fields from the following bytes.\n\nAccount for GUE_PLEN_REMCSUM when GUE_PFLAG_REMCSUM is present so that\nmalformed packets are rejected during option validation."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["include/net/gue.h"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"c1aa8347e73e4092411fbd96cc59531fb7e76d04","lessThan":"158b9995d3c87f3b93f5c22df54a12e12a3438b3","versionType":"git","status":"affected"},{"version":"c1aa8347e73e4092411fbd96cc59531fb7e76d04","lessThan":"7c6876ec1b227261b51803f784c7be1b2242a1a0","versionType":"git","status":"affected"},{"version":"c1aa8347e73e4092411fbd96cc59531fb7e76d04","lessThan":"2c4de9988e9ddc760b750d6b6e701c35ff60ad14","versionType":"git","status":"affected"},{"version":"c1aa8347e73e4092411fbd96cc59531fb7e76d04","lessThan":"2a99224c120823987e4d829726f4ecb33e03fc1e","versionType":"git","status":"affected"},{"version":"c1aa8347e73e4092411fbd96cc59531fb7e76d04","lessThan":"61e78679c7c9ca685bff58e4b6348304dc60aafd","versionType":"git","status":"affected"},{"version":"c1aa8347e73e4092411fbd96cc59531fb7e76d04","lessThan":"4a4a1d41c6e901e773bcf795f562a47fa71f692a","versionType":"git","status":"affected"},{"version":"c1aa8347e73e4092411fbd96cc59531fb7e76d04","lessThan":"f618cbe9b24cd0202004d2db781d5f80ab77037f","versionType":"git","status":"affected"},{"version":"c1aa8347e73e4092411fbd96cc59531fb7e76d04","lessThan":"d335dcc6f521571d57117b8deeebc940836e5450","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["include/net/gue.h"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"3.19","status":"affected"},{"version":"0","lessThan":"3.19","versionType":"semver","status":"unaffected"},{"version":"5.10.261","lessThanOrEqual":"5.10.*","versionType":"semver","status":"unaffected"},{"version":"5.15.212","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.178","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.97","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc3","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/158b9995d3c87f3b93f5c22df54a12e12a3438b3","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/2a99224c120823987e4d829726f4ecb33e03fc1e","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/2c4de9988e9ddc760b750d6b6e701c35ff60ad14","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/4a4a1d41c6e901e773bcf795f562a47fa71f692a","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/61e78679c7c9ca685bff58e4b6348304dc60aafd","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/7c6876ec1b227261b51803f784c7be1b2242a1a0","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/d335dcc6f521571d57117b8deeebc940836e5450","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/f618cbe9b24cd0202004d2db781d5f80ab77037f","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-72352","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:22:08.633","lastModified":"2026-08-15T06:22:08.633","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nHID: bpf: Fix hid_bpf_get_data() range check\n\nhid_bpf_get_data() returns a pointer into the HID-BPF context data when\nthe caller-provided offset and size fit inside ctx->allocated_size.\n\nThe current check adds rdwr_buf_size and offset before comparing the\nresult against ctx->allocated_size. Since both values are unsigned, a\nvery large size can wrap the sum below ctx->allocated_size and make the\nhelper return a pointer even though the requested range is not contained\nin the backing buffer.\n\nUse check_add_overflow() to reject wrapped range ends before comparing\nthe requested range end against ctx->allocated_size."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/hid/bpf/hid_bpf_dispatch.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"658ee5a64fcfbbf758447fa3af425729eaabb0dc","lessThan":"ca373549140dfb386aa2de38364b58441b1f4885","versionType":"git","status":"affected"},{"version":"658ee5a64fcfbbf758447fa3af425729eaabb0dc","lessThan":"61a959b82f1aecd6d2d35c208013dd077cac9d10","versionType":"git","status":"affected"},{"version":"658ee5a64fcfbbf758447fa3af425729eaabb0dc","lessThan":"f81bc5a709dcbaf2a3bbef4ca7167f93900cc39f","versionType":"git","status":"affected"},{"version":"658ee5a64fcfbbf758447fa3af425729eaabb0dc","lessThan":"2d044049421dd48212b28646a850749d4a2d57fa","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/hid/bpf/hid_bpf_dispatch.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.3","status":"affected"},{"version":"0","lessThan":"6.3","versionType":"semver","status":"unaffected"},{"version":"6.12.97","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc3","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/2d044049421dd48212b28646a850749d4a2d57fa","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/61a959b82f1aecd6d2d35c208013dd077cac9d10","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/ca373549140dfb386aa2de38364b58441b1f4885","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/f81bc5a709dcbaf2a3bbef4ca7167f93900cc39f","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-72353","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:22:08.730","lastModified":"2026-08-15T06:22:08.730","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nntfs: avoid stale runlist element dereference in fallocate\n\nntfs_attr_fallocate() allocates holes and delayed allocations inside\ninitialized size by looking up the current runlist element under\nni->runlist.lock. The returned struct runlist_element is only a borrowed\npointer into ni->runlist.rl. A writer can replace and free that array\nafter the read lock is dropped, so later reads of rl->lcn, rl->length and\nrl->vcn can touch freed memory.\n\nThe buggy scenario involves two paths, with each column showing the order\nwithin that path:\n\nntfs_attr_fallocate():\n  1. Take ni->runlist.lock for read.\n  2. Get rl from ntfs_attr_find_vcn_nolock().\n  3. Drop ni->runlist.lock.\n  4. Read rl->lcn, rl->length and rl->vcn.\n\nmmap page_mkwrite:\n  1. Enter ntfs_filemap_page_mkwrite().\n  2. Reach __ntfs_write_iomap_begin() and ntfs_attr_map_cluster().\n  3. Merge allocation state with ntfs_runlists_merge().\n  4. Reallocate ni->runlist.rl in ntfs_rl_realloc(), freeing the old array.\n\nValidation reproduced this kernel report:\nBUG: KASAN: slab-use-after-free in ntfs_attr_fallocate+0xbb8/0xd00\n\nCall Trace:\n <TASK>\n dump_stack_lvl+0x66/0xa0\n print_report+0xce/0x630\n ? ntfs_attr_fallocate+0xbb8/0xd00\n ? srso_alias_return_thunk+0x5/0xfbef5\n ? __virt_addr_valid+0x20d/0x410\n ? ntfs_attr_fallocate+0xbb8/0xd00\n kasan_report+0xe0/0x110\n ? ntfs_attr_fallocate+0xbb8/0xd00\n ntfs_attr_fallocate+0xbb8/0xd00\n ? lock_acquire+0x2b8/0x2f0\n ? __pfx_ntfs_attr_fallocate+0x10/0x10\n ? 0xffffffffc0000095\n ? down_write+0x10d/0x1e0\n ntfs_fallocate+0x5c9/0x1d00\n ? __pfx_ntfs_fallocate+0x10/0x10\n ? srso_alias_return_thunk+0x5/0xfbef5\n ? lock_acquire+0x2b8/0x2f0\n ? srso_alias_return_thunk+0x5/0xfbef5\n ? selinux_file_permission+0x3a7/0x510\n vfs_fallocate+0x29d/0xd30\n __x64_sys_fallocate+0xc7/0x150\n ? do_syscall_64+0x81/0x6a0\n do_syscall_64+0x115/0x6a0\n entry_SYSCALL_64_after_hwframe+0x77/0x7f\n\nAllocated by task 410:\n kasan_save_stack+0x33/0x60\n kasan_save_track+0x14/0x30\n __kasan_kmalloc+0xaa/0xb0\n __kvmalloc_node_noprof+0x353/0x920\n ntfs_rl_realloc+0x3f/0x110\n ntfs_runlists_merge+0xaa3/0x3010\n ntfs_attr_map_cluster+0x4e5/0xf80\n ntfs_attr_fallocate+0x53f/0xd00\n ntfs_fallocate+0x5c9/0x1d00\n vfs_fallocate+0x29d/0xd30\n __x64_sys_fallocate+0xc7/0x150\n do_syscall_64+0x115/0x6a0\n entry_SYSCALL_64_after_hwframe+0x77/0x7f\n\nFreed by task 424:\n kasan_save_stack+0x33/0x60\n kasan_save_track+0x14/0x30\n kasan_save_free_info+0x3b/0x60\n __kasan_slab_free+0x5f/0x80\n kfree+0x307/0x580\n ntfs_rl_realloc+0x6f/0x110\n ntfs_runlists_merge+0x7b1/0x3010\n ntfs_attr_map_cluster+0x4e5/0xf80\n __ntfs_write_iomap_begin+0x8cd/0x2280\n iomap_iter+0x6de/0x11e0\n iomap_page_mkwrite+0x391/0x650\n ntfs_filemap_page_mkwrite+0x1ac/0x400\n do_page_mkwrite+0x15c/0x280\n __handle_mm_fault+0xd6d/0x1ca0\n handle_mm_fault+0x19c/0x470\n do_user_addr_fault+0x23b/0x9c0\n exc_page_fault+0x5c/0xc0\n asm_exc_page_fault+0x26/0x30\n\nFix this by copying the needed runlist fields while the read lock is still\nheld and using only those scalar snapshots after unlocking.\n\nAfter the snapshot, ntfs_attr_map_cluster() can also find that the range\nis already mapped and return balloc=false. Only call ntfs_dio_zero_range()\nwhen new clusters were allocated, matching the write iomap path and\npreserving the zero-newly-allocated-holes behavior."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["fs/ntfs/attrib.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"495e90fa334828d4119061e2726af51d0a0fb4ed","lessThan":"3dd3e43f17cda174009a51fe668046ed7afef46a","versionType":"git","status":"affected"},{"version":"495e90fa334828d4119061e2726af51d0a0fb4ed","lessThan":"88496c4ac5a6ade75619f4b1015706a8b924d50a","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["fs/ntfs/attrib.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"7.1","status":"affected"},{"version":"0","lessThan":"7.1","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc3","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/3dd3e43f17cda174009a51fe668046ed7afef46a","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/88496c4ac5a6ade75619f4b1015706a8b924d50a","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-72354","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:22:08.840","lastModified":"2026-08-15T06:22:08.840","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nntfs: avoid stale runlist element dereference in MFT writeback\n\nntfs_write_mft_block() maps each $MFT record through the $MFT data\nrunlist. For sub-folio clusters it looks up a struct runlist_element under\nni->runlist.lock, drops the lock, and later uses rl->length and rl->vcn\nwhen choosing folio_sz.\n\nThat pointer is only borrowed from ni->runlist.rl. Concurrent $MFT\nallocation extension can merge a replacement runlist under the same lock,\nand ntfs_rl_realloc() can free the old backing array. If that happens\nbetween the lookup and the later folio_sz decision, writeback can\ndereference freed runlist storage.\n\nThe buggy scenario involves two paths, with each column showing the order\nwithin that path:\n\nMFT writeback path:               $MFT allocation extension:\n1. Look up rl under               1. Extend the $MFT data allocation.\n   ni->runlist.lock.              2. Publish a replacement runlist.\n2. Drop ni->runlist.lock.         3. Free the old runlist array.\n3. Read rl->length and rl->vcn\n   to choose folio_sz.\n\nCompute the remaining run length while ni->runlist.lock is still held, and\nuse that scalar after unlock. This preserves the existing folio sizing\ndecision without carrying a borrowed runlist_element across the lock\nboundary.\n\nValidation reproduced this kernel report:\nBUG: KASAN: slab-use-after-free in ntfs_mft_writepages+0x1c8d/0x1fb0\n\nCall Trace:\n <TASK>\n dump_stack_lvl+0x66/0xa0\n print_report+0xce/0x630\n ? ntfs_mft_writepages+0x1c8d/0x1fb0\n ? srso_alias_return_thunk+0x5/0xfbef5\n ? __virt_addr_valid+0x20d/0x410\n ? ntfs_mft_writepages+0x1c8d/0x1fb0\n kasan_report+0xe0/0x110\n ? ntfs_mft_writepages+0x1c8d/0x1fb0\n ntfs_mft_writepages+0x1c8d/0x1fb0\n ? __pfx_ntfs_mft_writepages+0x10/0x10\n ? __pfx___mutex_unlock_slowpath+0x10/0x10\n ? srso_alias_return_thunk+0x5/0xfbef5\n ? iput+0x92/0xa80\n do_writepages+0x219/0x530\n ? __pfx_do_writepages+0x10/0x10\n __writeback_single_inode+0x117/0xf50\n ? do_raw_spin_lock+0x130/0x270\n ? __pfx_do_raw_spin_lock+0x10/0x10\n ? __pfx___writeback_single_inode+0x10/0x10\n ? srso_alias_return_thunk+0x5/0xfbef5\n writeback_sb_inodes+0x65b/0x1810\n ? srso_alias_return_thunk+0x5/0xfbef5\n ? lock_acquire+0x2b8/0x2f0\n ? __pfx_writeback_sb_inodes+0x10/0x10\n ? lock_release+0x1e0/0x280\n ? _raw_spin_unlock+0x23/0x40\n ? move_expired_inodes+0x2b8/0x850\n __writeback_inodes_wb+0xf4/0x270\n ? __pfx___writeback_inodes_wb+0x10/0x10\n ? srso_alias_return_thunk+0x5/0xfbef5\n ? queue_io+0x2e4/0x410\n wb_writeback+0x666/0x880\n ? srso_alias_return_thunk+0x5/0xfbef5\n ? __pfx_wb_writeback+0x10/0x10\n ? srso_alias_return_thunk+0x5/0xfbef5\n ? srso_alias_return_thunk+0x5/0xfbef5\n ? get_nr_dirty_inodes+0x1c/0x170\n wb_workfn+0x75e/0xbb0\n ? srso_alias_return_thunk+0x5/0xfbef5\n ? _raw_spin_unlock_irqrestore+0x27/0x60\n ? __pfx_wb_workfn+0x10/0x10\n ? __pfx_debug_object_deactivate+0x10/0x10\n ? lock_acquire+0x2b8/0x2f0\n ? srso_alias_return_thunk+0x5/0xfbef5\n ? lock_release+0x1e0/0x280\n process_one_work+0x8d0/0x1870\n ? __pfx_process_one_work+0x10/0x10\n ? srso_alias_return_thunk+0x5/0xfbef5\n worker_thread+0x575/0xf80\n ? __pfx_worker_thread+0x10/0x10\n kthread+0x2e7/0x3c0\n ? __pfx_kthread+0x10/0x10\n ret_from_fork+0x576/0x810\n ? __pfx_ret_from_fork+0x10/0x10\n ? srso_alias_return_thunk+0x5/0xfbef5\n ? __switch_to+0x57e/0xe10\n ? __switch_to_asm+0x33/0x70\n ? __pfx_kthread+0x10/0x10\n ret_from_fork_asm+0x1a/0x30\n </TASK>\n\nAllocated by task 970:\n kasan_save_stack+0x33/0x60\n kasan_save_track+0x14/0x30\n __kasan_kmalloc+0xaa/0xb0\n __kvmalloc_node_noprof+0x353/0x920\n ntfs_rl_realloc+0x3c/0x80\n ntfs_runlists_merge+0x1212/0x3010\n ntfs_mft_data_extend_allocation_nolock+0x3e0/0x1f40\n ntfs_mft_record_alloc+0x1ab4/0x4f10\n __ntfs_create+0x680/0x2e50\n ntfs_create+0x1e6/0x3a0\n path_openat+0x2b55/0x3c10\n do_file_open+0x1f4/0x460\n do_sys_openat2+0xde/0x170\n __x64_sys_openat+0x122/0x1e0\n do_syscall_64+0x115/0x6a0\n entry_SYSCALL_64_after_hwframe+0x77/0x7f\n\nFreed by task 1294:\n kasan_save_\n---truncated---"}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["fs/ntfs/mft.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"115380f9a2f9675c7924563cbba70d40cae8fb81","lessThan":"9a2e36963a3fc52401586657d34e3f1c5a01ea56","versionType":"git","status":"affected"},{"version":"115380f9a2f9675c7924563cbba70d40cae8fb81","lessThan":"81fe702ff1760da32bcd3ef4494b2a33dbeced72","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["fs/ntfs/mft.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"7.1","status":"affected"},{"version":"0","lessThan":"7.1","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc3","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/81fe702ff1760da32bcd3ef4494b2a33dbeced72","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/9a2e36963a3fc52401586657d34e3f1c5a01ea56","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-72355","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:22:08.960","lastModified":"2026-08-15T06:22:08.960","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nnetfs: Fix barriering when walking subrequest list\n\nFix the barriering used when walking the subrequest list in retry as\nthere's a possibility of seeing a subreq that's just been added by the\napplication thread."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["fs/netfs/read_retry.c","fs/netfs/write_retry.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"288ace2f57c9d06dd2e42bd80d03747d879a4068","lessThan":"be47c047250671c9225c0319ca4695be9b391c59","versionType":"git","status":"affected"},{"version":"288ace2f57c9d06dd2e42bd80d03747d879a4068","lessThan":"5c6ce05e406520290c1d89da97fb3cd70c09137d","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["fs/netfs/read_retry.c","fs/netfs/write_retry.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.10","status":"affected"},{"version":"0","lessThan":"6.10","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc2","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/5c6ce05e406520290c1d89da97fb3cd70c09137d","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/be47c047250671c9225c0319ca4695be9b391c59","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-72356","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:22:09.053","lastModified":"2026-08-15T06:22:09.053","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\ncifs: Fix missing credit release on failure in cifs_issue_read()\n\nFix missing release of credits in the failure path in cifs_issue_read()\nlest retrying the subreq just overwrites the credits value."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["fs/smb/client/file.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"69c3c023af25edb5433a2db824d3e7cc328f0183","lessThan":"b9ee1f0347bf56d019ca28ddff090234bb45b05c","versionType":"git","status":"affected"},{"version":"69c3c023af25edb5433a2db824d3e7cc328f0183","lessThan":"86652704a7fd41a5a8459027e08640bbd1952826","versionType":"git","status":"affected"},{"version":"69c3c023af25edb5433a2db824d3e7cc328f0183","lessThan":"3a303f985c6bec8787c2ad4a16b39c14c5bcd765","versionType":"git","status":"affected"},{"version":"69c3c023af25edb5433a2db824d3e7cc328f0183","lessThan":"c16b8c4cfb4fe2244cc33e469a93c1ab8684146b","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["fs/smb/client/file.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.10","status":"affected"},{"version":"0","lessThan":"6.10","versionType":"semver","status":"unaffected"},{"version":"6.12.97","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc2","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/3a303f985c6bec8787c2ad4a16b39c14c5bcd765","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/86652704a7fd41a5a8459027e08640bbd1952826","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/b9ee1f0347bf56d019ca28ddff090234bb45b05c","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/c16b8c4cfb4fe2244cc33e469a93c1ab8684146b","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-72357","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:22:09.147","lastModified":"2026-08-15T06:22:09.147","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nuprobes/x86: Use proper mm_struct in __in_uprobe_trampoline\n\nIn the unregister path we use __in_uprobe_trampoline check with\ncurrent->mm for the VMA lookup, which is wrong, because we are\nin the tracer context, not the traced process.\n\nAdd mm_struct pointer argument to __in_uprobe_trampoline and\nchanging related callers to pass proper mm_struct pointer."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["arch/x86/kernel/uprobes.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"ba2bfc97b4629b10bd8d02b36e04f3932a04cac4","lessThan":"c9170c83b0e0fc2065a4c2bca5bf1f90c5880156","versionType":"git","status":"affected"},{"version":"ba2bfc97b4629b10bd8d02b36e04f3932a04cac4","lessThan":"1acddd3e22dd6912dd5d54f80462405a1f1e6bae","versionType":"git","status":"affected"},{"version":"ba2bfc97b4629b10bd8d02b36e04f3932a04cac4","lessThan":"169328645663bae30e9abad4012d52441e085a71","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["arch/x86/kernel/uprobes.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.18","status":"affected"},{"version":"0","lessThan":"6.18","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc2","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/169328645663bae30e9abad4012d52441e085a71","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/1acddd3e22dd6912dd5d54f80462405a1f1e6bae","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/c9170c83b0e0fc2065a4c2bca5bf1f90c5880156","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-72358","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:22:09.243","lastModified":"2026-08-15T06:22:09.243","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/xe/pt: prevent invalid cursor access for purged BOs\n\nDuring a page table walk for binding, xe_pt_stage_bind() explicitly\nskips initializing the xe_res_cursor for purged BOs, treating them\nsimilarly to NULL VMAs by only setting the cursor size.\n\nHowever, xe_pt_hugepte_possible() and xe_pt_scan_64K() did not check\nif the BO was purged before attempting to walk the cursor using\nxe_res_dma() and xe_res_next(). Because the cursor was left\nuninitialized for purged BOs, this falls through and triggers\nwarnings like:\n\n  WARNING: drivers/gpu/drm/xe/xe_res_cursor.h:274 at xe_res_next\n\nFix this by explicitly checking if the BO is purged in both\nxe_pt_hugepte_possible() and xe_pt_scan_64K(), returning early just\nas we do for NULL VMAs, avoiding the invalid cursor accesses entirely.\n\nAs a precaution, also zero-initialize the cursor in xe_pt_stage_bind()\nto ensure we don't pass garbage data into the page table walkers\nif we ever hit a similar edge case in the future.\n\n(cherry picked from commit 4c7b9c6ece32440e5a435a92076d049450cd2d2e)"}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/gpu/drm/xe/xe_pt.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"ad9843aac91a1eda12912a4922042ea04cfc29dc","lessThan":"2b6b3f98d0e93856bee38699b783c71cb0e9d67f","versionType":"git","status":"affected"},{"version":"ad9843aac91a1eda12912a4922042ea04cfc29dc","lessThan":"8a0fb57675be578c4db19deb4298ed08a70f0f1a","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/gpu/drm/xe/xe_pt.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"7.1","status":"affected"},{"version":"0","lessThan":"7.1","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc2","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/2b6b3f98d0e93856bee38699b783c71cb0e9d67f","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/8a0fb57675be578c4db19deb4298ed08a70f0f1a","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-72359","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:22:09.337","lastModified":"2026-08-15T06:22:09.337","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/xe: fix NPD in bo_meminfo()\n\nWhen a buffer object is purged, its ttm.resource is set to NULL via the\nTTM pipeline gutting flow. However, the BO remains in the client's\nobject list until userspace explicitly closes the GEM handle. If memory\nstats are queried during this time, accessing bo->ttm.resource->mem_type\nwill result in a NULL pointer dereference.\n\nFix this by safely skipping purged BOs in bo_meminfo, as they no longer\nconsume any memory.\n\nUser is getting NPD on device resume, and possible theory is that in\nbo_move(), if we need to evict something to SYSTEM to save the CCS state,\nbut the BO is marked as dontneed, this won't trigger a move but will\nnuke the pages, leaving us with a NULL bo resource. And the meminfo()\ndoesn't look ready to handle a NULL resource.\n\nv2 (Sashiko):\n - There could potentially be other cases where we might end up with a\n   NULL resource, so make this a general NULL check for now.\n\n(cherry picked from commit c9a8e7daa0afe3161111e27fd92176e608c7f186)"}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/gpu/drm/xe/xe_drm_client.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"ad9843aac91a1eda12912a4922042ea04cfc29dc","lessThan":"5ff2212f0e0779b0b0cbf91fbf970144107c4257","versionType":"git","status":"affected"},{"version":"ad9843aac91a1eda12912a4922042ea04cfc29dc","lessThan":"b5c55015d4164a0f206bcdcf2985da948b3c7837","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/gpu/drm/xe/xe_drm_client.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"7.1","status":"affected"},{"version":"0","lessThan":"7.1","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc2","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/5ff2212f0e0779b0b0cbf91fbf970144107c4257","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/b5c55015d4164a0f206bcdcf2985da948b3c7837","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-72360","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:22:09.430","lastModified":"2026-08-15T06:22:09.430","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/xe/pf: Don't attempt to process FAST_REQ or EVENT relays\n\nCurrently defined VF/PF relay actions use regular REQUEST messages\nonly and the PF shouldn't attempt to handle FAST_REQUEST nor EVENT\nmessages as this would result in breaking the VFPF ABI protocol\nand also might trigger an assert on the PF side.\n\n(cherry picked from commit 1714d360fc5ae2e0886a69e979095d9c7ff3568a)"}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/gpu/drm/xe/xe_guc_relay.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"98e62805921cebcd2fcac3692037ca2ebef63b4a","lessThan":"499be4b5d64209e9f18c9442f9fbeef7155ae900","versionType":"git","status":"affected"},{"version":"98e62805921cebcd2fcac3692037ca2ebef63b4a","lessThan":"adc7dda728ca3e340a413e3bbc10cf159e1866a4","versionType":"git","status":"affected"},{"version":"98e62805921cebcd2fcac3692037ca2ebef63b4a","lessThan":"a4208d8032abd7f591581994f31e23b80b8fe659","versionType":"git","status":"affected"},{"version":"98e62805921cebcd2fcac3692037ca2ebef63b4a","lessThan":"ed8b0d731892c68b41ecbd27c952af284816dec1","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/gpu/drm/xe/xe_guc_relay.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.11","status":"affected"},{"version":"0","lessThan":"6.11","versionType":"semver","status":"unaffected"},{"version":"6.12.97","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc2","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/499be4b5d64209e9f18c9442f9fbeef7155ae900","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/a4208d8032abd7f591581994f31e23b80b8fe659","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/adc7dda728ca3e340a413e3bbc10cf159e1866a4","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/ed8b0d731892c68b41ecbd27c952af284816dec1","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-72361","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:22:09.530","lastModified":"2026-08-15T06:22:09.530","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/xe/hw_engine: Fix double-free of managed BO in error path\n\nThe error path in hw_engine_init() explicitly frees a BO allocated\nwith xe_managed_bo_create_pin_map() via xe_bo_unpin_map_no_vm().\nSince the managed BO already has a devm cleanup action registered,\nthis causes a double-free when devm unwinds during probe failure.\n\nRemove the explicit free and let devm handle it, consistent with\nall other xe_managed_bo_create_pin_map() callers.\n\n(cherry picked from commit e459a3bdeb117be496d7f229e2ea1f6c9fe4080b)"}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/gpu/drm/xe/xe_hw_engine.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"0e1a47fcabc8ffa6f460c60c2caa04e51170fa22","lessThan":"1f6b44d555ecce61e249220f2ca4d75cdb90caf6","versionType":"git","status":"affected"},{"version":"0e1a47fcabc8ffa6f460c60c2caa04e51170fa22","lessThan":"a0a56b4480a0dc921a42cd70e9fc081a12ab8359","versionType":"git","status":"affected"},{"version":"0e1a47fcabc8ffa6f460c60c2caa04e51170fa22","lessThan":"23ee91355e31947595b86ebb9ef4664f20fd926d","versionType":"git","status":"affected"},{"version":"0e1a47fcabc8ffa6f460c60c2caa04e51170fa22","lessThan":"7ac3cae7a251d28e9079de07a991bd4eb2bb7fd8","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/gpu/drm/xe/xe_hw_engine.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.8","status":"affected"},{"version":"0","lessThan":"6.8","versionType":"semver","status":"unaffected"},{"version":"6.12.97","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc2","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/1f6b44d555ecce61e249220f2ca4d75cdb90caf6","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/23ee91355e31947595b86ebb9ef4664f20fd926d","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/7ac3cae7a251d28e9079de07a991bd4eb2bb7fd8","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/a0a56b4480a0dc921a42cd70e9fc081a12ab8359","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-72362","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:22:09.627","lastModified":"2026-08-15T06:22:09.627","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/xe/pt: Fix NULL pointer dereference in xe_pt_zap_ptes_entry()\n\nThe page-table walk framework may pass a NULL *child pointer for\nunpopulated entries. xe_pt_zap_ptes_entry() called container_of(*child)\nbefore checking for NULL, then dereferenced the result, causing a crash.\n\nMove the container_of() call after a NULL guard, so the function returns\nearly instead of proceeding with an invalid pointer. XE_WARN_ON is kept\nto help root cause the issue, but we now bail instead of crashing the\ndriver.\n\nv2: Comment that triggering XE_WARN_ON is unexpected behavior (Matt Brost)\n\n(cherry picked from commit b9297d19d9df5d4b6c994648570c5dcd1cac68ff)"}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/gpu/drm/xe/xe_pt.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"dd08ebf6c3525a7ea2186e636df064ea47281987","lessThan":"ff330ce16c846b70164ff0eb544c81219d4c5c08","versionType":"git","status":"affected"},{"version":"dd08ebf6c3525a7ea2186e636df064ea47281987","lessThan":"78b1074966d290d4517f42bc81e13c4349368d12","versionType":"git","status":"affected"},{"version":"dd08ebf6c3525a7ea2186e636df064ea47281987","lessThan":"d94b9922b2ae5ee6e900f8da0bd537b251c6110c","versionType":"git","status":"affected"},{"version":"dd08ebf6c3525a7ea2186e636df064ea47281987","lessThan":"3feeb667197bd58a17f4edfdbcad249ffcb3c864","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/gpu/drm/xe/xe_pt.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.8","status":"affected"},{"version":"0","lessThan":"6.8","versionType":"semver","status":"unaffected"},{"version":"6.12.97","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc2","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/3feeb667197bd58a17f4edfdbcad249ffcb3c864","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/78b1074966d290d4517f42bc81e13c4349368d12","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/d94b9922b2ae5ee6e900f8da0bd537b251c6110c","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/ff330ce16c846b70164ff0eb544c81219d4c5c08","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-72363","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:22:09.723","lastModified":"2026-08-15T06:22:09.723","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nnetfs: Fix folio state after ENOMEM whilst under writeback iteration\n\nFix the state of the current folio when ENOMEM occurs during writeback\niteration.  The folio needs to be redirtied and unlocked before the\nterminal writeback_iter() is invoked."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["fs/netfs/write_issue.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"06fa229ceb36898e68022b5654c017d2c6582d7d","lessThan":"a9b89752c2726e88ea67994fb97a0316b24d30b7","versionType":"git","status":"affected"},{"version":"06fa229ceb36898e68022b5654c017d2c6582d7d","lessThan":"1a4421c7a5611db554328f721a4f7642440b44bd","versionType":"git","status":"affected"},{"version":"06fa229ceb36898e68022b5654c017d2c6582d7d","lessThan":"b6a713fd34b9498ee2164d5d3e8460732a392efc","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["fs/netfs/write_issue.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.14","status":"affected"},{"version":"0","lessThan":"6.14","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc2","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/1a4421c7a5611db554328f721a4f7642440b44bd","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/a9b89752c2726e88ea67994fb97a0316b24d30b7","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/b6a713fd34b9498ee2164d5d3e8460732a392efc","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-72364","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:22:09.823","lastModified":"2026-08-15T06:22:09.823","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nnetfs: Fix writeback error handling\n\nFix the error handling in writeback_iter() loop.  If an error occurs,\nwriteback_iter() needs to be called again with *error set to the error so\nthat it can clean up iteration state.  Further, the current folio needs\nunlocking and redirtying."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["fs/netfs/write_issue.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"288ace2f57c9d06dd2e42bd80d03747d879a4068","lessThan":"fb39ffd3cc5422887fd118668ff45ebfdbc83302","versionType":"git","status":"affected"},{"version":"288ace2f57c9d06dd2e42bd80d03747d879a4068","lessThan":"1bb33d959aabcde07d724b5eb9992462e91fa79a","versionType":"git","status":"affected"},{"version":"288ace2f57c9d06dd2e42bd80d03747d879a4068","lessThan":"89df9c158a25d0a7c6ca079a9bd9ca7009d75c7b","versionType":"git","status":"affected"},{"version":"288ace2f57c9d06dd2e42bd80d03747d879a4068","lessThan":"ac5f95ac5d6d0f4c567b8b642825705a2bf0d79e","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["fs/netfs/write_issue.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.10","status":"affected"},{"version":"0","lessThan":"6.10","versionType":"semver","status":"unaffected"},{"version":"6.12.97","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc2","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/1bb33d959aabcde07d724b5eb9992462e91fa79a","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/89df9c158a25d0a7c6ca079a9bd9ca7009d75c7b","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/ac5f95ac5d6d0f4c567b8b642825705a2bf0d79e","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/fb39ffd3cc5422887fd118668ff45ebfdbc83302","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-72365","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:22:09.923","lastModified":"2026-08-15T06:22:09.923","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nnetfs: Fix writethrough to use collection offload\n\nFix writethrough write to set NETFS_RREQ_OFFLOAD_COLLECTION on the request\nso that collection is processed asynchronously rather than only right at\nthe end - and also so that asynchronous O_SYNC writes get collected at all."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["fs/netfs/write_issue.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"288ace2f57c9d06dd2e42bd80d03747d879a4068","lessThan":"7838131e296dfbb639ea278901a53c018322c11e","versionType":"git","status":"affected"},{"version":"288ace2f57c9d06dd2e42bd80d03747d879a4068","lessThan":"0348e3fa0dfbf152af687e86ce079742b1860da9","versionType":"git","status":"affected"},{"version":"288ace2f57c9d06dd2e42bd80d03747d879a4068","lessThan":"ba6a9f6533c77c628eef0c0c5c19cd316e2be1b4","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["fs/netfs/write_issue.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.10","status":"affected"},{"version":"0","lessThan":"6.10","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc2","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/0348e3fa0dfbf152af687e86ce079742b1860da9","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/7838131e296dfbb639ea278901a53c018322c11e","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/ba6a9f6533c77c628eef0c0c5c19cd316e2be1b4","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-72366","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:22:10.017","lastModified":"2026-08-15T06:22:10.017","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nnetfs: Fix netfs_create_write_req() to handle async cache object creation\n\nnetfs_create_write_req() will skip caching if the fscache cookie is\ndisabled, but this is a problem because async cache object creation might\nnot have got far enough yet that has been enabled - thereby causing the\ncall to fscache_begin_write_operation() to be skipped.\n\nFix this by removing the checks on the cookie and delegating this to\nfscache_begin_write_operation()."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["fs/netfs/write_issue.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"7b589a9b45ae32aa9d7bece597490e141198d7a6","lessThan":"8ab75e445c161c4cb504aa98e20ce1dd1ecd8e9a","versionType":"git","status":"affected"},{"version":"7b589a9b45ae32aa9d7bece597490e141198d7a6","lessThan":"1188a9846fadeacf9d1430b528e5217f749d665b","versionType":"git","status":"affected"},{"version":"7b589a9b45ae32aa9d7bece597490e141198d7a6","lessThan":"dbd6f56d975b23241b7bbb11bb8f562af548a0aa","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["fs/netfs/write_issue.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.11","status":"affected"},{"version":"0","lessThan":"6.11","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc2","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/1188a9846fadeacf9d1430b528e5217f749d665b","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/8ab75e445c161c4cb504aa98e20ce1dd1ecd8e9a","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/dbd6f56d975b23241b7bbb11bb8f562af548a0aa","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-72367","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:22:10.117","lastModified":"2026-08-15T06:22:10.117","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\niomap: guard io_size EOF trim against concurrent truncate underflow\n\niomap: fix zero padding data issue in concurrent append writes\nchanged ioend accounting so that io_size tracks only valid data\nwithin EOF.  This trims io_size when a writeback range extends\npast end_pos:\n\n    ioend->io_size += map_len;\n    if (ioend->io_offset + ioend->io_size > end_pos)\n        ioend->io_size = end_pos - ioend->io_offset;\n\nHowever, if end_pos ends up below ioend->io_offset, the subtraction\nbecomes negative and is stored in size_t io_size, causing an unsigned\nwrap to a huge value.  This can happen when writeback continues past\nbyte-level EOF up to a block-aligned range, or when a concurrent\ntruncate shrinks the file after end_pos was sampled in\niomap_writeback_handle_eof().\n\nA wrapped io_size can mislead append detection and corrupt\ncompletion-time size handling, since filesystem end_io paths consume\nio_size for decisions such as on-disk EOF updates and unwritten/COW\ncompletion ranges.\n\nFix this by clamping io_size to zero when EOF has moved to or before\nthe ioend start offset.  This preserves the original intent of trimming\nio_size to valid in-EOF data while avoiding the underflow."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["fs/iomap/ioend.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"51d20d1dacbec589d459e11fc88fbca419f84a99","lessThan":"1f38f65bf965fce9aa159d45c5347538f56c5973","versionType":"git","status":"affected"},{"version":"51d20d1dacbec589d459e11fc88fbca419f84a99","lessThan":"7f7780abb4c0fdc9a2603aea8e985ff14ee900e0","versionType":"git","status":"affected"},{"version":"51d20d1dacbec589d459e11fc88fbca419f84a99","lessThan":"55ec50d046c03b3724741957f7b007856e36dbe7","versionType":"git","status":"affected"},{"version":"82c59a86a247a8970d353d10f52a37e5564fb137","versionType":"git","status":"affected"},{"version":"6.12.10","lessThan":"6.13","versionType":"semver","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["fs/iomap/ioend.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.13","status":"affected"},{"version":"0","lessThan":"6.13","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc2","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/1f38f65bf965fce9aa159d45c5347538f56c5973","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/55ec50d046c03b3724741957f7b007856e36dbe7","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/7f7780abb4c0fdc9a2603aea8e985ff14ee900e0","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-72368","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:22:10.227","lastModified":"2026-08-15T06:22:10.227","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\ncachefiles: Fix double unlock in nomem_d_alloc error path\n\nWhen start_creating() fails and returns -ENOMEM, it has already\nreleased the parent directory lock in __start_dirop():\n\n    static struct dentry *__start_dirop(...)\n    {\n        ...\n        inode_lock_nested(dir, I_MUTEX_PARENT);\n        dentry = lookup_one_qstr_excl(name, parent, lookup_flags);\n        if (IS_ERR(dentry))\n            inode_unlock(dir);  <-- Lock released on error\n        return dentry;\n    }\n\nHowever, the nomem_d_alloc error path in cachefiles_get_directory()\nunconditionally calls inode_unlock(d_inode(dir)) again, causing a\ndouble unlock that corrupts the rwsem state.\n\nThis is a leftover from commit 7ab96df840e60 which replaced manual\nlocking with start_creating() but failed to update the nomem_d_alloc\npath (while correctly updating mkdir_error and lookup_error paths)."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["fs/cachefiles/namei.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"7ab96df840e60eb933abfe65fc5fe44e72f16dc0","lessThan":"26757dac15175f2a42e3537f1ba86e62456d48f1","versionType":"git","status":"affected"},{"version":"7ab96df840e60eb933abfe65fc5fe44e72f16dc0","lessThan":"8c256fba2b46020004201c500b2a1fbc707a33ef","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["fs/cachefiles/namei.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.19","status":"affected"},{"version":"0","lessThan":"6.19","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc2","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/26757dac15175f2a42e3537f1ba86e62456d48f1","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/8c256fba2b46020004201c500b2a1fbc707a33ef","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-72369","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:22:10.340","lastModified":"2026-08-15T06:22:10.340","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nminix: avoid overflow in bitmap block count calculation\n\nminix_check_superblock() uses minix_blocks_needed() to verify that the\non-disk imap and zmap block counts are large enough for the advertised\ninode and zone counts.\n\nThe helper currently performs DIV_ROUND_UP() in unsigned int arithmetic.\nA Minix v3 image can set s_ninodes or s_zones near UINT_MAX so the\naddition inside DIV_ROUND_UP() wraps to zero. That makes a zero imap/zmap\nblock count look valid, after which minix_fill_super() can dereference\ns_imap[0] or s_zmap[0] even though no bitmap buffers were allocated.\n\nImpact: mounting a crafted Minix v3 image whose s_ninodes or s_zones is\nnear UINT_MAX makes minix_check_superblock() accept a zero bitmap-block\ncount and minix_fill_super() dereference s_imap[0]/s_zmap[0], panicking\nthe kernel.\n\nThe divisor is the bitmap capacity in bits, blocksize * 8, which is\nalways a power of two: minix_fill_super() obtains the block size through\nsb_set_blocksize(), and blk_validate_block_size() rejects any size that\nis not a power of two. Use DIV_ROUND_UP_POW2(), which divides before\nadding the round-up term and so cannot overflow for a power-of-two\ndivisor."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["fs/minix/minix.h"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"2bb588cede1c1969e49c0a2822c8cb8b346b7682","lessThan":"a11ebaab50d27d6c4c78506f84ff36452e0b901d","versionType":"git","status":"affected"},{"version":"f57ccd4657c7f082dc47e5b9e18a883bb5f9118f","lessThan":"959c95340a9e19cd333b4c18935fdeecbb2f319d","versionType":"git","status":"affected"},{"version":"31fefc18096cdc5549cfa54964d90e0b3229aedc","lessThan":"abe3536a4bedcc43de80b6d4d7e3d57e9ba382a5","versionType":"git","status":"affected"},{"version":"8c97a6ddc95690a938ded44b4e3202f03f15078c","lessThan":"8a29e60e2176b02e04f8737c8b32b696230eb0c5","versionType":"git","status":"affected"},{"version":"8c97a6ddc95690a938ded44b4e3202f03f15078c","lessThan":"fb3e566cafc38fe3ba35e6843a2d529a3748870c","versionType":"git","status":"affected"},{"version":"a051ecf5c5b0387840dc210413ed3bc7fbdaa69c","versionType":"git","status":"affected"},{"version":"d791c544efd6b9c944b43cf7f502e5bcb02fb941","versionType":"git","status":"affected"},{"version":"66c7c239c65341f99ae388d4d53dc9df2bcb9925","versionType":"git","status":"affected"},{"version":"1efc128ee4adbc23e082715425ff895449d233bc","versionType":"git","status":"affected"},{"version":"6.6.128","lessThan":"6.6.145","versionType":"semver","status":"affected"},{"version":"6.12.75","lessThan":"6.12.97","versionType":"semver","status":"affected"},{"version":"6.18.16","lessThan":"6.18.40","versionType":"semver","status":"affected"},{"version":"5.10.252","lessThan":"5.11","versionType":"semver","status":"affected"},{"version":"5.15.202","lessThan":"5.16","versionType":"semver","status":"affected"},{"version":"6.1.165","lessThan":"6.2","versionType":"semver","status":"affected"},{"version":"6.19.6","lessThan":"6.20","versionType":"semver","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["fs/minix/minix.h"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"7.0","status":"affected"},{"version":"0","lessThan":"7.0","versionType":"semver","status":"unaffected"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.97","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc2","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/8a29e60e2176b02e04f8737c8b32b696230eb0c5","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/959c95340a9e19cd333b4c18935fdeecbb2f319d","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/a11ebaab50d27d6c4c78506f84ff36452e0b901d","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/abe3536a4bedcc43de80b6d4d7e3d57e9ba382a5","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/fb3e566cafc38fe3ba35e6843a2d529a3748870c","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-72370","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:22:10.473","lastModified":"2026-08-15T06:22:10.473","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\niomap: release pages on atomic dio size mismatch\n\nIf bio_iov_iter_get_pages() or the bounce helper succeeds but builds a\nshort bio, the REQ_ATOMIC size check rejects it before submission.  The\nold error path only dropped the bio reference, leaving any pages already\nattached to the bio unreleased.\n\nRelease or unbounce the pages before falling through to out_put_bio on\nthis error path.\n\nThis bug was reported by sashiko:\nhttps://sashiko.dev/#/patchset/20260608073134.95964-1-changfengnan%40bytedance.com"}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["fs/iomap/direct-io.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"9e0933c21c128d6d8ac4d8aae0babaf9a43100b8","lessThan":"27ddd3442fc6f698fb8577c7cfb243ddd81ea8c0","versionType":"git","status":"affected"},{"version":"9e0933c21c128d6d8ac4d8aae0babaf9a43100b8","lessThan":"681e452683b69a8e1a571cba0f238f8ceacf55d2","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["fs/iomap/direct-io.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.13","status":"affected"},{"version":"0","lessThan":"6.13","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc2","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/27ddd3442fc6f698fb8577c7cfb243ddd81ea8c0","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/681e452683b69a8e1a571cba0f238f8ceacf55d2","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-72371","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:22:10.570","lastModified":"2026-08-15T06:22:10.570","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nafs: Fix the volume AFS_VOLUME_RM_TREE is set on\n\nFix afs_insert_volume_into_cell() to set AFS_VOLUME_RM_TREE on the volume\nreplaced, not the new volume, as it's now removed from the cell's volume\ntree.  This will cause the old volume to be removed from the tree twice and\nthe new volume never to be removed."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["fs/afs/volume.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"98fb5eaade749e9d366fdd1f622d560ad68bdedd","lessThan":"6fa9a8a73e16aa22fce6e41cc00d59c767f0a540","versionType":"git","status":"affected"},{"version":"9b4c95a63e2dfe5ea73d92fb82ec34c3efa76284","lessThan":"c421bc6b957e56e45e12dbaeaf70a60db20d6465","versionType":"git","status":"affected"},{"version":"c3215484ca1f64b6b8af03847856499e5364e65a","lessThan":"1607075220cf57161d9116512994c159eacefc0d","versionType":"git","status":"affected"},{"version":"9a6b294ab496650e9f270123730df37030911b55","lessThan":"d154c20837f379343f192d4b8d9dd4ef145562e6","versionType":"git","status":"affected"},{"version":"9a6b294ab496650e9f270123730df37030911b55","lessThan":"158c5a0b1dfc0e6a419efe18404047a4d2dff59e","versionType":"git","status":"affected"},{"version":"9a6b294ab496650e9f270123730df37030911b55","lessThan":"d0c8ad418b47891a03426c5e02ebb0537f8d68f8","versionType":"git","status":"affected"},{"version":"9a6b294ab496650e9f270123730df37030911b55","lessThan":"56b4e4b26f84411d880f968a539207b0a8889c8c","versionType":"git","status":"affected"},{"version":"5.15.146","lessThan":"5.15.212","versionType":"semver","status":"affected"},{"version":"6.1.70","lessThan":"6.1.178","versionType":"semver","status":"affected"},{"version":"6.6.9","lessThan":"6.6.145","versionType":"semver","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["fs/afs/volume.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.7","status":"affected"},{"version":"0","lessThan":"6.7","versionType":"semver","status":"unaffected"},{"version":"5.15.212","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.178","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.97","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc2","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/158c5a0b1dfc0e6a419efe18404047a4d2dff59e","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/1607075220cf57161d9116512994c159eacefc0d","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/56b4e4b26f84411d880f968a539207b0a8889c8c","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/6fa9a8a73e16aa22fce6e41cc00d59c767f0a540","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/c421bc6b957e56e45e12dbaeaf70a60db20d6465","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/d0c8ad418b47891a03426c5e02ebb0537f8d68f8","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/d154c20837f379343f192d4b8d9dd4ef145562e6","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-72372","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:22:10.680","lastModified":"2026-08-15T06:22:10.680","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nafs: Fix lack of locking around modifications of net->cells_dyn_ino\n\nFix the lack of locking around modifications of net->cells_dyn_ino by\ntaking net->cells_lock exclusively.  This also requires to cell to be\nremoved from net->cells_dyn_ino in afs_destroy_cell_work() rather than in\nafs_cell_destroy() as the latter runs in RCU cleanup context and sleeping\nlocks cannot be taken there."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["fs/afs/cell.c","fs/afs/dynroot.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"537b0105952578531f748c7fb3ce36ae9a514784","lessThan":"4d8a2fe8847859f4fa4e9a2fa1221c9c1158e66b","versionType":"git","status":"affected"},{"version":"1d0b929fc070b4115403a0a6206a0c6a62dd61f5","lessThan":"2ffb70a8a01988046bb207b7d0af9358a8337378","versionType":"git","status":"affected"},{"version":"1d0b929fc070b4115403a0a6206a0c6a62dd61f5","lessThan":"e94f92fd56c553a8bf9421c3289e1b85c7c08857","versionType":"git","status":"affected"},{"version":"1d0b929fc070b4115403a0a6206a0c6a62dd61f5","lessThan":"55e841836c6f4646490f7b0347192b7a92d431ba","versionType":"git","status":"affected"},{"version":"6.12.97","lessThan":"6.12.101","versionType":"semver","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["fs/afs/cell.c","fs/afs/dynroot.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.15","status":"affected"},{"version":"0","lessThan":"6.15","versionType":"semver","status":"unaffected"},{"version":"6.12.101","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc2","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/2ffb70a8a01988046bb207b7d0af9358a8337378","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/4d8a2fe8847859f4fa4e9a2fa1221c9c1158e66b","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/55e841836c6f4646490f7b0347192b7a92d431ba","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/e94f92fd56c553a8bf9421c3289e1b85c7c08857","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-72373","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:22:10.777","lastModified":"2026-08-15T06:22:10.777","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nafs: Fix missing NULL pointer check in afs_break_some_callbacks()\n\nFix afs_break_some_callbacks() to check to see if afs_lookup_volume_rcu()\nreturned NULL (e.g. the specified volume is unknown)."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["fs/afs/callback.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"8230fd8217b7ea76f838ae88e4a5a8e54f37099f","lessThan":"a99a617701186dc68c7b330d35fc2253f48e2ab2","versionType":"git","status":"affected"},{"version":"8230fd8217b7ea76f838ae88e4a5a8e54f37099f","lessThan":"5492799ec5d27be3bd454dcaf046bc7054f637ae","versionType":"git","status":"affected"},{"version":"8230fd8217b7ea76f838ae88e4a5a8e54f37099f","lessThan":"e3e59ff22a0de01ed0cf3a3e25558811abc3b70a","versionType":"git","status":"affected"},{"version":"8230fd8217b7ea76f838ae88e4a5a8e54f37099f","lessThan":"794a01110390c1b76f59ece773fb0fbfd89c6f5c","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["fs/afs/callback.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"5.8","status":"affected"},{"version":"0","lessThan":"5.8","versionType":"semver","status":"unaffected"},{"version":"6.12.97","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc2","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/5492799ec5d27be3bd454dcaf046bc7054f637ae","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/794a01110390c1b76f59ece773fb0fbfd89c6f5c","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/a99a617701186dc68c7b330d35fc2253f48e2ab2","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/e3e59ff22a0de01ed0cf3a3e25558811abc3b70a","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-72374","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:22:10.873","lastModified":"2026-08-15T06:22:10.873","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nafs: Fix callback service message parsers to pass through -EAGAIN\n\nThe AFS filesystem client uses an rxrpc server to listen for callback\nnotifications.  Each callback call type handler has a delivery function\nthat parses the incoming request stream, and this should return -EAGAIN the\nlast packet hasn't yet been seen, but all currently queued received data is\nconsumed.  afs_extract_data() does this, but the -EAGAIN return is switched\nto 0 inadvertantly\n\nFix callback service message parsers to pass through -EAGAIN"}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["fs/afs/cmservice.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"d001648ec7cf8b21ae9eec8b9ba4a18295adfb14","lessThan":"26b737b3769e92493fe94c34620399d93ca231ae","versionType":"git","status":"affected"},{"version":"d001648ec7cf8b21ae9eec8b9ba4a18295adfb14","lessThan":"09c67a7ded481482155b836c8c7f078a3075f8de","versionType":"git","status":"affected"},{"version":"d001648ec7cf8b21ae9eec8b9ba4a18295adfb14","lessThan":"239cd337c9d047e7097f5b2ebbb41ddfb8180bc6","versionType":"git","status":"affected"},{"version":"d001648ec7cf8b21ae9eec8b9ba4a18295adfb14","lessThan":"5a39b145a8fb49f316e7ec1f29ba51d68095c7e4","versionType":"git","status":"affected"},{"version":"d001648ec7cf8b21ae9eec8b9ba4a18295adfb14","lessThan":"772850871a2e772e26f9d93f1e9ddd413b3eeaa4","versionType":"git","status":"affected"},{"version":"d001648ec7cf8b21ae9eec8b9ba4a18295adfb14","lessThan":"0acbc09d2aca0432af45cec114f20d55ceafaec4","versionType":"git","status":"affected"},{"version":"d001648ec7cf8b21ae9eec8b9ba4a18295adfb14","lessThan":"f14dd036fad3d359f26f1282199cec06b3a9362b","versionType":"git","status":"affected"},{"version":"d001648ec7cf8b21ae9eec8b9ba4a18295adfb14","lessThan":"0f36469d7ce98b362934113c550d08bb0c784231","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["fs/afs/cmservice.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"4.9","status":"affected"},{"version":"0","lessThan":"4.9","versionType":"semver","status":"unaffected"},{"version":"5.10.261","lessThanOrEqual":"5.10.*","versionType":"semver","status":"unaffected"},{"version":"5.15.212","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.178","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.97","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc2","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/09c67a7ded481482155b836c8c7f078a3075f8de","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/0acbc09d2aca0432af45cec114f20d55ceafaec4","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/0f36469d7ce98b362934113c550d08bb0c784231","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/239cd337c9d047e7097f5b2ebbb41ddfb8180bc6","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/26b737b3769e92493fe94c34620399d93ca231ae","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/5a39b145a8fb49f316e7ec1f29ba51d68095c7e4","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/772850871a2e772e26f9d93f1e9ddd413b3eeaa4","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/f14dd036fad3d359f26f1282199cec06b3a9362b","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-72375","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:22:10.987","lastModified":"2026-08-15T06:22:10.987","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nafs: Fix reinitialisation of the inode, in particular ->lock_work\n\nIt seems that initalising afs_vnode::lock_work a single time in the slab's\ninit function isn't sufficient for work_structs.  This results in the\nDEBUG_OBJECTS debugging stuff producing a warning occasionally when running\nthe generic/131 xfstest:\n\n ODEBUG: activate not available (active state 0) object: 0000000016d8760f object type: work_struct hint: afs_lock_work+0x0/0x220\n WARNING: lib/debugobjects.c:629 at debug_print_object+0x4b/0x90, CPU#3: locktest/7695\n ...\n CPU: 3 UID: 0 PID: 7695 Comm: locktest Tainted: G S                  7.1.0-build3+ #2771 PREEMPT\n ...\n RIP: 0010:debug_print_object+0x65/0x90\n ...\n Call Trace:\n  <TASK>\n  ? __pfx_afs_lock_work+0x10/0x10\n  debug_object_activate+0x122/0x170\n  insert_work+0x25/0x60\n  __queue_work+0x2e0/0x340\n  queue_delayed_work_on+0x48/0x70\n  afs_fl_release_private+0x57/0x70\n  locks_release_private+0x5c/0xa0\n  locks_free_lock+0xe/0x20\n  posix_lock_inode+0x55f/0x5b0\n  locks_lock_inode_wait+0x81/0x140\n  ? file_write_and_wait_range+0x50/0x70\n  afs_lock+0xcd/0x110\n  fcntl_setlk+0x10d/0x260\n  do_fcntl+0x24e/0x5b0\n  __do_sys_fcntl+0x6a/0x90\n  do_syscall_64+0x11e/0x310\n  entry_SYSCALL_64_after_hwframe+0x71/0x79\n\nFix this by reinitialising ->lock_work after allocating an inode.\n\nAlso, flush ->lock_work when the inode is being evicted to make sure it's\nnot still running."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["fs/afs/inode.c","fs/afs/super.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"e8d6c554126b830217c5e9f549e0e21f865a0a8a","lessThan":"63d3f283858fae097fb09ddd4ce46bb0bc1f9d01","versionType":"git","status":"affected"},{"version":"e8d6c554126b830217c5e9f549e0e21f865a0a8a","lessThan":"ebfd13c0367adb43d7c0a72f5cd7e004e60c6b28","versionType":"git","status":"affected"},{"version":"e8d6c554126b830217c5e9f549e0e21f865a0a8a","lessThan":"5597fbd1e7c161914f20315a726e54025b0fdadb","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["fs/afs/inode.c","fs/afs/super.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"2.6.23","status":"affected"},{"version":"0","lessThan":"2.6.23","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc2","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/5597fbd1e7c161914f20315a726e54025b0fdadb","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/63d3f283858fae097fb09ddd4ce46bb0bc1f9d01","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/ebfd13c0367adb43d7c0a72f5cd7e004e60c6b28","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-72376","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:22:11.090","lastModified":"2026-08-15T06:22:11.090","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nafs: Fix misplaced inc of net->cells_outstanding\n\nFix net->cells_outstanding being incremented before the check for failure\nof idr_alloc_cyclic(), leaving the count incremented on error."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["fs/afs/cell.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"88c853c3f5c0a07c5db61b494ee25152535cfeee","lessThan":"6e310f818abcef947a06584158b9e6c6cd0c98d3","versionType":"git","status":"affected"},{"version":"88c853c3f5c0a07c5db61b494ee25152535cfeee","lessThan":"5ea289ca751c47125f6a4138c93ba10c05cd28f0","versionType":"git","status":"affected"},{"version":"88c853c3f5c0a07c5db61b494ee25152535cfeee","lessThan":"654a546c34f3921dd03f9ea74e60139ebffd9e20","versionType":"git","status":"affected"},{"version":"88c853c3f5c0a07c5db61b494ee25152535cfeee","lessThan":"c9c3b615a462a4023bd148f02c564e175ed10502","versionType":"git","status":"affected"},{"version":"e44b8d2aa1543f5c554fda7839574abe8a5ef5ba","versionType":"git","status":"affected"},{"version":"f339eda9b90e49e82043c145ac628d679d913638","versionType":"git","status":"affected"},{"version":"5.8.17","lessThan":"5.9","versionType":"semver","status":"affected"},{"version":"5.9.2","lessThan":"5.10","versionType":"semver","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["fs/afs/cell.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"5.10","status":"affected"},{"version":"0","lessThan":"5.10","versionType":"semver","status":"unaffected"},{"version":"6.12.97","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc2","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/5ea289ca751c47125f6a4138c93ba10c05cd28f0","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/654a546c34f3921dd03f9ea74e60139ebffd9e20","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/6e310f818abcef947a06584158b9e6c6cd0c98d3","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/c9c3b615a462a4023bd148f02c564e175ed10502","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-72377","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:22:11.180","lastModified":"2026-08-15T06:22:11.180","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nafs: Remove setting of AS_RELEASE_ALWAYS for symlinks and mountpoints\n\nRegular AFS files correctly use afs_file_aops which have release_folio\nset as netfs_release_folio, so AS_RELEASE_ALWAYS is valid for them\nwhen fscache is enabled (set via afs_vnode_set_cache()).\nSymlinks and mountpoints in AFS use afs_dir_aops, which does not provide\na release_folio callback. However, afs_apply_status() unconditionally\ncalls mapping_set_release_always() for these.\n\nIn such case when memory management code attempts to release folios,\nfilemap_release_folio() checks folio_needs_release() which\nreturns true due to AS_RELEASE_ALWAYS being set. Since there is no\nrelease_folio callback, it falls through to try_to_free_buffers(),\nwhich at present expects buffer_heads to be not null. For symlinks\nand mountpoints without buffer_heads, this causes pointer dereference.\n\n[dh: Added more bits that were missed]"}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["fs/afs/inode.c","fs/afs/internal.h"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"eae9e78951bb02a7b94a9adef6e981413d13c564","lessThan":"9d6b0f6d437e2f8350e08678e5e1d20c11c364f3","versionType":"git","status":"affected"},{"version":"eae9e78951bb02a7b94a9adef6e981413d13c564","lessThan":"81e985b4c3a6cbcc443fcdcd3ebda7fcc845d459","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["fs/afs/inode.c","fs/afs/internal.h"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.14","status":"affected"},{"version":"0","lessThan":"6.14","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc2","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/81e985b4c3a6cbcc443fcdcd3ebda7fcc845d459","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/9d6b0f6d437e2f8350e08678e5e1d20c11c364f3","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-72378","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:22:11.277","lastModified":"2026-08-15T06:22:11.277","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nafs: Fix error code in afs_extract_vl_addrs()\n\nThe error codes on these paths are only set on the first iteration\nthrough the loop.  Set the correct error code on every iteration."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["fs/afs/vl_list.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"0a5143f2f89cc88d8a3eada8e8ccd86c1e988257","lessThan":"7ce6737a975ea3e0dc2e5946628d233779ca0caf","versionType":"git","status":"affected"},{"version":"0a5143f2f89cc88d8a3eada8e8ccd86c1e988257","lessThan":"4e0b047848a855f2c933a6439f76a01743ba5620","versionType":"git","status":"affected"},{"version":"0a5143f2f89cc88d8a3eada8e8ccd86c1e988257","lessThan":"f70fbf2b974b63a7042705c2b0464cb8c97e9f34","versionType":"git","status":"affected"},{"version":"0a5143f2f89cc88d8a3eada8e8ccd86c1e988257","lessThan":"9ad9016e3333c3c1f9284a253ff0658369e07aac","versionType":"git","status":"affected"},{"version":"0a5143f2f89cc88d8a3eada8e8ccd86c1e988257","lessThan":"cb33dd2968588c78fad78dec19f61cabe5785494","versionType":"git","status":"affected"},{"version":"0a5143f2f89cc88d8a3eada8e8ccd86c1e988257","lessThan":"8530206911fd66ad739ca5ce95f1d069f3d42204","versionType":"git","status":"affected"},{"version":"0a5143f2f89cc88d8a3eada8e8ccd86c1e988257","lessThan":"bdcd80ff12939d172043fac5eb822b92366a1bab","versionType":"git","status":"affected"},{"version":"0a5143f2f89cc88d8a3eada8e8ccd86c1e988257","lessThan":"4897cb71d4ab1f7e1a214adb1e4b80176702368d","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["fs/afs/vl_list.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"4.20","status":"affected"},{"version":"0","lessThan":"4.20","versionType":"semver","status":"unaffected"},{"version":"5.10.261","lessThanOrEqual":"5.10.*","versionType":"semver","status":"unaffected"},{"version":"5.15.212","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.178","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.97","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc2","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/4897cb71d4ab1f7e1a214adb1e4b80176702368d","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/4e0b047848a855f2c933a6439f76a01743ba5620","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/7ce6737a975ea3e0dc2e5946628d233779ca0caf","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/8530206911fd66ad739ca5ce95f1d069f3d42204","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/9ad9016e3333c3c1f9284a253ff0658369e07aac","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/bdcd80ff12939d172043fac5eb822b92366a1bab","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/cb33dd2968588c78fad78dec19f61cabe5785494","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/f70fbf2b974b63a7042705c2b0464cb8c97e9f34","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-72379","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:22:11.387","lastModified":"2026-08-15T06:22:11.387","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nfs: refuse O_TMPFILE creation with an unmapped fsuid or fsgid\n\nvfs_tmpfile() never checked that the caller's fsuid and fsgid map into\nthe filesystem.  On an idmapped mount whose idmapping does not cover the\ncaller's fs{u,g}id, the ->tmpfile() instance initializes the new inode\nthrough inode_init_owner(), where mapped_fsuid()/mapped_fsgid() return\nINVALID_UID/INVALID_GID, and the tmpfile ends up owned by (uid_t)-1.\n\nEvery other creation path already refuses this: may_o_create() (O_CREAT)\nand may_create_dentry() (mkdir, mknod, symlink, link) bail out with\n-EOVERFLOW via fsuidgid_has_mapping() precisely so that an object cannot\nbe created with an owner the filesystem cannot represent.  An O_TMPFILE\nis no exception: it is created I_LINKABLE and linkat(2) can splice it\ninto the namespace afterwards, so the same guarantee must hold.\n\nAdd the missing fsuidgid_has_mapping() check to vfs_tmpfile().  On a\nnon-idmapped mount the caller's fs{u,g}id always map in the superblock's\nuser namespace, so this is a no-op there and only takes effect on an\nidmapped mount that does not map the caller.  It applies to every\nfilesystem that sets FS_ALLOW_IDMAP and implements ->tmpfile() (tmpfs,\next4, btrfs, xfs, f2fs, ...), and to overlayfs, whose upper-layer\ntmpfile creation funnels through vfs_tmpfile() via backing_tmpfile_open()."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["fs/namei.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"8e5389132ab429604c1a2459b52f0c849a71cc61","lessThan":"bac8fb0d60254846f3b56957435dcd870ae12948","versionType":"git","status":"affected"},{"version":"8e5389132ab429604c1a2459b52f0c849a71cc61","lessThan":"503d0568a525b168d9aa5ca046ec72fc5477df84","versionType":"git","status":"affected"},{"version":"8e5389132ab429604c1a2459b52f0c849a71cc61","lessThan":"a2038514e69371eb493083a6a897ed20fcbb8acb","versionType":"git","status":"affected"},{"version":"8e5389132ab429604c1a2459b52f0c849a71cc61","lessThan":"47e434da476b5a8bcd1e6e52ab03c5ee7764ee78","versionType":"git","status":"affected"},{"version":"8e5389132ab429604c1a2459b52f0c849a71cc61","lessThan":"539dce1144651f7976fa418e618b0b574bf15eeb","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["fs/namei.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"5.13","status":"affected"},{"version":"0","lessThan":"5.13","versionType":"semver","status":"unaffected"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.97","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc2","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/47e434da476b5a8bcd1e6e52ab03c5ee7764ee78","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/503d0568a525b168d9aa5ca046ec72fc5477df84","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/539dce1144651f7976fa418e618b0b574bf15eeb","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/a2038514e69371eb493083a6a897ed20fcbb8acb","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/bac8fb0d60254846f3b56957435dcd870ae12948","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-72380","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:22:11.493","lastModified":"2026-08-15T06:22:11.493","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nxen/pvcalls: bound backend response req_id before indexing rsp[]\n\npvcalls_front_event_handler() takes req_id directly from the\nbackend-supplied ring response and uses it to index the fixed-size\nbedata->rsp[] array for a memcpy() and a store, with no range check. A\nmalicious or buggy backend can set req_id past PVCALLS_NR_RSP_PER_RING\nand drive an out-of-bounds write past the bedata allocation.\n\nreq_id was also declared int while the wire field rsp->req_id is u32, so\na range check on the signed value alone is insufficient: a backend\nreq_id of 0xffffffff becomes -1, passes a >= PVCALLS_NR_RSP_PER_RING\ntest and indexes bedata->rsp[-1]. Declare req_id as u32 so a single\nbound covers both ends.\n\nA backend that sends an out-of-range req_id has violated the wire\nprotocol, so rather than silently dropping the response, log once and\nstop trusting the backend: set bedata->disabled. The event handler then\nignores further responses, and the request paths that wait for a\nresponse return -EIO instead of blocking forever. This mirrors the\nfatal-error handling xen-netback uses (xenvif_fatal_tx_err()).\n\nThe pvcalls frontend currently trusts its backend, so this is not a\nclassic-Xen security issue, but it matters for hardening PV frontends\nagainst malicious backends (confidential and disaggregated deployments)."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/xen/pvcalls-front.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"2195046bfd69e487d9a76dc47840f15c8412840c","lessThan":"d1297a9e2fd6ce08678b370d41bc980ca798f809","versionType":"git","status":"affected"},{"version":"2195046bfd69e487d9a76dc47840f15c8412840c","lessThan":"d33846c8dcc06b83b7acdeac1e8bfbb5c0c26cb2","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/xen/pvcalls-front.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"4.15","status":"affected"},{"version":"0","lessThan":"4.15","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc2","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/d1297a9e2fd6ce08678b370d41bc980ca798f809","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/d33846c8dcc06b83b7acdeac1e8bfbb5c0c26cb2","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-72381","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:22:11.587","lastModified":"2026-08-15T06:22:11.587","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nksmbd: fix use-after-free of fp->owner.name in durable handle owner check\n\nTwo concurrent SMB2 durable reconnects (DH2C/DHnC) on the same\npersistent_id race the fp->owner.name compare-read in\nksmbd_vfs_compare_durable_owner() against the kfree() in\nksmbd_reopen_durable_fd()'s reopen-success path. fp->owner.name is a\nstandalone kstrdup() buffer whose lifetime is independent of the fp\nrefcount, and the two sites share no lock: the compare reads the buffer\nwhile the reopen frees it, so the strcmp() can dereference freed memory.\n\nCommit 7ce4fc40018d (\"ksmbd: fix durable reconnect double-bind race in\nksmbd_reopen_durable_fd\") made the fp->conn claim atomic under\nglobal_ft.lock (closing the owner.name double-free and the ksmbd_file\nwrite-UAF), but the compare-read versus reopen-free pair was left\nunserialized.\n\n  BUG: KASAN: slab-use-after-free in strcmp+0x2c/0x80\n  Read of size 1 by task kworker\n    strcmp\n    ksmbd_vfs_compare_durable_owner\n    smb2_check_durable_oplock\n    smb2_open\n  Freed by task kworker:\n    kfree\n    ksmbd_reopen_durable_fd\n    smb2_open\n  Allocated by task kworker:\n    kstrdup\n    session_fd_check\n    smb2_session_logoff\n  The buggy address belongs to the cache kmalloc-8\n\nSerialize both sides of the race with fp->f_lock.  The global durable\nfile-table lock still protects the durable reconnect claim, but\nfp->owner.name is per-open state and does not need to block unrelated\ndurable table lookups or reconnects.  The teardown is left at its\nexisting location after the reopen-success point so that an __open_id()\nrollback still retains owner.name for a later legitimate reconnect to\nverify."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["fs/smb/server/vfs_cache.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"712cdf917e77a6444ce3836874829d770db20ee6","lessThan":"fb978d72052704c6b06c6b0f129fcd60b77169f5","versionType":"git","status":"affected"},{"version":"c7f0f0d01c88bdcb8b1694d7d321670013f7ed7d","lessThan":"93d4d46bf9d442a12ea87278049ec416962c627f","versionType":"git","status":"affected"},{"version":"00ce8d6789dae72d042a4522264964c72891ca37","lessThan":"5a5ac2852cd326529d02f778bc1aa6184701f4d7","versionType":"git","status":"affected"},{"version":"49110a8ce654bbe56bef7c5e44cce31f4b102b8a","lessThan":"ed98719be41389d416953b8ef9f07a07dfea6b2b","versionType":"git","status":"affected"},{"version":"49110a8ce654bbe56bef7c5e44cce31f4b102b8a","lessThan":"38637163501fd9e2f684b8cd275d0db5d79f37c6","versionType":"git","status":"affected"},{"version":"c908c853f304a4969b5aa10eba0b50350cc65b80","versionType":"git","status":"affected"},{"version":"6.6.142","lessThan":"6.6.145","versionType":"semver","status":"affected"},{"version":"6.12.92","lessThan":"6.12.97","versionType":"semver","status":"affected"},{"version":"6.18.25","lessThan":"6.18.40","versionType":"semver","status":"affected"},{"version":"7.0.2","lessThan":"7.1","versionType":"semver","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["fs/smb/server/vfs_cache.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"7.1","status":"affected"},{"version":"0","lessThan":"7.1","versionType":"semver","status":"unaffected"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.97","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc2","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/38637163501fd9e2f684b8cd275d0db5d79f37c6","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/5a5ac2852cd326529d02f778bc1aa6184701f4d7","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/93d4d46bf9d442a12ea87278049ec416962c627f","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/ed98719be41389d416953b8ef9f07a07dfea6b2b","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/fb978d72052704c6b06c6b0f129fcd60b77169f5","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-72382","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:22:11.707","lastModified":"2026-08-15T06:22:11.707","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nksmbd: reject undersized DACLs before parsing ACEs\n\nparse_dacl() limits the attacker-controlled ACE count by comparing it\nwith the number of minimal ACEs that fit in the DACL size. The DACL size\nfield is 16 bits, but the expression subtracts sizeof(struct smb_acl).\nBecause sizeof() is unsigned, a DACL size smaller than the ACL header\nunderflows to a large size_t.\n\nA malicious client can reach this with:\n\nSMB2_SET_INFO (InfoType=SMB2_O_INFO_SECURITY)\n  -> smb2_set_info_sec()\n  -> set_info_sec()\n  -> parse_sec_desc()\n  -> parse_dacl()\n     -> init_acl_state(..., 0xffff)\n     -> init_acl_state(..., 0xffff)\n     -> kmalloc_objs(..., 0xffff)\n\nThus a malformed security descriptor can make num_aces pass the guard\nand drive large temporary ACL state and pointer-array allocations.\n\nReject DACLs smaller than struct smb_acl before doing the subtraction,\nso the ACE count check cannot be bypassed by the underflow."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["fs/smb/server/smbacl.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"e2f34481b24db2fd634b5edb0a5bd0e4d38cc6e9","lessThan":"16fb65ec15fe7c90f50a2115854bfd9a032d4023","versionType":"git","status":"affected"},{"version":"e2f34481b24db2fd634b5edb0a5bd0e4d38cc6e9","lessThan":"282847c0cf22f2e961155ac8e42f6eeab7e16049","versionType":"git","status":"affected"},{"version":"e2f34481b24db2fd634b5edb0a5bd0e4d38cc6e9","lessThan":"d020e7f27bf65eecd3805404702f716b2b6d9e73","versionType":"git","status":"affected"},{"version":"e2f34481b24db2fd634b5edb0a5bd0e4d38cc6e9","lessThan":"15a9e9b8f7f5d7f380ae54c6f5bcbc0bdcb0f3cd","versionType":"git","status":"affected"},{"version":"e2f34481b24db2fd634b5edb0a5bd0e4d38cc6e9","lessThan":"60908f7ebcd9b6cde74ad5711fab0f49c7970949","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["fs/smb/server/smbacl.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"5.15","status":"affected"},{"version":"0","lessThan":"5.15","versionType":"semver","status":"unaffected"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.97","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc2","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/15a9e9b8f7f5d7f380ae54c6f5bcbc0bdcb0f3cd","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/16fb65ec15fe7c90f50a2115854bfd9a032d4023","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/282847c0cf22f2e961155ac8e42f6eeab7e16049","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/60908f7ebcd9b6cde74ad5711fab0f49c7970949","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/d020e7f27bf65eecd3805404702f716b2b6d9e73","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-72383","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:22:11.813","lastModified":"2026-08-15T06:22:11.813","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nsctp: fix addr_wq_timer race in sctp_free_addr_wq()\n\nsctp_free_addr_wq() previously removed addr_wq_timer using timer_delete()\nwhile holding addr_wq_lock. However, timer_delete() does not guarantee that\na currently running timer handler has completed.\n\nThis allows a race with sctp_addr_wq_timeout_handler(), where the handler\nmay still run after addr_waitq has been freed, acquire addr_wq_lock, and\naccess freed memory, leading to a use-after-free.\n\nFix this by calling timer_shutdown_sync() before taking addr_wq_lock.  This\nguarantees that any in-flight timer handler has finished and prevents the\ntimer from being re-armed during teardown, making subsequent cleanup safe."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["net/sctp/protocol.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"4db67e808640e3934d82ce61ee8e2e89fd877ba8","lessThan":"a8323fb2ab6cd6978f359daeed6688e0cadf32ba","versionType":"git","status":"affected"},{"version":"4db67e808640e3934d82ce61ee8e2e89fd877ba8","lessThan":"c3e5cac47519d77ad36b9c03a1df1536aaa0c4a1","versionType":"git","status":"affected"},{"version":"4db67e808640e3934d82ce61ee8e2e89fd877ba8","lessThan":"976c19de0f22a857ba0112f39635f8fd7a257568","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["net/sctp/protocol.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"3.7","status":"affected"},{"version":"0","lessThan":"3.7","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc2","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/976c19de0f22a857ba0112f39635f8fd7a257568","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/a8323fb2ab6cd6978f359daeed6688e0cadf32ba","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/c3e5cac47519d77ad36b9c03a1df1536aaa0c4a1","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-72384","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:22:11.907","lastModified":"2026-08-15T06:22:11.907","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nirqchip/ts4800: Fix missing chained handler cleanup on remove\n\nThe driver installs a chained handler for the parent interrupt during probe\nusing irq_set_chained_handler_and_data(), but the remove function does not\nclear this handler. This leaves a dangling handler that may be called when\nthe parent interrupt fires after the driver has been removed, potentially\naccessing freed memory and causing a kernel crash.\n\nAdditionally, the parent_irq obtained via irq_of_parse_and_map() is not\nstored, making it inaccessible in the remove function. Moreover, interrupt\nmappings created during probe are not properly disposed.\n\nFix this by:\n\n   - Saving parent_irq in probe\n   - Clearing the chained handler with NULL in ts4800_ic_remove()\n   - Disposing all IRQ mappings before domain removal to prevent resource\n     leaks"}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/irqchip/irq-ts4800.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"d01f8633d52e4dac5ee598b87d49fd23346ccfd6","lessThan":"b5b2b2cb6a91908e6c23958c9ce6d5ba2fdb686c","versionType":"git","status":"affected"},{"version":"d01f8633d52e4dac5ee598b87d49fd23346ccfd6","lessThan":"e6b674dc341c6add7d85bec2ec22caf1aad35795","versionType":"git","status":"affected"},{"version":"d01f8633d52e4dac5ee598b87d49fd23346ccfd6","lessThan":"3f31f49afffa169cd01e6c37568c4df3eb1051af","versionType":"git","status":"affected"},{"version":"d01f8633d52e4dac5ee598b87d49fd23346ccfd6","lessThan":"4e8d498d32b6c67d73bb8b317ff316ff37897a3e","versionType":"git","status":"affected"},{"version":"d01f8633d52e4dac5ee598b87d49fd23346ccfd6","lessThan":"9ed0dca2aa05908b33ecf0bb15c7953947529542","versionType":"git","status":"affected"},{"version":"d01f8633d52e4dac5ee598b87d49fd23346ccfd6","lessThan":"98bf7e54cec07d514b3575c11896a8b12d50ecc4","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/irqchip/irq-ts4800.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"4.5","status":"affected"},{"version":"0","lessThan":"4.5","versionType":"semver","status":"unaffected"},{"version":"6.1.178","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.97","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc2","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/3f31f49afffa169cd01e6c37568c4df3eb1051af","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/4e8d498d32b6c67d73bb8b317ff316ff37897a3e","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/98bf7e54cec07d514b3575c11896a8b12d50ecc4","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/9ed0dca2aa05908b33ecf0bb15c7953947529542","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/b5b2b2cb6a91908e6c23958c9ce6d5ba2fdb686c","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/e6b674dc341c6add7d85bec2ec22caf1aad35795","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-72385","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:22:12.017","lastModified":"2026-08-15T06:22:12.017","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\ntracing/fprobe: Fix NULL pointer dereference in fprobe_fgraph_entry()\n\nfprobe_fgraph_entry() sizes a shadow-stack reservation in one walk of\nthe per-ip fprobe list and fills it in a second walk, both under\nrcu_read_lock() only. A fprobe registered on an already-live ip can\nbecome visible between the two walks, so the fill walk processes an\nexit_handler the sizing walk did not count and used runs past\nreserved_words. If the sizing walk counted nothing, fgraph_data is NULL\nand the first write_fprobe_header() faults:\n\n  Oops: general protection fault, probably for non-canonical address ...\n  KASAN: null-ptr-deref in range [0x0000000000000000-0x0000000000000007]\n  RIP: 0010:fprobe_fgraph_entry+0xa38/0xf10 kernel/trace/fprobe.c:167\n  Call Trace:\n   <TASK>\n   function_graph_enter_regs+0x44c/0xa10 kernel/trace/fgraph.c:677\n   ftrace_graph_func+0xc5/0x140 arch/x86/kernel/ftrace.c:671\n   __kernel_text_address+0x9/0x40 kernel/extable.c:78\n   arch_stack_walk+0x117/0x170 arch/x86/kernel/stacktrace.c:26\n   kmem_cache_free+0x188/0x580 mm/slub.c:6378\n   tcp_data_queue+0x18d/0x6550 net/ipv4/tcp_input.c:5590\n   [...]\n   </TASK>\n\nThe list cannot be frozen across the two walks, so skip a node that does\nnot fit the reservation and count it as missed."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["kernel/trace/fprobe.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"4346ba1604093305a287e08eb465a9c15ba05b80","lessThan":"62988204162fc382cfc7d9a185d40a751261e3a3","versionType":"git","status":"affected"},{"version":"4346ba1604093305a287e08eb465a9c15ba05b80","lessThan":"d655cca1c6e67eb081214d37eb231a869ead2f97","versionType":"git","status":"affected"},{"version":"4346ba1604093305a287e08eb465a9c15ba05b80","lessThan":"367c49d6e283c17b56a31e7a8d964a079244264c","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["kernel/trace/fprobe.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.14","status":"affected"},{"version":"0","lessThan":"6.14","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc2","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/367c49d6e283c17b56a31e7a8d964a079244264c","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/62988204162fc382cfc7d9a185d40a751261e3a3","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/d655cca1c6e67eb081214d37eb231a869ead2f97","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-72386","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:22:12.117","lastModified":"2026-08-15T06:22:12.117","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/panthor: Fix a leak when a group is evicted before the tiler OOM is serviced\n\nA group ref is tied to the pending tiler_oom_work, so we need to release\nit if the cancel was effective."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/gpu/drm/panthor/panthor_sched.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"de85488138247d034eb3241840424a54d660926b","lessThan":"490fe7d00fcdac2dd0c204b0007f3a945a09f918","versionType":"git","status":"affected"},{"version":"de85488138247d034eb3241840424a54d660926b","lessThan":"a9d098b346db561ec3ab24d6b1adfc4aec4c728f","versionType":"git","status":"affected"},{"version":"de85488138247d034eb3241840424a54d660926b","lessThan":"893ed1a7c837a824b2a25543e46fbf19dc41f6b5","versionType":"git","status":"affected"},{"version":"de85488138247d034eb3241840424a54d660926b","lessThan":"6efeb9ddb4fbf5ac30aff03e8f09ffbdf966abd0","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/gpu/drm/panthor/panthor_sched.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.10","status":"affected"},{"version":"0","lessThan":"6.10","versionType":"semver","status":"unaffected"},{"version":"6.12.97","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc2","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/490fe7d00fcdac2dd0c204b0007f3a945a09f918","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/6efeb9ddb4fbf5ac30aff03e8f09ffbdf966abd0","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/893ed1a7c837a824b2a25543e46fbf19dc41f6b5","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/a9d098b346db561ec3ab24d6b1adfc4aec4c728f","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-72387","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:22:12.210","lastModified":"2026-08-15T06:22:12.210","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/panthor: Fix potential invalid pointer deref in group_process_tiler_oom()\n\nIf heaps is an ERR_PTR(), panthor_heap_pool_put() will deref an invalid\npointer. Make sure we set it to NULL in that case."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/gpu/drm/panthor/panthor_sched.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"de85488138247d034eb3241840424a54d660926b","lessThan":"bfc5b91ab3ddddf636d8c1c050455bf4e14c912b","versionType":"git","status":"affected"},{"version":"de85488138247d034eb3241840424a54d660926b","lessThan":"dd0b2976b7c0f4ea806855ed19ffad967d36610e","versionType":"git","status":"affected"},{"version":"de85488138247d034eb3241840424a54d660926b","lessThan":"053522ba615888e874adc04e675d9ed2e13f35af","versionType":"git","status":"affected"},{"version":"de85488138247d034eb3241840424a54d660926b","lessThan":"b39436d0ba1571dbcda69d20ec567344b3eecfc7","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/gpu/drm/panthor/panthor_sched.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.10","status":"affected"},{"version":"0","lessThan":"6.10","versionType":"semver","status":"unaffected"},{"version":"6.12.97","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc2","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/053522ba615888e874adc04e675d9ed2e13f35af","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/b39436d0ba1571dbcda69d20ec567344b3eecfc7","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/bfc5b91ab3ddddf636d8c1c050455bf4e14c912b","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/dd0b2976b7c0f4ea806855ed19ffad967d36610e","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-72388","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:22:12.307","lastModified":"2026-08-15T06:22:12.307","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/panthor: Always use the IRQ-safe variant when acquiring the fence lock\n\nSince dma_fence objects can be shared with other subsystems, they may be\naccessed from hardirq context in those drivers, and we have to take\nthat into account by also using the IRQ-safe variant when acquiring\nthe lock.\n\nWhile at it, switch to the guard model."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/gpu/drm/panthor/panthor_sched.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"de85488138247d034eb3241840424a54d660926b","lessThan":"2946aa6c97ac0e0d777baef8c0e6d944da8724a3","versionType":"git","status":"affected"},{"version":"de85488138247d034eb3241840424a54d660926b","lessThan":"778c57d624974e64535ef1c9d9b4d8e5066153f4","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/gpu/drm/panthor/panthor_sched.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.10","status":"affected"},{"version":"0","lessThan":"6.10","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc2","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/2946aa6c97ac0e0d777baef8c0e6d944da8724a3","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/778c57d624974e64535ef1c9d9b4d8e5066153f4","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-72389","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:22:12.397","lastModified":"2026-08-15T06:22:12.397","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nbridge: stp: Fix a potential use-after-free when deleting a bridge\n\nThe three STP timers are not supposed to be armed while the bridge is\nadministratively down. They are synchronously deactivated when the\nbridge is put administratively down and the various call sites check for\n'IFF_UP' before arming them.\n\nThis check is missing from br_topology_change_detection() and it is\npossible to engineer a situation in which the topology change timer is\narmed while the bridge is administratively down, resulting in a\nuse-after-free [1] when the bridge is deleted.\n\nFix by adding the missing check and for good measures synchronously\nshutdown the three timers when the bridge is deleted.\n\n[1]\nODEBUG: free active (active state 0) object: ffff88811662b9b0 object type: timer_list hint: br_topology_change_timer_expired (net/bridge/br_stp_timer.c:120)\nWARNING: lib/debugobjects.c:629 at debug_print_object+0x1bc/0x450, CPU#9: ip/359"}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["net/bridge/br_if.c","net/bridge/br_stp.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"c86579b0a2d201792bcb59316629f4ba4758cfc8","versionType":"git","status":"affected"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"297a747f59bff6573196d7236178144d66524e68","versionType":"git","status":"affected"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"4c40eec06eeac37c58e47a6058eb32901218d5d4","versionType":"git","status":"affected"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"39283907a25e5caf0f2bd2947f6e56644b01e2b7","versionType":"git","status":"affected"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"b4b3458ef88df4798632619f018791d4344bcd92","versionType":"git","status":"affected"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"40cbfa3a28e0919469d1b086629bb3ce38a83593","versionType":"git","status":"affected"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"2a00517db8de4be7df3d483b215c5544fb30a191","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["net/bridge/br_if.c","net/bridge/br_stp.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"2.6.12","status":"affected"},{"version":"0","lessThan":"2.6.12","versionType":"semver","status":"unaffected"},{"version":"5.15.212","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.178","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.97","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc2","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/297a747f59bff6573196d7236178144d66524e68","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/2a00517db8de4be7df3d483b215c5544fb30a191","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/39283907a25e5caf0f2bd2947f6e56644b01e2b7","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/40cbfa3a28e0919469d1b086629bb3ce38a83593","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/4c40eec06eeac37c58e47a6058eb32901218d5d4","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/b4b3458ef88df4798632619f018791d4344bcd92","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/c86579b0a2d201792bcb59316629f4ba4758cfc8","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-72390","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:22:12.510","lastModified":"2026-08-15T06:22:12.510","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nnet/sched: sch_teql: Introduce slaves_lock to avoid race condition and UAF\n\nThe teql master->slaves singly linked list is not protected against\nmultiple writes. It can be mod'ed concurently from teql_master_xmit(),\nteql_dequeue(), teql_init() and teql_destroy() without holding any list\nlock or RCU protection.\n\nzdi-disclosures@trendmicro.com has demonstrated that the qdisc is freed\nafter an RCU grace period, but teql_master_xmit() running on another\nCPU can still hold a stale pointer into the list, resulting in a\nslab-use-after-free:\n\nBUG: KASAN: slab-use-after-free in teql_master_xmit+0xf0f/0x16b0\nRead of size 8 at addr ffff888013fb0440 by task poc/332\nFreed 512-byte region [ffff888013fb0400, ffff888013fb0600) (kmalloc-512)\n\nThe fix?\nAdd a per-master slaves_lock spinlock that serializes all mutations of\nmaster->slaves and the NEXT_SLAVE() links in teql_destroy() and\nteql_qdisc_init(). teql_master_xmit() also takes the same slaves_lock\naround those updates.\nAnnotate master->slaves and the per-slave ->next pointer with __rcu and\nuse the appropriate RCU accessors everywhere they are touched:\nrcu_assign_pointer() on the writer side (under slaves_lock),\nrcu_dereference_protected() for the writer-side loads (also under\nslaves_lock), rcu_dereference_bh() for the loads in teql_master_xmit() and\nrtnl_dereference() for the loads in teql_master_open()/teql_master_mtu(),\nwhich run under RTNL.\nPair this with rcu_read_lock_bh()/rcu_read_unlock_bh() around the list\ntraversal in teql_master_xmit(), so that readers either observe a fully\nlinked list or are deferred until the in-flight mutation completes. The two\nearly-return paths in teql_master_xmit() are updated to release the RCU-bh\nread-side critical section before returning, since leaving it held would\ndisable BH on that CPU for good."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["net/sched/sch_teql.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"03c67781254c574ae7fa75e881239a78473bdf42","versionType":"git","status":"affected"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"735567bde7401f82b064f9f107b52ee1bf84ed8c","versionType":"git","status":"affected"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"11402e6e18e96df615cbcc58157818dd604b23ff","versionType":"git","status":"affected"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"9b7d05cbaa60108642402100efa6aa288dd33023","versionType":"git","status":"affected"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"b26aa9d993537a4c3167d8ceead3b7c69c3a0aac","versionType":"git","status":"affected"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"e5b811fe793166aecc59b085c1b7c31262ef2316","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["net/sched/sch_teql.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"2.6.12","status":"affected"},{"version":"0","lessThan":"2.6.12","versionType":"semver","status":"unaffected"},{"version":"6.1.178","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.97","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc2","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/03c67781254c574ae7fa75e881239a78473bdf42","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/11402e6e18e96df615cbcc58157818dd604b23ff","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/735567bde7401f82b064f9f107b52ee1bf84ed8c","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/9b7d05cbaa60108642402100efa6aa288dd33023","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/b26aa9d993537a4c3167d8ceead3b7c69c3a0aac","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/e5b811fe793166aecc59b085c1b7c31262ef2316","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-72391","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:22:12.627","lastModified":"2026-08-15T06:22:12.627","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nnet: phy: sfp: free mii_bus in sfp_i2c_mdiobus_destroy\n\nsfp_i2c_mdiobus_create() allocates the I2C MDIO bus with mdio_i2c_alloc(),\na plain (non-devm) allocation, and registers it. sfp_i2c_mdiobus_destroy()\nonly unregisters the bus and clears sfp->i2c_mii without calling\nmdiobus_free(). As the only reference to the bus is then cleared, the\nstruct mii_bus is leaked.\n\nThis is hit whenever a copper/RollBall SFP module that instantiated an MDIO\nbus is removed: sfp_sm_main() takes the global teardown path and calls\nsfp_i2c_mdiobus_destroy(). sfp_cleanup(), on driver unbind, frees\nsfp->i2c_mii directly, which is why the leak only triggered on module\nhot-removal and not on unbind.\n\nFree the bus in sfp_i2c_mdiobus_destroy() to match the allocation done in\nsfp_i2c_mdiobus_create()."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/net/phy/sfp.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"e85b1347ace677c3822c12d9332dfaaffe594da6","lessThan":"92dd9a522f01ef57f633a8c1953cf6d48ef2bcd5","versionType":"git","status":"affected"},{"version":"e85b1347ace677c3822c12d9332dfaaffe594da6","lessThan":"d2c37f26d1a37f8177be5f354537f8ee3ec31cc2","versionType":"git","status":"affected"},{"version":"e85b1347ace677c3822c12d9332dfaaffe594da6","lessThan":"3183b6f5510c876a1c4b4a6bdc3d0ad8940fe742","versionType":"git","status":"affected"},{"version":"e85b1347ace677c3822c12d9332dfaaffe594da6","lessThan":"86d379fcf1b79bdf4bc2ac891297f30f63d041d8","versionType":"git","status":"affected"},{"version":"e85b1347ace677c3822c12d9332dfaaffe594da6","lessThan":"2381bf3f484e8e4fd89a225445872ec14e036ab5","versionType":"git","status":"affected"},{"version":"e85b1347ace677c3822c12d9332dfaaffe594da6","lessThan":"8f31efff9206f9f0adb853cad6916086aac4d5ef","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/net/phy/sfp.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.1","status":"affected"},{"version":"0","lessThan":"6.1","versionType":"semver","status":"unaffected"},{"version":"6.1.178","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.97","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc2","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/2381bf3f484e8e4fd89a225445872ec14e036ab5","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/3183b6f5510c876a1c4b4a6bdc3d0ad8940fe742","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/86d379fcf1b79bdf4bc2ac891297f30f63d041d8","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/8f31efff9206f9f0adb853cad6916086aac4d5ef","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/92dd9a522f01ef57f633a8c1953cf6d48ef2bcd5","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/d2c37f26d1a37f8177be5f354537f8ee3ec31cc2","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-72392","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:22:12.733","lastModified":"2026-08-15T06:22:12.733","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nipv6: fib6: fix NULL deref in fib6_walk_continue() on multi-batch dump\n\ninet6_dump_fib() saves its progress in cb->args[1] as a positional\nindex within the current hash chain.  Between batches, a concurrent\nfib6_new_table() can insert a new table at the chain head, shifting\nall existing entries.  The saved index then lands on a different\ntable, causing fib6_dump_table() to set w->root to the wrong table\nwhile w->node still points into the previous one.\nfib6_walk_continue() dereferences w->node->parent (NULL) and panics:\n\n  BUG: kernel NULL pointer dereference, address: 0000000000000008\n  RIP: 0010:fib6_walk_continue+0x6e/0x170\n  Call Trace:\n   <TASK>\n   fib6_dump_table.isra.0+0xc5/0x240\n   inet6_dump_fib+0xf6/0x420\n   rtnl_dumpit+0x30/0xa0\n   netlink_dump+0x15b/0x460\n   netlink_recvmsg+0x1d6/0x2a0\n   ____sys_recvmsg+0x17a/0x190\n\nFix by storing tb->tb6_id in cb->args[1] instead of a positional\nindex.  On resume, skip entries until the id matches; a concurrent\nhead-insert can never match the saved id, so the walker always\nresumes on the correct table."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["net/ipv6/ip6_fib.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"1b43af5480c351dbcb2eef478bafe179cbeb6e83","lessThan":"89f9c5fee3c64c5cabc34e65599308fd3c879cf9","versionType":"git","status":"affected"},{"version":"1b43af5480c351dbcb2eef478bafe179cbeb6e83","lessThan":"27210d433a8c5fe6bf7278a04bbaeb49a81d0290","versionType":"git","status":"affected"},{"version":"1b43af5480c351dbcb2eef478bafe179cbeb6e83","lessThan":"059efb48dd746518898faaa9b965511009b59639","versionType":"git","status":"affected"},{"version":"1b43af5480c351dbcb2eef478bafe179cbeb6e83","lessThan":"d8a01d27873e04bebd357dc87859aa756e0b28b2","versionType":"git","status":"affected"},{"version":"1b43af5480c351dbcb2eef478bafe179cbeb6e83","lessThan":"110ccbd28c9444866fcc84ba96a2ad64fa6e95ae","versionType":"git","status":"affected"},{"version":"1b43af5480c351dbcb2eef478bafe179cbeb6e83","lessThan":"9facb861dc6b9b9ea9793ef5032a9a826f7a4229","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["net/ipv6/ip6_fib.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"2.6.19","status":"affected"},{"version":"0","lessThan":"2.6.19","versionType":"semver","status":"unaffected"},{"version":"5.15.212","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.6.151","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.97","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc2","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/059efb48dd746518898faaa9b965511009b59639","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/110ccbd28c9444866fcc84ba96a2ad64fa6e95ae","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/27210d433a8c5fe6bf7278a04bbaeb49a81d0290","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/89f9c5fee3c64c5cabc34e65599308fd3c879cf9","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/9facb861dc6b9b9ea9793ef5032a9a826f7a4229","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/d8a01d27873e04bebd357dc87859aa756e0b28b2","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-72393","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:22:12.847","lastModified":"2026-08-15T06:22:12.847","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\neth: fbnic: don't cache shinfo across skb realloc\n\nfbnic_tx_lso() calls skb_cow_head() which may reallocate the skb\nincluding the shared info. We can't use the pointer calculated\nbefore the call.\n\n    BUG: KASAN: slab-use-after-free in fbnic_tx_lso.isra.0+0x668/0x8e0\n    Read of size 4 at addr ff110000262edd98 by task swapper/5/0\n    Call Trace:\n     fbnic_tx_lso.isra.0+0x668/0x8e0\n     fbnic_xmit_frame+0x622/0xba0\n     dev_hard_start_xmit+0xf4/0x620\n\n    Allocated by task 8653:\n     __alloc_skb+0x11e/0x5f0\n     alloc_skb_with_frags+0xcc/0x6c0\n     sock_alloc_send_pskb+0x327/0x3f0\n     __ip_append_data+0x188b/0x47a0\n     ip_make_skb+0x24a/0x300\n     udp_sendmsg+0x14d2/0x21e0\n\n    Freed by task 0:\n     kfree+0x123/0x5a0\n     pskb_expand_head+0x36c/0xfa0\n     fbnic_tx_lso.isra.0+0x500/0x8e0\n     fbnic_xmit_frame+0x622/0xba0\n     dev_hard_start_xmit+0xf4/0x620\n     sch_direct_xmit+0x25b/0x1100\n\n    The buggy address belongs to the object at ff110000262edc40\n     which belongs to the cache skbuff_small_head of size 640\n    The buggy address is located 344 bytes inside of\n     freed 640-byte region [ff110000262edc40, ff110000262ede"}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/net/ethernet/meta/fbnic/fbnic_txrx.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"b0b0f52042acb324cd39fbefb2b1ae83af8f8ae1","lessThan":"83df3e2594cd78aa40b1246a19879abb4891945b","versionType":"git","status":"affected"},{"version":"b0b0f52042acb324cd39fbefb2b1ae83af8f8ae1","lessThan":"21f304c2aae46625e050c28d979f4b9d83faa85e","versionType":"git","status":"affected"},{"version":"b0b0f52042acb324cd39fbefb2b1ae83af8f8ae1","lessThan":"62b68b774f06bf52e329f254f0199bc43d350ccf","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/net/ethernet/meta/fbnic/fbnic_txrx.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.15","status":"affected"},{"version":"0","lessThan":"6.15","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc2","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/21f304c2aae46625e050c28d979f4b9d83faa85e","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/62b68b774f06bf52e329f254f0199bc43d350ccf","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/83df3e2594cd78aa40b1246a19879abb4891945b","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-72394","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:22:12.943","lastModified":"2026-08-15T06:22:12.943","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nhwmon: (aspeed-g6-pwm-tach) Guard fan RPM calculation against divide-by-zero\n\nSashiko reports:\n\nIn the aspeed-g6-pwm-tacho driver, the aspeed_tach_val_to_rpm() function\ncalculates the fan RPM using the tachometer value. However, it does not\ncheck if the tachometer value is zero before performing the division.\n\nIf the hardware reports a tachometer value of 0 (which can happen due to\nan extremely fast pulse, a stuck edge, or a hardware glitch), the\ncalculated tach_div evaluates to 0. The subsequent call to do_div() with\ntach_div as the divisor triggers a divide-by-zero exception, leading to\na kernel panic.\n\nCheck the divisor against zero to fix the problem."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/hwmon/aspeed-g6-pwm-tach.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"7e1449cd15d1096157d1a9923b82e37602fb7eb0","lessThan":"a3f98bd397398e2d4a7f98e006b5aaf4d54ebdf3","versionType":"git","status":"affected"},{"version":"7e1449cd15d1096157d1a9923b82e37602fb7eb0","lessThan":"898ca04b096b9e4640300eab91468c826a1ec92b","versionType":"git","status":"affected"},{"version":"7e1449cd15d1096157d1a9923b82e37602fb7eb0","lessThan":"fb8a5afe6f1f8aa7f19c6dda23d277dd6ae5d9e1","versionType":"git","status":"affected"},{"version":"7e1449cd15d1096157d1a9923b82e37602fb7eb0","lessThan":"fe87b8dc67f1b2c64e76a66e78468c533d3c44ca","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/hwmon/aspeed-g6-pwm-tach.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.9","status":"affected"},{"version":"0","lessThan":"6.9","versionType":"semver","status":"unaffected"},{"version":"6.12.97","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc2","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/898ca04b096b9e4640300eab91468c826a1ec92b","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/a3f98bd397398e2d4a7f98e006b5aaf4d54ebdf3","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/fb8a5afe6f1f8aa7f19c6dda23d277dd6ae5d9e1","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/fe87b8dc67f1b2c64e76a66e78468c533d3c44ca","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-72395","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:22:13.043","lastModified":"2026-08-15T06:22:13.043","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nhwmon: (pmbus) Fix passing events to regulator core\n\nSashiko reports:\n\nCommit 754bd2b4a084 (\"hwmon: (pmbus/core) Protect regulator operations with\nmutex\") introduced a worker to batch regulator events over time using\natomic_or(). The delayed worker then passes the combined bitmask unmodified\nto regulator_notifier_call_chain().\n\nThe core regulator subsystem's regulator_handle_critical() function\nevaluates the event parameter using a strict switch statement. If\nmultiple distinct faults occur before the worker runs (e.g.,\nREGULATOR_EVENT_UNDER_VOLTAGE | REGULATOR_EVENT_OVER_CURRENT), the combined\nbitmask fails to match any case. This leaves the reason as NULL and\ncompletely bypasses the critical hw_protection_trigger().\n\nFix the problem by passing events bit by bit to the regulator event\nhandler."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/hwmon/pmbus/pmbus_core.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"b26849cffaa7c43355b82e9bef3725e786973a1a","lessThan":"2106bf4056858fcce3624e0c51f6fee4d41d3f2f","versionType":"git","status":"affected"},{"version":"acf04e2863132f6d9222f71f3a76fb9782cbe061","lessThan":"48fe43666950efefb7ac5fbdc012c1b3604096bf","versionType":"git","status":"affected"},{"version":"4e9d723d9f198b86f6882a84c501ba1f39e8d055","lessThan":"489291b6b56978cc50d34e8e13f9636ea296ba8a","versionType":"git","status":"affected"},{"version":"754bd2b4a084b90b5e7b630e1f423061a9b9b761","lessThan":"b0ff6b6ae9c5183ef701ece7016698bde5a5bfba","versionType":"git","status":"affected"},{"version":"754bd2b4a084b90b5e7b630e1f423061a9b9b761","lessThan":"9ef7dacd44216bf5ea05c8aef49eba4d145f4047","versionType":"git","status":"affected"},{"version":"2c77ae315f3ce9d2c8e1609be74c9358c1fe4e07","versionType":"git","status":"affected"},{"version":"6.6.143","lessThan":"6.6.145","versionType":"semver","status":"affected"},{"version":"6.12.92","lessThan":"6.12.97","versionType":"semver","status":"affected"},{"version":"6.18.21","lessThan":"6.18.40","versionType":"semver","status":"affected"},{"version":"6.19.11","lessThan":"6.20","versionType":"semver","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/hwmon/pmbus/pmbus_core.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"7.0","status":"affected"},{"version":"0","lessThan":"7.0","versionType":"semver","status":"unaffected"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.97","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc2","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/2106bf4056858fcce3624e0c51f6fee4d41d3f2f","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/489291b6b56978cc50d34e8e13f9636ea296ba8a","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/48fe43666950efefb7ac5fbdc012c1b3604096bf","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/9ef7dacd44216bf5ea05c8aef49eba4d145f4047","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/b0ff6b6ae9c5183ef701ece7016698bde5a5bfba","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-72396","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:22:13.150","lastModified":"2026-08-15T06:22:13.150","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nhwmon: adm1275: Prevent reading uninitialized stack\n\nWhile adding support for the ROHM BD127X0 hot-swap controllers, sashiko\nreported an error in device-name comparison, which can lead to reading\nuninitialized stack memory.\n\nQuoting Sashiko:\n\nThis is a pre-existing issue, but I noticed that just before this block in\nadm1275_probe(), there might be an out-of-bounds stack read:\n\n    ret = i2c_smbus_read_block_data(client, PMBUS_MFR_MODEL, block_buffer);\n    if (ret < 0) { ... }\n    for (mid = adm1275_id; mid->name[0]; mid++) {\n            if (!strncasecmp(mid->name, block_buffer, strlen(mid->name)))\n                    break;\n    }\n\nSince i2c_smbus_read_block_data() reads up to 32 bytes into the\nuninitialized stack array block_buffer without appending a null\nterminator, strncasecmp() could read past the valid bytes returned in ret.\n\nFor example, if the device returns a shorter string like \"adm12\", checking\nit against \"adm1275\" up to the length of \"adm1275\" will continue reading\ninto uninitialized stack bounds.\n\nPrevent reading uninitialized memory by zeroing the stack array."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/hwmon/pmbus/adm1275.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"87102808d03948c825c3bdc48316e48f6422fd7e","lessThan":"57d583f069fa9d3d0c0831e34b967d1f61edae94","versionType":"git","status":"affected"},{"version":"87102808d03948c825c3bdc48316e48f6422fd7e","lessThan":"82e4ab03a6ab9b87667410f5143bc484d7a62bdc","versionType":"git","status":"affected"},{"version":"87102808d03948c825c3bdc48316e48f6422fd7e","lessThan":"c9e04a52663bc6651c06c2427df088b751062bd6","versionType":"git","status":"affected"},{"version":"87102808d03948c825c3bdc48316e48f6422fd7e","lessThan":"39a581bd64a0e91112ec8017a2dd4e70c1336e99","versionType":"git","status":"affected"},{"version":"87102808d03948c825c3bdc48316e48f6422fd7e","lessThan":"aa35cee30686e6be3c890bf741429c5025d55abe","versionType":"git","status":"affected"},{"version":"87102808d03948c825c3bdc48316e48f6422fd7e","lessThan":"36554592e2f5cac16ff8bf73720d38a6d9ef4a20","versionType":"git","status":"affected"},{"version":"87102808d03948c825c3bdc48316e48f6422fd7e","lessThan":"93b96e723bdcba6172a5814262be875abcc5d269","versionType":"git","status":"affected"},{"version":"87102808d03948c825c3bdc48316e48f6422fd7e","lessThan":"553f9517813912a5ab661af5504485d96824a61c","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/hwmon/pmbus/adm1275.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"3.3","status":"affected"},{"version":"0","lessThan":"3.3","versionType":"semver","status":"unaffected"},{"version":"5.10.261","lessThanOrEqual":"5.10.*","versionType":"semver","status":"unaffected"},{"version":"5.15.212","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.178","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.97","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc2","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/36554592e2f5cac16ff8bf73720d38a6d9ef4a20","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/39a581bd64a0e91112ec8017a2dd4e70c1336e99","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/553f9517813912a5ab661af5504485d96824a61c","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/57d583f069fa9d3d0c0831e34b967d1f61edae94","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/82e4ab03a6ab9b87667410f5143bc484d7a62bdc","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/93b96e723bdcba6172a5814262be875abcc5d269","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/aa35cee30686e6be3c890bf741429c5025d55abe","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/c9e04a52663bc6651c06c2427df088b751062bd6","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-72397","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:22:13.270","lastModified":"2026-08-15T06:22:13.270","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nhwmon: (pmbus/core) honor vrm_version in pmbus_data2reg_vid()\n\npmbus_data2reg_vid() hardcoded the VR11 encoding regardless of the\nvrm_version configured by the driver, while pmbus_reg2data_vid()\nalready switched on it. Any driver that selects a non-VR11 VID mode\nand exposes a regulator (or hwmon vout setter) sent dangerously\nwrong codes to PMBUS_VOUT_COMMAND -- e.g. an nvidia195mv part asked\nfor 200 mV got the VR11 clamp to 500 mV encoded as 0xB2, which the\nchip interprets as 1080 mV.\n\nMirror pmbus_reg2data_vid() so writes round-trip with reads."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/hwmon/pmbus/pmbus_core.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"068c227056b9223fea1a759e08db2558d5cbb5ad","lessThan":"5bd0d47640395f8a8c34446b62d1781b88869dfa","versionType":"git","status":"affected"},{"version":"068c227056b9223fea1a759e08db2558d5cbb5ad","lessThan":"828cd614e2af053ca5e1d6da767bbd8a1b5cabfb","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/hwmon/pmbus/pmbus_core.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"4.3","status":"affected"},{"version":"0","lessThan":"4.3","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc2","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/5bd0d47640395f8a8c34446b62d1781b88869dfa","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/828cd614e2af053ca5e1d6da767bbd8a1b5cabfb","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-72398","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:22:13.363","lastModified":"2026-08-15T06:22:13.363","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nsctp: add INIT verification after cookie unpacking\n\nIn SCTP handshake, the INIT chunk is initially processed by the server\nand embedded into the cookie carried in INIT-ACK. The client then\nreturns this cookie via COOKIE-ECHO, where the server unpacks it and\nreconstructs the original INIT chunk.\n\nWhen cookie authentication is enabled, the cookie contents are protected\nagainst tampering, so reusing the unpacked INIT without re-verification\nis safe.\n\nHowever, when cookie authentication is disabled, the reconstructed INIT\ncan no longer be trusted. In this case, the INIT must be explicitly\nvalidated after unpacking to avoid processing potentially tampered data.\n\nAdd sctp_verify_init() checks after cookie unpacking in COOKIE-ECHO\nprocessing paths (sctp_sf_do_5_1D_ce() and sctp_sf_do_5_2_4_dupcook())\nwhen cookie_auth_enable is disabled. On failure, the new association is\nfreed and the packet is discarded.\n\nAlso tighten cookie validation in sctp_unpack_cookie() by verifying the\nembedded chunk type is SCTP_CID_INIT before treating it as an INIT\nchunk.\n\nFinally, update sctp_verify_init() to validate parameter bounds using\nthe actual embedded INIT length instead of chunk->chunk_end, since the\nINIT stored in COOKIE-ECHO may not span the entire chunk buffer."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["net/sctp/sm_make_chunk.c","net/sctp/sm_statefuns.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"bca3100f550281c2f2418652338bced3b35af0e6","versionType":"git","status":"affected"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"062bcbf8d1f1051fdeb20b94920031b0e2cb95a2","versionType":"git","status":"affected"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"414c5447fe6a200613dd46d7fdc8454622076cb1","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["net/sctp/sm_make_chunk.c","net/sctp/sm_statefuns.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"2.6.12","status":"affected"},{"version":"0","lessThan":"2.6.12","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc2","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/062bcbf8d1f1051fdeb20b94920031b0e2cb95a2","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/414c5447fe6a200613dd46d7fdc8454622076cb1","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/bca3100f550281c2f2418652338bced3b35af0e6","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-72399","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:22:13.460","lastModified":"2026-08-15T06:22:13.460","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nnet: enetc: check the number of BDs needed for xdp_frame\n\nThe size of xdp_redirect_arr array is ENETC_MAX_SKB_FRAGS. However, the\nnumber of fragments contained in xdp_frame may be greater than or equal\nto ENETC_MAX_SKB_FRAGS, which will cause the access to xdp_redirect_arr\nto be out of bounds."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/net/ethernet/freescale/enetc/enetc.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"9d2b68cc108db2fdb35022ed2d88cfb305c441a6","lessThan":"1ecb199b0e6d12ab6c26c0b7edf1a8f4472d9aed","versionType":"git","status":"affected"},{"version":"9d2b68cc108db2fdb35022ed2d88cfb305c441a6","lessThan":"f55276160ffad3e235b657ee4b7304eb99b90e5c","versionType":"git","status":"affected"},{"version":"9d2b68cc108db2fdb35022ed2d88cfb305c441a6","lessThan":"cfbc6e9b84dcc0aa2d65c84ea4745af327763209","versionType":"git","status":"affected"},{"version":"9d2b68cc108db2fdb35022ed2d88cfb305c441a6","lessThan":"1681cc7974a6123f5d5740b03bc11e4784bd2542","versionType":"git","status":"affected"},{"version":"9d2b68cc108db2fdb35022ed2d88cfb305c441a6","lessThan":"d22829101ab675607ad6c3d420fb3ab875f46bbb","versionType":"git","status":"affected"},{"version":"9d2b68cc108db2fdb35022ed2d88cfb305c441a6","lessThan":"555c5475e787802eeae0d2b91c2f66c330db2767","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/net/ethernet/freescale/enetc/enetc.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"5.13","status":"affected"},{"version":"0","lessThan":"5.13","versionType":"semver","status":"unaffected"},{"version":"6.1.178","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.97","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc2","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/1681cc7974a6123f5d5740b03bc11e4784bd2542","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/1ecb199b0e6d12ab6c26c0b7edf1a8f4472d9aed","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/555c5475e787802eeae0d2b91c2f66c330db2767","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/cfbc6e9b84dcc0aa2d65c84ea4745af327763209","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/d22829101ab675607ad6c3d420fb3ab875f46bbb","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/f55276160ffad3e235b657ee4b7304eb99b90e5c","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-72400","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:22:13.567","lastModified":"2026-08-15T06:22:13.567","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nseg6: validate SRH length before reading fixed fields\n\nseg6_validate_srh() reads fixed SRH fields such as srh->type and\nsrh->hdrlen before checking that the supplied length covers the fixed\nstruct ipv6_sr_hdr fields.\n\nThe BPF SEG6 encap path reaches this with a BPF program-supplied pointer\nand length: bpf_lwt_push_encap() and the SEG6 local BPF END_B6 and\nEND_B6_ENCAP actions call bpf_push_seg6_encap(), which forwards the\nlength to seg6_validate_srh() with no minimum-size guard.  A 2-byte SEG6\nencap header can therefore make the validator read srh->type at offset 2\nbeyond the caller-supplied buffer.\n\nReject lengths shorter than the fixed SRH at the top of\nseg6_validate_srh(), before any field is read.  This fixes the BPF helper\npath and keeps the common validator robust."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["net/ipv6/seg6.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"fe94cc290f535709d3c5ebd1e472dfd0aec7ee79","lessThan":"715eb12e453df752f1b4baaf972c3acff0ab9402","versionType":"git","status":"affected"},{"version":"fe94cc290f535709d3c5ebd1e472dfd0aec7ee79","lessThan":"7247d05c987c3eec4bb7c2306dbd77ecdf3b7c73","versionType":"git","status":"affected"},{"version":"fe94cc290f535709d3c5ebd1e472dfd0aec7ee79","lessThan":"071f1a38d7ddbadee29c09b9e3ee0ff3a61e6a0e","versionType":"git","status":"affected"},{"version":"fe94cc290f535709d3c5ebd1e472dfd0aec7ee79","lessThan":"804bb969f194c93497ba632b98343794c6367fdc","versionType":"git","status":"affected"},{"version":"fe94cc290f535709d3c5ebd1e472dfd0aec7ee79","lessThan":"0fc7069d39239978130c37ebceaec85c8948d3f1","versionType":"git","status":"affected"},{"version":"fe94cc290f535709d3c5ebd1e472dfd0aec7ee79","lessThan":"8dba7a94a269b88e500aafc25ad567ef6a423698","versionType":"git","status":"affected"},{"version":"fe94cc290f535709d3c5ebd1e472dfd0aec7ee79","lessThan":"c9961336aa5ff83092f23e33ee86666a9dbd1b2a","versionType":"git","status":"affected"},{"version":"fe94cc290f535709d3c5ebd1e472dfd0aec7ee79","lessThan":"a75d99f46bf21b45965ce39c5cfb3b8bb5ffb1aa","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["net/ipv6/seg6.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"4.18","status":"affected"},{"version":"0","lessThan":"4.18","versionType":"semver","status":"unaffected"},{"version":"5.10.261","lessThanOrEqual":"5.10.*","versionType":"semver","status":"unaffected"},{"version":"5.15.212","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.178","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.97","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc2","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/071f1a38d7ddbadee29c09b9e3ee0ff3a61e6a0e","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/0fc7069d39239978130c37ebceaec85c8948d3f1","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/715eb12e453df752f1b4baaf972c3acff0ab9402","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/7247d05c987c3eec4bb7c2306dbd77ecdf3b7c73","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/804bb969f194c93497ba632b98343794c6367fdc","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/8dba7a94a269b88e500aafc25ad567ef6a423698","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/a75d99f46bf21b45965ce39c5cfb3b8bb5ffb1aa","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/c9961336aa5ff83092f23e33ee86666a9dbd1b2a","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-72401","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:22:13.687","lastModified":"2026-08-15T06:22:13.687","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nbpf: Fix insn_aux_data leak on verifier err_free_env path\n\nWhen bpf_check() allocates env->insn_aux_data successfully but later\nfails to allocate env->succ, it jumps directly to err_free_env.\n\nThe existing vfree(env->insn_aux_data) sits before the err_free_env\nlabel, so that direct jump bypasses it and leaks insn_aux_data.\n\nMove vfree(env->insn_aux_data) into err_free_env so all early and late\nexit paths release it consistently."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["kernel/bpf/verifier.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"2f69c5685427308d2f312646779313f3677536bc","lessThan":"d8df91756890de058646597367507b239a6d2025","versionType":"git","status":"affected"},{"version":"2f69c5685427308d2f312646779313f3677536bc","lessThan":"26490a375cb9be9bac96b5171610fd85ca6c2305","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["kernel/bpf/verifier.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.19","status":"affected"},{"version":"0","lessThan":"6.19","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc2","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/26490a375cb9be9bac96b5171610fd85ca6c2305","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/d8df91756890de058646597367507b239a6d2025","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-72402","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:22:13.780","lastModified":"2026-08-15T06:22:13.780","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nbpf: Mask pseudo pointer values in verifier logs\n\nprint_bpf_insn() masks ldimm64 immediates for pointer-bearing pseudo\nsources when pointer leaks are not allowed, but the mask only covers\nBPF_PSEUDO_MAP_FD and BPF_PSEUDO_MAP_VALUE.\n\nBPF_PSEUDO_MAP_IDX, BPF_PSEUDO_MAP_IDX_VALUE, and BPF_PSEUDO_BTF_ID can\nalso be resolved to kernel pointer values before the verifier log prints\nthe instruction. Include them in the existing pointer classification so\nthe log prints 0x0 instead of the rewritten address."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["kernel/bpf/disasm.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"4976b718c3551faba2c0616ef55ebeb74db1c5ca","lessThan":"1c53d16b174dd9e02243fc0e85089e2aa6a0d21a","versionType":"git","status":"affected"},{"version":"4976b718c3551faba2c0616ef55ebeb74db1c5ca","lessThan":"72a85e9464a5332fb2cd7efd26d9295275ceda2d","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["kernel/bpf/disasm.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"5.10","status":"affected"},{"version":"0","lessThan":"5.10","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc2","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/1c53d16b174dd9e02243fc0e85089e2aa6a0d21a","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/72a85e9464a5332fb2cd7efd26d9295275ceda2d","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-72403","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:22:13.870","lastModified":"2026-08-15T06:22:13.870","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nALSA: FCP: Fix NULL pointer dereference in interface lookup\n\nA malformed USB device can provide a vendor-specific interface without\nany endpoint descriptors. fcp_find_fc_interface() currently selects the\nfirst vendor-specific interface and reads endpoint 0 from it, without\nchecking whether the interface actually has any endpoints.\n\nWhen bNumEndpoints is zero, no endpoint array is allocated for the parsed\nalternate setting, so get_endpoint(..., 0) yields an invalid endpoint\ndescriptor pointer. Dereferencing it through usb_endpoint_num() then\ntriggers a NULL pointer dereference.\n\nSkip vendor-specific interfaces that do not have any endpoints."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["sound/usb/fcp.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"46757a3e7d50dac923888e7fbe68377736f13c70","lessThan":"f28d7b5f1578a7501ab17b10643ed1e4f729187e","versionType":"git","status":"affected"},{"version":"46757a3e7d50dac923888e7fbe68377736f13c70","lessThan":"3ab06151ffcb8c3aeb8f78508658b6c0f05be932","versionType":"git","status":"affected"},{"version":"46757a3e7d50dac923888e7fbe68377736f13c70","lessThan":"e1e31e0ec8a609e17fd2e86b77bc00d9cbb24d7c","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["sound/usb/fcp.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.14","status":"affected"},{"version":"0","lessThan":"6.14","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/3ab06151ffcb8c3aeb8f78508658b6c0f05be932","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/e1e31e0ec8a609e17fd2e86b77bc00d9cbb24d7c","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/f28d7b5f1578a7501ab17b10643ed1e4f729187e","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-72404","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:22:13.970","lastModified":"2026-08-15T06:22:13.970","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\ntipc: fix UAF in cleanup_bearer() due to premature dst_cache_destroy()\n\nTIPC UDP media bearer teardown calls dst_cache_destroy() on its\nreplicast caches before calling synchronize_net() to wait for\nconcurrent RCU readers (transmitters) to finish:\n\nstatic void cleanup_bearer(struct work_struct *work)\n{\n...\n\tlist_for_each_entry_safe(rcast, tmp, &ub->rcast.list, list) {\n\t\tdst_cache_destroy(&rcast->dst_cache);\n\t\tlist_del_rcu(&rcast->list);\n\t\tkfree_rcu(rcast, rcu);\n\t}\n...\n\tdst_cache_destroy(&ub->rcast.dst_cache);\n\tudp_tunnel_sock_release(ub->sk);\n\tsynchronize_net();\n...\n}\n\nThis is highly buggy because dst_cache_destroy() immediately frees the\nper-CPU cache memory (free_percpu()) and releases the cached dst\nentries without any synchronization.\n\nIf a concurrent transmitter (e.g., tipc_udp_xmit()) is running on another\nCPU under RCU protection, it can call dst_cache_get() concurrently,\nleading to:\n1. Use-After-Free on the per-CPU cache pointer itself (crash).\n2. \"rcuref - imbalanced put()\" warning if it attempts to release a\n   dst that was concurrently released by dst_cache_destroy().\n\nFurthermore, calling kfree(ub) immediately after synchronize_net() without\nclosing the socket first (or waiting after closing it) leaves a window\nwhere a concurrent receiver (tipc_udp_recv()) could start after\nsynchronize_net(), access ub, and suffer a UAF when kfree(ub) runs.\n\nTo fix this, we must defer dst_cache_destroy() and kfree(ub) until after\nwe have ensured that no more readers can see the bearer/socket and all\nexisting readers have finished:\n\n1. Defer rcast entry destruction (both dst_cache_destroy() and kfree())\n   to an RCU callback using call_rcu_hurry().\n   Using call_rcu_hurry() ensures the dst entries are released quickly.\n\n2. Release the bearer socket using udp_tunnel_sock_release() (stops\n   new receive readers).\n\n3. Call synchronize_net() to wait for all outstanding RCU readers\n   (both transmit and receive) to finish.\n\n4. Now that it is safe, call dst_cache_destroy() on the main bearer\n   cache, and free ub.\n\nNote: 3) and 4) can be changed later in net-next to also use\ncall_rcu_hurry() and get rid of the synchronize_net() latency."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["net/tipc/udp_media.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"e9c1a793210f29f32ee4cf048e04d7d9bb3221cc","lessThan":"1c8393eefa3cadf4ca0b61119ad1321aa32d3c8c","versionType":"git","status":"affected"},{"version":"e9c1a793210f29f32ee4cf048e04d7d9bb3221cc","lessThan":"7116764ca53ff529335d7ab7c364a69f094b23a5","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["net/tipc/udp_media.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"5.3","status":"affected"},{"version":"0","lessThan":"5.3","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/1c8393eefa3cadf4ca0b61119ad1321aa32d3c8c","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/7116764ca53ff529335d7ab7c364a69f094b23a5","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-72405","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:22:14.077","lastModified":"2026-08-15T06:22:14.077","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nnet: udp_tunnel: prevent double queueing in udp_tunnel_nic_device_sync\n\nYue Sun reported a use-after-free and debugobjects warning in\nudp_tunnel_nic_device_sync_work() during concurrent device operations.\n\nThe workqueue core clears the internal pending bit before invoking the\nworker. At that point, a concurrent thread can queue the work again.\nWhen the already running worker eventually clears the work_pending flag\nto 0, it mistakenly clears the flag for the newly queued instance.\nudp_tunnel_nic_unregister() then observes work_pending as 0 and frees\nthe structure while the second work item is still active in the queue,\nleading to UAF.\n\nFix this by returning early in udp_tunnel_nic_device_sync() if\nwork_pending is already set, preventing redundant work queueing."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["net/ipv4/udp_tunnel_nic.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"cc4e3835eff474aa274d6e1d18f69d9d296d3b76","lessThan":"cee6688e5731c0591643521716d1a1a5c1a98bf8","versionType":"git","status":"affected"},{"version":"cc4e3835eff474aa274d6e1d18f69d9d296d3b76","lessThan":"9075efb9b2c1d9d7a8285c937b64aa93ca0c41b7","versionType":"git","status":"affected"},{"version":"cc4e3835eff474aa274d6e1d18f69d9d296d3b76","lessThan":"54292b167466cdf42176b7b6f01da66c184deb12","versionType":"git","status":"affected"},{"version":"cc4e3835eff474aa274d6e1d18f69d9d296d3b76","lessThan":"ecf69d4b43370c587e48d4d70289dbdb7e039d4d","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["net/ipv4/udp_tunnel_nic.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"5.9","status":"affected"},{"version":"0","lessThan":"5.9","versionType":"semver","status":"unaffected"},{"version":"6.12.97","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/54292b167466cdf42176b7b6f01da66c184deb12","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/9075efb9b2c1d9d7a8285c937b64aa93ca0c41b7","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/cee6688e5731c0591643521716d1a1a5c1a98bf8","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/ecf69d4b43370c587e48d4d70289dbdb7e039d4d","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-72406","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:22:14.177","lastModified":"2026-08-15T06:22:14.177","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nnet: sungem: fix probe error cleanup\n\ngem_init_one() calls gem_remove_one() when register_netdev() fails.\ngem_remove_one() unregisters and frees resources owned by the net_device,\nincluding the DMA block, MMIO mapping, PCI regions, and the net_device\nitself. gem_init_one() then falls through to its own cleanup labels and\nfrees the same resources again.\n\nKeep the register_netdev() error path in gem_init_one(): clear drvdata so\nPM/remove paths do not see a half-registered device, remove the NAPI\ninstance added during probe, and let the existing cleanup labels release\nthe resources once.\n\nThe issue was found by a local static-analysis checker for probe error\npaths. The reported path was manually inspected before sending this fix.\n\nCompile-tested with CONFIG_SUNGEM=y. Runtime testing was not performed\nbecause no sungem hardware is available."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/net/ethernet/sun/sungem.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"f3bd60b26814b7c3c57c629abb0857dfc76d214a","versionType":"git","status":"affected"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"f1d04fefb0c2a2de32d9cee22cdc2088be3758d1","versionType":"git","status":"affected"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"331c99029a1cee1111f82f63d15b3cdebefbd341","versionType":"git","status":"affected"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"a63eaf7605d1579cf3f551792e478cfaf5ac37d1","versionType":"git","status":"affected"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"fb73cdc50b6755e5c3a80a195b2708a39ada0230","versionType":"git","status":"affected"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"b15a3cc68e2450aa0edd94a74a7bdd45fcc17dd9","versionType":"git","status":"affected"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"bc49e8746584564dba47d963d1916cc876fc6f6b","versionType":"git","status":"affected"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"36dea2f639249460d13f6ca66b2a9064187cd34d","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/net/ethernet/sun/sungem.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"2.6.12","status":"affected"},{"version":"0","lessThan":"2.6.12","versionType":"semver","status":"unaffected"},{"version":"5.10.261","lessThanOrEqual":"5.10.*","versionType":"semver","status":"unaffected"},{"version":"5.15.212","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.178","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.97","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/331c99029a1cee1111f82f63d15b3cdebefbd341","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/36dea2f639249460d13f6ca66b2a9064187cd34d","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/a63eaf7605d1579cf3f551792e478cfaf5ac37d1","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/b15a3cc68e2450aa0edd94a74a7bdd45fcc17dd9","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/bc49e8746584564dba47d963d1916cc876fc6f6b","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/f1d04fefb0c2a2de32d9cee22cdc2088be3758d1","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/f3bd60b26814b7c3c57c629abb0857dfc76d214a","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/fb73cdc50b6755e5c3a80a195b2708a39ada0230","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-72407","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:22:14.300","lastModified":"2026-08-15T06:22:14.300","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\ngeneve: validate inner network offset in geneve_gro_complete()\n\nEven with both paths gated on gs->gro_hint, geneve_gro_complete()\nre-derives the inner dispatch type and length from the packet and the\ncurrent gs->gro_hint, independently of geneve_gro_receive(). The two can\ndisagree if gs->gro_hint flips under a concurrent geneve_quiesce()/\ngeneve_unquiesce() (sk_user_data is NULL across a synchronize_net()), or if\nthe re-read option bytes differ from the ones receive parsed.\n\ngeneve_gro_receive() already records the inner network header position in\nNAPI_GRO_CB()->inner_network_offset. Have geneve_gro_complete() compute the\noffset it is about to dispatch at, adding ETH_HLEN in the ETH_P_TEB case\nwhere eth_gro_complete() steps over the inner MAC header, and bail out if\nit lands past inner_network_offset.\n\nUse a lower bound rather than exact equality: between gh_len and the inner\nL3 header, geneve_gro_receive() may also have pulled an inner VLAN tag\n(vlan_gro_receive() advances the recorded offset past it), which only moves\ninner_network_offset further out. A valid frame therefore always satisfies\ninner_nh <= inner_network_offset, while a gh_len inflated by a hint\ngro_receive() did not honour dispatches past the validated inner header,\ni.e. the out-of-bounds completion. Only the latter is rejected."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/net/geneve.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"fd0dd796576e1a560e1441e665810129f0a82be0","lessThan":"e2087447f562692ff0cd08a0554d8d4ad083aa5c","versionType":"git","status":"affected"},{"version":"fd0dd796576e1a560e1441e665810129f0a82be0","lessThan":"cbb0d30a1ad6fc9439b1dc9b4f5a7a9140d3b11f","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/net/geneve.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"7.0","status":"affected"},{"version":"0","lessThan":"7.0","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/cbb0d30a1ad6fc9439b1dc9b4f5a7a9140d3b11f","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/e2087447f562692ff0cd08a0554d8d4ad083aa5c","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-72408","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:22:14.397","lastModified":"2026-08-15T06:22:14.397","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\ngeneve: gate GRO hint in geneve_gro_complete() on gs->gro_hint\n\ngeneve_gro_receive() reads the GRO hint through geneve_sk_gro_hint_off(),\nwhich honours it only when the socket enabled IFLA_GENEVE_GRO_HINT\n(gs->gro_hint). geneve_gro_complete() instead calls the low-level\ngeneve_opt_gro_hint_off() and acts on the hint unconditionally.\n\nOn a tunnel without the hint, receive aggregates the frames as plain\nETH_P_TEB while complete still honours an attacker-supplied hint option: it\ninflates gh_len by gro_hint->nested_hdr_len (u8) and redirects the dispatch\ntype, so the inner gro_complete handler runs at nhoff + gh_len, an offset\nreceive never pulled nor validated, reading out of bounds of the skb head:\n\n  BUG: KASAN: slab-out-of-bounds in ipv6_gro_complete (net/ipv6/ip6_offload.c:196)\n  Read of size 1 at addr ffff88800fe91980 by task exploit/153\n   ipv6_gro_complete (net/ipv6/ip6_offload.c:196)\n   geneve_gro_complete (drivers/net/geneve.c:965)\n   udp_gro_complete (net/ipv4/udp_offload.c:940)\n   inet_gro_complete (net/ipv4/af_inet.c:1621)\n   __gro_flush (net/core/gro.c:306)\n\nGate the complete path on gs->gro_hint too via geneve_sk_gro_hint_off(), so\nboth paths agree. Tunnels that enable the hint are unaffected."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/net/geneve.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"fd0dd796576e1a560e1441e665810129f0a82be0","lessThan":"49c2e7c0a69999a75ef5eaebe1559a20d0b3c15a","versionType":"git","status":"affected"},{"version":"fd0dd796576e1a560e1441e665810129f0a82be0","lessThan":"2651c174445884ac9e85622aeade9c1f7b98d8e5","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/net/geneve.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"7.0","status":"affected"},{"version":"0","lessThan":"7.0","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/2651c174445884ac9e85622aeade9c1f7b98d8e5","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/49c2e7c0a69999a75ef5eaebe1559a20d0b3c15a","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-72409","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:22:14.493","lastModified":"2026-08-15T06:22:14.493","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nnet: mvneta: re-enable percpu interrupt on resume\n\nOn Marvell MPIC platforms (Armada 370/XP/38x), mvneta uses a percpu\nIRQ disable/enable scheme for NAPI: the ISR (mvneta_percpu_isr) calls\ndisable_percpu_irq() to mask the MPIC per-CPU interrupt and schedules\nNAPI poll, which calls enable_percpu_irq() on completion to unmask.\n\nIf suspend occurs while NAPI poll is pending (between\ndisable_percpu_irq in the ISR and enable_percpu_irq in poll\ncompletion), the interrupt is never re-enabled:\n\n  1. mvneta_percpu_isr: disable_percpu_irq() + napi_schedule()\n     => MPIC masked, percpu_enabled cpumask bit cleared\n  2. NAPI poll does not complete before suspend proceeds\n     (on PREEMPT_RT this is highly likely since softirqs run in\n     ksoftirqd which gets frozen; on non-RT it can happen when\n     softirq processing is deferred to ksoftirqd)\n  3. mvneta_stop_dev => napi_disable(): cancels the pending poll\n     without executing the completion path\n  4. suspend_device_irqs => IRQCHIP_MASK_ON_SUSPEND: masks MPIC\n     (already masked, but records IRQS_SUSPENDED)\n  5. Resume: mpic_resume checks irq_percpu_is_enabled() => false\n     (bit was cleared in step 1) => skips unmask\n  6. mvneta_start_dev only restores device-level INTR_NEW_MASK,\n     does not touch the MPIC per-CPU mask\n\nResult: MPIC per-CPU interrupt stays masked permanently. The NIC\ngenerates interrupts (INTR_NEW_CAUSE != 0) but the CPU never\nreceives them, causing complete loss of network connectivity.\n\nFix by calling on_each_cpu(mvneta_percpu_enable) in the resume path\nto unconditionally unmask the MPIC per-CPU interrupt regardless of\npre-suspend state."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/net/ethernet/marvell/mvneta.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"12bb03b436dad56692e9a103ed26156156bef5d2","lessThan":"bf88cd3b649bc3e638f1e8a77649581852747a68","versionType":"git","status":"affected"},{"version":"12bb03b436dad56692e9a103ed26156156bef5d2","lessThan":"8c7a489aa71d2693752b2e794a68bf672d16c829","versionType":"git","status":"affected"},{"version":"12bb03b436dad56692e9a103ed26156156bef5d2","lessThan":"82c13027ed283b856017adee970dbfdffce5c6b8","versionType":"git","status":"affected"},{"version":"12bb03b436dad56692e9a103ed26156156bef5d2","lessThan":"be626ac1faadd49c2cead9f9cd06ba8752d81563","versionType":"git","status":"affected"},{"version":"12bb03b436dad56692e9a103ed26156156bef5d2","lessThan":"1cc312dc8bc78fa24c80d5bc193dbf5b57a99cc6","versionType":"git","status":"affected"},{"version":"12bb03b436dad56692e9a103ed26156156bef5d2","lessThan":"b84dd48f9da1eb132bdc06a944423cd5a1641ef1","versionType":"git","status":"affected"},{"version":"12bb03b436dad56692e9a103ed26156156bef5d2","lessThan":"5bdb33ff6e58bdc43632e98b30723eb65352d671","versionType":"git","status":"affected"},{"version":"12bb03b436dad56692e9a103ed26156156bef5d2","lessThan":"fd398d6480987e4c84fff0aaab6b9d6642a93343","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/net/ethernet/marvell/mvneta.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"4.4","status":"affected"},{"version":"0","lessThan":"4.4","versionType":"semver","status":"unaffected"},{"version":"5.10.261","lessThanOrEqual":"5.10.*","versionType":"semver","status":"unaffected"},{"version":"5.15.212","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.178","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.97","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/1cc312dc8bc78fa24c80d5bc193dbf5b57a99cc6","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/5bdb33ff6e58bdc43632e98b30723eb65352d671","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/82c13027ed283b856017adee970dbfdffce5c6b8","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/8c7a489aa71d2693752b2e794a68bf672d16c829","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/b84dd48f9da1eb132bdc06a944423cd5a1641ef1","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/be626ac1faadd49c2cead9f9cd06ba8752d81563","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/bf88cd3b649bc3e638f1e8a77649581852747a68","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/fd398d6480987e4c84fff0aaab6b9d6642a93343","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-72410","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:22:14.623","lastModified":"2026-08-15T06:22:14.623","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nocteontx2-af: Validate NIX maximum LFs correctly\n\nNIX maximum number of LFs can be set via devlink command\nbut that can be done before assigning any LFs to a PF/VF.\nThe condition used to check whether any LFs are assigned is\nincorrect. This patch fixes that condition."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/net/ethernet/marvell/octeontx2/af/rvu_devlink.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"dd7842878633453e38d6a4927593dd28b9d8ab91","lessThan":"0933fe0130eb71af0c3ab481b40f543b458a8c54","versionType":"git","status":"affected"},{"version":"dd7842878633453e38d6a4927593dd28b9d8ab91","lessThan":"e0ac054416bf4e913fe96cefefe94e3331bbe6fa","versionType":"git","status":"affected"},{"version":"dd7842878633453e38d6a4927593dd28b9d8ab91","lessThan":"b1f6381acf9d55fab208e8b4c252a5a671820bd9","versionType":"git","status":"affected"},{"version":"dd7842878633453e38d6a4927593dd28b9d8ab91","lessThan":"1576d12a39860418d6a68b402fda71a48f04a57c","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/net/ethernet/marvell/octeontx2/af/rvu_devlink.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.8","status":"affected"},{"version":"0","lessThan":"6.8","versionType":"semver","status":"unaffected"},{"version":"6.12.97","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/0933fe0130eb71af0c3ab481b40f543b458a8c54","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/1576d12a39860418d6a68b402fda71a48f04a57c","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/b1f6381acf9d55fab208e8b4c252a5a671820bd9","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/e0ac054416bf4e913fe96cefefe94e3331bbe6fa","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-72411","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:22:14.720","lastModified":"2026-08-15T06:22:14.720","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nnet: dsa: mxl862xx: fix use-after-free of DSA ports in crc_err_work\n\nUpon an MDIO CRC error mxl862xx_crc_err_work_fn() walks the DSA ports\nand closes the CPU port conduits:\n\n\tdsa_switch_for_each_cpu_port(dp, priv->ds)\n\t\tdev_close(dp->conduit);\n\nmxl862xx_remove() unregisters the switch before cancelling this work:\n\n\tset_bit(MXL862XX_FLAG_WORK_STOPPED, &priv->flags);\n\tcancel_delayed_work_sync(&priv->stats_work);\n\tdsa_unregister_switch(ds);\n\tmxl862xx_host_shutdown(priv);\n\ndsa_unregister_switch() frees the dsa_port objects. If a CRC error\nschedules the work during teardown it can run after the ports have been\nfreed and dereference freed memory.\n\nGuard the port walk with MXL862XX_FLAG_WORK_STOPPED, which is already set\nbefore dsa_unregister_switch(). DSA tears the ports down under\nrtnl_lock(), so checking the flag under rtnl_lock() means the work either\nruns before teardown and sees valid ports, or runs afterwards, observes\nthe flag and skips the walk. This mirrors the host_flood_work handler,\nwhich skips torn-down ports under rtnl_lock()."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/net/dsa/mxl862xx/mxl862xx-host.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"a319d0c8c8cede3b63538c9f111f84651d078bf6","lessThan":"cf52622fbc274eb4ca9a2066b258da2ae3dc7406","versionType":"git","status":"affected"},{"version":"a319d0c8c8cede3b63538c9f111f84651d078bf6","lessThan":"bcb3b8314611ed9cb4ff4bff484ef9b154fd1b83","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/net/dsa/mxl862xx/mxl862xx-host.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"7.1","status":"affected"},{"version":"0","lessThan":"7.1","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/bcb3b8314611ed9cb4ff4bff484ef9b154fd1b83","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/cf52622fbc274eb4ca9a2066b258da2ae3dc7406","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-72412","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:22:14.817","lastModified":"2026-08-15T06:22:14.817","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\ns390/mm: Fix handling of _PAGE_UNUSED pte bit\n\nThe _PAGE_UNUSED softbit should not really be lying around. Its sole\npurpose is to signal to try_to_unmap_one() and try_to_migrate_one()\nthat the page can be discarded instead of being moved / swapped.\n\nKVM has no way to know why a page is being unmapped, so it sets the bit\non userspace ptes corresponding to unused guest pages every time they\nget unmapped. KVM has no reasonable way to clear the bit once the page\nis in use again.\n\nWhile set_ptes() checks and clears the bit, other paths that set new\nptes did not. This led to used pages being thrown out as if they were\nunused, causing guest corruption.\n\nFix the issue by clearing the _PAGE_UNUSED bit for present ptes in\nset_pte(), i.e. whenever a present pte is getting set. The check in\nset_ptes() is then redundant and can be removed.\n\nAlso fix gmap_helper_try_set_pte_unused() to only set the bit if the\npte is present; the _PAGE_UNUSED bit is only defined for present ptes\nand thus should not be set for non-present ptes."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["arch/s390/include/asm/pgtable.h","arch/s390/mm/gmap_helpers.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"c98175b7917fa81cd499b1527c4a57fd7d36711e","lessThan":"fda07c8e4b54b9105f1ca73f0adea7b244d405f4","versionType":"git","status":"affected"},{"version":"c98175b7917fa81cd499b1527c4a57fd7d36711e","lessThan":"d4bb00704a66024502261fa7a523c07420249fea","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["arch/s390/include/asm/pgtable.h","arch/s390/mm/gmap_helpers.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"7.0","status":"affected"},{"version":"0","lessThan":"7.0","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/d4bb00704a66024502261fa7a523c07420249fea","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/fda07c8e4b54b9105f1ca73f0adea7b244d405f4","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-72413","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:22:14.910","lastModified":"2026-08-15T06:22:14.910","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nsctp: fix err_chunk memory leaks in INIT handling\n\nWhen sctp_verify_init() encounters unrecognized parameters, it allocates an\nerr_chunk to report them. However, this chunk is leaked in several code\npaths:\n\n1. In sctp_sf_do_5_1B_init(), if security_sctp_assoc_request() fails after\n   sctp_verify_init() has populated err_chunk, the function returns\n   immediately without freeing it.\n\n2. In sctp_sf_do_unexpected_init(), the same leak occurs on the\n   security_sctp_assoc_request() failure path.\n\n3. In sctp_sf_do_unexpected_init(), on the success path after copying\n   unrecognized parameters to the INIT-ACK, the function returns without\n   freeing err_chunk, unlike sctp_sf_do_5_1B_init() which properly frees\n   it.\n\nFix all three leaks by adding sctp_chunk_free(err_chunk) calls before\nreturning in the error paths and on the success path in\nsctp_sf_do_unexpected_init()."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["net/sctp/sm_statefuns.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"94f55994e19e8f0676990b9d5015b58ab6a97e00","versionType":"git","status":"affected"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"9f58a0a4d6c2ed5d341bba64f058f15d1b0c36f2","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["net/sctp/sm_statefuns.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"2.6.12","status":"affected"},{"version":"0","lessThan":"2.6.12","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/94f55994e19e8f0676990b9d5015b58ab6a97e00","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/9f58a0a4d6c2ed5d341bba64f058f15d1b0c36f2","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-72414","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:22:15.003","lastModified":"2026-08-15T06:22:15.003","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nnet: dsa: sja1105: round up PTP perout pin duration\n\npin_duration is converted from the user-provided period to SJA1105\nclock ticks and is later passed as the cycle_time argument to\nfuture_base_time().\n\nVery small period values may become zero after the conversion,\nwhich can lead to a division by zero in future_base_time().\n\nRound zero pin_duration up to 1 tick so that the smallest unsupported\nperiods use the minimum non-zero hardware duration instead of passing\nzero to future_base_time()."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/net/dsa/sja1105/sja1105_ptp.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"747e5eb31d59d047972a0dab03e5430fe4264332","lessThan":"aaf446099ca497c8d9a8e511fedf5d0e547bf8ec","versionType":"git","status":"affected"},{"version":"747e5eb31d59d047972a0dab03e5430fe4264332","lessThan":"201dcbbfb27f3db85c8cf125a75f3164a83ceb32","versionType":"git","status":"affected"},{"version":"747e5eb31d59d047972a0dab03e5430fe4264332","lessThan":"9952291db7125b8a62bf19800b93dcac81fc70c0","versionType":"git","status":"affected"},{"version":"747e5eb31d59d047972a0dab03e5430fe4264332","lessThan":"fc62bfd30d30af07356f0f7121c826e1e753582f","versionType":"git","status":"affected"},{"version":"747e5eb31d59d047972a0dab03e5430fe4264332","lessThan":"28d13a89a211cc07caeef32069eaa847131b7351","versionType":"git","status":"affected"},{"version":"747e5eb31d59d047972a0dab03e5430fe4264332","lessThan":"410629528067029096dba7ad7bc49e4a5e92708d","versionType":"git","status":"affected"},{"version":"747e5eb31d59d047972a0dab03e5430fe4264332","lessThan":"09efce96c909dff1a9317ec3714b7ddb4751b7af","versionType":"git","status":"affected"},{"version":"747e5eb31d59d047972a0dab03e5430fe4264332","lessThan":"aee5836273b07b439fb245fb43930664d8b78518","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/net/dsa/sja1105/sja1105_ptp.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"5.7","status":"affected"},{"version":"0","lessThan":"5.7","versionType":"semver","status":"unaffected"},{"version":"5.10.261","lessThanOrEqual":"5.10.*","versionType":"semver","status":"unaffected"},{"version":"5.15.212","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.178","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.97","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/09efce96c909dff1a9317ec3714b7ddb4751b7af","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/201dcbbfb27f3db85c8cf125a75f3164a83ceb32","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/28d13a89a211cc07caeef32069eaa847131b7351","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/410629528067029096dba7ad7bc49e4a5e92708d","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/9952291db7125b8a62bf19800b93dcac81fc70c0","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/aaf446099ca497c8d9a8e511fedf5d0e547bf8ec","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/aee5836273b07b439fb245fb43930664d8b78518","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/fc62bfd30d30af07356f0f7121c826e1e753582f","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-72415","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:22:15.127","lastModified":"2026-08-15T06:22:15.127","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nASoC: SDCA: Validate written enum value in ge_put_enum_double()\n\nge_put_enum_double() passes the user-supplied enumeration index\nitem[0] to snd_soc_enum_item_to_val() without checking it against the\nnumber of items in the enum:\n\n\tret = snd_soc_enum_item_to_val(e, item[0]);\n\nsnd_soc_enum_item_to_val() indexes the heap-allocated e->values[] array\nwith that index (e->values is set from a devm_kcalloc() of e->items\nentries), so a control write with an out-of-range item[0] reads past the\nend of the values buffer.  The bounds check in\nsnd_soc_dapm_put_enum_double() only runs afterwards, so it does not\nprevent the read here.\n\nReject an out-of-range item before using it, matching the other enum put\nhandlers.\n\nThis issue was pointed out by the Sashiko AI review bot while reviewing a\nrelated enum-validation series:\nhttps://lore.kernel.org/all/20260609125735.CEB651F00893@smtp.kernel.org/"}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["sound/soc/sdca/sdca_asoc.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"812ff1baa764080ba37bb0729e0c23c0e869b542","lessThan":"33387bf9bb6116a0429f823f8dab3accf8f8e09c","versionType":"git","status":"affected"},{"version":"812ff1baa764080ba37bb0729e0c23c0e869b542","lessThan":"1ce42a11bed134903e352010a01fa53073a6b395","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["sound/soc/sdca/sdca_asoc.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"7.0","status":"affected"},{"version":"0","lessThan":"7.0","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/1ce42a11bed134903e352010a01fa53073a6b395","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/33387bf9bb6116a0429f823f8dab3accf8f8e09c","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-72416","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:22:15.223","lastModified":"2026-08-15T06:22:15.223","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nnetfilter: nft_compat: ebtables emulation must reject non-bridge targets\n\nxtables targets return netfilter verdicts: NF_ACCEPT, NF_DROP, and so\non.  ebtables targets return incompatible verdicts: EBT_ACCEPT,\nEBT_DROP, ...   We cannot allow fallback to NFPROTO_UNSPEC.\n\nebtables doesn't permit this since\n11ff7288beb2 (\"netfilter: ebtables: reject non-bridge targets\")\nbut that commit missed the nft_compat layer."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["net/netfilter/nft_compat.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"0ca743a5599199152a31a7146b83213c786c2eb2","lessThan":"efc17b9240d821c424bc5191a5c6e9384a06293e","versionType":"git","status":"affected"},{"version":"0ca743a5599199152a31a7146b83213c786c2eb2","lessThan":"b3f7a84540a0d014ec42343ff5909657c1bd1994","versionType":"git","status":"affected"},{"version":"0ca743a5599199152a31a7146b83213c786c2eb2","lessThan":"33e1875d6b5b552a2e5652b40074c604199354ee","versionType":"git","status":"affected"},{"version":"0ca743a5599199152a31a7146b83213c786c2eb2","lessThan":"c129b0185e707dce405968e21afccd5728b2ce63","versionType":"git","status":"affected"},{"version":"0ca743a5599199152a31a7146b83213c786c2eb2","lessThan":"9dbba7e694ec045f21ede2f892fb42b81b4e1692","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["net/netfilter/nft_compat.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"3.13","status":"affected"},{"version":"0","lessThan":"3.13","versionType":"semver","status":"unaffected"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.97","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/33e1875d6b5b552a2e5652b40074c604199354ee","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/9dbba7e694ec045f21ede2f892fb42b81b4e1692","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/b3f7a84540a0d014ec42343ff5909657c1bd1994","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/c129b0185e707dce405968e21afccd5728b2ce63","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/efc17b9240d821c424bc5191a5c6e9384a06293e","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-72417","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:22:15.323","lastModified":"2026-08-15T06:22:15.323","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nnetfilter: flowtable: Validate iph->ihl in nf_flow_ip4_tunnel_proto()\n\nAdd sanity check for iph->ihl field in nf_flow_ip4_tunnel_proto() before\nusing it to compute the header size, avoiding out-of-bounds access with\nmalformed IP headers.\nWhile at it, use iph->protocol instead of the hardcoded IPPROTO_IPIP\nconstant when setting ctx->tun.proto and reference ctx->tun.hdr_size\nwhen updating ctx->offset."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["net/netfilter/nf_flow_table_ip.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"ab427db17885814069bae891834f20842f0ac3a4","lessThan":"025a41e76b51fbc7b8eaa5bacbaa9621d00e6aa7","versionType":"git","status":"affected"},{"version":"ab427db17885814069bae891834f20842f0ac3a4","lessThan":"84460b644329e25809b4a6d9279d6359d7fd8ebc","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["net/netfilter/nf_flow_table_ip.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.19","status":"affected"},{"version":"0","lessThan":"6.19","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/025a41e76b51fbc7b8eaa5bacbaa9621d00e6aa7","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/84460b644329e25809b4a6d9279d6359d7fd8ebc","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-72418","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:22:15.420","lastModified":"2026-08-15T06:22:15.420","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nnetfilter: nf_conncount: prevent connlimit drops for early confirmed ct\n\nCommit 69894e5b4c5e (\"netfilter: nft_connlimit: update the count if add\nwas skipped\") introduced a regression where packets for valid\nconnections are dropped when using connlimit for soft-limiting\nscenarios.\n\nThe issue occurs when a new connection reuses a socket currently in\nthe TIME_WAIT state. In this scenario, the connection tracking entry\nis evaluated as already confirmed. Previously, __nf_conncount_add()\nassumed that if a connection was confirmed and did not originate from\nthe loopback interface, it should skip the addition and return -EEXIST.\n\nSkipping the addition triggers a garbage collection run that cleans up\nthe TIME_WAIT connection. Consequently, the active connection count\ndrops to 0, which xt_connlimit mishandles, leading to the false rejection\nof the perfectly valid new connection.\n\nFix this by replacing the interface check with protocol-agnostic state\nchecks. We now skip the tree insertion and preserve the lockless garbage\ncollection optimization only if the connection is IPS_ASSURED. This\nallows early-confirmed setup packets (such as reused TIME_WAIT sockets\nor locally generated SYN-ACKs) to be properly evaluated and counted\nwithout falsely dropping. The goto check_connections path is maintained\nto ensure these setup packets are deduplicated correctly.\n\nThis has been tested with slowhttptest and HTTP server configured\nlocally to ensure we are not breaking soft-limiting scenarios for local\nor external connections. In addition, it was tested with a OVS zone\nlimit too."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["net/netfilter/nf_conncount.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"460c112e1d887b58b06b56e8e0230058906ff2c3","lessThan":"000ac6830b56499d6b65fd91486ce6689eb02be4","versionType":"git","status":"affected"},{"version":"53bc0ac47f4f7621c991807bc90e01df49561ac8","lessThan":"cbe2d14a7c5b1fc71821fbfee5c4963917411e92","versionType":"git","status":"affected"},{"version":"ca8b4d1d6304a84ce2016fa2fe9a114b9607b839","lessThan":"3793d24de224943e0a6016bbeffb6f5c4cea2e3d","versionType":"git","status":"affected"},{"version":"8286c02fe9100330475331253fc590f047963f90","lessThan":"abef7f817217fcb62c11821d6b895063eadb2828","versionType":"git","status":"affected"},{"version":"b29ddccf36946a90323486221f39e9f88cc01b8e","lessThan":"ebfe8249ba79e4ff0f1e3aad8787b992ef27f026","versionType":"git","status":"affected"},{"version":"77ea3d8ac3d3d59b5ac9ad639e4ba107c0f2ff1e","lessThan":"329f2626ee5cb8fafdf6b58b624311529c57cb45","versionType":"git","status":"affected"},{"version":"69894e5b4c5e28cda5f32af33d4a92b7a4b93b0e","lessThan":"be52572c6d55f677ba76869d3c63805c0d4891a3","versionType":"git","status":"affected"},{"version":"69894e5b4c5e28cda5f32af33d4a92b7a4b93b0e","lessThan":"c8b6f36f766991e3ebebec6596daee4b04dcbc49","versionType":"git","status":"affected"},{"version":"f85623af16b83615e5f64a9b19ae1d584805cb07","versionType":"git","status":"affected"},{"version":"5.10.248","lessThan":"5.10.261","versionType":"semver","status":"affected"},{"version":"5.15.198","lessThan":"5.15.212","versionType":"semver","status":"affected"},{"version":"6.1.160","lessThan":"6.1.178","versionType":"semver","status":"affected"},{"version":"6.6.120","lessThan":"6.6.145","versionType":"semver","status":"affected"},{"version":"6.12.63","lessThan":"6.12.97","versionType":"semver","status":"affected"},{"version":"6.18.2","lessThan":"6.18.40","versionType":"semver","status":"affected"},{"version":"6.17.13","lessThan":"6.18","versionType":"semver","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["net/netfilter/nf_conncount.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.19","status":"affected"},{"version":"0","lessThan":"6.19","versionType":"semver","status":"unaffected"},{"version":"5.10.261","lessThanOrEqual":"5.10.*","versionType":"semver","status":"unaffected"},{"version":"5.15.212","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.178","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.97","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/000ac6830b56499d6b65fd91486ce6689eb02be4","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/329f2626ee5cb8fafdf6b58b624311529c57cb45","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/3793d24de224943e0a6016bbeffb6f5c4cea2e3d","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/abef7f817217fcb62c11821d6b895063eadb2828","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/be52572c6d55f677ba76869d3c63805c0d4891a3","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/c8b6f36f766991e3ebebec6596daee4b04dcbc49","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/cbe2d14a7c5b1fc71821fbfee5c4963917411e92","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/ebfe8249ba79e4ff0f1e3aad8787b992ef27f026","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-72419","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:22:15.573","lastModified":"2026-08-15T06:22:15.573","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nnetfilter: nf_nat: avoid invalid nat_net pointer use on failed nf_nat_init()\n\nWe ran into below KASAN splat, which is mostly uninteresting, beside\nfor having nf_nat_register_fn() in the call chain as a cause for the\noffending access:\n\n==================================================================\nBUG: KASAN: slab-out-of-bounds in nf_nat_register_fn+0x5f9/0x640\nRead of size 8 at addr ffff890031e54c20 by task iptables/9510\n\nCPU: 0 UID: 0 PID: 9510 Comm: iptables Not tainted 6.18.18-grsec-full-20260320181326 #1 PREEMPT(voluntary)\nHardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS 1.16.3-debian-1.16.3-2 04/01/2014\nCall Trace:\n <TASK>\n […] dump_stack_lvl+0xee/0x160 ffff88004117eeb8\n […] print_report+0x6e/0x640 ffff88004117eee0\n […] ? __phys_addr+0x8e/0x140 ffff88004117eef0\n […] ? kasan_addr_to_slab+0x51/0xe0 ffff88004117ef08\n […] ? complete_report_info+0xec/0x1c0 ffff88004117ef20\n […] ? nf_nat_register_fn+0x5f9/0x640 ffff88004117ef48\n […] kasan_report+0xbc/0x140 ffff88004117ef50\n […] ? nf_nat_register_fn+0x5f9/0x640 ffff88004117ef90\n […] nf_nat_register_fn+0x5f9/0x640 ffff88004117eff8\n […] ? nf_nat_icmp_reply_translation+0x6e0/0x6e0 ffff88004117f070\n […] nf_tables_register_hook.part.0+0xa0/0x220 ffff88004117f080\n […] nf_tables_addchain.constprop.0+0x1054/0x1fc0 ffff88004117f0b8\n […] ? nft_chain_lookup.part.0+0x4ce/0xac0 ffff88004117f130\n […] ? nf_tables_abort+0x3d80/0x3d80 ffff88004117f190\n […] ? nf_tables_dumpreset_obj+0x100/0x100 ffff88004117f1c8\n […] ? nft_table_lookup.part.0+0x255/0x300 ffff88004117f310\n […] ? nf_tables_newchain+0x21a4/0x2fa0 ffff88004117f358\n […] nf_tables_newchain+0x21a4/0x2fa0 ffff88004117f360\n […] ? nf_tables_addchain.constprop.0+0x1fc0/0x1fc0 ffff88004117f458\n […] ? nla_get_range_signed+0x4a0/0x4a0 ffff88004117f488\n […] ? lock_acquire+0x16f/0x320 ffff88004117f490\n […] ? find_held_lock+0x3b/0xe0 ffff88004117f4b0\n […] ? __nla_parse+0x45/0x80 ffff88004117f500\n […] nfnetlink_rcv_batch+0xbca/0x19a0 ffff88004117f550\n […] ? nfnetlink_net_exit_batch+0x120/0x120 ffff88004117f618\n […] ? __sanitizer_cov_trace_switch+0x63/0xe0 ffff88004117f720\n […] ? gr_acl_handle_mmap+0x1c4/0x320 ffff88004117f7c0\n […] ? nla_get_range_signed+0x4a0/0x4a0 ffff88004117f7e8\n […] ? gr_is_capable+0x6f/0xe0 ffff88004117f830\n […] ? __nla_parse+0x45/0x80 ffff88004117f860\n […] ? skb_pull+0x103/0x1a0 ffff88004117f880\n […] nfnetlink_rcv+0x3db/0x4a0 ffff88004117f8b0\n […] ? nfnetlink_rcv_batch+0x19a0/0x19a0 ffff88004117f8d8\n […] ? netlink_lookup+0xe2/0x240 ffff88004117f900\n […] netlink_unicast+0x74b/0xb00 ffff88004117f930\n […] ? netlink_attachskb+0xb20/0xb20 ffff88004117f980\n […] ? __check_object_size+0x3e/0xaa0 ffff88004117f998\n […] ? security_netlink_send+0x51/0x160 ffff88004117f9c8\n […] netlink_sendmsg+0xa03/0x1200 ffff88004117f9f8\n […] ? netlink_unicast+0xb00/0xb00 ffff88004117fa70\n […] ? netlink_unicast+0xb00/0xb00 ffff88004117fac8\n […] ? ____sys_sendmsg+0xe2a/0x1040 ffff88004117faf8\n […] ____sys_sendmsg+0xe2a/0x1040 ffff88004117fb00\n […] ? kernel_recvmsg+0x300/0x300 ffff88004117fb60\n […] ? reacquire_held_locks+0xe9/0x260 ffff88004117fbc8\n […] ___sys_sendmsg+0x138/0x200 ffff88004117fbf8\n […] ? do_recvmmsg+0x7e0/0x7e0 ffff88004117fc30\n […] ? lockdep_hardirqs_on_prepare+0x101/0x1e0 ffff88004117fc50\n […] ? lock_acquire+0x16f/0x320 ffff88004117fd20\n […] ? lock_acquire+0x16f/0x320 ffff88004117fd58\n […] ? find_held_lock+0x3b/0xe0 ffff88004117fd70\n […] __sys_sendmsg+0x17a/0x260 ffff88004117fdc8\n […] ? __sys_sendmsg_sock+0x80/0x80 ffff88004117fdf0\n […] ? syscall_trace_enter+0x15e/0x2c0 ffff88004117fe98\n […] do_syscall_64+0x7d/0x400 ffff88004117fec8\n […] entry_SYSCALL_64_safe_stack+0x4a/0x60 ffff88004117fef8\n </TASK>\n==================================================================\n\nThe out-of-bounds report, though, is a red herring as it is f\n---truncated---"}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["net/netfilter/nf_nat_core.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"cbc1dd5b659f5a2c3cba88b197b7443679bb35a0","lessThan":"359d8ff97362a4662356104540e4814bff9dad7c","versionType":"git","status":"affected"},{"version":"cbc1dd5b659f5a2c3cba88b197b7443679bb35a0","lessThan":"87f7a720de2545fdac29c85acb7163676feacdaf","versionType":"git","status":"affected"},{"version":"cbc1dd5b659f5a2c3cba88b197b7443679bb35a0","lessThan":"e794f633021defcfa98e17d73b955cd07590831f","versionType":"git","status":"affected"},{"version":"cbc1dd5b659f5a2c3cba88b197b7443679bb35a0","lessThan":"a73e7ac3f3b69e9581ec7bfd889ff3e9b8c773f7","versionType":"git","status":"affected"},{"version":"cbc1dd5b659f5a2c3cba88b197b7443679bb35a0","lessThan":"eb14aba91163c33d8c99f9d7c06690e08b56a250","versionType":"git","status":"affected"},{"version":"cbc1dd5b659f5a2c3cba88b197b7443679bb35a0","lessThan":"069cfe3de2a5e16069485893cd04665ab769c1d8","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["net/netfilter/nf_nat_core.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.1","status":"affected"},{"version":"0","lessThan":"6.1","versionType":"semver","status":"unaffected"},{"version":"6.1.178","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.97","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/069cfe3de2a5e16069485893cd04665ab769c1d8","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/359d8ff97362a4662356104540e4814bff9dad7c","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/87f7a720de2545fdac29c85acb7163676feacdaf","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/a73e7ac3f3b69e9581ec7bfd889ff3e9b8c773f7","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/e794f633021defcfa98e17d73b955cd07590831f","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/eb14aba91163c33d8c99f9d7c06690e08b56a250","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-72420","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:22:15.743","lastModified":"2026-08-15T06:22:15.743","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nmd/raid5: avoid R5_Overlap races while breaking stripe batches\n\nKCSAN report a race in break_stripe_batch_list() vs. raid5_make_request()\non sh->dev[i].flags (plain word write vs. atomic bit op)..\n\nand .. one possible scenario is:\n\nCPU1                            CPU2\nbreak_stripe_batch_list(sh1)\n-> handle sh2\n-> lock(sh2)\n-> sh2->batch_head = NULL\n-> unlock(sh2)\n-> test_and_clear_bit(R5_Overlap, sh2->dev[i].flags)\n-> wake_up_bit(sh2->dev[i].flags)\n                                raid5_make_request()\n                                -> add_all_stripe_bios(sh2)\n                                -> lock(sh2)\n                                -> stripe_bio_overlaps(sh2) returns true\n\t\t\t\t   batch_head is NULL, so new bio overlap\n\t\t\t\t   exist bio on sh2 -> true\n                                -> set_bit(R5_Overlap, sh2->dev[i].flags)\n                                -> unlock(sh2)\n                                -> wait_on_bit(sh2->dev[i].flags)\n-> sh2->dev[i].flags = sh1->dev[i].flags & ~R5_Overlap\n\nNo wait_up_bit(), CPU2 could be wait_on_bit() forever...\n\nFix by :\n- Expand the protect zone.\n- Use batch_head's device flag's snaphot when no held head_sh->stripe_lock.\n- Move sh/head_sh->batch_head = NULL to the end of protected zone , and ,\n  any concurrent add_all_stripe_bios() grabs sh->stripe_lock now either:\n\t- see batch_head != null, and , is rejected by stripe_bio_overlaps()\n\t  under the lock (no R5_Overlap wait ) , or ,\n\t- sees batch_head == NULL, only after dev[i].flags has already been\n\t  set and the prior R5_Overlap waiters worken.\n\nKCSAN report:\n================================================\n  BUG: KCSAN: data-race in break_stripe_batch_list / raid5_make_request\n\n  write (marked) to 0xffff8e89c8117548 of 8 bytes by task 4042 on cpu 0:\n    raid5_make_request+0xea0/0x2930\n    md_handle_request+0x4a2/0xa40\n    md_submit_bio+0x109/0x1a0\n    __submit_bio+0x2ec/0x390\n    submit_bio_noacct_nocheck+0x457/0x710\n    submit_bio_noacct+0x2a7/0xc20\n    submit_bio+0x56/0x250\n    blkdev_direct_IO+0x54c/0xda0\n    blkdev_write_iter+0x38f/0x570\n    aio_write+0x22b/0x490\n    io_submit_one+0xa51/0xf70\n    __x64_sys_io_submit+0xf7/0x220\n    x64_sys_call+0x1907/0x1c60\n    do_syscall_64+0x130/0x570\n    entry_SYSCALL_64_after_hwframe+0x76/0x7e\n\n  read to 0xffff8e89c8117548 of 8 bytes by task 4010 on cpu 5:\n    break_stripe_batch_list+0x249/0x480\n    handle_stripe_clean_event+0x720/0x9b0\n    handle_stripe+0x32fb/0x4500\n    handle_active_stripes.isra.0+0x6e0/0xa50\n    raid5d+0x7e0/0xba0\n    md_thread+0x15a/0x2d0\n    kthread+0x1e3/0x220\n    ret_from_fork+0x37a/0x410\n    ret_from_fork_asm+0x1a/0x30\n\n  value changed: 0x0000000000000019 -> 0x0000000000000099 --> R5_Overlap"}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/md/raid5.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"fb642b92c267beeefd352af9bc461eac93a7552c","lessThan":"8031b0d02bd221a5f9add4357e291fc2a527b83a","versionType":"git","status":"affected"},{"version":"fb642b92c267beeefd352af9bc461eac93a7552c","lessThan":"4d919c9b770996365806b6c8d701912d52baa306","versionType":"git","status":"affected"},{"version":"fb642b92c267beeefd352af9bc461eac93a7552c","lessThan":"d684b72dfbd320623ccaab0779aa841190488e7c","versionType":"git","status":"affected"},{"version":"fb642b92c267beeefd352af9bc461eac93a7552c","lessThan":"55b77337bdd088c77461588e5ec094421b89911b","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/md/raid5.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"4.1","status":"affected"},{"version":"0","lessThan":"4.1","versionType":"semver","status":"unaffected"},{"version":"6.12.97","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/4d919c9b770996365806b6c8d701912d52baa306","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/55b77337bdd088c77461588e5ec094421b89911b","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/8031b0d02bd221a5f9add4357e291fc2a527b83a","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/d684b72dfbd320623ccaab0779aa841190488e7c","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-72421","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:22:15.867","lastModified":"2026-08-15T06:22:15.867","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nipv4: fib: Don't ignore error route in local/main tables.\n\nWhen CONFIG_IP_MULTIPLE_TABLES is enabled but no rule is added,\nfib_lookup() performs route lookup directly on two tables.\n\nSince the first lookup does not properly bail out, the result\nof an error route in the merged local/main table could be\noverwritten by another route in the default table:\n\n  # unshare -n\n  # ip link set lo up\n  # ip route add 192.168.0.0/24 dev lo table 253\n  # ip route add unreachable 192.168.0.0/24\n  # ip route get 192.168.0.1\n  192.168.0.1 dev lo table default uid 0\n      cache <local>\n\nOnce a random rule is added, the error route is respected:\n\n  # ip rule add table 0\n  # ip rule del table 0\n  # ip route get 192.168.0.1\n  RTNETLINK answers: No route to host\n\nLet's fix the inconsistent behaviour."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["include/net/ip_fib.h"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"f4530fa574df4d833506c53697ed1daa0d390bf4","lessThan":"a29e95fbc51e8a1b932773fd0e259b2080881443","versionType":"git","status":"affected"},{"version":"f4530fa574df4d833506c53697ed1daa0d390bf4","lessThan":"5ae18d87a45698e8244d0fcba64c658c35a7dd3d","versionType":"git","status":"affected"},{"version":"f4530fa574df4d833506c53697ed1daa0d390bf4","lessThan":"9127589aabdee588278e8d0d0bd3709a760a92c8","versionType":"git","status":"affected"},{"version":"f4530fa574df4d833506c53697ed1daa0d390bf4","lessThan":"49eaf1403201357762d745a35882fb734107d763","versionType":"git","status":"affected"},{"version":"f4530fa574df4d833506c53697ed1daa0d390bf4","lessThan":"fd25996f57a95d56bc568c89b4921edcf334b7d8","versionType":"git","status":"affected"},{"version":"f4530fa574df4d833506c53697ed1daa0d390bf4","lessThan":"828fad4fd418bcdb9f5d66fec0d184c52a85ec31","versionType":"git","status":"affected"},{"version":"f4530fa574df4d833506c53697ed1daa0d390bf4","lessThan":"a668fa160247d7bbe921548cb845f607b8b9305f","versionType":"git","status":"affected"},{"version":"f4530fa574df4d833506c53697ed1daa0d390bf4","lessThan":"b72f0db64205d9ce462038ba995d5d31eff32dc1","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["include/net/ip_fib.h"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"3.6","status":"affected"},{"version":"0","lessThan":"3.6","versionType":"semver","status":"unaffected"},{"version":"5.10.261","lessThanOrEqual":"5.10.*","versionType":"semver","status":"unaffected"},{"version":"5.15.212","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.178","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.97","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/49eaf1403201357762d745a35882fb734107d763","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/5ae18d87a45698e8244d0fcba64c658c35a7dd3d","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/828fad4fd418bcdb9f5d66fec0d184c52a85ec31","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/9127589aabdee588278e8d0d0bd3709a760a92c8","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/a29e95fbc51e8a1b932773fd0e259b2080881443","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/a668fa160247d7bbe921548cb845f607b8b9305f","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/b72f0db64205d9ce462038ba995d5d31eff32dc1","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/fd25996f57a95d56bc568c89b4921edcf334b7d8","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-72422","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:22:15.987","lastModified":"2026-08-15T06:22:15.987","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nksmbd: fix use-after-free of conn->preauth_info in concurrent SMB2 NEGOTIATE\n\nconn->preauth_info is shared connection state (struct\npreauth_integrity_info, kmalloc-96) that is allocated and freed by the\nSMB2 NEGOTIATE handler and read by the response send path.\n\nsmb2_handle_negotiate() allocates conn->preauth_info, and on a\ndeassemble_neg_contexts() failure kfrees it and sets it to NULL. Both the\nallocation and the free/NULL happen under ksmbd_conn_lock(conn) (the\nconnection srv_mutex), which is held across the whole handler body.\n\nThe response send path smb3_preauth_hash_rsp(), called from the send:\nblock of __handle_ksmbd_work(), reads conn->preauth_info and dereferences\nconn->preauth_info->Preauth_HashValue (via\nksmbd_gen_preauth_integrity_hash()) without taking conn_lock. When a\nclient drives two SMB2 NEGOTIATE requests on the same connection, one\nworker can free conn->preauth_info on the failing-negotiate path while a\nconcurrent send-path worker is reading it, producing a slab\nuse-after-free read (KASAN-confirmed).\n\nThe send-path read tested conn->preauth_info for NULL but raced with the\nfree that occurs between the NULL check and the dereference, so the NULL\nguard alone does not close the window.\n\nSerialize the NEGOTIATE-branch read in smb3_preauth_hash_rsp() under\nksmbd_conn_lock(conn) and re-check conn->preauth_info inside the lock.\nBecause the negotiate handler holds conn_lock across its kfree + NULL\nassignment, a reader that also takes conn_lock either runs fully before\nthe allocation or fully after the NULL store, and can never observe the\nfreed-but-not-yet-NULLed pointer. ksmbd_gen_preauth_integrity_hash()\ntakes no locks itself (it only computes a SHA-512 over the buffer), so\nno lock-ordering inversion is introduced, and conn_lock is a sleepable\nmutex which is safe on this send path (it already performs network I/O)."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["fs/smb/server/smb2pdu.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"dd4e4c811898410e6a3ae3b63207b7c542860907","lessThan":"c7bef84740d1d57848c74f6f5b996606e43ea4fe","versionType":"git","status":"affected"},{"version":"aa7253c2393f6dcd6a1468b0792f6da76edad917","lessThan":"d0a469122e7bf8338fec1949fb1e8e1290ed8caa","versionType":"git","status":"affected"},{"version":"aa7253c2393f6dcd6a1468b0792f6da76edad917","lessThan":"7470511d085af1c7a043a60e53d52b512d5a10b1","versionType":"git","status":"affected"},{"version":"aa7253c2393f6dcd6a1468b0792f6da76edad917","lessThan":"16a1ecf39c217e3d164bd32ef2a4f650abc067fa","versionType":"git","status":"affected"},{"version":"aa7253c2393f6dcd6a1468b0792f6da76edad917","lessThan":"77bb0bbfcc4e777ca653174689e5e363f8ee63d1","versionType":"git","status":"affected"},{"version":"aa7253c2393f6dcd6a1468b0792f6da76edad917","lessThan":"1c89da3baa2b1f269178afa87dc30479b8535776","versionType":"git","status":"affected"},{"version":"aa7253c2393f6dcd6a1468b0792f6da76edad917","lessThan":"0c054227479ed7e36ebccb3a558bc0ef698264f6","versionType":"git","status":"affected"},{"version":"8a8315a5960bd2b5ffc75f44fc089e57c3b17c44","versionType":"git","status":"affected"},{"version":"ff20f1875889dbe4a67c9298e609d7c88cf6456d","versionType":"git","status":"affected"},{"version":"5.15.61","lessThan":"5.15.212","versionType":"semver","status":"affected"},{"version":"5.18.18","lessThan":"5.19","versionType":"semver","status":"affected"},{"version":"5.19.2","lessThan":"5.20","versionType":"semver","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["fs/smb/server/smb2pdu.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.0","status":"affected"},{"version":"0","lessThan":"6.0","versionType":"semver","status":"unaffected"},{"version":"5.15.212","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.178","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.97","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/0c054227479ed7e36ebccb3a558bc0ef698264f6","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/16a1ecf39c217e3d164bd32ef2a4f650abc067fa","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/1c89da3baa2b1f269178afa87dc30479b8535776","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/7470511d085af1c7a043a60e53d52b512d5a10b1","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/77bb0bbfcc4e777ca653174689e5e363f8ee63d1","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/c7bef84740d1d57848c74f6f5b996606e43ea4fe","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/d0a469122e7bf8338fec1949fb1e8e1290ed8caa","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-72423","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:22:16.117","lastModified":"2026-08-15T06:22:16.117","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nbpf: Guard conntrack opts error writes\n\nThe conntrack lookup and allocation kfuncs take an opts pointer\ntogether with an opts__sz argument. The verifier checks only the memory\nrange described by opts__sz, but the wrappers unconditionally write\nopts->error whenever the internal lookup or allocation helper returns an\nerror.\n\nFor an invalid size smaller than the end of opts->error, that write can\nland outside the verifier-checked range. Keep returning NULL for invalid\narguments, but only report the error through opts->error when the\nsupplied size includes the field.\n\nThis preserves error reporting for the supported 12-byte and 16-byte\nlayouts, and for other invalid sizes that still include opts->error."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["net/netfilter/nf_conntrack_bpf.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"b4c2b9593a1c4c3a718370e34af28e817fd5e5c6","lessThan":"dd74c80203842a21b2ebb9f70d1260d9aa20fa05","versionType":"git","status":"affected"},{"version":"b4c2b9593a1c4c3a718370e34af28e817fd5e5c6","lessThan":"6f6183a39533d727deaa5061cadae6dd9e6744d0","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["net/netfilter/nf_conntrack_bpf.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"5.18","status":"affected"},{"version":"0","lessThan":"5.18","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/6f6183a39533d727deaa5061cadae6dd9e6744d0","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/dd74c80203842a21b2ebb9f70d1260d9aa20fa05","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-72424","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:22:16.210","lastModified":"2026-08-15T06:22:16.210","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nrtc: msc313: fix NULL deref in shared IRQ handler at probe\n\nmsc313_rtc_probe() calls devm_request_irq() with IRQF_SHARED and\n&pdev->dev as the cookie, but platform_set_drvdata() is only called\nlater after the clock setup. With a shared IRQ line, another device\non the same line can trigger the handler in that window. The\nhandler does dev_get_drvdata() on the cookie, gets NULL, and\ndereferences priv->rtc_base in interrupt context.\n\nPass priv as the cookie directly so the handler reads it from\ndev_id without the lookup, removing the dependency on probe order."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/rtc/rtc-msc313.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"be7d9c9161b9c76edeff15e79edc2f256568fe05","lessThan":"ece7b9ffde23e2ccd7567761ac27463ded43932c","versionType":"git","status":"affected"},{"version":"be7d9c9161b9c76edeff15e79edc2f256568fe05","lessThan":"52c73b6992b46ed476590ed526faa033d4fbfc5d","versionType":"git","status":"affected"},{"version":"be7d9c9161b9c76edeff15e79edc2f256568fe05","lessThan":"bc1f61a9b97d65de21c2681bcf0b5b1392c58486","versionType":"git","status":"affected"},{"version":"be7d9c9161b9c76edeff15e79edc2f256568fe05","lessThan":"1f6a4aec0d36647eb2f67cd69db22bd28cabe2cb","versionType":"git","status":"affected"},{"version":"be7d9c9161b9c76edeff15e79edc2f256568fe05","lessThan":"bb3e624808c981fe881cb79037be63e680ed7d38","versionType":"git","status":"affected"},{"version":"be7d9c9161b9c76edeff15e79edc2f256568fe05","lessThan":"a369f48be8de426a7d2bca18dbd46c2ad1138803","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/rtc/rtc-msc313.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"5.16","status":"affected"},{"version":"0","lessThan":"5.16","versionType":"semver","status":"unaffected"},{"version":"6.1.178","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.97","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/1f6a4aec0d36647eb2f67cd69db22bd28cabe2cb","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/52c73b6992b46ed476590ed526faa033d4fbfc5d","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/a369f48be8de426a7d2bca18dbd46c2ad1138803","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/bb3e624808c981fe881cb79037be63e680ed7d38","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/bc1f61a9b97d65de21c2681bcf0b5b1392c58486","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/ece7b9ffde23e2ccd7567761ac27463ded43932c","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-72425","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:22:16.317","lastModified":"2026-08-15T06:22:16.317","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nice: fix FDIR CTRL VSI resource leak in ice_reset_all_vfs()\n\nResetting all VFs causes resource leak on VFs with FDIR filters\nenabled as CTRL VSIs are only invalidated and not freed. Fix by using\nice_vf_ctrl_vsi_release() instead of ice_vf_ctrl_invalidate_vsi() which\naligns behavior with the ice_reset_vf() function.\n\nReproduction:\n  echo 1 > /sys/class/net/$pf/device/sriov_numvfs\n  ethtool -N $vf flow-type ether proto 0x9000 action 0\n  echo 1 > /sys/class/net/$pf/device/reset"}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/net/ethernet/intel/ice/ice_vf_lib.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"da62c5ff9dcdac67204d6647f3cd43ad931a59f4","lessThan":"b409a9dc37db8bd798122fc5bcdcfaccaf80db1e","versionType":"git","status":"affected"},{"version":"da62c5ff9dcdac67204d6647f3cd43ad931a59f4","lessThan":"335c2dd21ad9d520102906f96edb99fd5e89ac32","versionType":"git","status":"affected"},{"version":"da62c5ff9dcdac67204d6647f3cd43ad931a59f4","lessThan":"87a042e45bf4870dc75ea05b4fc0286abecb2a4d","versionType":"git","status":"affected"},{"version":"da62c5ff9dcdac67204d6647f3cd43ad931a59f4","lessThan":"dd6d8e4412f805937f61f00bbfdfe831978be235","versionType":"git","status":"affected"},{"version":"da62c5ff9dcdac67204d6647f3cd43ad931a59f4","lessThan":"b1fc5bafbc5f84df457b6f987ac993e0802f8d93","versionType":"git","status":"affected"},{"version":"da62c5ff9dcdac67204d6647f3cd43ad931a59f4","lessThan":"ebbe8868cf473f698e0fbaf436d2618b2bcda806","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/net/ethernet/intel/ice/ice_vf_lib.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"5.13","status":"affected"},{"version":"0","lessThan":"5.13","versionType":"semver","status":"unaffected"},{"version":"6.1.178","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.97","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/335c2dd21ad9d520102906f96edb99fd5e89ac32","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/87a042e45bf4870dc75ea05b4fc0286abecb2a4d","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/b1fc5bafbc5f84df457b6f987ac993e0802f8d93","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/b409a9dc37db8bd798122fc5bcdcfaccaf80db1e","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/dd6d8e4412f805937f61f00bbfdfe831978be235","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/ebbe8868cf473f698e0fbaf436d2618b2bcda806","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-72426","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:22:16.427","lastModified":"2026-08-15T06:22:16.427","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nbpf: Preserve pointer spill metadata during half-slot cleanup\n\n__clean_func_state() cleans dead stack slots in 4-byte halves. When the\nhigh half of a STACK_SPILL slot is dead and the low half remains live,\ncleanup converts the live low half to STACK_MISC or STACK_ZERO and clears\nthe saved spilled_ptr metadata.\n\nThat conversion is safe only for scalar spills. For a pointer spill, this\nmetadata clear lets a later 32-bit fill from the still-live half avoid the\nnormal non-scalar register-fill check and be treated as an ordinary scalar\nstack read.\n\nLeave non-scalar spill slots intact in this half-live shape. This is\nconservative for pruning and preserves the existing\ncheck_stack_read_fixed_off() rejection path for partial fills from pointer\nspills."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["kernel/bpf/states.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"be23266b4a08540aa43d8503a2ea10247c8daebe","lessThan":"0f9278b22cda6fd2525049930157b79b4036b4ef","versionType":"git","status":"affected"},{"version":"be23266b4a08540aa43d8503a2ea10247c8daebe","lessThan":"3a354149bceacadbcf7d7b4766f5ef26a85892ab","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["kernel/bpf/states.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"7.1","status":"affected"},{"version":"0","lessThan":"7.1","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/0f9278b22cda6fd2525049930157b79b4036b4ef","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/3a354149bceacadbcf7d7b4766f5ef26a85892ab","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-72427","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:22:16.520","lastModified":"2026-08-15T06:22:16.520","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nbpf: Fix effective prog array index with BPF_F_PREORDER\n\nreplace_effective_prog() and purge_effective_progs() located the slot in\nthe effective array by walking the program hlist and counting entries\nlinearly. That count does not match the array layout: compute_effective_\nprogs() places BPF_F_PREORDER programs at the front (ancestor cgroup\nfirst, attach order within a cgroup) and the rest after them (descendant\ncgroup first). So when a preorder program is present, the linear hlist\nposition no longer equals the program's index in the effective array.\n\nFor replace_effective_prog() (bpf_link_update()) this overwrote the\nwrong slot, corrupting the effective order. For purge_effective_progs(),\nit could dummy out a slot belonging to a different program and leave the\ndetached program in the array while bpf_prog_put() drops its reference,\ni.e. a use-after-free.\n\nFix both by replaying compute_effective_progs()'s placement (including\nthe per-cgroup preorder reversal) in a shared effective_prog_pos()\nhelper. Identify the entry by its struct bpf_prog_list pointer rather\nthan by (prog, link) value, so the lookup resolves to exactly the\nattachment the syscall selected even when the same bpf_prog is attached\nto several cgroups in the hierarchy."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["kernel/bpf/cgroup.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"bc8023ef3b11410682e5d4990e05e5bc2d3e1c94","lessThan":"525e408c27ae714e538b8c608c3a974df3ab6c92","versionType":"git","status":"affected"},{"version":"555c0b713ca83968d3c843cb15485b9ba3367b1b","lessThan":"41b4320b84fdafe1ab586b06453d30d50415db59","versionType":"git","status":"affected"},{"version":"4b82b181a26cff8bf7adc3a85a88d121d92edeaf","lessThan":"9697db03e010391c55ae75192cbdf30c5a72c114","versionType":"git","status":"affected"},{"version":"4b82b181a26cff8bf7adc3a85a88d121d92edeaf","lessThan":"b584f107ab90222bd825dcb4c5977326ff684109","versionType":"git","status":"affected"},{"version":"4b82b181a26cff8bf7adc3a85a88d121d92edeaf","lessThan":"f08aaee3152d0dfc578b3f2586932d82062701dd","versionType":"git","status":"affected"},{"version":"4707ad649cf662add3058bff47430817811b048d","versionType":"git","status":"affected"},{"version":"6.6.93","lessThan":"6.6.145","versionType":"semver","status":"affected"},{"version":"6.12.31","lessThan":"6.12.97","versionType":"semver","status":"affected"},{"version":"6.14.9","lessThan":"6.15","versionType":"semver","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["kernel/bpf/cgroup.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.15","status":"affected"},{"version":"0","lessThan":"6.15","versionType":"semver","status":"unaffected"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.97","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/41b4320b84fdafe1ab586b06453d30d50415db59","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/525e408c27ae714e538b8c608c3a974df3ab6c92","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/9697db03e010391c55ae75192cbdf30c5a72c114","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/b584f107ab90222bd825dcb4c5977326ff684109","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/f08aaee3152d0dfc578b3f2586932d82062701dd","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-72428","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:22:16.637","lastModified":"2026-08-15T06:22:16.637","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nbpf: Fix stack slot index in nospec checks\n\ncheck_stack_write_fixed_off() computes the byte slot for a fixed-offset\nstack write as -off - 1, and records each written byte in slot_type[] with\n(slot - i) % BPF_REG_SIZE.\n\nThe Spectre v4 sanitization pre-check uses slot_type[i] instead. For a\n4-byte write at fp-8 after the lower half of fp-8 has been zeroed, the\npre-check scans bytes 0..3 and sees STACK_ZERO while the actual write updates\nbytes 7..4. That can leave the second half-slot write without nospec_result\neven though the bytes being overwritten still require sanitization.\n\nUse the same slot index in the sanitization pre-check that the write path uses\nwhen updating slot_type[]."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["kernel/bpf/verifier.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"0e9280654aa482088ee6ef3deadef331f5ac5fb0","lessThan":"e62268e695075a481a6c4feeb022c19cf57422a6","versionType":"git","status":"affected"},{"version":"2039f26f3aca5b0e419b98f65dd36481337b86ee","lessThan":"a71eb8f730a91271cf47ce291e785b6b7e54622f","versionType":"git","status":"affected"},{"version":"2039f26f3aca5b0e419b98f65dd36481337b86ee","lessThan":"ca119656baa8f48a56e0c2f3ab63fdd33ca9e307","versionType":"git","status":"affected"},{"version":"2039f26f3aca5b0e419b98f65dd36481337b86ee","lessThan":"475405593de2b796224c6297aece44f321195919","versionType":"git","status":"affected"},{"version":"2039f26f3aca5b0e419b98f65dd36481337b86ee","lessThan":"f1471aa76d74e0df3b2a90731ca0208f498c670b","versionType":"git","status":"affected"},{"version":"2039f26f3aca5b0e419b98f65dd36481337b86ee","lessThan":"68b41e68a62299f26cb16af422b5c7d1c69dafd9","versionType":"git","status":"affected"},{"version":"2039f26f3aca5b0e419b98f65dd36481337b86ee","lessThan":"db8f1dcf5950b91886b9df4270bc816370d292c1","versionType":"git","status":"affected"},{"version":"2039f26f3aca5b0e419b98f65dd36481337b86ee","lessThan":"d1d53aa30ab3b5ae89161c9cc840b3f7489ad386","versionType":"git","status":"affected"},{"version":"872968502114d68c21419cf7eb5ab97717e7b803","versionType":"git","status":"affected"},{"version":"f5893af2704eb763eb982f01d573f5b19f06b623","versionType":"git","status":"affected"},{"version":"0b27bdf02c400684225ee5ee99970bcbf5082282","versionType":"git","status":"affected"},{"version":"5.10.56","lessThan":"5.10.261","versionType":"semver","status":"affected"},{"version":"4.19.207","lessThan":"4.20","versionType":"semver","status":"affected"},{"version":"5.4.146","lessThan":"5.5","versionType":"semver","status":"affected"},{"version":"5.13.8","lessThan":"5.14","versionType":"semver","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["kernel/bpf/verifier.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"5.14","status":"affected"},{"version":"0","lessThan":"5.14","versionType":"semver","status":"unaffected"},{"version":"5.10.261","lessThanOrEqual":"5.10.*","versionType":"semver","status":"unaffected"},{"version":"5.15.212","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.178","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.97","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/475405593de2b796224c6297aece44f321195919","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/68b41e68a62299f26cb16af422b5c7d1c69dafd9","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/a71eb8f730a91271cf47ce291e785b6b7e54622f","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/ca119656baa8f48a56e0c2f3ab63fdd33ca9e307","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/d1d53aa30ab3b5ae89161c9cc840b3f7489ad386","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/db8f1dcf5950b91886b9df4270bc816370d292c1","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/e62268e695075a481a6c4feeb022c19cf57422a6","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/f1471aa76d74e0df3b2a90731ca0208f498c670b","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-72429","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:22:16.770","lastModified":"2026-08-15T06:22:16.770","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nipv6: ioam: fix type confusion of dst_entry\n\nIOAM uses a dummy dst_entry(null_dst) to mark that the destination should\nnot be changed after the transformation. This dst is stored in the IOAM lwt\nstate and may be passed to dst_cache_set_ip6().\n\nHowever, the IPv6 dst cache path eventually calls rt6_get_cookie(), which\ntreats the dst_entry as part of a struct rt6_info. Since the null_dst was\nembedded directly as a struct dst_entry in struct ioam6_lwt, this resulted\nin an invalid cast and rt6_get_cookie() reading fields from the wrong\nobject.\n\nIn practice, the wrong cookie is not used while dst->obsolete is zero, but\nrt6_get_cookie() may also access per-cpu value when rt->sernum is\nzero. In this case, rt->sernum aliases ioam6_lwt::cache::reset_ts, which\ncan become zero, making this a potential invalid pointer access.\n\nFix this by embedding a full struct rt6_info for the dummy IPv6 route and\npassing its dst member to the dst APIs."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["net/ipv6/ioam6_iptunnel.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"47ce7c854563fe8450e9cb8dcd62c6470e28076b","lessThan":"ea24f911ead85ba3d570a31e37c52b6c949f6928","versionType":"git","status":"affected"},{"version":"47ce7c854563fe8450e9cb8dcd62c6470e28076b","lessThan":"5a3b2ee1e96d0580a8ed8deda6dfa430604f9ab0","versionType":"git","status":"affected"},{"version":"47ce7c854563fe8450e9cb8dcd62c6470e28076b","lessThan":"9ed19e11d2146076d117d51a940643990118449b","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["net/ipv6/ioam6_iptunnel.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.16","status":"affected"},{"version":"0","lessThan":"6.16","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/5a3b2ee1e96d0580a8ed8deda6dfa430604f9ab0","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/9ed19e11d2146076d117d51a940643990118449b","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/ea24f911ead85ba3d570a31e37c52b6c949f6928","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-72430","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:22:16.863","lastModified":"2026-08-15T06:22:16.863","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nnet/sched: act_ct: fix nf_connlabels leak on two error paths\n\ntcf_ct_fill_params() calls nf_connlabels_get() (setting put_labels) when\nTCA_CT_LABELS is present, but two later error sites use a bare return\ninstead of \"goto err\", skipping the err: nf_connlabels_put() cleanup.\nThey also precede the \"p->put_labels = put_labels\" assignment, so the\ntcf_ct_params_free() fallback does not release the count either. Each\nfailed RTM_NEWACTION on these paths leaks one nf_connlabels reference:\nnet->ct.labels_used is incremented and never released. The action is\nreachable with CAP_NET_ADMIN over the netns, i.e. from an unprivileged\nuser namespace on default-userns kernels.\n\nImpact: an unprivileged user with CAP_NET_ADMIN over a network namespace\n(e.g. via user namespaces) leaks one nf_connlabels reference per failed\nRTM_NEWACTION on the two error paths; net->ct.labels_used is never\nreleased.\n\nThe err: label is safe to reach from both sites: p->tmpl is still NULL\nthere (kzalloc'd, not yet assigned) and nf_ct_put(NULL) is a no-op, so\nno inline release is needed."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["net/sched/act_ct.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"70f06c115bcca26ceeebf938e48bc8143668e38b","lessThan":"13b561c893c741635adce3781490a7a1099106c8","versionType":"git","status":"affected"},{"version":"70f06c115bcca26ceeebf938e48bc8143668e38b","lessThan":"1d51aff78f078af1a80e9496c2f4643f4c0ef0a0","versionType":"git","status":"affected"},{"version":"70f06c115bcca26ceeebf938e48bc8143668e38b","lessThan":"0c3d8fc87e10e38fe054ece009d6d1f66bef2cd4","versionType":"git","status":"affected"},{"version":"70f06c115bcca26ceeebf938e48bc8143668e38b","lessThan":"16e088016f38cf728a0de709c3335cc5a3850476","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["net/sched/act_ct.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.7","status":"affected"},{"version":"0","lessThan":"6.7","versionType":"semver","status":"unaffected"},{"version":"6.12.97","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/0c3d8fc87e10e38fe054ece009d6d1f66bef2cd4","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/13b561c893c741635adce3781490a7a1099106c8","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/16e088016f38cf728a0de709c3335cc5a3850476","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/1d51aff78f078af1a80e9496c2f4643f4c0ef0a0","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-72431","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:22:16.960","lastModified":"2026-08-15T06:22:16.960","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nalloc_tag: fix use-after-free in /proc/allocinfo after module unload\n\nallocinfo_start() only reinitializes the codetag iterator at position 0. \nFor subsequent reads (position > 0), it reuses cached iterator state from\nthe previous batch.  allocinfo_stop() drops mod_lock between read batches,\nwhich allows module unload to complete and free the module memory that the\ncached iterator still references:\n\n  CPU0 (read)                        CPU1 (rmmod)\n  ----                               ----\n  allocinfo_start(pos=0)\n    down_read(mod_lock)\n    allocinfo_show()\n    ...\n  allocinfo_stop()\n    up_read(mod_lock)\n                                     codetag_unload_module()\n                                       kfree(cmod)\n                                       release_module_tags()\n                                     ...\n                                     free_mod_mem()\n  allocinfo_start(pos=N)\n    down_read(mod_lock)\n    // reuses cached iter, skips re-init\n  allocinfo_show()\n    ct->filename   <-- UAF\n\nAfter free_mod_mem() frees the module's .rodata, allocinfo_show()\ndereferences ct->filename, ct->function which point there.\n\nSave the iterator state in allocinfo_next() and resume from it in\nallocinfo_start() with codetag_next_ct(), which detects module removal via\nidr_find() returning NULL and skips to the next module."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["lib/alloc_tag.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"9f44df50fee4d2f6cb374177244ccfa9f0a5cc95","lessThan":"37e3e8a2c3bfdd503209f043f8bbfbdcf5a1d92f","versionType":"git","status":"affected"},{"version":"9f44df50fee4d2f6cb374177244ccfa9f0a5cc95","lessThan":"008ceffd44040f809aead6d7bef7cb1210c4149a","versionType":"git","status":"affected"},{"version":"9f44df50fee4d2f6cb374177244ccfa9f0a5cc95","lessThan":"2956268efc457cb05d29c1bf94de1e8e684d7bbc","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["lib/alloc_tag.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.17","status":"affected"},{"version":"0","lessThan":"6.17","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/008ceffd44040f809aead6d7bef7cb1210c4149a","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/2956268efc457cb05d29c1bf94de1e8e684d7bbc","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/37e3e8a2c3bfdd503209f043f8bbfbdcf5a1d92f","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-72432","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:22:17.057","lastModified":"2026-08-15T06:22:17.057","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\ntpm_crb: Check ACPI_COMPANION() against NULL during probe\n\nEvery platform driver can be forced to match a device that doesn't match\nits list of device IDs because of device_match_driver_override(), so\nplatform drivers that rely on the existence of a device's ACPI companion\nobject need to verify its presence.\n\nAccordingly, add a requisite ACPI_COMPANION() check against NULL to the\ntpm_crb driver."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/char/tpm/tpm_crb.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"48fe2cddc85c7849463bd01ae8b8c6b575ff508b","lessThan":"c041d2be785feb9b5e36331921eadaefbe65349d","versionType":"git","status":"affected"},{"version":"48fe2cddc85c7849463bd01ae8b8c6b575ff508b","lessThan":"ddd33806b8911fa2ef849e8bbbab1e3fcb26adc0","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/char/tpm/tpm_crb.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"7.1","status":"affected"},{"version":"0","lessThan":"7.1","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/c041d2be785feb9b5e36331921eadaefbe65349d","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/ddd33806b8911fa2ef849e8bbbab1e3fcb26adc0","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-72433","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:22:17.137","lastModified":"2026-08-15T06:22:17.137","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nnetfilter: nft_meta_bridge: fix NFT_META_BRI_IIFPVID stack leak\n\nThis needs to test for nonzero retval."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["net/bridge/netfilter/nft_meta_bridge.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"c54c7c685494fc0f1662091d4d0c4fc26e810471","lessThan":"c37a39b963034cc2d141baf46017614cb1fc275f","versionType":"git","status":"affected"},{"version":"c54c7c685494fc0f1662091d4d0c4fc26e810471","lessThan":"a853c3769b73ceb2d2b735aff621d1d51fe0553d","versionType":"git","status":"affected"},{"version":"c54c7c685494fc0f1662091d4d0c4fc26e810471","lessThan":"b1b0b9efe641afa5c2d4ba2ec77aed7b6f4bc398","versionType":"git","status":"affected"},{"version":"c54c7c685494fc0f1662091d4d0c4fc26e810471","lessThan":"f73b7de5338fcca7f63ca88597a050c119501531","versionType":"git","status":"affected"},{"version":"c54c7c685494fc0f1662091d4d0c4fc26e810471","lessThan":"92c9682b36f0c8f7a1f14d4558b72793f62e90a1","versionType":"git","status":"affected"},{"version":"c54c7c685494fc0f1662091d4d0c4fc26e810471","lessThan":"7e23965d44f06ed93fb5362fb1e321b769eecc3b","versionType":"git","status":"affected"},{"version":"c54c7c685494fc0f1662091d4d0c4fc26e810471","lessThan":"4dce8bf588a89bef99b446136d15685a837e7acf","versionType":"git","status":"affected"},{"version":"c54c7c685494fc0f1662091d4d0c4fc26e810471","lessThan":"27dd2997746d54ebc079bb13161cc1bdd401d4a6","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["net/bridge/netfilter/nft_meta_bridge.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"5.3","status":"affected"},{"version":"0","lessThan":"5.3","versionType":"semver","status":"unaffected"},{"version":"5.10.261","lessThanOrEqual":"5.10.*","versionType":"semver","status":"unaffected"},{"version":"5.15.212","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.178","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.97","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/27dd2997746d54ebc079bb13161cc1bdd401d4a6","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/4dce8bf588a89bef99b446136d15685a837e7acf","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/7e23965d44f06ed93fb5362fb1e321b769eecc3b","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/92c9682b36f0c8f7a1f14d4558b72793f62e90a1","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/a853c3769b73ceb2d2b735aff621d1d51fe0553d","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/b1b0b9efe641afa5c2d4ba2ec77aed7b6f4bc398","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/c37a39b963034cc2d141baf46017614cb1fc275f","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/f73b7de5338fcca7f63ca88597a050c119501531","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-72434","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:22:17.247","lastModified":"2026-08-15T06:22:17.247","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nnetfilter: ipset: make sure gc is properly stopped\n\nSashiko noticed that when destroying a set,\ncancel_delayed_work_sync() was called while gc\ncalls queue_delayed_work() unconditionally which\ncan lead not to properly shutting down the gc."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["net/netfilter/ipset/ip_set_hash_gen.h"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"f66ee0410b1c3481ee75e5db9b34547b4d582465","lessThan":"c940d1b96248c3081b664ede5418078bdc7c8c07","versionType":"git","status":"affected"},{"version":"f66ee0410b1c3481ee75e5db9b34547b4d582465","lessThan":"12088da6add5b003657c8506c5b0fcef835083b8","versionType":"git","status":"affected"},{"version":"f66ee0410b1c3481ee75e5db9b34547b4d582465","lessThan":"c78bd5195a5998094a5866df702fbeafda60dafb","versionType":"git","status":"affected"},{"version":"f66ee0410b1c3481ee75e5db9b34547b4d582465","lessThan":"4a597a87e2e2f608edb6be2c510dc826b4fdfb53","versionType":"git","status":"affected"},{"version":"5dd9488ae41070b69d2f4acb580f77db5705f9ca","versionType":"git","status":"affected"},{"version":"a469bab3386aebff33c59506f3a95e35b91118fd","versionType":"git","status":"affected"},{"version":"5.4.24","lessThan":"5.5","versionType":"semver","status":"affected"},{"version":"5.5.8","lessThan":"5.6","versionType":"semver","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["net/netfilter/ipset/ip_set_hash_gen.h"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"5.6","status":"affected"},{"version":"0","lessThan":"5.6","versionType":"semver","status":"unaffected"},{"version":"6.12.97","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/12088da6add5b003657c8506c5b0fcef835083b8","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/4a597a87e2e2f608edb6be2c510dc826b4fdfb53","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/c78bd5195a5998094a5866df702fbeafda60dafb","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/c940d1b96248c3081b664ede5418078bdc7c8c07","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-72435","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:22:17.343","lastModified":"2026-08-15T06:22:17.343","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nnetfilter: ipset: fix order of kfree_rcu() and rcu_assign_pointer()\n\nSashiko pointed out that kfree_rcu() was called before\nrcu_assign_pointer() in handling the comment extension.\nFix the order so that rcu_assign_pointer() called first."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["net/netfilter/ipset/ip_set_core.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"b57b2d1fa53fe8563bdfc66a33b844463b9af285","lessThan":"c9787d7c24ffd83019f379455e1b97fb4f0f75eb","versionType":"git","status":"affected"},{"version":"b57b2d1fa53fe8563bdfc66a33b844463b9af285","lessThan":"6e98407cb94e035bba98956adc9096a76d8b2a9f","versionType":"git","status":"affected"},{"version":"b57b2d1fa53fe8563bdfc66a33b844463b9af285","lessThan":"50b70f56f3baaff46599f59b2d93fa2540120776","versionType":"git","status":"affected"},{"version":"b57b2d1fa53fe8563bdfc66a33b844463b9af285","lessThan":"d01b4b471f0fc5c396af62845e972ccf99cee29a","versionType":"git","status":"affected"},{"version":"b57b2d1fa53fe8563bdfc66a33b844463b9af285","lessThan":"fcb565966534909377a16be5f7b065db2e25c8b5","versionType":"git","status":"affected"},{"version":"b57b2d1fa53fe8563bdfc66a33b844463b9af285","lessThan":"8087bb360a936a6314d22b567e4b861656943eb6","versionType":"git","status":"affected"},{"version":"b57b2d1fa53fe8563bdfc66a33b844463b9af285","lessThan":"93a775fd67f3ef34949a9523bfa69403ee74efdd","versionType":"git","status":"affected"},{"version":"b57b2d1fa53fe8563bdfc66a33b844463b9af285","lessThan":"3ca9982a8882470aa0ac4e8bb9a552b181d1efcd","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["net/netfilter/ipset/ip_set_core.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"4.2","status":"affected"},{"version":"0","lessThan":"4.2","versionType":"semver","status":"unaffected"},{"version":"5.10.261","lessThanOrEqual":"5.10.*","versionType":"semver","status":"unaffected"},{"version":"5.15.212","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.178","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.97","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/3ca9982a8882470aa0ac4e8bb9a552b181d1efcd","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/50b70f56f3baaff46599f59b2d93fa2540120776","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/6e98407cb94e035bba98956adc9096a76d8b2a9f","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/8087bb360a936a6314d22b567e4b861656943eb6","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/93a775fd67f3ef34949a9523bfa69403ee74efdd","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/c9787d7c24ffd83019f379455e1b97fb4f0f75eb","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/d01b4b471f0fc5c396af62845e972ccf99cee29a","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/fcb565966534909377a16be5f7b065db2e25c8b5","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-72436","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:22:17.453","lastModified":"2026-08-15T06:22:17.453","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nnetfilter: ipset: Don't use test_bit() in lockless RCU readers in hash types\n\nSashiko pointed out that there are a few lockless RCU readers\nusing test_bit() which is a relaxed atomic operation and\nprovides no memory barrier guarantees. Use test_bit_acquire()\ninstead where the operation may run parallel with add/del/gc,\ni.e. is not one from the next cases\n\n- protected by region lock\n- in a set destroy phase\n- in a new/temporary set creation phase"}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["net/netfilter/ipset/ip_set_hash_gen.h"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"18f84d41d34fa35d0d64bbaea01fe664553ecc06","lessThan":"c107233d2ff4fd7cef5d02f9124b99194957a710","versionType":"git","status":"affected"},{"version":"18f84d41d34fa35d0d64bbaea01fe664553ecc06","lessThan":"6329d3a9afe715fddda0460cfa46b496d61c2fe0","versionType":"git","status":"affected"},{"version":"18f84d41d34fa35d0d64bbaea01fe664553ecc06","lessThan":"7445fe965b7d8756070a40e80f8b73348ccda1d7","versionType":"git","status":"affected"},{"version":"18f84d41d34fa35d0d64bbaea01fe664553ecc06","lessThan":"c4d257734e91bfcdc71d41843392dd6400b5bb1b","versionType":"git","status":"affected"},{"version":"18f84d41d34fa35d0d64bbaea01fe664553ecc06","lessThan":"3219d74e4536658c937fd878a327257b86ce80dd","versionType":"git","status":"affected"},{"version":"18f84d41d34fa35d0d64bbaea01fe664553ecc06","lessThan":"e4b4984e28c16406ecb318444dea4a8bf47def3e","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["net/netfilter/ipset/ip_set_hash_gen.h"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"4.2","status":"affected"},{"version":"0","lessThan":"4.2","versionType":"semver","status":"unaffected"},{"version":"6.1.178","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.97","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/3219d74e4536658c937fd878a327257b86ce80dd","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/6329d3a9afe715fddda0460cfa46b496d61c2fe0","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/7445fe965b7d8756070a40e80f8b73348ccda1d7","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/c107233d2ff4fd7cef5d02f9124b99194957a710","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/c4d257734e91bfcdc71d41843392dd6400b5bb1b","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/e4b4984e28c16406ecb318444dea4a8bf47def3e","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-72437","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:22:17.560","lastModified":"2026-08-15T06:22:17.560","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nmd/raid1: free r1_bio when REQ_NOWAIT is set and read would block on retry\n\nWhen a read is retried, raid1_read_request() may be called with a\npre-allocated r1_bio. If wait_read_barrier() fails for a REQ_NOWAIT\nread, the bio is completed and the function returns immediately. In this\ncase the existing r1_bio is leaked.\n\nThis fixes a leak of pre-allocated r1_bio structures for retried reads."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/md/raid1.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"5aa705039c4fca84575539bfa2b8a28454a3d2ca","lessThan":"d1eda529a4bf6b866d02755723ee0eb1f037a5ed","versionType":"git","status":"affected"},{"version":"5aa705039c4fca84575539bfa2b8a28454a3d2ca","lessThan":"c66ed3e6371f5dba8f5d8ab810d6683ddc99201e","versionType":"git","status":"affected"},{"version":"5aa705039c4fca84575539bfa2b8a28454a3d2ca","lessThan":"db58075bc9c2ad2731f9c063859b47104bc2e7ef","versionType":"git","status":"affected"},{"version":"5aa705039c4fca84575539bfa2b8a28454a3d2ca","lessThan":"6d92dbd73d19a0622f60352ce9d9379f7a760112","versionType":"git","status":"affected"},{"version":"5aa705039c4fca84575539bfa2b8a28454a3d2ca","lessThan":"c6e6354295845698d2fdfa20b71fc404786f7e93","versionType":"git","status":"affected"},{"version":"5aa705039c4fca84575539bfa2b8a28454a3d2ca","lessThan":"69ad6ce47f9bf2b9fe0ed69b042db993d33bbf12","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/md/raid1.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"5.17","status":"affected"},{"version":"0","lessThan":"5.17","versionType":"semver","status":"unaffected"},{"version":"6.1.178","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.97","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/69ad6ce47f9bf2b9fe0ed69b042db993d33bbf12","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/6d92dbd73d19a0622f60352ce9d9379f7a760112","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/c66ed3e6371f5dba8f5d8ab810d6683ddc99201e","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/c6e6354295845698d2fdfa20b71fc404786f7e93","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/d1eda529a4bf6b866d02755723ee0eb1f037a5ed","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/db58075bc9c2ad2731f9c063859b47104bc2e7ef","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-72438","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:22:17.660","lastModified":"2026-08-15T06:22:17.660","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nmd/raid10: fix writes_pending and barrier reference leaks on discard failures\n\nraid10_make_request() acquires a writes_pending reference with\nmd_write_start() before calling raid10_handle_discard(). Several failure\npaths in raid10_handle_discard() complete the bio and return without\nreleasing the corresponding reference, causing md_write_end() to be\nskipped.\n\nCall md_write_end() before returning from these failure paths to keep\nwrites_pending accounting balanced.\n\nAdditionally, discard split allocation failures can occur after\nwait_barrier() succeeds. Those paths return without calling\nallow_barrier(), leaking the associated barrier reference.\n\nRelease the barrier before returning from those paths."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/md/raid10.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"c9aa889b035fca4598ae985a0f0c76ebbb547ad2","lessThan":"d1324b41dabd26787559efaeb430643c627c1eb0","versionType":"git","status":"affected"},{"version":"c9aa889b035fca4598ae985a0f0c76ebbb547ad2","lessThan":"393d687131d8aa8c7e4de2cb494438e145d20fc2","versionType":"git","status":"affected"},{"version":"39db562b3fedb93978a7e42dd216b306740959f8","versionType":"git","status":"affected"},{"version":"5.15.111","lessThan":"5.16","versionType":"semver","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/md/raid10.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"5.17","status":"affected"},{"version":"0","lessThan":"5.17","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/393d687131d8aa8c7e4de2cb494438e145d20fc2","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/d1324b41dabd26787559efaeb430643c627c1eb0","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-72439","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:22:17.753","lastModified":"2026-08-15T06:22:17.753","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nmd/raid10: fix writes_pending leak on write request failures\n\nraid10_make_request() acquires a writes_pending reference with\nmd_write_start() before dispatching write requests. Several failure\npaths in raid10_write_request() complete the bio and return without\nreaching the normal write completion path, causing the corresponding\nmd_write_end() to be skipped.\n\nMake raid10_write_request() return a status indicating whether the write\nrequest was successfully queued. This allows raid10_make_request() to\nrelease the writes_pending reference with md_write_end() when a write\nrequest fails."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/md/raid10.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"c9aa889b035fca4598ae985a0f0c76ebbb547ad2","lessThan":"f94031c94eaebe14a7c9e91720064de0c5a54a6c","versionType":"git","status":"affected"},{"version":"c9aa889b035fca4598ae985a0f0c76ebbb547ad2","lessThan":"e045d6ed33f8faa3e3dd6dc33c62ec01e3ad275d","versionType":"git","status":"affected"},{"version":"39db562b3fedb93978a7e42dd216b306740959f8","versionType":"git","status":"affected"},{"version":"5.15.111","lessThan":"5.16","versionType":"semver","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/md/raid10.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"5.17","status":"affected"},{"version":"0","lessThan":"5.17","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/e045d6ed33f8faa3e3dd6dc33c62ec01e3ad275d","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/f94031c94eaebe14a7c9e91720064de0c5a54a6c","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-72440","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:22:17.843","lastModified":"2026-08-15T06:22:17.843","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nmd/raid1: fix writes_pending and barrier reference leaks on write failures\n\nraid1_make_request() acquires a writes_pending reference with\nmd_write_start() before calling raid1_write_request(). Several failure\npaths in raid1_write_request() complete the bio and return without\nreaching the normal write completion path, causing the corresponding\nmd_write_end() to be skipped.\n\nMake raid1_write_request() return a status indicating whether the write\nrequest was successfully queued. This allows raid1_make_request() to\ncall md_write_end() when raid1_write_request() fails.\n\nAdditionally, if wait_blocked_rdev() fails after wait_barrier()\nsucceeds, the associated barrier reference is not released.\n\nCall allow_barrier() before returning from that path to keep the barrier\naccounting balanced."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/md/raid1.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"5aa705039c4fca84575539bfa2b8a28454a3d2ca","lessThan":"bffbbfcbd9393e315a7a4286dcd70e875265db9a","versionType":"git","status":"affected"},{"version":"5aa705039c4fca84575539bfa2b8a28454a3d2ca","lessThan":"8e065a1602511282fc0da2dc89445e0eb71a681c","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/md/raid1.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"5.17","status":"affected"},{"version":"0","lessThan":"5.17","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/8e065a1602511282fc0da2dc89445e0eb71a681c","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/bffbbfcbd9393e315a7a4286dcd70e875265db9a","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-72441","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:22:17.937","lastModified":"2026-08-15T06:22:17.937","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nieee802154: fix kernel-infoleak in dgram_recvmsg()\n\nKMSAN reported a kernel-infoleak in move_addr_to_user():\n\nBUG: KMSAN: kernel-infoleak in instrument_copy_to_user\ninclude/linux/instrumented.h:131 [inline]\nBUG: KMSAN: kernel-infoleak in _inline_copy_to_user\ninclude/linux/uaccess.h:205 [inline]\nBUG: KMSAN: kernel-infoleak in _copy_to_user+0xcc/0x120\nlib/usercopy.c:26\n instrument_copy_to_user include/linux/instrumented.h:131 [inline]\n _inline_copy_to_user include/linux/uaccess.h:205 [inline]\n _copy_to_user+0xcc/0x120 lib/usercopy.c:26\n copy_to_user include/linux/uaccess.h:236 [inline]\n move_addr_to_user+0x2e7/0x440 net/socket.c:302\n ____sys_recvmsg+0x232/0x610 net/socket.c:2925\n ...\n Uninit was stored to memory at:\n ieee802154_addr_to_sa include/net/ieee802154_netdev.h:369 [inline]\n dgram_recvmsg+0xa09/0xbe0 net/ieee802154/socket.c:739\n\nThe issue occurs because the `pan_id` field of `struct ieee802154_addr`\nis left uninitialized when the address mode is `IEEE802154_ADDR_NONE`.\nThe execution flow is as follows:\n\n1. `__ieee802154_rx_handle_packet()` declares a local `struct\nieee802154_hdr hdr` on the stack.\n2. `ieee802154_hdr_pull()` calls `ieee802154_hdr_get_addr()` to parse\nthe source and destination addresses into this structure.\n3. If the address mode is `IEEE802154_ADDR_NONE`,\n`ieee802154_hdr_get_addr()` previously only set the `mode` field,\nleaving the `pan_id` field containing uninitialized stack memory.\n4. This uninitialized `pan_id` is later copied into a `struct\nsockaddr_ieee802154` in `dgram_recvmsg()` via `ieee802154_addr_to_sa()`.\n5. Finally, `move_addr_to_user()` copies the socket address structure to\nuser space, leaking the uninitialized bytes.\n\nFix this by using `memset` to zero out the address structure in\n`ieee802154_hdr_get_addr()` when the mode is `IEEE802154_ADDR_NONE`."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["net/ieee802154/header_ops.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"94b4f6c21cf54029377a0645675a9d81b6cf890d","lessThan":"a2ee1a038a16e286d084bc293a7522d010a59ec3","versionType":"git","status":"affected"},{"version":"94b4f6c21cf54029377a0645675a9d81b6cf890d","lessThan":"09cfe665f2c5d7a8a5ed4d6b487434a011325368","versionType":"git","status":"affected"},{"version":"94b4f6c21cf54029377a0645675a9d81b6cf890d","lessThan":"c88e687e44cb9c7690f5039a5a5941dba1f6a204","versionType":"git","status":"affected"},{"version":"94b4f6c21cf54029377a0645675a9d81b6cf890d","lessThan":"71b5add66c51d6764325de5f2e300bbf4f39e7a6","versionType":"git","status":"affected"},{"version":"94b4f6c21cf54029377a0645675a9d81b6cf890d","lessThan":"fc8766467b53335220b4b594ba15bc8f8cee0c76","versionType":"git","status":"affected"},{"version":"94b4f6c21cf54029377a0645675a9d81b6cf890d","lessThan":"de3bd9809af7555611334cb6a071806744430ef7","versionType":"git","status":"affected"},{"version":"94b4f6c21cf54029377a0645675a9d81b6cf890d","lessThan":"f14802465f5956baafe5f4b4541eb626b06b41f1","versionType":"git","status":"affected"},{"version":"94b4f6c21cf54029377a0645675a9d81b6cf890d","lessThan":"4db86f8ab11b5a41bfc36680be837e6ac1375ec6","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["net/ieee802154/header_ops.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"3.15","status":"affected"},{"version":"0","lessThan":"3.15","versionType":"semver","status":"unaffected"},{"version":"5.10.261","lessThanOrEqual":"5.10.*","versionType":"semver","status":"unaffected"},{"version":"5.15.212","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.178","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.97","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/09cfe665f2c5d7a8a5ed4d6b487434a011325368","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/4db86f8ab11b5a41bfc36680be837e6ac1375ec6","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/71b5add66c51d6764325de5f2e300bbf4f39e7a6","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/a2ee1a038a16e286d084bc293a7522d010a59ec3","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/c88e687e44cb9c7690f5039a5a5941dba1f6a204","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/de3bd9809af7555611334cb6a071806744430ef7","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/f14802465f5956baafe5f4b4541eb626b06b41f1","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/fc8766467b53335220b4b594ba15bc8f8cee0c76","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-72442","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:22:18.063","lastModified":"2026-08-15T06:22:18.063","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nnetfilter: flowtable: fix and simplify IP6IP6 tunnel handling\n\nFix nf_flow_ip6_tunnel_proto() to use pskb_may_pull() instead of\nskb_header_pointer() to ensure the outer IPv6 header is in the skb\nheadroom, which is required for subsequent packet processing. Move\nctx->offset update inside the IPPROTO_IPV6 conditional block since it\nshould only be adjusted when an IP6IP6 tunnel is actually detected.\nSimplify the rx path by removing ipv6_skip_exthdr() and checking\nip6h->nexthdr directly, as the flowtable fast path only handles simple\nIP6IP6 encapsulation without extension headers.\nDrop the tunnel encapsulation limit destination option support from the\ntx path to match, since the rx path no longer handles extension headers.\nRemove the encap_limit parameter from nf_flow_offload_ipv6_forward(),\nnf_flow_tunnel_ip6ip6_push() and nf_flow_tunnel_v6_push(), along with\nthe ipv6_tel_txoption struct and related headroom/MTU adjustments."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["net/ipv6/ip6_tunnel.c","net/netfilter/nf_flow_table_ip.c","tools/testing/selftests/net/netfilter/nft_flowtable.sh"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"d98103575dcdd3a730e0901ab457791a9ac6930c","lessThan":"7f8d816a9aa2729d270418f00c9ef5e85bfc1b31","versionType":"git","status":"affected"},{"version":"d98103575dcdd3a730e0901ab457791a9ac6930c","lessThan":"f4c2d8668d85ed125985da663c824a9c25498257","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["net/ipv6/ip6_tunnel.c","net/netfilter/nf_flow_table_ip.c","tools/testing/selftests/net/netfilter/nft_flowtable.sh"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"7.0","status":"affected"},{"version":"0","lessThan":"7.0","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/7f8d816a9aa2729d270418f00c9ef5e85bfc1b31","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/f4c2d8668d85ed125985da663c824a9c25498257","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-72443","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:22:18.160","lastModified":"2026-08-15T06:22:18.160","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nALSA: usb-audio: Kill MIDI 2.0 URBs before freeing endpoints\n\nMIDI 2.0 input URBs are started during snd_usb_midi_v2_create(). A\nlater setup failure can still jump to snd_usb_midi_v2_free(), which\ncurrently frees each endpoint and its coherent URB buffers without first\nstopping the submitted URBs. A completion can then dereference the\nembedded URB context and endpoint state after they have been freed, or\ntry to resubmit from the stale endpoint.\n\nThis was observed as a KASAN slab-use-after-free in\ninput_urb_complete().\n\nThe buggy scenario involves two paths, with each column showing the order\nwithin that path:\n\nprobe error path:                         USB completion path:\n1. start_input_streams() submits          1. The HCD still owns a\n   input URBs.                               submitted input URB.\n2. A later setup helper returns           2. input_urb_complete() runs\n   an error.                                 with urb->context in ep.\n3. snd_usb_midi_v2_free() frees           3. The completion reads ep\n   endpoint storage and URB buffers.         state and can requeue URBs.\n\nMake the endpoint destructor follow the same teardown ordering used for\ndisconnect when the endpoint has not already been disconnected: publish\nep->disconnected, kill the URBs synchronously, and drain the endpoint\nbefore freeing URB buffers and endpoint storage. The guard avoids\nrepeating the stop sequence after the normal\nsnd_usb_midi_v2_disconnect_all() path, while still synchronizing the\ndirect MIDI 2.0 create-error free path.\n\nValidation reproduced this kernel report:\nBUG: KASAN: slab-use-after-free in input_urb_complete+0x37/0x1b0\nWorkqueue: usb_hub_wq hub_event\nRIP: 0010:_raw_spin_unlock_irq+0x2e/0x50\nRead of size 8\nCall trace:\n  dump_stack_lvl+0x77/0xb0\n  print_report+0xce/0x5f0\n  input_urb_complete+0x37/0x1b0 (sound/usb/midi2.c:186)\n  srso_alias_return_thunk+0x5/0xfbef5\n  __virt_addr_valid+0x19f/0x330\n  kasan_report+0xe0/0x110\n  __usb_hcd_giveback_urb+0x112/0x1d0\n  dummy_timer+0xaaa/0x19a0\n  lock_is_held_type+0x9a/0x110\n  __lock_acquire+0x467/0x28b0\n  mark_held_locks+0x40/0x70\n  _raw_spin_unlock_irqrestore+0x44/0x60\n  lockdep_hardirqs_on_prepare+0xbb/0x1a0\n  __hrtimer_run_queues+0x101/0x520\n  hrtimer_run_softirq+0xd0/0x130\n  handle_softirqs+0x15b/0x670\n  __irq_exit_rcu+0xd0/0x170\n  irq_exit_rcu+0xe/0x20\n  sysvec_apic_timer_interrupt+0x6c/0x80\n  asm_sysvec_apic_timer_interrupt+0x1a/0x20"}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["sound/usb/midi2.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"d9c99876868c861afd0e9ce2cea407bbc446b3c9","lessThan":"bcdd5a7363bdd287253c406a9c0205f5722058e7","versionType":"git","status":"affected"},{"version":"d9c99876868c861afd0e9ce2cea407bbc446b3c9","lessThan":"3d961032a6e58fa485b3a4c0fe0f649334d887de","versionType":"git","status":"affected"},{"version":"d9c99876868c861afd0e9ce2cea407bbc446b3c9","lessThan":"4c16176fc11a61b7545464cb47c98b0c8a055fcb","versionType":"git","status":"affected"},{"version":"d9c99876868c861afd0e9ce2cea407bbc446b3c9","lessThan":"68286258698e15fe75073fb8d017003f8e493db1","versionType":"git","status":"affected"},{"version":"d9c99876868c861afd0e9ce2cea407bbc446b3c9","lessThan":"f199c8a8bdd54296d3458777e70fe82a78bd9817","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["sound/usb/midi2.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.5","status":"affected"},{"version":"0","lessThan":"6.5","versionType":"semver","status":"unaffected"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.97","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/3d961032a6e58fa485b3a4c0fe0f649334d887de","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/4c16176fc11a61b7545464cb47c98b0c8a055fcb","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/68286258698e15fe75073fb8d017003f8e493db1","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/bcdd5a7363bdd287253c406a9c0205f5722058e7","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/f199c8a8bdd54296d3458777e70fe82a78bd9817","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-72444","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:22:18.280","lastModified":"2026-08-15T06:22:18.280","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nflow_dissector: check device type before reading ETH_ADDRS\n\n__skb_flow_dissect() unconditionally reads 12 bytes from eth_hdr(skb)\nwhen FLOW_DISSECTOR_KEY_ETH_ADDRS is requested. This assumes the skb\nhas a valid Ethernet header at mac_header, which is not always the case.\n\nThe problem can be triggered by:\n 1. Creating a TUN device in L3 mode (IFF_TUN, hard_header_len=0)\n 2. Attaching a multiq qdisc with a flower filter matching on eth_src\n 3. Sending a packet through AF_PACKET\n\nSince TUN in L3 mode has no link-layer header, mac_header points to\nthe L3 data area. The flow dissector reads 12 bytes of uninitialized\nskb memory, which then propagates through fl_set_masked_key() and is\nused as a rhashtable lookup key in __fl_lookup(), as reported by KMSAN.\n\nRejecting the filter in the control path (at tc filter add time) is\nnot feasible because TC filter blocks can be shared between arbitrary\ndevices -- a filter installed on an Ethernet device may later classify\npackets on a headerless device through a shared block. The device\nassociation is not fixed at filter creation time.\n\nFix this by gating the memcpy on dev->type == ARPHRD_ETHER, which\nensures only true Ethernet-framed packets have their addresses read.\nThis is more precise than the previous hard_header_len >= 12 check,\nwhich would incorrectly pass for non-Ethernet link types like IPoIB\n(ARPHRD_INFINIBAND, hard_header_len=24) and FDDI (hard_header_len=21)\nwhose L2 headers are not in Ethernet format. Additionally check\nskb_mac_header_was_set() to guard against the pathological case where\nmac_header is the unset sentinel (~0U), which would cause eth_hdr() to\nreturn a wild pointer.\n\nFor the act_mirred redirect case (Ethernet packet redirected to a\nnon-Ethernet device sharing a TC block), zeroing the key is the correct\nbehavior: the packet is now being classified on the target device, where\nEthernet address matching is not semantically meaningful.\n\nNote: on non-Ethernet devices, the zeroed key will match a filter\nconfigured with all-zero MAC addresses. This is an improvement over the\nprevious behavior where uninitialized memory could randomly match any\nfilter."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["net/core/flow_dissector.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"67a900cc0436d74e7ff89042371760def087680d","lessThan":"0fe6455b8e1a22414f39c07bc90a1df12b52ec74","versionType":"git","status":"affected"},{"version":"67a900cc0436d74e7ff89042371760def087680d","lessThan":"9a65860959db594dfc1820c7fdc09285fb7556bf","versionType":"git","status":"affected"},{"version":"67a900cc0436d74e7ff89042371760def087680d","lessThan":"594c90b197141944f25991b8314de5c26ee27a7e","versionType":"git","status":"affected"},{"version":"67a900cc0436d74e7ff89042371760def087680d","lessThan":"c6d3bcb0f934d4297ac5fa1c8656ae40694fb601","versionType":"git","status":"affected"},{"version":"67a900cc0436d74e7ff89042371760def087680d","lessThan":"825de39f0c35a112148799b3cbe45af3766c018a","versionType":"git","status":"affected"},{"version":"67a900cc0436d74e7ff89042371760def087680d","lessThan":"bf6e8af2c8be77489bedeae9f8a9654cb710e500","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["net/core/flow_dissector.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"4.2","status":"affected"},{"version":"0","lessThan":"4.2","versionType":"semver","status":"unaffected"},{"version":"6.1.178","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.97","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/0fe6455b8e1a22414f39c07bc90a1df12b52ec74","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/594c90b197141944f25991b8314de5c26ee27a7e","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/825de39f0c35a112148799b3cbe45af3766c018a","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/9a65860959db594dfc1820c7fdc09285fb7556bf","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/bf6e8af2c8be77489bedeae9f8a9654cb710e500","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/c6d3bcb0f934d4297ac5fa1c8656ae40694fb601","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-72445","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:22:18.403","lastModified":"2026-08-15T06:22:18.403","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nALSA: usb-audio: qcom: clear opened when stream enable fails\n\nOn enable, subs->opened is set before the service_interval is validated;\nan invalid interval jumps to the response label without clearing it, so\nthe substream is wedged at -EBUSY until a disable or disconnect.\n\nClear subs->opened on the enable error path."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["sound/usb/qcom/qc_audio_offload.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"326bbc348298ab0946c5560defe024a5f6ef28bb","lessThan":"53c23d56b46b1ae51574d92110895086aead7ad7","versionType":"git","status":"affected"},{"version":"326bbc348298ab0946c5560defe024a5f6ef28bb","lessThan":"ec6fb1ecada8ddfc3d0e1728e4792d16ae55dcdb","versionType":"git","status":"affected"},{"version":"326bbc348298ab0946c5560defe024a5f6ef28bb","lessThan":"3c7af07943b2718087ae791cad450af5cf646d90","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["sound/usb/qcom/qc_audio_offload.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.16","status":"affected"},{"version":"0","lessThan":"6.16","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/3c7af07943b2718087ae791cad450af5cf646d90","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/53c23d56b46b1ae51574d92110895086aead7ad7","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/ec6fb1ecada8ddfc3d0e1728e4792d16ae55dcdb","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-72446","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:22:18.500","lastModified":"2026-08-15T06:22:18.500","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nALSA: usb-audio: qcom: reject stream disable with no active interface\n\nhandle_uaudio_stream_req() resolves an interface index with\ninfo_idx_from_ifnum(), which returns -EINVAL when no interface matches.\nThe enable branch and the response: cleanup label both guard against a\nnegative index, but the disable branch does not: it forms\ninfo = &uadev[pcm_card_num].info[info_idx] and dereferences it.\n\nuadev[].info is a pointer allocated only when a stream is first enabled,\nso a negative info_idx on the disable path is unsafe in two ways:\n\n - If the card was never enabled, .info is NULL and &info[-EINVAL] is a\n   wild pointer; reading info->data_ep_pipe faults (kernel oops).\n\n - If the card was enabled at least once (.info allocated) and the\n   disable names an interface that does not match, &info[-EINVAL] points\n   before the allocation; info->data_ep_pipe / info->sync_ep_pipe are an\n   out-of-bounds slab read and, when non-zero, an out-of-bounds 4-byte\n   write (both pipe fields are cleared to 0). That is memory corruption,\n   not just a NULL dereference.\n\nThe request is reachable from unprivileged local userspace over\nAF_QIPCRTR. Reject a disable request with no resolved interface, matching\nthe guard the enable path already has."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["sound/usb/qcom/qc_audio_offload.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"326bbc348298ab0946c5560defe024a5f6ef28bb","lessThan":"25a867aa5e67a84333fa6e5c21292c5bcff86b90","versionType":"git","status":"affected"},{"version":"326bbc348298ab0946c5560defe024a5f6ef28bb","lessThan":"a22356d1f731553e99aa2707dbd38c659bdd28d8","versionType":"git","status":"affected"},{"version":"326bbc348298ab0946c5560defe024a5f6ef28bb","lessThan":"bdb640be82e645e2828731648f485224d0c2587b","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["sound/usb/qcom/qc_audio_offload.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.16","status":"affected"},{"version":"0","lessThan":"6.16","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/25a867aa5e67a84333fa6e5c21292c5bcff86b90","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/a22356d1f731553e99aa2707dbd38c659bdd28d8","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/bdb640be82e645e2828731648f485224d0c2587b","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-72447","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:22:18.600","lastModified":"2026-08-15T06:22:18.600","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nsctp: hold socket lock when dumping endpoints in sctp_diag\n\nSCTP_DIAG endpoint dumping was traversing endpoint address lists without\nholding lock_sock(), while those lists could change concurrently via\nsocket operations (e.g., bindx changes). This creates a race where\nnla_reserve() counts addresses under RCU protection, but the subsequent\ncopy may see fewer entries, potentially leaking uninitialized memory to\nuserspace.\n\nFix this by:\n\n- Taking a reference on each endpoint during hash traversal\n- Moving socket operations (lock_sock()) outside read_lock_bh()\n- Serializing address list access during dump\n- Reworking sctp_for_each_endpoint() to support restart-based traversal\n  with (net, pos) tracking\n\nAlso:\n\n- Add WARN_ON_ONCE() for inconsistent address counts\n- Fix idiag_states filtering for LISTEN vs association cases\n- Skip dumping endpoints being freed (ep->base.dead)\n- Move dump position tracking into iterator, removing cb->args[4] and\n  its comment for sctp_ep_dump().,\n- Update the comment for cb->args[4] and remove the comment for unused\n  cb->args[5] for sctp_sock_dump().\n\nNote: traversal is restart-based and may re-scan buckets multiple times,\nbut this is acceptable due to small bucket sizes and required to support\nsleeping-safe callbacks.\n\nThis issue was reported by Nico Yip (@_cyeaa_) working with TrendAI Zero\nDay Initiative."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["include/net/sctp/sctp.h","net/sctp/diag.c","net/sctp/socket.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"8f840e47f190cbe61a96945c13e9551048d42cef","lessThan":"f98c294a9369b6fe89e652c06357ee594be4dfa2","versionType":"git","status":"affected"},{"version":"8f840e47f190cbe61a96945c13e9551048d42cef","lessThan":"8b38e3dcfde3077dbc03eb8ef88e03cc19f70b8a","versionType":"git","status":"affected"},{"version":"8f840e47f190cbe61a96945c13e9551048d42cef","lessThan":"ec3c2d59a192e17e1014ba71afc368ba162ecac3","versionType":"git","status":"affected"},{"version":"8f840e47f190cbe61a96945c13e9551048d42cef","lessThan":"722576aba0a6d9423714550b1c03239b0f0def77","versionType":"git","status":"affected"},{"version":"8f840e47f190cbe61a96945c13e9551048d42cef","lessThan":"abe7f8828e6ac8be858870c2bf836258844f97d5","versionType":"git","status":"affected"},{"version":"8f840e47f190cbe61a96945c13e9551048d42cef","lessThan":"207bb4ce8fe7de961ae7bb33569ad2cd61f44954","versionType":"git","status":"affected"},{"version":"8f840e47f190cbe61a96945c13e9551048d42cef","lessThan":"f09a245f33e567b604efa1960b7a2d25dd9c8713","versionType":"git","status":"affected"},{"version":"8f840e47f190cbe61a96945c13e9551048d42cef","lessThan":"7d8297e26b4e20b5d1c3c3fe51fe81a1c7fbc823","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["include/net/sctp/sctp.h","net/sctp/diag.c","net/sctp/socket.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"4.7","status":"affected"},{"version":"0","lessThan":"4.7","versionType":"semver","status":"unaffected"},{"version":"5.10.261","lessThanOrEqual":"5.10.*","versionType":"semver","status":"unaffected"},{"version":"5.15.212","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.178","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.97","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/207bb4ce8fe7de961ae7bb33569ad2cd61f44954","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/722576aba0a6d9423714550b1c03239b0f0def77","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/7d8297e26b4e20b5d1c3c3fe51fe81a1c7fbc823","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/8b38e3dcfde3077dbc03eb8ef88e03cc19f70b8a","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/abe7f8828e6ac8be858870c2bf836258844f97d5","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/ec3c2d59a192e17e1014ba71afc368ba162ecac3","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/f09a245f33e567b604efa1960b7a2d25dd9c8713","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/f98c294a9369b6fe89e652c06357ee594be4dfa2","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-72448","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:22:18.723","lastModified":"2026-08-15T06:22:18.723","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nocteontx2-pf: Fix leak of SQ timestamp buffer on teardown\n\nThe send-queue timestamp ring is allocated with qmem_alloc() when\ntimestamping is used, but otx2_free_sq_res() never freed sq->timestamps,\nleaking that memory across ifdown and device removal.  Add the missing\nqmem_free() alongside the other SQ companion buffers."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/net/ethernet/marvell/octeontx2/nic/otx2_pf.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"c9c12d339d93366732112d7ff472958834bfc3c5","lessThan":"c642a530aaaeb9a3e356cedfe77955e7f983380e","versionType":"git","status":"affected"},{"version":"c9c12d339d93366732112d7ff472958834bfc3c5","lessThan":"e68ada66afcae0bc2a7c06b43c5a9a081d29e7b4","versionType":"git","status":"affected"},{"version":"c9c12d339d93366732112d7ff472958834bfc3c5","lessThan":"d6c0b0c802d3c49b86cad665a7f3790dc55a0394","versionType":"git","status":"affected"},{"version":"c9c12d339d93366732112d7ff472958834bfc3c5","lessThan":"19d2d36e193c3fb515c052a56bfc83d8ac7b6764","versionType":"git","status":"affected"},{"version":"c9c12d339d93366732112d7ff472958834bfc3c5","lessThan":"e8e9dff204e8d8553495893e1a44d2b5021648de","versionType":"git","status":"affected"},{"version":"c9c12d339d93366732112d7ff472958834bfc3c5","lessThan":"3d45d40b872aec0073d4cf08956a6c9b87c5e396","versionType":"git","status":"affected"},{"version":"c9c12d339d93366732112d7ff472958834bfc3c5","lessThan":"452ec5058ea4ed63adae8d6beeac9ee687fe8061","versionType":"git","status":"affected"},{"version":"c9c12d339d93366732112d7ff472958834bfc3c5","lessThan":"a056db30de92945ff8ee6033096678bfbae878e3","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/net/ethernet/marvell/octeontx2/nic/otx2_pf.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"5.10","status":"affected"},{"version":"0","lessThan":"5.10","versionType":"semver","status":"unaffected"},{"version":"5.10.261","lessThanOrEqual":"5.10.*","versionType":"semver","status":"unaffected"},{"version":"5.15.212","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.178","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.97","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/19d2d36e193c3fb515c052a56bfc83d8ac7b6764","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/3d45d40b872aec0073d4cf08956a6c9b87c5e396","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/452ec5058ea4ed63adae8d6beeac9ee687fe8061","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/a056db30de92945ff8ee6033096678bfbae878e3","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/c642a530aaaeb9a3e356cedfe77955e7f983380e","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/d6c0b0c802d3c49b86cad665a7f3790dc55a0394","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/e68ada66afcae0bc2a7c06b43c5a9a081d29e7b4","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/e8e9dff204e8d8553495893e1a44d2b5021648de","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-72449","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:22:18.837","lastModified":"2026-08-15T06:22:18.837","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amdkfd: fix list_del corruption in kfd_criu_resume_svm\n\nThe cleanup tail of kfd_criu_resume_svm() walks\nsvms->criu_svm_metadata_list and kfree()s each struct criu_svm_metadata\nwithout removing it from the list. The list head is left pointing at\nfreed kmalloc-96 objects.\n\nA second AMDKFD_IOC_CRIU_OP from the same process re-enters: list_empty()\nreads the dangling ->next (use-after-free), the loop walks freed entries,\nand each is kfree()'d again (double-free). This is reachable by an\nunprivileged render-group user via /dev/kfd with no capabilities required.\n\nAdd list_del() before the kfree() so the list is properly emptied. The\nlist_for_each_entry_safe() iterator already caches the next pointer, so\nunlinking during the walk is safe.\n\n(cherry picked from commit 6322d278a298e2c1430b9d2697743d3a04b788b1)"}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/gpu/drm/amd/amdkfd/kfd_svm.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"2a909ae718715b3bac75d945e38dc0a5e4a0f1ba","lessThan":"c8a8d350a273c005a48c64c4519d21b2a51c5ceb","versionType":"git","status":"affected"},{"version":"2a909ae718715b3bac75d945e38dc0a5e4a0f1ba","lessThan":"506e635aed05dbdeef11e3c59f6e42980cda5b6d","versionType":"git","status":"affected"},{"version":"2a909ae718715b3bac75d945e38dc0a5e4a0f1ba","lessThan":"838b57b3e7ce8cce0fda56d0861add3d464dd6c8","versionType":"git","status":"affected"},{"version":"2a909ae718715b3bac75d945e38dc0a5e4a0f1ba","lessThan":"96ac562a9ea3020981f536384711190841c81aa8","versionType":"git","status":"affected"},{"version":"2a909ae718715b3bac75d945e38dc0a5e4a0f1ba","lessThan":"e33a3bd5cb8d0cf1557dee014115f812c9686130","versionType":"git","status":"affected"},{"version":"2a909ae718715b3bac75d945e38dc0a5e4a0f1ba","lessThan":"8fa5655da368d0306c03e9dc9cda8ae2a7840926","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/gpu/drm/amd/amdkfd/kfd_svm.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"5.18","status":"affected"},{"version":"0","lessThan":"5.18","versionType":"semver","status":"unaffected"},{"version":"6.1.178","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.97","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/506e635aed05dbdeef11e3c59f6e42980cda5b6d","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/838b57b3e7ce8cce0fda56d0861add3d464dd6c8","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/8fa5655da368d0306c03e9dc9cda8ae2a7840926","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/96ac562a9ea3020981f536384711190841c81aa8","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/c8a8d350a273c005a48c64c4519d21b2a51c5ceb","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/e33a3bd5cb8d0cf1557dee014115f812c9686130","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-72450","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:22:18.950","lastModified":"2026-08-15T06:22:18.950","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nxfrm: validate selector family and prefixlen during match\n\nsyzbot reported a shift-out-of-bounds in xfrm_selector_match()\ndue to AF_UNSPEC selector with large prefixlen (e.g. 128) matched\nagainst IPv4 flow (when XFRM_STATE_AF_UNSPEC is set).\n\nFix this by:\n\n- Rejecting mismatched families in xfrm_selector_match.\n- Returning false in addr4_match if prefixlen > 32.\n- Returning false in addr_match if prefixlen > 128 (prevents overflow)."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["include/net/xfrm.h","net/xfrm/xfrm_policy.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"8df5cd51fd70c33aa1776e5cbcd82b0a86649d73","lessThan":"87a5bbccc7ff4edb3f42fea387124237d2ba91ee","versionType":"git","status":"affected"},{"version":"2d08a6c31c65f23db71a5385ee9cf9d8f9a67a71","lessThan":"bd7f202cf77556cff59f68dc30e4cdf40cb6e33b","versionType":"git","status":"affected"},{"version":"bce1afaa212ec380bf971614f70909a27882b862","lessThan":"a3968ad4195d72c8fddcc6c0ef39da95ac98711a","versionType":"git","status":"affected"},{"version":"7d9868180bd1e4cf37e7c5067362658971162366","lessThan":"efa9e3b9f3dea2e1ea4c7edf4edc863faef85986","versionType":"git","status":"affected"},{"version":"3f0ab59e6537c6a8f9e1b355b48f9c05a76e8563","lessThan":"78783fefdc8f36879b1a17efa0d3195ea5f2dc5f","versionType":"git","status":"affected"},{"version":"3f0ab59e6537c6a8f9e1b355b48f9c05a76e8563","lessThan":"6d99379c58f7f1c6ab2cc7aba01a4f52d71adcfe","versionType":"git","status":"affected"},{"version":"3f0ab59e6537c6a8f9e1b355b48f9c05a76e8563","lessThan":"5a03a2ee17e8259dde631ed84fd8322db06cb2ae","versionType":"git","status":"affected"},{"version":"3f0ab59e6537c6a8f9e1b355b48f9c05a76e8563","lessThan":"40f0b1047918539f0b0f795ac65e35336b4c2c78","versionType":"git","status":"affected"},{"version":"f31398570acf0f0804c644006f7bfa9067106b0a","versionType":"git","status":"affected"},{"version":"401ad99a5ae7180dd9449eac104cb755f442e7f3","versionType":"git","status":"affected"},{"version":"e68dd80ba498265d2266b12dc3459164f4ff0c4a","versionType":"git","status":"affected"},{"version":"5.10.229","lessThan":"5.10.261","versionType":"semver","status":"affected"},{"version":"5.15.170","lessThan":"5.15.212","versionType":"semver","status":"affected"},{"version":"6.1.115","lessThan":"6.1.178","versionType":"semver","status":"affected"},{"version":"6.6.59","lessThan":"6.6.145","versionType":"semver","status":"affected"},{"version":"4.19.323","lessThan":"4.20","versionType":"semver","status":"affected"},{"version":"5.4.285","lessThan":"5.5","versionType":"semver","status":"affected"},{"version":"6.11.6","lessThan":"6.12","versionType":"semver","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["include/net/xfrm.h","net/xfrm/xfrm_policy.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.12","status":"affected"},{"version":"0","lessThan":"6.12","versionType":"semver","status":"unaffected"},{"version":"5.10.261","lessThanOrEqual":"5.10.*","versionType":"semver","status":"unaffected"},{"version":"5.15.212","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.178","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.97","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/40f0b1047918539f0b0f795ac65e35336b4c2c78","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/5a03a2ee17e8259dde631ed84fd8322db06cb2ae","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/6d99379c58f7f1c6ab2cc7aba01a4f52d71adcfe","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/78783fefdc8f36879b1a17efa0d3195ea5f2dc5f","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/87a5bbccc7ff4edb3f42fea387124237d2ba91ee","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/a3968ad4195d72c8fddcc6c0ef39da95ac98711a","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/bd7f202cf77556cff59f68dc30e4cdf40cb6e33b","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/efa9e3b9f3dea2e1ea4c7edf4edc863faef85986","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-72451","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:22:19.087","lastModified":"2026-08-15T06:22:19.087","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nxfrm: Fix xfrm state cache insertion race\n\nThe xfrm input state cache insertion code checks the validity of\nthe state before acquiring the global xfrm_state_lock.  Thus it's\npossible for someone else to kill the state after it passed the\nvalidity check, and then the insertion will add the dead state\nto the cache.\n\nFix this by moving the validity check inside the lock.\n\nThis entire function is called on the input path, where BH must\nbe off (e.g., the caller of this function xfrm_input acquires\nits spinlocks without disabling BH).\n\nSo there is no need to disable BH here or take the RCU read lock.\nRemove both and replace them with an assertion that trips if BH\nis accidentally enabled on some future calling path."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["net/xfrm/xfrm_state.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"5e4334dc39443645415450163ff5ff1ee7e79784","lessThan":"6dab4dec9a49121d079981ac913569f232c06b06","versionType":"git","status":"affected"},{"version":"81a331a0e72ddc2f75092603d9577bd1a0ca23ad","lessThan":"a1a3360a0c44b8b5c134db2a9d0667b61c9cf523","versionType":"git","status":"affected"},{"version":"81a331a0e72ddc2f75092603d9577bd1a0ca23ad","lessThan":"041859fd55c81ea55e76d051e39b7b79975b8c7d","versionType":"git","status":"affected"},{"version":"81a331a0e72ddc2f75092603d9577bd1a0ca23ad","lessThan":"ddd3d0132920319ac426e12456013eadbae67e15","versionType":"git","status":"affected"},{"version":"6.12.13","lessThan":"6.12.97","versionType":"semver","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["net/xfrm/xfrm_state.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.13","status":"affected"},{"version":"0","lessThan":"6.13","versionType":"semver","status":"unaffected"},{"version":"6.12.97","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/041859fd55c81ea55e76d051e39b7b79975b8c7d","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/6dab4dec9a49121d079981ac913569f232c06b06","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/a1a3360a0c44b8b5c134db2a9d0667b61c9cf523","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/ddd3d0132920319ac426e12456013eadbae67e15","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-72452","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:22:19.183","lastModified":"2026-08-15T06:22:19.183","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/i915: clear CRTC color blob pointers after dropping refs\n\nintel_crtc_put_color_blobs() drops the CRTC color blob references, but\nleaves the corresponding pointers unchanged.\n\nThis can matter in intel_crtc_prepare_cleared_state(), which frees the\nold CRTC hw state before calling intel_dp_tunnel_atomic_clear_stream_bw().\nThe latter can fail while looking up the DP tunnel group state, for\nexample with -EDEADLK.\n\nIf that happens, the function returns without completing the cleared\nstate preparation. The failed atomic state will then be cleared by the\natomic core and intel_crtc_free_hw_state() can be called again for the\nsame state, dropping the same blob references again.\n\nClear the blob pointers after dropping the references so repeated cleanup\nof the same CRTC hw state is safe.\n\n(cherry picked from commit d5005addb5f68e8a0edce249506757bdc9e3d8c8)"}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/gpu/drm/i915/display/intel_atomic.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"9a6cbb4a5c168e94a69a0cbec572b3738205232b","lessThan":"164afa1a3af8e8c91b4a6d5fd7b79a44ec70abf0","versionType":"git","status":"affected"},{"version":"8581466b827fdf0300a3e2e93900ddefd8240053","lessThan":"2024940522ef451098c940ab0b82d647de5e5d9b","versionType":"git","status":"affected"},{"version":"77fcf58df15edcf3f5b5421f24814fb72796def9","lessThan":"ac554ad943610031a25795d6ef71316f6164c136","versionType":"git","status":"affected"},{"version":"77fcf58df15edcf3f5b5421f24814fb72796def9","lessThan":"31f077088e0faae6be8377741f356dea1b94ba46","versionType":"git","status":"affected"},{"version":"674fc4a50b667be65c947d81af63a9367deafb5c","versionType":"git","status":"affected"},{"version":"6.12.80","lessThan":"6.12.97","versionType":"semver","status":"affected"},{"version":"6.18.21","lessThan":"6.18.40","versionType":"semver","status":"affected"},{"version":"6.19.11","lessThan":"6.20","versionType":"semver","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/gpu/drm/i915/display/intel_atomic.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"7.0","status":"affected"},{"version":"0","lessThan":"7.0","versionType":"semver","status":"unaffected"},{"version":"6.12.97","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/164afa1a3af8e8c91b4a6d5fd7b79a44ec70abf0","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/2024940522ef451098c940ab0b82d647de5e5d9b","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/31f077088e0faae6be8377741f356dea1b94ba46","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/ac554ad943610031a25795d6ef71316f6164c136","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-72453","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:22:19.290","lastModified":"2026-08-15T06:22:19.290","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nregcache: Do not overwrite error code when finalizing cache after error\n\nDuring regcache initialization, if an error occurs in the\ncache_ops->populate callback, and if cache operations include an exit\ncallback, the error code from populate() is overwritten with the return\nvalue from exit(). This hides the error condition from the caller of\nregcache_init(), and can cause NULL pointer dereferences when the regcache\nis later accessed."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/base/regmap/regcache.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"94a3a95f03154d8d4c6206950a7f6ef9a30baec6","lessThan":"9f171aa115ec76be02c76c5765cd2c865279e34a","versionType":"git","status":"affected"},{"version":"94a3a95f03154d8d4c6206950a7f6ef9a30baec6","lessThan":"9108f7fa493b4c88cbc09503e0c164244456bad5","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/base/regmap/regcache.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.19","status":"affected"},{"version":"0","lessThan":"6.19","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/9108f7fa493b4c88cbc09503e0c164244456bad5","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/9f171aa115ec76be02c76c5765cd2c865279e34a","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-72454","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:22:19.387","lastModified":"2026-08-15T06:22:19.387","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\ni3c: mipi-i3c-hci: Fix race in i3c_hci_addr_to_dev()\n\ni3c_hci_addr_to_dev() walks bus->devs.i3c, which is protected by\nbus.lock (rwsem).  However, it is invoked from the MIPI I3C HCI IRQ\nhandler, which cannot take bus.lock.  This allows concurrent device\naddition/removal in the I3C core to modify the list while it is being\ntraversed, potentially leading to use-after-free or crashes.\n\nRemove the dependency on the bus device list and introduce a dedicated\nlookup table.  Add an ibi_devs[] array indexed by DAT entry, maintained\nunder hci->lock.  Update the array when IBIs are enabled or disabled,\nso that it always reflects the set of devices allowed to generate IBIs.\nAlso update when IBIs are freed, to cover the corner case when an IBI is\nfreed without first being disabled (e.g. oldedev in\ni3c_master_add_i3c_dev_locked()).\n\nMove i3c_hci_addr_to_dev() into core.c, reimplement it using the new\narray, and add a lockdep assertion to enforce that hci->lock is held\nby callers.\n\nDemote a message in PIO and DMA IBI handling, from an error to a debug\nmessage, because there is a race window when the condition can arise\nnormally."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/i3c/master/mipi-i3c-hci/core.c","drivers/i3c/master/mipi-i3c-hci/dma.c","drivers/i3c/master/mipi-i3c-hci/hci.h","drivers/i3c/master/mipi-i3c-hci/ibi.h","drivers/i3c/master/mipi-i3c-hci/pio.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"9ad9a52cce2828d932ae9495181e3d6414f72c07","lessThan":"8f851cab401c28287d536b1347d76f6e219c0db6","versionType":"git","status":"affected"},{"version":"9ad9a52cce2828d932ae9495181e3d6414f72c07","lessThan":"650716f23eac488c6696babdc7805f6a6b7427ad","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/i3c/master/mipi-i3c-hci/core.c","drivers/i3c/master/mipi-i3c-hci/dma.c","drivers/i3c/master/mipi-i3c-hci/hci.h","drivers/i3c/master/mipi-i3c-hci/ibi.h","drivers/i3c/master/mipi-i3c-hci/pio.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"5.11","status":"affected"},{"version":"0","lessThan":"5.11","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/650716f23eac488c6696babdc7805f6a6b7427ad","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/8f851cab401c28287d536b1347d76f6e219c0db6","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-72455","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:22:19.480","lastModified":"2026-08-15T06:22:19.480","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\napparmor: fix uninitialised pointer passed to audit_log_untrustedstring()\n\nCommit 4a134723f9f1 (\"apparmor: move check for aa_null file to cover all cases\")\nintrdouced a small bug, where path_name() may pass a potentially uninitialized\n*name to aa_audit_file() if the path->dentry had been replaced with\naa_null.dentry earlier on. This can lead to page fault like one observed on\n7.0.2 openSUSE Tumbleweed kernel:\n\n[51692.242756] [  T24690] BUG: unable to handle page fault for address: 0000000f00000003\n[51692.242762] [  T24690] #PF: supervisor read access in kernel mode\n[51692.242763] [  T24690] #PF: error_code(0x0000) - not-present page\n[51692.242765] [  T24690] PGD 0 P4D 0\n[51692.242768] [  T24690] Oops: Oops: 0000 [#1] SMP NOPTI\n[51692.242772] [  T24690] CPU: 3 UID: 1020 PID: 24690 Comm: snap-confine Tainted: G           O        7.0.2-1-default #1 PREEMPT(full) openSUSE Tumbleweed  ab90b4c9940707f9cafa19bdad80b2cec52dbe51\n[51692.242775] [  T24690] Tainted: [O]=OOT_MODULE\n[51692.242777] [  T24690] Hardware name: Framework Laptop 13 (AMD Ryzen 7040Series)/FRANMDCP05, BIOS 03.18 01/08/2026\n[51692.242778] [  T24690] RIP: 0010:strlen+0x4/0x30\n[51692.242783] [  T24690] Code: f7 75 ec 31 c0 e9 17 9f 00 ff 48 89 f8 e9 0f 9f 00 ff 0f 1f 40 00 90 90 90 90 90 90 90 90 90 90 90 90 90 90 90 90 f3 0f 1e fa <80> 3f 00 74 18 48 89 f8 0f 1f 40 00 48 83 c0 01 80 38 00 75 f7 48\n[51692.242785] [  T24690] RSP: 0018:ffffd015eb1e3608 EFLAGS: 00010282\n[51692.242787] [  T24690] RAX: 0000000000000000 RBX: ffff89796198a360 RCX: 0000000000000000\n[51692.242788] [  T24690] RDX: 00000000000000d1 RSI: 0000000f00000003 RDI: 0000000f00000003\n[51692.242790] [  T24690] RBP: ffffffffb7ede090 R08: 00000000000005f5 R09: 0000000000000000\n[51692.242791] [  T24690] R10: 0000000000000000 R11: 0000000000000000 R12: ffffd015eb1e3700\n[51692.242792] [  T24690] R13: ffff8977a22bc380 R14: ffffffffb7ec5190 R15: ffff8977a0c8aa80\n[51692.242794] [  T24690] FS:  0000000000000000(0000) GS:ffff897f640d8000(0000) knlGS:0000000000000000\n[51692.242796] [  T24690] CS:  0010 DS: 0000 ES: 0000 CR0: 0000000080050033\n[51692.242797] [  T24690] CR2: 0000000f00000003 CR3: 00000006ad15f000 CR4: 0000000000f50ef0\n[51692.242799] [  T24690] PKRU: 55555554\n[51692.242800] [  T24690] Call Trace:\n[51692.242802] [  T24690]  <TASK>\n[51692.242804] [  T24690]  audit_log_untrustedstring+0x1d/0x40\n[51692.242811] [  T24690]  common_lsm_audit+0x71/0x1d0\n[51692.242816] [  T24690]  aa_audit+0x5a/0x170\n[51692.242819] [  T24690]  aa_audit_file+0x18a/0x1b0\n[51692.242825] [  T24690]  path_name+0xd2/0x100\n[51692.242829] [  T24690]  profile_path_perm.part.0+0x58/0xb0\n[51692.242832] [  T24690]  aa_path_perm+0xef/0x150\n[51692.242837] [  T24690]  apparmor_file_open+0x153/0x2e0\n[51692.242840] [  T24690]  security_file_open+0x46/0xd0\n[51692.242844] [  T24690]  do_dentry_open+0xe9/0x4d0\n[51692.242848] [  T24690]  vfs_open+0x30/0x100\n\nWhile here, initialise variables which are passed down to path_name()."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["security/apparmor/file.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"b2a8011ae8749215f3939881239b454728a2d88b","lessThan":"2791dd42d41e38805572b12116f721c97c4fcc0c","versionType":"git","status":"affected"},{"version":"4a134723f9f1ad2f3621566259db673350d19cb1","lessThan":"a5c79d44ef19203bd7cf6f3de8ff088112ebff95","versionType":"git","status":"affected"},{"version":"4a134723f9f1ad2f3621566259db673350d19cb1","lessThan":"bcd1b34c21748531a3febaf7440632b89d8deab7","versionType":"git","status":"affected"},{"version":"d276f52ecaf854e41549311e93802afea0abab5b","versionType":"git","status":"affected"},{"version":"6.18.14","lessThan":"6.18.40","versionType":"semver","status":"affected"},{"version":"6.19.4","lessThan":"6.20","versionType":"semver","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["security/apparmor/file.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"7.0","status":"affected"},{"version":"0","lessThan":"7.0","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/2791dd42d41e38805572b12116f721c97c4fcc0c","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/a5c79d44ef19203bd7cf6f3de8ff088112ebff95","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/bcd1b34c21748531a3febaf7440632b89d8deab7","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-72456","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:22:19.597","lastModified":"2026-08-15T06:22:19.597","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\napparmor: release exe file resources on path failure\n\nget_current_exe_path() takes both an exe_file reference and a path\nreference before resolving the path name. If aa_path_name() failed, it\nreturned immediately and leaked both references.\n\nRoute the failure through the common cleanup path so fput() and path_put()\nalways run after the references are acquired."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["security/apparmor/task.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"8d34e16f7f2b51f880957f2caadaae731ee28867","lessThan":"393809a05cfb60309ad63ee09138db8296d6b97e","versionType":"git","status":"affected"},{"version":"8d34e16f7f2b51f880957f2caadaae731ee28867","lessThan":"7306c41672487a6c28430714be063bc6942c28f2","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["security/apparmor/task.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"7.0","status":"affected"},{"version":"0","lessThan":"7.0","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/393809a05cfb60309ad63ee09138db8296d6b97e","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/7306c41672487a6c28430714be063bc6942c28f2","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-72457","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:22:19.690","lastModified":"2026-08-15T06:22:19.690","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\napparmor: fail policy unpack on accept2 allocation failure\n\nunpack_pdb() may need to allocate a missing ACCEPT2 table for older policy\ndata. If that allocation failed, it set an error message but jumped to the\nsuccess path, returning a policydb with the required table missing.\n\nReturn -ENOMEM through the normal failure path when the ACCEPT2 allocation\nfails. Remove the now-unused out label."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["security/apparmor/policy_unpack.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"2e12c5f060176ede209673e4f63ea5d0e3c5814c","lessThan":"22dc9433d458cff1270f120685114a9753e0ad1b","versionType":"git","status":"affected"},{"version":"2e12c5f060176ede209673e4f63ea5d0e3c5814c","lessThan":"106e909e12baf059538f0b0f1a59f87781d25b3c","versionType":"git","status":"affected"},{"version":"2e12c5f060176ede209673e4f63ea5d0e3c5814c","lessThan":"45cf568241048e560a81aa2053f06a62069f5640","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["security/apparmor/policy_unpack.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.17","status":"affected"},{"version":"0","lessThan":"6.17","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/106e909e12baf059538f0b0f1a59f87781d25b3c","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/22dc9433d458cff1270f120685114a9753e0ad1b","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/45cf568241048e560a81aa2053f06a62069f5640","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-72458","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:22:19.783","lastModified":"2026-08-15T06:22:19.783","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\napparmor: fix NULL pointer dereference in unpack_pdb\n\npdb->dfa could be NULL if unpack_dfa fails, causing a NULL pointer\ndereference."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["security/apparmor/policy_unpack.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"2e12c5f060176ede209673e4f63ea5d0e3c5814c","lessThan":"fbfdb5a94a48797bea232791e24c38f3aa3063c8","versionType":"git","status":"affected"},{"version":"2e12c5f060176ede209673e4f63ea5d0e3c5814c","lessThan":"73d86ca950b80cd39ca948e2c518d135bf2308c8","versionType":"git","status":"affected"},{"version":"2e12c5f060176ede209673e4f63ea5d0e3c5814c","lessThan":"7681ca43d2b1c776e62fe77e3167835fb1ab8319","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["security/apparmor/policy_unpack.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.17","status":"affected"},{"version":"0","lessThan":"6.17","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/73d86ca950b80cd39ca948e2c518d135bf2308c8","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/7681ca43d2b1c776e62fe77e3167835fb1ab8319","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/fbfdb5a94a48797bea232791e24c38f3aa3063c8","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-72459","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:22:19.877","lastModified":"2026-08-15T06:22:19.877","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\napparmor: aa_label_alloc use aa_label_free on alloc failure\n\naa_label_alloc() allocates a secid before allocating or taking the label\nproxy. If the later proxy step fails, the error path only freed the label\nmemory, leaking any resources initialized by aa_label_init().\n\nUse aa_label_free() on the failure path so partially initialized labels\nrelease their secid and other label resources before the backing memory is\nfreed."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["security/apparmor/label.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"f1bd904175e8190ce14aedee37e207ab51fe3b30","lessThan":"b14fbacad77d64594228983ec20d61a224f3f491","versionType":"git","status":"affected"},{"version":"f1bd904175e8190ce14aedee37e207ab51fe3b30","lessThan":"b5a9da5d36162d34db0f36abb15420e295176793","versionType":"git","status":"affected"},{"version":"f1bd904175e8190ce14aedee37e207ab51fe3b30","lessThan":"7cb69e109610bba500e1ecb870f7988a4717208a","versionType":"git","status":"affected"},{"version":"f1bd904175e8190ce14aedee37e207ab51fe3b30","lessThan":"cc2192899d502e3321e60cf1e91421e7309d089c","versionType":"git","status":"affected"},{"version":"f1bd904175e8190ce14aedee37e207ab51fe3b30","lessThan":"bf310b044e85d4de670c94295c5d8e4c5bc5e7bc","versionType":"git","status":"affected"},{"version":"f1bd904175e8190ce14aedee37e207ab51fe3b30","lessThan":"ae02e603c0b39b29f3ce6fe3efe01b286af1a2a4","versionType":"git","status":"affected"},{"version":"f1bd904175e8190ce14aedee37e207ab51fe3b30","lessThan":"6d91479174240f39e9edea250d95fa08c678a207","versionType":"git","status":"affected"},{"version":"f1bd904175e8190ce14aedee37e207ab51fe3b30","lessThan":"654fe7505dc6889724d4094fa64f89991afabfc3","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["security/apparmor/label.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"4.13","status":"affected"},{"version":"0","lessThan":"4.13","versionType":"semver","status":"unaffected"},{"version":"5.10.261","lessThanOrEqual":"5.10.*","versionType":"semver","status":"unaffected"},{"version":"5.15.212","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.178","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.97","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/654fe7505dc6889724d4094fa64f89991afabfc3","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/6d91479174240f39e9edea250d95fa08c678a207","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/7cb69e109610bba500e1ecb870f7988a4717208a","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/ae02e603c0b39b29f3ce6fe3efe01b286af1a2a4","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/b14fbacad77d64594228983ec20d61a224f3f491","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/b5a9da5d36162d34db0f36abb15420e295176793","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/bf310b044e85d4de670c94295c5d8e4c5bc5e7bc","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/cc2192899d502e3321e60cf1e91421e7309d089c","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-72460","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:22:19.993","lastModified":"2026-08-15T06:22:19.993","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\napparmor: check label build before no_new_privs test\n\naa_change_profile() builds a replacement label with\nfn_label_build_in_scope() before the no_new_privs subset check. The build\nhelper can fail and return NULL or an ERR_PTR, but the result was passed\nto aa_label_is_unconfined_subset() before the existing IS_ERR_OR_NULL()\ncheck.\n\nReuse the existing target-label build failure handling immediately after\nthe build. This preserves the current audit handling while preventing the\nsubset helper from dereferencing an invalid label."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["security/apparmor/domain.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"e00b02bb6ac2a1893227ce8014b649028d6425d2","lessThan":"a29f06db44b4c94597ded58f639eed3e21781ac3","versionType":"git","status":"affected"},{"version":"e00b02bb6ac2a1893227ce8014b649028d6425d2","lessThan":"cfc224866530a6842b6c2d2d30ef6a9b0e64bb9c","versionType":"git","status":"affected"},{"version":"e00b02bb6ac2a1893227ce8014b649028d6425d2","lessThan":"31cb109db5e6322ed22304fd5c0dedbaa438d6d3","versionType":"git","status":"affected"},{"version":"e00b02bb6ac2a1893227ce8014b649028d6425d2","lessThan":"b7c45c05a396a017c49ac7949de240a0dfc0ac4e","versionType":"git","status":"affected"},{"version":"e00b02bb6ac2a1893227ce8014b649028d6425d2","lessThan":"d84bb195d208adbf77f012ca2a96e11163f6def1","versionType":"git","status":"affected"},{"version":"e00b02bb6ac2a1893227ce8014b649028d6425d2","lessThan":"d82160132345688a09cbaa648cfdd16bb32e8ea2","versionType":"git","status":"affected"},{"version":"e00b02bb6ac2a1893227ce8014b649028d6425d2","lessThan":"ec926b2a351eeeb31e6c9aee02e0c32f94b5588f","versionType":"git","status":"affected"},{"version":"e00b02bb6ac2a1893227ce8014b649028d6425d2","lessThan":"a58cafd38b46fb1a2220e2fbbcfe291ea75fa147","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["security/apparmor/domain.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"4.13","status":"affected"},{"version":"0","lessThan":"4.13","versionType":"semver","status":"unaffected"},{"version":"5.10.261","lessThanOrEqual":"5.10.*","versionType":"semver","status":"unaffected"},{"version":"5.15.212","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.178","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.97","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/31cb109db5e6322ed22304fd5c0dedbaa438d6d3","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/a29f06db44b4c94597ded58f639eed3e21781ac3","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/a58cafd38b46fb1a2220e2fbbcfe291ea75fa147","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/b7c45c05a396a017c49ac7949de240a0dfc0ac4e","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/cfc224866530a6842b6c2d2d30ef6a9b0e64bb9c","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/d82160132345688a09cbaa648cfdd16bb32e8ea2","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/d84bb195d208adbf77f012ca2a96e11163f6def1","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/ec926b2a351eeeb31e6c9aee02e0c32f94b5588f","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-72461","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:22:20.113","lastModified":"2026-08-15T06:22:20.113","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\napparmor: fix refcount leak when updating the sk_ctx\n\nCurrently update_sk_ctx() transfers the plabel reference, unfortunately\nit is also unconditionally put in the caller. Ideally we would make\nthe caller conditionally put the reference based on whether it was\ntransferred but for now just fix the bug by getting a reference."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["security/apparmor/af_unix.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"88fec3526e84123997ecebd6bb6778eb4ce779b7","lessThan":"045dbe89ac31709abd73390d0805d52fece7ef39","versionType":"git","status":"affected"},{"version":"88fec3526e84123997ecebd6bb6778eb4ce779b7","lessThan":"b8642f1478982a97ca2eb59f70f631a9de42ae11","versionType":"git","status":"affected"},{"version":"88fec3526e84123997ecebd6bb6778eb4ce779b7","lessThan":"6d25e7b47616cb2db43351210929c8f19dc305a3","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["security/apparmor/af_unix.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.17","status":"affected"},{"version":"0","lessThan":"6.17","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/045dbe89ac31709abd73390d0805d52fece7ef39","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/6d25e7b47616cb2db43351210929c8f19dc305a3","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/b8642f1478982a97ca2eb59f70f631a9de42ae11","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-72462","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:22:20.210","lastModified":"2026-08-15T06:22:20.210","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\napparmor: fix race in unix socket mediation when peer_path is used\n\nThe holding a reference to the peer_sk is not enough to ensure access\nto the peer sk path. Accessing the path outside of the state lock\nallows for a race with unix_release_sock(). Fix this by taking the\nstate lock and getting a reference to the path under lock.\n\nIdeally for connected sockets we would cache this information so we\ndon't have to take the lock here. But for now just fix the race."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["security/apparmor/af_unix.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"bc6e5f6933b8e7b74858ac830d5b9b4ca10a099a","lessThan":"d8ea44f6090c087fe255d9512fb808574b4d88e8","versionType":"git","status":"affected"},{"version":"bc6e5f6933b8e7b74858ac830d5b9b4ca10a099a","lessThan":"d680472db98823d90fc91362910901e468269318","versionType":"git","status":"affected"},{"version":"bc6e5f6933b8e7b74858ac830d5b9b4ca10a099a","lessThan":"b1aea2c1960771a276d7e68c7424168eccd0c3da","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["security/apparmor/af_unix.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.17","status":"affected"},{"version":"0","lessThan":"6.17","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/b1aea2c1960771a276d7e68c7424168eccd0c3da","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/d680472db98823d90fc91362910901e468269318","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/d8ea44f6090c087fe255d9512fb808574b4d88e8","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-72463","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:22:20.303","lastModified":"2026-08-15T06:22:20.303","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nxfrm: Fix dev use-after-free in xfrm async resumption\n\nxfrm async resumption hold skb->dev refcnt until after transport_finish.\nHowever, xfrm_rcv_cb may modify skb->dev to tunnel dev without taking\ndevice reference, such as vti_rcv_cb. The subsequent async resumption\nwill decrement the tunnel device's reference count, which lead to uaf\nof tunnel dev and refcnt leak of orig dev as below:\n\nunregister_netdevice: waiting for vti1 to become free. Usage count = -2\n\nStash the original skb->dev to fix refcnt imbalance. The new skb->dev set\nby xfrm_rcv_cb can race with device teardown. Extend rcu protection over\nxfrm_rcv_cb and transport_finish to prevent races."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["net/ipv4/xfrm4_input.c","net/ipv6/xfrm6_input.c","net/xfrm/xfrm_input.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"1c428b03840094410c5fb6a5db30640486bbbfcb","lessThan":"63a30015199912bd5055bead8001b1ae68a67cdb","versionType":"git","status":"affected"},{"version":"1c428b03840094410c5fb6a5db30640486bbbfcb","lessThan":"8045c0df98d4f14c54e5cb875f1c9c0ce89fe4ff","versionType":"git","status":"affected"},{"version":"4236c30b437b80f673b9e08c8fae38b8d471ac9e","versionType":"git","status":"affected"},{"version":"0f451b43c88bf2b9c038b414be580efee42e031b","versionType":"git","status":"affected"},{"version":"5002beda5cac69d522dc54da0d5d463ed9c963d2","versionType":"git","status":"affected"},{"version":"6.12.94","lessThan":"6.13","versionType":"semver","status":"affected"},{"version":"6.18.23","lessThan":"6.19","versionType":"semver","status":"affected"},{"version":"6.19.13","lessThan":"6.20","versionType":"semver","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["net/ipv4/xfrm4_input.c","net/ipv6/xfrm6_input.c","net/xfrm/xfrm_input.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"7.0","status":"affected"},{"version":"0","lessThan":"7.0","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/63a30015199912bd5055bead8001b1ae68a67cdb","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/8045c0df98d4f14c54e5cb875f1c9c0ce89fe4ff","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-72464","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:22:20.400","lastModified":"2026-08-15T06:22:20.400","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nxprtrdma: Repost Receive buffers for malformed replies\n\nrpcrdma_wc_receive() decrements the transport's Receive count for\nevery completion before it dispatches a successful Receive to\nrpcrdma_reply_handler(). The handler must post a replacement\nReceive WR before returning unless ownership of the rep has moved\nelsewhere, as on the backchannel path.\n\nCommit 2ae50ad68cd7 (\"xprtrdma: Close window between waking RPC\nsenders and posting Receives\") moved the Receive refill out of\nrpcrdma_wc_receive(), where it had run ahead of every reply, into\nrpcrdma_reply_handler() so that the responder's credit grant could\nbe parsed before reposting. The bad-version and short-reply exits\nnever reach that refill: they recycle the rep and return without\ncalling rpcrdma_post_recvs().\n\nA remote peer can therefore drain the client's posted Receive\nqueue by sending a sustained stream of replies that are shorter\nthan the fixed transport header or that carry an unrecognized\nRPC/RDMA version. Each such reply consumes one posted Receive\nwithout replacing it. Once the queue empties, the peer's next\nSend finds no posted Receive and the transport stalls until\nreconnect.\n\nRoute both malformed-reply exits through the shared repost tail\nafter recycling the rep, refilling against buf->rb_credits, the\nmost recent accepted credit grant. Neither exit updates the\ncongestion window, so RPCs admitted under the previous grant\nremain in flight awaiting replies. A smaller refill target would\nlet a stream of malformed replies ratchet the posted Receive count\ndown to the batch floor while the congestion window still admits\nrb_credits RPCs; a burst of valid replies to those RPCs could then\noverrun the posted Receives, and because the client connects with\nrnr_retry_count of zero, a single RNR NAK terminates the\nconnection. Refilling against rb_credits also restores the target\nthat applied to malformed replies before commit 2ae50ad68cd7\n(\"xprtrdma: Close window between waking RPC senders and posting\nReceives\") when rpcrdma_post_recvs() computed it from rb_credits\ninternally. rb_credits is at least one from connection\nestablishment onward, so the repost path always keeps Receives\nposted."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["net/sunrpc/xprtrdma/rpc_rdma.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"2ae50ad68cd79224198b525f7bd645c9da98b6ff","lessThan":"ef6fb8a5c521f1a07f85202d13e8f2898f247362","versionType":"git","status":"affected"},{"version":"2ae50ad68cd79224198b525f7bd645c9da98b6ff","lessThan":"4322fd9645ee769ad29ce5caea74a1cd9b17269d","versionType":"git","status":"affected"},{"version":"2ae50ad68cd79224198b525f7bd645c9da98b6ff","lessThan":"19fae02b272ee4bcdfb5db57f402d28f1697167a","versionType":"git","status":"affected"},{"version":"2ae50ad68cd79224198b525f7bd645c9da98b6ff","lessThan":"007b4da2f38dcc16a13265416f4ca9f179bab610","versionType":"git","status":"affected"},{"version":"2ae50ad68cd79224198b525f7bd645c9da98b6ff","lessThan":"d7c531ab477ae94fd03771d707fd29c787408039","versionType":"git","status":"affected"},{"version":"2ae50ad68cd79224198b525f7bd645c9da98b6ff","lessThan":"abc011ddaf1617e3e82d8a1e87daa7ddbfb9bac5","versionType":"git","status":"affected"},{"version":"3791c5982ba1eebf2900ee7ca7b9a89619c26d54","versionType":"git","status":"affected"},{"version":"5.4.13","lessThan":"5.5","versionType":"semver","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["net/sunrpc/xprtrdma/rpc_rdma.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"5.5","status":"affected"},{"version":"0","lessThan":"5.5","versionType":"semver","status":"unaffected"},{"version":"6.1.178","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.97","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/007b4da2f38dcc16a13265416f4ca9f179bab610","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/19fae02b272ee4bcdfb5db57f402d28f1697167a","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/4322fd9645ee769ad29ce5caea74a1cd9b17269d","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/abc011ddaf1617e3e82d8a1e87daa7ddbfb9bac5","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/d7c531ab477ae94fd03771d707fd29c787408039","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/ef6fb8a5c521f1a07f85202d13e8f2898f247362","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-72465","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:22:20.527","lastModified":"2026-08-15T06:22:20.527","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nxprtrdma: Sanitize the reply credit grant after parsing\n\nThe out_norqst exit in rpcrdma_reply_handler() branches away before\nthe credit clamp, so a reply that matches no pending request reaches\nout_post carrying the raw credit value parsed from the wire.\nrpcrdma_post_recvs() does not bound its @needed argument: the refill\nloop allocates and chains Receive WRs until the count is satisfied or\nallocation fails. A peer that sends a well-formed reply carrying an\nunknown XID and an inflated credit grant therefore drives rep\nallocation and Receive posting past re_max_requests on every such\nreply.\n\nMove the clamp to immediately after the credit field is parsed,\nahead of the first branch that can reach out_post, so every later\nconsumer sees a sanitized value. The cwnd update stays on the\nmatched-request path."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["net/sunrpc/xprtrdma/rpc_rdma.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"d01d6670c169316115b26dfb3585a73dfe40b563","lessThan":"7cf332b3d82d73ffceedca6b4a120be074172021","versionType":"git","status":"affected"},{"version":"d1b159356a3584943192712392fcb2439aafb8c1","lessThan":"41634242140173eabbf54f899f9c70b5c685e786","versionType":"git","status":"affected"},{"version":"17da9e0caa8615f6fc3b4022eadbd78a9aea1a2a","lessThan":"8be1bb378def94a5cb8f7527a191e476407118ec","versionType":"git","status":"affected"},{"version":"e7ae0883c8c89b901226de43862184bf37054338","lessThan":"469b22376ee73369711ecf2761bd122ef4195963","versionType":"git","status":"affected"},{"version":"704f3f640f72db4d44ec5ce3db8d4e150c974bc7","lessThan":"33db78b1b24fc6a464ae08aa4d2538c5f883eb5e","versionType":"git","status":"affected"},{"version":"704f3f640f72db4d44ec5ce3db8d4e150c974bc7","lessThan":"c3a628aab2dc8f5fd7bff86ceaeae64de590e60a","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["net/sunrpc/xprtrdma/rpc_rdma.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"7.1","status":"affected"},{"version":"0","lessThan":"7.1","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/33db78b1b24fc6a464ae08aa4d2538c5f883eb5e","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/41634242140173eabbf54f899f9c70b5c685e786","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/469b22376ee73369711ecf2761bd122ef4195963","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/7cf332b3d82d73ffceedca6b4a120be074172021","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/8be1bb378def94a5cb8f7527a191e476407118ec","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/c3a628aab2dc8f5fd7bff86ceaeae64de590e60a","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-72466","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:22:20.637","lastModified":"2026-08-15T06:22:20.637","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nxprtrdma: Fix bcall rep leak and unbounded peek\n\nrpcrdma_is_bcall() decodes a reply's first words to decide whether\nthe frame is a backchannel call. Two issues in that decode path\nlet a short or malformed reply leak the receive buffer and drain\nthe Receive queue.\n\nFirst, the speculative peek\n\n    p = xdr_inline_decode(xdr, 0);\n    /* five p++ reads follow */\n\nasks xdr_inline_decode() for zero bytes, which returns xdr->p\nwithout consulting xdr->end. The five subsequent __be32 reads can\nthen walk up to 20 bytes past the wire payload into stale regbuf\ncontents and misclassify the reply as a backchannel call.\n\nSecond, after the post-peek\n\n    p = xdr_inline_decode(xdr, 3 * sizeof(*p));\n    if (unlikely(!p))\n            return true;\n\nthe short-header arm returns true without calling\nrpcrdma_bc_receive_call(). The contract with the caller is that a\ntrue return transfers ownership of rep to the backchannel path:\n\n    rpcrdma_reply_handler()\n      if (rpcrdma_is_bcall(r_xprt, rep))\n              return;        /* bare return, skips out_post */\n      ...\n    out_post:\n      rpcrdma_post_recvs(r_xprt, credits + ...);\n\nBecause rpcrdma_bc_receive_call() never ran, no one took rep, but\nrpcrdma_reply_handler still bare-returns past rpcrdma_rep_put()\nand rpcrdma_post_recvs(). The rep, with its persistently\nDMA-mapped receive buffer, is orphaned on rb_all_reps and freed\nonly at transport teardown. This completion reposts nothing, so\nits slot is reclaimed only when a later forward-channel reply\nreaches out_post and rpcrdma_post_recvs() allocates a fresh rep to\nbackfill; absent that traffic the Receive queue drains and the\npeer's Sends draw RNR NAKs.\n\nFix by consulting xdr->end after the zero-length peek so the five\n__be32 reads cannot run unless 20 bytes of wire payload remain. A\nbyte-precise comparison against xdr->end is required because a\nnon-4-aligned receive rounds the stream's word count up past the\ntrue payload. Also return false from the short-header arm so the\nreply falls through the normal out_norqst cleanup chain\n(rpcrdma_rep_put() plus rpcrdma_post_recvs())."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["net/sunrpc/xprtrdma/rpc_rdma.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"41c8f70f5a3db7e06179186b6525fd9ee1d7d314","lessThan":"0cee8f9c3b14bd6dee9c4310090a7f45b89b834f","versionType":"git","status":"affected"},{"version":"41c8f70f5a3db7e06179186b6525fd9ee1d7d314","lessThan":"7afc2f8d2fd9394724df9eaf22ce7a71029a5fba","versionType":"git","status":"affected"},{"version":"41c8f70f5a3db7e06179186b6525fd9ee1d7d314","lessThan":"88b5346284a184a6b7d019912232a571d672d3e3","versionType":"git","status":"affected"},{"version":"41c8f70f5a3db7e06179186b6525fd9ee1d7d314","lessThan":"07aa506436be7634e381e1e1f6d0efa9efc81ecc","versionType":"git","status":"affected"},{"version":"41c8f70f5a3db7e06179186b6525fd9ee1d7d314","lessThan":"d7a2870dde3bb09d51d6b9c877642996ad6b92dd","versionType":"git","status":"affected"},{"version":"41c8f70f5a3db7e06179186b6525fd9ee1d7d314","lessThan":"118a16a18c59f7ad8084b2d13988839b669fca10","versionType":"git","status":"affected"},{"version":"41c8f70f5a3db7e06179186b6525fd9ee1d7d314","lessThan":"c7653d5cebc8492c77ec0415b5e9c0fb3e644bc6","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["net/sunrpc/xprtrdma/rpc_rdma.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"4.14","status":"affected"},{"version":"0","lessThan":"4.14","versionType":"semver","status":"unaffected"},{"version":"5.15.212","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.178","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.97","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/07aa506436be7634e381e1e1f6d0efa9efc81ecc","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/0cee8f9c3b14bd6dee9c4310090a7f45b89b834f","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/118a16a18c59f7ad8084b2d13988839b669fca10","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/7afc2f8d2fd9394724df9eaf22ce7a71029a5fba","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/88b5346284a184a6b7d019912232a571d672d3e3","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/c7653d5cebc8492c77ec0415b5e9c0fb3e644bc6","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/d7a2870dde3bb09d51d6b9c877642996ad6b92dd","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-72467","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:22:20.770","lastModified":"2026-08-15T06:22:20.770","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nxprtrdma: Check frwr_wp_create() during connect\n\nfrwr_wp_create() creates the singleton Memory Region used to encode\npadding for Write chunks whose payload length is not XDR-aligned. Its\nfailure paths return a negative errno and leave ep->re_write_pad_mr set\nto NULL.\n\nrpcrdma_xprt_connect() currently ignores that return value. If\nfrwr_wp_create() fails after the rest of the connection setup succeeds,\nxprt_rdma_connect_worker() treats the connection attempt as successful\nand sets XPRT_CONNECTED. A later NFS/RDMA read with a non-4-byte-aligned\nreceive page length reaches rpcrdma_encode_write_list(), passes the NULL\nwrite-pad MR to encode_rdma_segment(), and dereferences it.\n\nThis is locally triggerable on an NFS/RDMA client after a connect or\nreconnect hits a local MR allocation, DMA-map, MR-map, or post-send\nfailure; a remote peer alone cannot force the local MR setup failure.\n\nCheck the return value and fail the connect as -ENOTCONN, matching the\nadjacent setup failures. This keeps XPRT_CONNECTED clear and lets the\nnormal reconnect path retry."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["net/sunrpc/xprtrdma/verbs.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"21037b8c2258ec40de3b31be9ced43ceb3b784f7","lessThan":"3b252fe1778b2cdd68283146455929801bc2abd7","versionType":"git","status":"affected"},{"version":"21037b8c2258ec40de3b31be9ced43ceb3b784f7","lessThan":"dd798b76a3481e392820c3ae86ed4592858c6b0f","versionType":"git","status":"affected"},{"version":"21037b8c2258ec40de3b31be9ced43ceb3b784f7","lessThan":"6b7be4f3feae322f1c2c40a3bdc99db93574a49e","versionType":"git","status":"affected"},{"version":"21037b8c2258ec40de3b31be9ced43ceb3b784f7","lessThan":"7471e66373a4444a57ef2192f8c4081202c54f45","versionType":"git","status":"affected"},{"version":"21037b8c2258ec40de3b31be9ced43ceb3b784f7","lessThan":"ef3b79edf14b6bfb0d21a26ccb0463f9cf82c6a9","versionType":"git","status":"affected"},{"version":"21037b8c2258ec40de3b31be9ced43ceb3b784f7","lessThan":"0f13fc7c7d2e0427517e63c739277a4cd338b0c5","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["net/sunrpc/xprtrdma/verbs.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"5.16","status":"affected"},{"version":"0","lessThan":"5.16","versionType":"semver","status":"unaffected"},{"version":"6.1.178","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.97","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/0f13fc7c7d2e0427517e63c739277a4cd338b0c5","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/3b252fe1778b2cdd68283146455929801bc2abd7","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/6b7be4f3feae322f1c2c40a3bdc99db93574a49e","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/7471e66373a4444a57ef2192f8c4081202c54f45","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/dd798b76a3481e392820c3ae86ed4592858c6b0f","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/ef3b79edf14b6bfb0d21a26ccb0463f9cf82c6a9","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-72468","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:22:20.877","lastModified":"2026-08-15T06:22:20.877","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nxprtrdma: Initialize re_id before removal registration\n\nrpcrdma_create_id() registers ep->re_rn with the rpcrdma ib_client\nbefore returning the new rdma_cm_id to rpcrdma_ep_create(). However\nrpcrdma_ep_create() currently stores that pointer in ep->re_id only\nafter rpcrdma_create_id() returns.\n\nA local administrator can race an NFS/RDMA mount against RDMA device\nremoval. If rpcrdma_remove_one() observes the just-registered\nnotification before rpcrdma_ep_create() assigns ep->re_id,\nrpcrdma_ep_removal_done() calls trace_xprtrdma_device_removal(NULL).\nThe tracepoint dereferences id->device->name and copies\nid->route.addr.dst_addr, so the callback can crash the kernel with a\nNULL pointer dereference.\n\nStore the rdma_cm_id in ep->re_id immediately before publishing\nep->re_rn. The existing error path still destroys the id directly if\nregistration fails; ep is then freed by the caller without using\nep->re_id. Remove the later duplicate assignment in rpcrdma_ep_create()."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["net/sunrpc/xprtrdma/verbs.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"3f4eb9ff923413cdb4c7e171c06d3564f6286712","lessThan":"51248d877bbc6e604e38aeaf776c2781cb4f0dbd","versionType":"git","status":"affected"},{"version":"3f4eb9ff923413cdb4c7e171c06d3564f6286712","lessThan":"28743571c17b58c21a7216fc9faaf8028df5869b","versionType":"git","status":"affected"},{"version":"3f4eb9ff923413cdb4c7e171c06d3564f6286712","lessThan":"264ccd7871915749bee55fe0c39467a7f08d5479","versionType":"git","status":"affected"},{"version":"3f4eb9ff923413cdb4c7e171c06d3564f6286712","lessThan":"bb7caa63e1db22fd03e8dc591b12169e99169dff","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["net/sunrpc/xprtrdma/verbs.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.11","status":"affected"},{"version":"0","lessThan":"6.11","versionType":"semver","status":"unaffected"},{"version":"6.12.97","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/264ccd7871915749bee55fe0c39467a7f08d5479","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/28743571c17b58c21a7216fc9faaf8028df5869b","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/51248d877bbc6e604e38aeaf776c2781cb4f0dbd","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/bb7caa63e1db22fd03e8dc591b12169e99169dff","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-72469","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:22:20.997","lastModified":"2026-08-15T06:22:20.997","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nxprtrdma: Fix ep kref imbalance on ADDR_CHANGE\n\nrpcrdma_cm_event_handler() falls through to the disconnected: label\non RDMA_CM_EVENT_ADDR_CHANGE and calls rpcrdma_ep_put() with no\nmatching get when the event arrives before RDMA_CM_EVENT_ESTABLISHED.\nThe kref then underflows during connect teardown and\nrpcrdma_xprt_disconnect() operates on a freed ep.\n\nReference counts across a normal connection lifecycle:\n\n    rpcrdma_ep_create()             kref_init     ->1\n    rpcrdma_xprt_connect()          ep_get        ->2  (before post_recvs)\n    RDMA_CM_EVENT_ESTABLISHED       ep_get        ->3\n    RDMA_CM_EVENT_DISCONNECTED      ep_put        ->2\n    rpcrdma_xprt_drain()            ep_put        ->1\n    rpcrdma_xprt_disconnect() tail  ep_put        ->0  (ep_destroy)\n\nThe connect-time get in rpcrdma_xprt_connect(), taken just before\nrpcrdma_post_recvs() \"while there are outstanding Receives,\" is\nbalanced by rpcrdma_xprt_drain. ADDR_CHANGE before ESTABLISHED has\nno get to consume, so its put drops the count to 1 and the drain\nput then frees the ep while rpcrdma_xprt_disconnect() still holds a\npointer to it.\n\nFix by dispatching on the prior re_connect_status via xchg(): for\nprev == 0 (pre-ESTABLISHED) wake the connect waiter and return with\nno put; for prev == 1 call rpcrdma_force_disconnect() and return.\nThe case-1 arm relies on the subsequent RDMA_CM_EVENT_DISCONNECTED\nevent -- reliably delivered when rdma_disconnect() is called on a\nstill-connected cm_id -- to balance the ESTABLISHED get;\nrpcrdma_xprt_drain() continues to balance only that connect-time\nget. Any other prior value means teardown is already in flight."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["net/sunrpc/xprtrdma/verbs.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"2acc5cae292355f5f18ad377a2a966e7f03c8fec","lessThan":"cfd1bab66b042da7a778786685125656c695931b","versionType":"git","status":"affected"},{"version":"2acc5cae292355f5f18ad377a2a966e7f03c8fec","lessThan":"d0479c2b12974aa188b10d221a5770126b118b6d","versionType":"git","status":"affected"},{"version":"2acc5cae292355f5f18ad377a2a966e7f03c8fec","lessThan":"ffc07790539736a5d029f6a3c966b46c529f93a8","versionType":"git","status":"affected"},{"version":"2acc5cae292355f5f18ad377a2a966e7f03c8fec","lessThan":"af9b65b29af341932625c4283dc7a23cdb62688a","versionType":"git","status":"affected"},{"version":"2fcbf07a4f23174a45e015b62a8e42ddbc2e53ef","versionType":"git","status":"affected"},{"version":"5.7.9","lessThan":"5.8","versionType":"semver","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["net/sunrpc/xprtrdma/verbs.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"5.8","status":"affected"},{"version":"0","lessThan":"5.8","versionType":"semver","status":"unaffected"},{"version":"6.12.97","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/af9b65b29af341932625c4283dc7a23cdb62688a","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/cfd1bab66b042da7a778786685125656c695931b","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/d0479c2b12974aa188b10d221a5770126b118b6d","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/ffc07790539736a5d029f6a3c966b46c529f93a8","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-72470","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:22:21.103","lastModified":"2026-08-15T06:22:21.103","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nfs/ntfs3: resize log->one_page_buf when adopting on-disk page size\n\nlog_replay() allocates log->one_page_buf using the page size that was\nchosen from the host PAGE_SIZE:\n\n\tlog->one_page_buf = kmalloc(log->page_size, GFP_NOFS);\n\nLater, when a restart area is found, the log page size recorded on disk\nis adopted:\n\n\tt32 = le32_to_cpu(log->rst_info.r_page->sys_page_size);\n\tif (log->page_size != t32) {\n\t\tlog->l_size = log->orig_file_size;\n\t\tlog->page_size = norm_file_page(t32, &log->l_size,\n\t\t\t\t\t\tt32 == DefaultLogPageSize);\n\t}\n\nIf the on-disk page size is larger than the size used for the initial\nallocation, log->page_size grows but one_page_buf is left at its\noriginal, smaller size. A subsequent unaligned read_log_page() then\nreads log->page_size bytes into the undersized scratch buffer:\n\n\tpage_buf = page_off ? log->one_page_buf : *buffer;\n\terr = ntfs_read_run_nb_ra(ni->mi.sbi, &ni->file.run, page_vbo, page_buf,\n\t\t\t\t  log->page_size, NULL, &log->read_ahead);\n\noverflowing the allocation. This is reachable when mounting a dirty\nNTFS volume whose log was formatted with a page size larger than the\nbuffer initially allocated on the mounting host (for example a 64K-log\nvolume mounted on a host that allocated a 4K scratch buffer).\n\nGrow one_page_buf when the adopted on-disk page size exceeds the size\nused for the initial allocation. On krealloc() failure the original\nbuffer is left intact and freed by the existing error path."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["fs/ntfs3/fslog.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"b46acd6a6a627d876898e1c84d3f84902264b445","lessThan":"2097a2537d9d1c29c0e20ed0dbf717a0ccd8f374","versionType":"git","status":"affected"},{"version":"b46acd6a6a627d876898e1c84d3f84902264b445","lessThan":"f1422df595d69b997d23a8f11e12c528ccef7fad","versionType":"git","status":"affected"},{"version":"b46acd6a6a627d876898e1c84d3f84902264b445","lessThan":"4f129fc6f756f8541e5bff45b1804cc11b1ec712","versionType":"git","status":"affected"},{"version":"b46acd6a6a627d876898e1c84d3f84902264b445","lessThan":"c99444f6dfca893f6d310aae4a53c620f98f7b4f","versionType":"git","status":"affected"},{"version":"b46acd6a6a627d876898e1c84d3f84902264b445","lessThan":"5a35454179fe1041d9cd286f5d320ce0d448c12a","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["fs/ntfs3/fslog.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"5.15","status":"affected"},{"version":"0","lessThan":"5.15","versionType":"semver","status":"unaffected"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.97","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/2097a2537d9d1c29c0e20ed0dbf717a0ccd8f374","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/4f129fc6f756f8541e5bff45b1804cc11b1ec712","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/5a35454179fe1041d9cd286f5d320ce0d448c12a","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/c99444f6dfca893f6d310aae4a53c620f98f7b4f","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/f1422df595d69b997d23a8f11e12c528ccef7fad","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-72471","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:22:21.213","lastModified":"2026-08-15T06:22:21.213","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nfs/ntfs3: prevent potential lcn remains uninitialized\n\nThe target VCN being sought was not found within runs[0], causing\nrun_lookup() to return false. This causes run_lookup_entry() to return\nfalse, which in turn results in a len value of 0, and the new parameter\npassed to attr_data_get_block() is NULL. Collectively, these factors\nultimately cause attr_data_get_block_locked() to exit prematurely without\ninitializing lcn, thereby triggering [1].\n\nTo prevent [1], the clen check within ni_seek_data_or_hole() has been\nmoved to occur before the lcn check.\n\n[1]\nBUG: KMSAN: uninit-value in ni_seek_data_or_hole+0x24f/0x5f0 fs/ntfs3/frecord.c:2862\n ni_seek_data_or_hole+0x24f/0x5f0 fs/ntfs3/frecord.c:2862\n ntfs_llseek+0x22a/0x4a0 fs/ntfs3/file.c:1530\n vfs_llseek fs/read_write.c:391 [inline]"}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["fs/ntfs3/frecord.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"c61326967728392931f8a2240cb2cf4c81b523c1","lessThan":"7ae7e98b71438c494532492cbf58fc0d7f7988bb","versionType":"git","status":"affected"},{"version":"c61326967728392931f8a2240cb2cf4c81b523c1","lessThan":"57ac2831c8e0f168090d38e3de758c6a59db44db","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["fs/ntfs3/frecord.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"7.0","status":"affected"},{"version":"0","lessThan":"7.0","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/57ac2831c8e0f168090d38e3de758c6a59db44db","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/7ae7e98b71438c494532492cbf58fc0d7f7988bb","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-72472","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:22:21.313","lastModified":"2026-08-15T06:22:21.313","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nnfs: use nfsi->rwsem to protect traversal of the file lock list\n\nLingfeng identified a bug and suggested two solutions, but both appear\nto have issues.\n\nGenerally, we cannot release flc_lock while iterating over the file lock\nlist to avoid use-after-free (UAF) problems with file locks. However,\nfunctions like nfs_delegation_claim_locks and nfs4_reclaim_locks cannot\nadhere to this rule because recover_lock or nfs4_lock_delegation_recall\nmay take a long time. To resolve this, NFS switches to using nfsi->rwsem\nfor the same protection, and nfs_reclaim_locks follows this approach.\nAlthough nfs_delegation_claim_locks uses so_delegreturn_mutex instead,\nthis is inadequate since a single inode can have multiple nfs4_state\ninstances. Therefore, the fix is to also use nfsi->rwsem in this case.\n\nFurthermore, after commit c69899a17ca4 (\"NFSv4: Update of VFS byte range\nlock must be atomic with the stateid update\"), the functions\nnfs4_locku_done and nfs4_lock_done also break this rule because they\ncall locks_lock_inode_wait without holding nfsi->rwsem. Simply adding\nthis protection could cause many deadlocks, so instead, the call to\nlocks_lock_inode_wait is moved into _nfs4_proc_setlk. Regarding the bug\nfixed by commit c69899a17ca4 (\"NFSv4: Update of VFS byte range\nlock must be atomic with the stateid update\"), it has been resolved\nafter commit 0460253913e5 (\"NFSv4: nfs4_do_open() is incorrectly triggering\nstate recovery\") because all slots are drained before calling\nnfs4_do_reclaim, which prevents concurrent stateid changes along this path.\nAlso, nfs_delegation_claim_locks does not cause this concurrency either\nsince when _nfs4_proc_setlk is called with NFS_DELEGATED_STATE, no RPC is\nsent, so nfs4_lock_done is not called. Therefore,\nnfs4_lock_delegation_recall from nfs_delegation_claim_locks is the first\ntime the stateid is set."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["fs/nfs/delegation.c","fs/nfs/nfs4proc.c","include/linux/nfs_xdr.h"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"c69899a17ca4836230720e65493942d9582a0424","lessThan":"1cda95bf2e9c0e6b63545b7565fe4a1e474322f4","versionType":"git","status":"affected"},{"version":"c69899a17ca4836230720e65493942d9582a0424","lessThan":"f161ef7b0dd2f51fdb002ba4a4e9bf0ee7409218","versionType":"git","status":"affected"},{"version":"c69899a17ca4836230720e65493942d9582a0424","lessThan":"e68035178e65e2b3aa386ce61202ff33724ae418","versionType":"git","status":"affected"},{"version":"c69899a17ca4836230720e65493942d9582a0424","lessThan":"4837fb36219e6c08b666bc31a86841bad8526358","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["fs/nfs/delegation.c","fs/nfs/nfs4proc.c","include/linux/nfs_xdr.h"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"4.0","status":"affected"},{"version":"0","lessThan":"4.0","versionType":"semver","status":"unaffected"},{"version":"6.12.97","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/1cda95bf2e9c0e6b63545b7565fe4a1e474322f4","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/4837fb36219e6c08b666bc31a86841bad8526358","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/e68035178e65e2b3aa386ce61202ff33724ae418","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/f161ef7b0dd2f51fdb002ba4a4e9bf0ee7409218","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-72473","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:22:21.423","lastModified":"2026-08-15T06:22:21.423","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nxprtrdma: Decouple req recycling from RPC completion\n\nrl_kref formerly served two distinct lifetimes through a single\nrefcount: it gated when a Reply could wake its RPC task, and it\ngated when an rpcrdma_req could return to its free pool. The\nmarshal path took the Send-side reference only when SGEs needed\nDMA-unmap (sc_unmap_count > 0), which made a Send carrying only\npre-registered buffers an exception: the Reply handler dropped\nrl_kref from 1 to 0 and freed the req while the HCA might still\nbe DMA-reading from its send buffer.\n\nGive rl_kref a narrower job. The RPC layer takes one reference\nwhen slot allocation hands a req out. rpcrdma_prepare_send_sges()\ntakes a Send-side reference unconditionally after WR preparation\nsucceeds. xprt_rdma_free_slot() and xprt_rdma_bc_free_rqst() drop\nthe RPC-layer reference; rpcrdma_sendctx_unmap() drops the\nSend-side reference. The req returns to its free pool only after\nboth owners have signed off.\n\nThe existing kref_init(&req->rl_kref) call in\nrpcrdma_prepare_send_sges() is removed. Initialization moves to\nthe slot-allocation paths (xprt_rdma_alloc_slot and\nrpcrdma_bc_rqst_get), and the release callback re-arms rl_kref\nbefore the req returns to a free pool. A re-init in the marshal\npath would discard the RPC-layer reference that already exists\non entry.\n\nThree invariants follow:\n\n  - Any rpcrdma_req held by an rpc_rqst has rl_kref >= 1.\n    xprt_rdma_alloc_slot(), rpcrdma_bc_rqst_get(), and the\n    backlog-wake branch in xprt_rdma_alloc_slot() each kref_init\n    rl_kref before publishing the req. Without this invariant,\n    an RPC task that aborts between slot allocation and marshal\n    (gss_refresh failure or signal during call_connect, for\n    example) would drive xprt_release() ->\n    xprt_rdma_free_slot() -> kref_put against a refcount of\n    zero, saturating refcount_t and stranding the slot.\n\n  - The Send-side reference is taken only after WR prep\n    succeeds. A mapping failure in rpcrdma_prepare_send_sges()\n    runs rpcrdma_sendctx_cancel(), which DMA-unmaps the sendctx\n    and clears sc_req without touching rl_kref. The sendctx\n    ring walks in rpcrdma_sendctx_put_locked() and\n    rpcrdma_sendctxs_destroy() skip entries with sc_req == NULL,\n    so a burst of -EIO marshal failures cannot hold reqs off\n    rb_send_bufs.\n\n  - The release callback re-arms rl_kref so the next consumer\n    enters with the invariant satisfied.\n\nReplies now complete the RPC directly. rpcrdma_reply_handler()\ncalls rpcrdma_complete_rqst() in place of kref_put on the\nnon-LocalInv branch. The LocalInv branch already completes the\nRPC from frwr_unmap_async() and is unaffected.\n\nBecause Send-side references can now outlive RPC completion,\nconnection teardown drains sendctx entries whose unsignaled\nSends never had a later signaled completion to walk the ring.\nrpcrdma_sendctxs_destroy() walks the active range and runs\nrpcrdma_sendctx_unmap() on each entry with a non-NULL sc_req\nbefore the request buffers are reset, and is moved ahead of\nrpcrdma_reqs_reset() in rpcrdma_xprt_disconnect() so the reqs\nare still in their pre-reset state when the Send-side refs are\nreleased.\n\nThe drain creates a teardown-ordering hazard on the backchannel\npath. With the new lifetime, releasing a bc_prealloc req from\nrpcrdma_req_release() re-adds it to bc_pa_list. The disconnect\nin xprt_rdma_destroy() runs after xprt_destroy_backchannel() has\nalready emptied bc_pa_list, so the drained reqs would otherwise\nleak. xprt_rdma_destroy() now runs xprt_rdma_bc_destroy(xprt, 0)\na second time after the disconnect to reclaim them."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["net/sunrpc/xprtrdma/backchannel.c","net/sunrpc/xprtrdma/rpc_rdma.c","net/sunrpc/xprtrdma/transport.c","net/sunrpc/xprtrdma/verbs.c","net/sunrpc/xprtrdma/xprt_rdma.h"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"0ab115237025f5e379620bbcd56a02697d07b002","lessThan":"740975054a1970c0cf15f70ac39724a064f45847","versionType":"git","status":"affected"},{"version":"0ab115237025f5e379620bbcd56a02697d07b002","lessThan":"9f3d9b68c1c6c51746e5ecdb52b2e6a2901de37e","versionType":"git","status":"affected"},{"version":"0ab115237025f5e379620bbcd56a02697d07b002","lessThan":"e7632089523acddcdd8f090ad19e96fb3107b04d","versionType":"git","status":"affected"},{"version":"0ab115237025f5e379620bbcd56a02697d07b002","lessThan":"53442c7d0c888e51b8bc3da196970a669cc6b294","versionType":"git","status":"affected"},{"version":"0ab115237025f5e379620bbcd56a02697d07b002","lessThan":"8203f760a72bd39a3b66bc4eff0aa272a99fe22b","versionType":"git","status":"affected"},{"version":"0ab115237025f5e379620bbcd56a02697d07b002","lessThan":"e786233d2e0bbff9a82e43f02ae3a46ab4b08ec3","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["net/sunrpc/xprtrdma/backchannel.c","net/sunrpc/xprtrdma/rpc_rdma.c","net/sunrpc/xprtrdma/transport.c","net/sunrpc/xprtrdma/verbs.c","net/sunrpc/xprtrdma/xprt_rdma.h"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"5.3","status":"affected"},{"version":"0","lessThan":"5.3","versionType":"semver","status":"unaffected"},{"version":"6.1.178","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.97","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/53442c7d0c888e51b8bc3da196970a669cc6b294","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/740975054a1970c0cf15f70ac39724a064f45847","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/8203f760a72bd39a3b66bc4eff0aa272a99fe22b","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/9f3d9b68c1c6c51746e5ecdb52b2e6a2901de37e","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/e7632089523acddcdd8f090ad19e96fb3107b04d","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/e786233d2e0bbff9a82e43f02ae3a46ab4b08ec3","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-72474","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:22:21.563","lastModified":"2026-08-15T06:22:21.563","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\ndmaengine: dma-axi-dmac: use DMA pool to manange DMA descriptor\n\nFor architectures like Microblaze or arm64 (where this IP is used),\nDMA_DIRECT_REMAP is set which means that dma_alloc_coherent() might\nremap (and hence vmalloc()) some memory. This became visible in a design\nwhere dma_direct_use_pool() is not possible.\n\nWith the above, when calling dma_free_coherent(), vunmap() would be\ncalled from softirq context and thus leading to a BUG().\n\nTo fix it, use a dma pool that is allocated in\n.device_alloc_chan_resources() and allocate blocks from it. The key\npoint is that now dma_pool_free() is used in axi_dmac_free_desc() to\nfree the blocks and that just frees the blocks from the pool in the\nsense they can be used again. In other words, no actual call to\ndma_free_coherent() happens. That only happens when destroying the pool\nin axi_dmac_free_chan_resources() which does not happen in any interrupt\ncontext."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/dma/dma-axi-dmac.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"3f8fd25936ee5f52596f10d420f650c5b5e3285f","lessThan":"a4f41ceecfe68e117bae9c76c5ebc5e2b353fa56","versionType":"git","status":"affected"},{"version":"3f8fd25936ee5f52596f10d420f650c5b5e3285f","lessThan":"c0e6bb2b0408fcac6382158ee2bd9fdc45eceee9","versionType":"git","status":"affected"},{"version":"3f8fd25936ee5f52596f10d420f650c5b5e3285f","lessThan":"65e82fa24965b2eb6ad9412f6c530ed9a50a625f","versionType":"git","status":"affected"},{"version":"3f8fd25936ee5f52596f10d420f650c5b5e3285f","lessThan":"9e942c8579130e62734c14338e9f451780669164","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/dma/dma-axi-dmac.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.8","status":"affected"},{"version":"0","lessThan":"6.8","versionType":"semver","status":"unaffected"},{"version":"6.12.97","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/65e82fa24965b2eb6ad9412f6c530ed9a50a625f","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/9e942c8579130e62734c14338e9f451780669164","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/a4f41ceecfe68e117bae9c76c5ebc5e2b353fa56","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/c0e6bb2b0408fcac6382158ee2bd9fdc45eceee9","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-72475","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:22:21.660","lastModified":"2026-08-15T06:22:21.660","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\ndmaengine: dma-axi-dmac: Properly free struct axi_dmac_desc\n\nUse axi_dmac_free_desc() to free fully the descriptor at fail path when\ncall axi_dmac_alloc_desc() in axi_dmac_prep_peripheral_dma_vec()."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/dma/dma-axi-dmac.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"74609e5686701ed8e8adc3082d15f009e327286d","lessThan":"36e9cbbfc09ef792918e6a276dd7e2dbca7f31ce","versionType":"git","status":"affected"},{"version":"74609e5686701ed8e8adc3082d15f009e327286d","lessThan":"9f1ef67c041ef592c13603957ba08b6f21010004","versionType":"git","status":"affected"},{"version":"74609e5686701ed8e8adc3082d15f009e327286d","lessThan":"f055829151eed5a9ec4af98a6c1ce75dbaf2e372","versionType":"git","status":"affected"},{"version":"74609e5686701ed8e8adc3082d15f009e327286d","lessThan":"4910ce1b3b35687bb2a5e742c4bfbea3c647c980","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/dma/dma-axi-dmac.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.11","status":"affected"},{"version":"0","lessThan":"6.11","versionType":"semver","status":"unaffected"},{"version":"6.12.97","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/36e9cbbfc09ef792918e6a276dd7e2dbca7f31ce","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/4910ce1b3b35687bb2a5e742c4bfbea3c647c980","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/9f1ef67c041ef592c13603957ba08b6f21010004","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/f055829151eed5a9ec4af98a6c1ce75dbaf2e372","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-72476","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:22:21.757","lastModified":"2026-08-15T06:22:21.757","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\ndmaengine: Fix possible use after free\n\nIn dma_release_channel(), check chan->device->privatecnt after call\ndma_chan_put(). However, dma_chan_put() call dma_device_put() which could\nrelease the last reference of the device if the DMA provider is already\ngone and hence free it.\n\nFixes it by moving dma_chan_put() after the check."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/dma/dmaengine.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"0f571515c332e00b3515dbe0859ceaa30ab66e00","lessThan":"444f96066937f3fdf0e79b53289cff223c7d638b","versionType":"git","status":"affected"},{"version":"0f571515c332e00b3515dbe0859ceaa30ab66e00","lessThan":"ab438a9efb9042c79d2f8db28a326d55feb8591f","versionType":"git","status":"affected"},{"version":"0f571515c332e00b3515dbe0859ceaa30ab66e00","lessThan":"9bdc8dce4068dadbdf7cf5ad6d4983e2afffedce","versionType":"git","status":"affected"},{"version":"0f571515c332e00b3515dbe0859ceaa30ab66e00","lessThan":"5876f38b67a309c00628942cb25679749b53b397","versionType":"git","status":"affected"},{"version":"0f571515c332e00b3515dbe0859ceaa30ab66e00","lessThan":"3b0240483dc977dbec4f3bc7a5383d4691ecb625","versionType":"git","status":"affected"},{"version":"0f571515c332e00b3515dbe0859ceaa30ab66e00","lessThan":"329ec20a86091d2a6e5b4fe507545e7d678a22a2","versionType":"git","status":"affected"},{"version":"0f571515c332e00b3515dbe0859ceaa30ab66e00","lessThan":"0bc191050c3253da8ef4bfaf157c44efed6e22cd","versionType":"git","status":"affected"},{"version":"0f571515c332e00b3515dbe0859ceaa30ab66e00","lessThan":"92f853f0645aebf1d05d333e97ab7c342ace1892","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/dma/dmaengine.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"2.6.30","status":"affected"},{"version":"0","lessThan":"2.6.30","versionType":"semver","status":"unaffected"},{"version":"5.10.261","lessThanOrEqual":"5.10.*","versionType":"semver","status":"unaffected"},{"version":"5.15.212","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.178","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.97","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/0bc191050c3253da8ef4bfaf157c44efed6e22cd","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/329ec20a86091d2a6e5b4fe507545e7d678a22a2","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/3b0240483dc977dbec4f3bc7a5383d4691ecb625","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/444f96066937f3fdf0e79b53289cff223c7d638b","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/5876f38b67a309c00628942cb25679749b53b397","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/92f853f0645aebf1d05d333e97ab7c342ace1892","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/9bdc8dce4068dadbdf7cf5ad6d4983e2afffedce","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/ab438a9efb9042c79d2f8db28a326d55feb8591f","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-72477","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:22:21.867","lastModified":"2026-08-15T06:22:21.867","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nfs/ntfs3: call _ntfs_bad_inode() when failing to rename\n\nIt is safe to call _ntfs_bad_inode on live inodes since:\n  commit 519b078998ce (\"fs/ntfs3: Exclude call make_bad_inode for live nodes.\")\n\nThe WARN_ON was added when it wasn't safe by:\n  commit d99208b91933 (\"fs/ntfs3: cancle set bad inode after removing name fails\")\n\nReplace the WARN_ON with a call to _ntfs_bad_inode() to prevent further\noperations on the inconsistent inode."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["fs/ntfs3/frecord.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"519b078998ce6e729f98dccf35505b4756985d11","lessThan":"ff825bf0521f6da2f30878cbad18ab7b341bc31b","versionType":"git","status":"affected"},{"version":"519b078998ce6e729f98dccf35505b4756985d11","lessThan":"e8ed78f40eecd0176fda71d673f6957c98e7ffbe","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["fs/ntfs3/frecord.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.17","status":"affected"},{"version":"0","lessThan":"6.17","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/e8ed78f40eecd0176fda71d673f6957c98e7ffbe","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/ff825bf0521f6da2f30878cbad18ab7b341bc31b","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-72478","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:22:21.960","lastModified":"2026-08-15T06:22:21.960","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nfs/ntfs3: add bounds check to run_get_highest_vcn()\n\nrun_get_highest_vcn() parses a packed NTFS mapping-pairs buffer without\nany length bound, relying solely on a 0x00 terminator to stop.  A\ncrafted $LogFile UpdateMappingPairs record whose embedded attribute\ncontains mapping-pairs runs without a terminator causes the function to\nread past the slab allocation, triggering a KASAN slab-out-of-bounds\nread on mount.\n\nThe sibling function run_unpack() received an analogous bounds-check in\ncommit b62567bca474 (\"ntfs3: add buffer boundary checks to run_unpack()\"),\nbut run_get_highest_vcn() was missed.\n\nTake a run_buf_size parameter and reject any run header whose payload\nwould extend past the buffer end, mirroring the pattern used by\nrun_unpack().  The caller in fslog.c passes the remaining attribute\nbytes after the mapping-pairs offset.\n\nKASAN report (on mainline v7.1 merge window HEAD):\n\n  BUG: KASAN: slab-out-of-bounds in run_get_highest_vcn+0x3c0/0x410\n  Read of size 1 at addr ffff88800e2d5400 by task mount/72\n  Call Trace:\n   run_get_highest_vcn+0x3c0/0x410\n   do_action.isra.0+0x3ba8/0x7b50\n   log_replay+0x9ddd/0x10200\n   ntfs_loadlog_and_replay+0x4ad/0x610\n   ntfs_fill_super+0x214a/0x4540"}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["fs/ntfs3/fslog.c","fs/ntfs3/ntfs_fs.h","fs/ntfs3/run.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"425de2aba0d061b3e715d51a3b1992c112ed5b99","lessThan":"c69b9003332917b652175d5fa9d84158c5ed8617","versionType":"git","status":"affected"},{"version":"bf7ac4a1d3bfc6e56e54635c3d331a68170d37c9","lessThan":"8afc24a884aff6a6f08028bd779ee65c40054455","versionType":"git","status":"affected"},{"version":"e64f7dfcaff79e7dfff9121a382dd77f9b462f62","lessThan":"c23083b472a720c3f60b147db05b25b751c7c1bf","versionType":"git","status":"affected"},{"version":"d3012690a7065d9ca86521a525ad11e8af491d45","lessThan":"a31893206588374d7d16fad387189d8165c7efd3","versionType":"git","status":"affected"},{"version":"b62567bca47408e6739dee75f02a2113548af875","lessThan":"41081202eb823f5b27ff164b12010b24428100ad","versionType":"git","status":"affected"},{"version":"b62567bca47408e6739dee75f02a2113548af875","lessThan":"bb11485a87fbb2254b62cfed630b699d50e57da8","versionType":"git","status":"affected"},{"version":"bbad75336870b51b81979b97613746237fcb02fe","versionType":"git","status":"affected"},{"version":"41aadf5cb482793a24e05aa136224e179a778586","versionType":"git","status":"affected"},{"version":"6.1.175","lessThan":"6.1.178","versionType":"semver","status":"affected"},{"version":"6.6.140","lessThan":"6.6.145","versionType":"semver","status":"affected"},{"version":"6.12.86","lessThan":"6.12.97","versionType":"semver","status":"affected"},{"version":"6.18.27","lessThan":"6.18.40","versionType":"semver","status":"affected"},{"version":"5.15.209","lessThan":"5.16","versionType":"semver","status":"affected"},{"version":"7.0.4","lessThan":"7.1","versionType":"semver","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["fs/ntfs3/fslog.c","fs/ntfs3/ntfs_fs.h","fs/ntfs3/run.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"7.1","status":"affected"},{"version":"0","lessThan":"7.1","versionType":"semver","status":"unaffected"},{"version":"6.1.178","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.97","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/41081202eb823f5b27ff164b12010b24428100ad","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/8afc24a884aff6a6f08028bd779ee65c40054455","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/a31893206588374d7d16fad387189d8165c7efd3","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/bb11485a87fbb2254b62cfed630b699d50e57da8","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/c23083b472a720c3f60b147db05b25b751c7c1bf","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/c69b9003332917b652175d5fa9d84158c5ed8617","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-72479","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:22:22.093","lastModified":"2026-08-15T06:22:22.093","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\niio: accel: mma8452: handle I2C read error(s) in mma8452_read()\n\nCurrently, If i2c_smbus_read_i2c_block_data() fails but\nmma8452_set_runtime_pm_state() succeeds, mma8452_read() returns 0.\n\nAs a result, the caller mma8452_read_raw() assumes the read was\nsuccessful and proceeds to use a buffer containing uninitialized\nstack memory.\n\nAdd proper checking of the I2C read return value and propagate errors\nto the caller."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/iio/accel/mma8452.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"96c0cb2bbfe0a58bd0c37cf34d50a20f9cd75aa8","lessThan":"b488055e81d9faaaf2f8aaff45f9944040ac4493","versionType":"git","status":"affected"},{"version":"96c0cb2bbfe0a58bd0c37cf34d50a20f9cd75aa8","lessThan":"f9ec3f3e9cf27dd06cd3725eeaa44e3ce46be893","versionType":"git","status":"affected"},{"version":"96c0cb2bbfe0a58bd0c37cf34d50a20f9cd75aa8","lessThan":"b4932fc325e84a3233413daf230b043818c8a824","versionType":"git","status":"affected"},{"version":"96c0cb2bbfe0a58bd0c37cf34d50a20f9cd75aa8","lessThan":"eed69f8a10b82989ad732ace0fb43a9fb4e7fe35","versionType":"git","status":"affected"},{"version":"96c0cb2bbfe0a58bd0c37cf34d50a20f9cd75aa8","lessThan":"f3d905ea1e4996d933074481e80d96ecd74a9904","versionType":"git","status":"affected"},{"version":"96c0cb2bbfe0a58bd0c37cf34d50a20f9cd75aa8","lessThan":"1cddef80a180af74c33d2f26c962ce92b60fded4","versionType":"git","status":"affected"},{"version":"96c0cb2bbfe0a58bd0c37cf34d50a20f9cd75aa8","lessThan":"f3d413e701c5e54bef736b638967724dda880365","versionType":"git","status":"affected"},{"version":"96c0cb2bbfe0a58bd0c37cf34d50a20f9cd75aa8","lessThan":"5bdff291d20c31b365d9ddfe9c426fbfb41da5bb","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/iio/accel/mma8452.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"4.7","status":"affected"},{"version":"0","lessThan":"4.7","versionType":"semver","status":"unaffected"},{"version":"5.10.261","lessThanOrEqual":"5.10.*","versionType":"semver","status":"unaffected"},{"version":"5.15.212","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.178","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.97","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/1cddef80a180af74c33d2f26c962ce92b60fded4","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/5bdff291d20c31b365d9ddfe9c426fbfb41da5bb","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/b488055e81d9faaaf2f8aaff45f9944040ac4493","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/b4932fc325e84a3233413daf230b043818c8a824","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/eed69f8a10b82989ad732ace0fb43a9fb4e7fe35","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/f3d413e701c5e54bef736b638967724dda880365","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/f3d905ea1e4996d933074481e80d96ecd74a9904","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/f9ec3f3e9cf27dd06cd3725eeaa44e3ce46be893","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-72480","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:22:22.210","lastModified":"2026-08-15T06:22:22.210","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\niio: adc: xilinx-ams: fix out-of-bounds channel lookup in event handling\n\nams_event_to_channel() may return a pointer past the end of\ndev->channels when no matching scan_index is found. This can lead\nto invalid memory access in ams_handle_event().\n\nAdd a bounds check in ams_event_to_channel() and return NULL when\nno channel is found. Also guard the caller to safely handle this\ncase."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/iio/adc/xilinx-ams.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"d5c70627a79455154f5f636096abe6fe57510605","lessThan":"116d1f8805ae2daadbac89d24da4c0da50b9edae","versionType":"git","status":"affected"},{"version":"d5c70627a79455154f5f636096abe6fe57510605","lessThan":"94d158985b6ea011bdc26186f42d662a156da6cb","versionType":"git","status":"affected"},{"version":"d5c70627a79455154f5f636096abe6fe57510605","lessThan":"1d24f14e049fdd769146dda026496ed23b397ed9","versionType":"git","status":"affected"},{"version":"d5c70627a79455154f5f636096abe6fe57510605","lessThan":"9ac3675bf875792dced45efbf47116719a7c097b","versionType":"git","status":"affected"},{"version":"d5c70627a79455154f5f636096abe6fe57510605","lessThan":"3c374d33f1338dbb5676919c5194caa9c5aa1631","versionType":"git","status":"affected"},{"version":"d5c70627a79455154f5f636096abe6fe57510605","lessThan":"947eb6f0a274f8b15a0248051a65b069effd5057","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/iio/adc/xilinx-ams.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"5.17","status":"affected"},{"version":"0","lessThan":"5.17","versionType":"semver","status":"unaffected"},{"version":"6.1.178","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.97","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/116d1f8805ae2daadbac89d24da4c0da50b9edae","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/1d24f14e049fdd769146dda026496ed23b397ed9","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/3c374d33f1338dbb5676919c5194caa9c5aa1631","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/947eb6f0a274f8b15a0248051a65b069effd5057","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/94d158985b6ea011bdc26186f42d662a156da6cb","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/9ac3675bf875792dced45efbf47116719a7c097b","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-72481","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:22:22.313","lastModified":"2026-08-15T06:22:22.313","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\niio: magnetometer: ak8975: fix potential kernel stack memory leak\n\nCurrently in the AK8975 driver there are four instances where potential\nuninitialized kernel stack memory leaks can occur. If\ni2c_smbus_read_i2c_block_data_or_emulated() returns a value less than\nthe size of the buffer, uninitialized bytes are retained in the buffer\nand later the buffer is passed on to IIO buffers, potentially leaking\nmemory to userspace.\n\nFix this by adding checks whether the return value of the function is\nequal to the size of the buffer and subsequently if the value is\nlesser than zero to distinguish from a returned error code."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/iio/magnetometer/ak8975.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"bc11ca4a0b84a2f2ebaca2614b92998738d13b1e","lessThan":"12848f4ded022963944c063e09a192549a4dad1e","versionType":"git","status":"affected"},{"version":"bc11ca4a0b84a2f2ebaca2614b92998738d13b1e","lessThan":"a9cf46054f81972f8c0f1dc2a79d2a141999dbce","versionType":"git","status":"affected"},{"version":"bc11ca4a0b84a2f2ebaca2614b92998738d13b1e","lessThan":"9f920550abacedc7fc3163dea65ac2a7d0b0765d","versionType":"git","status":"affected"},{"version":"bc11ca4a0b84a2f2ebaca2614b92998738d13b1e","lessThan":"8cf346074533356d67a6a6a43a192328ad341f11","versionType":"git","status":"affected"},{"version":"bc11ca4a0b84a2f2ebaca2614b92998738d13b1e","lessThan":"b974566803bceb72f0b9b5f1d7270b79ba963766","versionType":"git","status":"affected"},{"version":"bc11ca4a0b84a2f2ebaca2614b92998738d13b1e","lessThan":"3d57672119525c59ed73ea21accb001ccbcd6cfd","versionType":"git","status":"affected"},{"version":"bc11ca4a0b84a2f2ebaca2614b92998738d13b1e","lessThan":"fb27ebf81136e796c7b719303ef6fd7e1ae5d488","versionType":"git","status":"affected"},{"version":"bc11ca4a0b84a2f2ebaca2614b92998738d13b1e","lessThan":"a9a00d727b7bbc5e913a919530a9dd468935bf95","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/iio/magnetometer/ak8975.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"4.7","status":"affected"},{"version":"0","lessThan":"4.7","versionType":"semver","status":"unaffected"},{"version":"5.10.261","lessThanOrEqual":"5.10.*","versionType":"semver","status":"unaffected"},{"version":"5.15.212","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.178","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.97","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/12848f4ded022963944c063e09a192549a4dad1e","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/3d57672119525c59ed73ea21accb001ccbcd6cfd","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/8cf346074533356d67a6a6a43a192328ad341f11","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/9f920550abacedc7fc3163dea65ac2a7d0b0765d","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/a9a00d727b7bbc5e913a919530a9dd468935bf95","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/a9cf46054f81972f8c0f1dc2a79d2a141999dbce","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/b974566803bceb72f0b9b5f1d7270b79ba963766","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/fb27ebf81136e796c7b719303ef6fd7e1ae5d488","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-72482","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:22:22.430","lastModified":"2026-08-15T06:22:22.430","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\ngpib: fix double decrement of descriptor_busy in command_ioctl()\n\ncommit d1857f8296dc (\"gpib: fix use-after-free in IO ioctl handlers\")\nintroduced a descriptor_busy reference counter to pin struct\ngpib_descriptor across IO ioctl operations.  In command_ioctl(), the\nerror path inside the loop decrements descriptor_busy and breaks, but\nexecution then falls through to the unconditional decrement after the\nloop, underflowing the counter to -1.\n\nThis re-enables the use-after-free that the original fix was meant to\nprevent: a concurrent close_dev_ioctl() sees descriptor_busy == 0 on\nan actively-used descriptor and frees it.\n\nRemove the early decrement from the error path.  The post-loop\ndecrement already handles all exit paths, matching the correct pattern\nused in read_ioctl() and write_ioctl()."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/gpib/common/gpib_os.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"cae26eff1b56d78bed7873cf3e60a2b1bdd4da6c","lessThan":"fdee9f207a48ce204ec6cfceaa1459d2473600a5","versionType":"git","status":"affected"},{"version":"d1857f8296dceb75d00ab857fc3c61bc00c7f5c6","lessThan":"8b5f1d295dda8677e4545ce340053fcfa8b634c7","versionType":"git","status":"affected"},{"version":"d1857f8296dceb75d00ab857fc3c61bc00c7f5c6","lessThan":"c4faab452b3c1ada003d49c477609dd80523b9bf","versionType":"git","status":"affected"},{"version":"28c75dd143ead62e0dfac564c79d251e21d5d74b","versionType":"git","status":"affected"},{"version":"6.18.22","lessThan":"6.18.40","versionType":"semver","status":"affected"},{"version":"6.19.12","lessThan":"6.20","versionType":"semver","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/gpib/common/gpib_os.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"7.0","status":"affected"},{"version":"0","lessThan":"7.0","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/8b5f1d295dda8677e4545ce340053fcfa8b634c7","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/c4faab452b3c1ada003d49c477609dd80523b9bf","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/fdee9f207a48ce204ec6cfceaa1459d2473600a5","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-72483","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:22:22.527","lastModified":"2026-08-15T06:22:22.527","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nusb: host: max3421: Fix shift-out-of-bounds in max3421_hub_control()\n\nThe `max3421_hub_control()` function handles USB hub class requests\nto the virtual root hub. In the `default` branches of both the\n`ClearPortFeature` and `SetPortFeature` switch statements, it modifies\n`max3421_hcd->port_status` by left shifting 1 by the request's `value`\nparameter. However, it does not validate whether this shift will exceed\nthe width of `port_status`.\n\nSo if a malicious userspace task with access to the root hub via\n/dev/bus/usb/.../001 issues a USBDEVFS_CONTROL ioctl with `wValue`\ngreater than or equal to 32, the left shift operation invokes\nshift-out-of-bounds undefined behavior. This results in arbitrary\nbit corruption of `port_status`, including the normally-immutable\nchange bits, which can bypass internal state checks and confuse the\nhub status.\n\nFix this by rejecting requests whose `value` exceeds the shift width\nbefore performing the shift.\n\nThis issue was found using a KLEE-based symbolic execution tool for\nkernel drivers that I'm currently developing."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/usb/host/max3421-hcd.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"2d53139f31626bad6f8983d8e519ddde2cbba921","lessThan":"e5fa9d8f40746ec3447335c9642c03410f5fd3af","versionType":"git","status":"affected"},{"version":"2d53139f31626bad6f8983d8e519ddde2cbba921","lessThan":"08b1d4cab0230697bc74c63fc4e40170a7559c54","versionType":"git","status":"affected"},{"version":"2d53139f31626bad6f8983d8e519ddde2cbba921","lessThan":"3be5f24e8270ba53b3c814d13689bb8644c86237","versionType":"git","status":"affected"},{"version":"2d53139f31626bad6f8983d8e519ddde2cbba921","lessThan":"d512bdefd241b98f4d7bcb5bab5614a86411fad4","versionType":"git","status":"affected"},{"version":"2d53139f31626bad6f8983d8e519ddde2cbba921","lessThan":"00dd025324b56d39d37e57a08f473dab3a660f30","versionType":"git","status":"affected"},{"version":"2d53139f31626bad6f8983d8e519ddde2cbba921","lessThan":"02d03c61e8a7b016956acb48e8a2512d16d87517","versionType":"git","status":"affected"},{"version":"2d53139f31626bad6f8983d8e519ddde2cbba921","lessThan":"4da073d57176d8e1c2bca34febfbc81d2560c1a5","versionType":"git","status":"affected"},{"version":"2d53139f31626bad6f8983d8e519ddde2cbba921","lessThan":"cff06b03b530ae1fe8a13e93a7848f2130e00fb4","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/usb/host/max3421-hcd.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"3.16","status":"affected"},{"version":"0","lessThan":"3.16","versionType":"semver","status":"unaffected"},{"version":"5.10.261","lessThanOrEqual":"5.10.*","versionType":"semver","status":"unaffected"},{"version":"5.15.212","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.178","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.97","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/00dd025324b56d39d37e57a08f473dab3a660f30","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/02d03c61e8a7b016956acb48e8a2512d16d87517","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/08b1d4cab0230697bc74c63fc4e40170a7559c54","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/3be5f24e8270ba53b3c814d13689bb8644c86237","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/4da073d57176d8e1c2bca34febfbc81d2560c1a5","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/cff06b03b530ae1fe8a13e93a7848f2130e00fb4","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/d512bdefd241b98f4d7bcb5bab5614a86411fad4","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/e5fa9d8f40746ec3447335c9642c03410f5fd3af","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-72484","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:22:22.647","lastModified":"2026-08-15T06:22:22.647","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nstaging: most: video: avoid double free on video register failure\n\ncomp_register_videodev() allocates a video_device with\nvideo_device_alloc() and releases it if video_register_device() fails.\n\nThis can double free the video_device when __video_register_device()\nreaches device_register() and that call fails:\n\n  video_register_device()\n    -> __video_register_device()\n       -> device_register() fails\n          -> put_device(&vdev->dev)\n             -> v4l2_device_release()\n                -> vdev->release(vdev)\n                   -> video_device_release(vdev)\n\n  comp_register_videodev()\n    -> video_device_release(mdev->vdev)\n\nUse video_device_release_empty() while registering the device so that\nregistration failure paths do not free mdev->vdev through vdev->release().\ncomp_register_videodev() then releases mdev->vdev exactly once on failure.\nRestore video_device_release() after successful registration so the\nregistered device keeps its normal lifetime handling.\n\nThis issue was found by a static analysis tool I am developing."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/staging/most/video/video.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"eab231c0398a91fbd294672bfe9e0ff45b368246","lessThan":"009d58b73500d0b49f6ae3833f8afcb0ebd9ddbb","versionType":"git","status":"affected"},{"version":"eab231c0398a91fbd294672bfe9e0ff45b368246","lessThan":"430ad4ea06a0767fb44a08e2212ceb3a996607ee","versionType":"git","status":"affected"},{"version":"eab231c0398a91fbd294672bfe9e0ff45b368246","lessThan":"46ea51f5b2ee1a3b40c05b7c750cbc5cabe94062","versionType":"git","status":"affected"},{"version":"eab231c0398a91fbd294672bfe9e0ff45b368246","lessThan":"4928096212b78262dbbeab3b3abf2352278ce22d","versionType":"git","status":"affected"},{"version":"eab231c0398a91fbd294672bfe9e0ff45b368246","lessThan":"80ed79787da3311f76b4d71d0ce7ab992a9e134d","versionType":"git","status":"affected"},{"version":"eab231c0398a91fbd294672bfe9e0ff45b368246","lessThan":"43078449ad6236d839e4d707954d2e36b10a6706","versionType":"git","status":"affected"},{"version":"eab231c0398a91fbd294672bfe9e0ff45b368246","lessThan":"7fc162453cfb7b8e93edb16287a84ba0130cac38","versionType":"git","status":"affected"},{"version":"eab231c0398a91fbd294672bfe9e0ff45b368246","lessThan":"7cb1c5b32a2bfde961fff8d5204526b609bcb30a","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/staging/most/video/video.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"4.9","status":"affected"},{"version":"0","lessThan":"4.9","versionType":"semver","status":"unaffected"},{"version":"5.10.261","lessThanOrEqual":"5.10.*","versionType":"semver","status":"unaffected"},{"version":"5.15.212","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.178","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.97","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/009d58b73500d0b49f6ae3833f8afcb0ebd9ddbb","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/43078449ad6236d839e4d707954d2e36b10a6706","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/430ad4ea06a0767fb44a08e2212ceb3a996607ee","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/46ea51f5b2ee1a3b40c05b7c750cbc5cabe94062","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/4928096212b78262dbbeab3b3abf2352278ce22d","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/7cb1c5b32a2bfde961fff8d5204526b609bcb30a","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/7fc162453cfb7b8e93edb16287a84ba0130cac38","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/80ed79787da3311f76b4d71d0ce7ab992a9e134d","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-72485","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:22:22.767","lastModified":"2026-08-15T06:22:22.767","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\ncoresight: platform: defer connection counter increment until alloc succeeds\n\ncoresight_add_out_conn() increments nr_outconns before calling\ndevm_krealloc_array() and again before devm_kmalloc(). If either\nallocation fails, the counter is already bumped while the corresponding\narray entry is NULL or uninitialized garbage.\n\ncoresight_add_in_conn() has the same problem with nr_inconns and\ndevm_krealloc_array().\n\nIn both cases the probe returns -ENOMEM, which causes\ncoresight_get_platform_data() to call coresight_release_platform_data()\nfor cleanup. That function iterates up to nr_outconns (or nr_inconns)\nentries and dereferences each pointer unconditionally, hitting the NULL\nor garbage entry and panicking instead of failing gracefully.\n\nFix by moving the counter increments to after all allocations succeed,\nso the struct is always consistent on any error path."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/hwtracing/coresight/coresight-platform.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"3d4ff657e454f8dba3e5e268e731e6e28c6031c1","lessThan":"8ca9adc805884d3bb5038082462577f86c2c4a10","versionType":"git","status":"affected"},{"version":"3d4ff657e454f8dba3e5e268e731e6e28c6031c1","lessThan":"1563ae33dc4f5ebac96b93af2ef72e72aaaa31ae","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/hwtracing/coresight/coresight-platform.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.5","status":"affected"},{"version":"0","lessThan":"6.5","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/1563ae33dc4f5ebac96b93af2ef72e72aaaa31ae","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/8ca9adc805884d3bb5038082462577f86c2c4a10","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-72486","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:22:22.860","lastModified":"2026-08-15T06:22:22.860","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nmailbox: mtk-adsp: fix UAF during device teardown\n\nWhen the SOF audio driver fails to initialize (e.g. firmware boot\ntimeout), its devres unwind frees the snd_sof_dev object that the\nmailbox client (mtk-adsp-ipc) reaches via chan->cl->rx_callback.\nThe mtk-adsp-mailbox shutdown clears the mailbox command registers\nbut leaves the IRQ line unmasked, so a late interrupt can still\nqueue a threaded handler after mbox_free_channel() had cleared\nchan->cl, and mbox_chan_received_data() would then trigger UAF:\n\n  BUG: KASAN: slab-use-after-free in sof_ipc3_validate_fw_version\n   sof_ipc3_validate_fw_version\n   sof_ipc3_do_rx_work\n   sof_ipc3_rx_msg\n   mt8196_dsp_handle_request\n   mtk_adsp_ipc_recv\n   mbox_chan_received_data\n   mtk_adsp_mbox_isr\n   irq_thread_fn\n  Freed by task ...:\n   kfree\n   devres_release_all\n   really_probe\n   ... (sof-audio-of-mt8196 probe failure)\n\nThe crash was observed roughly three seconds after the failed probe.\n\ndisable_irq() in shutdown and enable_irq() in startup. disable_irq()\nalso waits for any in-flight interrupts, so by the time\nmbox_free_channel() proceeds to clear chan->cl no rx_callback can run.\n\nIn addition, request the IRQ with IRQF_NO_AUTOEN so it stays masked\nbetween probe and the first client bind — otherwise an early interrupt\ncan crash on chan->cl == NULL in mbox_chan_received_data()."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/mailbox/mtk-adsp-mailbox.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"af2dfa96c52d042df5deb29fb6e32d3ff4d76a61","lessThan":"b6337a08a63eef8efcffe3c01d479badda6bbbdb","versionType":"git","status":"affected"},{"version":"af2dfa96c52d042df5deb29fb6e32d3ff4d76a61","lessThan":"e519c1d8c5efb5cd8d4c5bb3fe39b1bbb812bdb9","versionType":"git","status":"affected"},{"version":"af2dfa96c52d042df5deb29fb6e32d3ff4d76a61","lessThan":"fc6c3deb1d4c0adebf7dee0b8af4082af3f17690","versionType":"git","status":"affected"},{"version":"af2dfa96c52d042df5deb29fb6e32d3ff4d76a61","lessThan":"7d881615fb6373f71fc628b3f00186aeca87a3d5","versionType":"git","status":"affected"},{"version":"af2dfa96c52d042df5deb29fb6e32d3ff4d76a61","lessThan":"25d6ea6c76e1b1b7c57337b2f8f1b6fc8d5c52bc","versionType":"git","status":"affected"},{"version":"af2dfa96c52d042df5deb29fb6e32d3ff4d76a61","lessThan":"b57d1a40bc43258372fa1f4d39305e093947a262","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/mailbox/mtk-adsp-mailbox.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"5.18","status":"affected"},{"version":"0","lessThan":"5.18","versionType":"semver","status":"unaffected"},{"version":"6.1.178","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.97","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/25d6ea6c76e1b1b7c57337b2f8f1b6fc8d5c52bc","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/7d881615fb6373f71fc628b3f00186aeca87a3d5","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/b57d1a40bc43258372fa1f4d39305e093947a262","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/b6337a08a63eef8efcffe3c01d479badda6bbbdb","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/e519c1d8c5efb5cd8d4c5bb3fe39b1bbb812bdb9","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/fc6c3deb1d4c0adebf7dee0b8af4082af3f17690","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-72487","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:22:22.973","lastModified":"2026-08-15T06:22:22.973","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nPCI: Check ROM header and data structure addr before accessing\n\nWe meet a crash when running stress-ng on x86_64 machine:\n\n  BUG: unable to handle page fault for address: ffa0000007f40000\n  RIP: 0010:pci_get_rom_size+0x52/0x220\n  Call Trace:\n  <TASK>\n    pci_map_rom+0x80/0x130\n    pci_read_rom+0x4b/0xe0\n    kernfs_file_read_iter+0x96/0x180\n    vfs_read+0x1b1/0x300\n\nOur analysis reveals that the ROM space's start address is\n0xffa0000007f30000, and size is 0x10000. Because of broken ROM space,\nbefore calling readl(pds), the pds's value is 0xffa0000007f3ffff, which is\nalready pointed to the ROM space end, invoking readl() would read 4 bytes\ntherefore cause an out-of-bounds access and trigger a crash.  Fix this by\nadding image header and data structure checking.\n\nWe also found another crash on arm64 machine:\n\n  Unable to handle kernel paging request at virtual address ffff8000dd1393ff\n  Mem abort info:\n  ESR = 0x0000000096000021\n  EC = 0x25: DABT (current EL), IL = 32 bits\n  SET = 0, FnV = 0\n  EA = 0, S1PTW = 0\n  FSC = 0x21: alignment fault\n\nThe call trace is the same with x86_64, but the crash reason is that the\ndata structure addr is not aligned with 4, and arm64 machine report\n\"alignment fault\". Fix this by adding alignment checking.\n\n[bhelgaas: shorten function names, wrap comments]"}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/pci/rom.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"47b975d234eac39f3a72e5496d5f6158d8b806d1","lessThan":"cd5b242d5848369b9e957340a7e30adee7b6763d","versionType":"git","status":"affected"},{"version":"47b975d234eac39f3a72e5496d5f6158d8b806d1","lessThan":"4997873e3abbad47a9e1e4abd05f045f77a74f22","versionType":"git","status":"affected"},{"version":"47b975d234eac39f3a72e5496d5f6158d8b806d1","lessThan":"724042f8f98d2594b9d164549fd4292c6bd58120","versionType":"git","status":"affected"},{"version":"47b975d234eac39f3a72e5496d5f6158d8b806d1","lessThan":"1d495446ec7ace5b61da366ffb161ee8319dd9a2","versionType":"git","status":"affected"},{"version":"47b975d234eac39f3a72e5496d5f6158d8b806d1","lessThan":"721ad5b72448b5065ed309017ab563205f162404","versionType":"git","status":"affected"},{"version":"47b975d234eac39f3a72e5496d5f6158d8b806d1","lessThan":"538796b807fcfb81b2ce40cc97a614fd8588feb5","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/pci/rom.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"4.5","status":"affected"},{"version":"0","lessThan":"4.5","versionType":"semver","status":"unaffected"},{"version":"6.1.178","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.97","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/1d495446ec7ace5b61da366ffb161ee8319dd9a2","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/4997873e3abbad47a9e1e4abd05f045f77a74f22","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/538796b807fcfb81b2ce40cc97a614fd8588feb5","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/721ad5b72448b5065ed309017ab563205f162404","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/724042f8f98d2594b9d164549fd4292c6bd58120","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/cd5b242d5848369b9e957340a7e30adee7b6763d","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-72488","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:22:23.087","lastModified":"2026-08-15T06:22:23.087","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nsoundwire: fix bug in sdw_add_element_group_count found by syzkaller\n\nThe original implementation caused an out-of-bounds memory access\nin the sdw_add_element_group_count for-loop when i == num.\n\nfor (i = 0; i <= num; i++) {\n    if (rate == group->rates[i] && lane == group->lanes[i])\n        ...\n\nTo fix this error, the function now checks for existing rate/lane\nentries in the group(a function parameter) using a for-loop before\nadding them.\n\nNo functional changes apart from this fix."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/soundwire/generic_bandwidth_allocation.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"9026118f20e28f202dab34f219bbb831ffb8c4dc","lessThan":"a454f61747c97e2eadaa7a35ffc1f4b1645c6a53","versionType":"git","status":"affected"},{"version":"9026118f20e28f202dab34f219bbb831ffb8c4dc","lessThan":"e483a406a23a92d5202e8d324f206e127eef48ff","versionType":"git","status":"affected"},{"version":"9026118f20e28f202dab34f219bbb831ffb8c4dc","lessThan":"f772ff5a0e6758fd412803c09e03ba3bca5f5878","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/soundwire/generic_bandwidth_allocation.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"5.10","status":"affected"},{"version":"0","lessThan":"5.10","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/a454f61747c97e2eadaa7a35ffc1f4b1645c6a53","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/e483a406a23a92d5202e8d324f206e127eef48ff","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/f772ff5a0e6758fd412803c09e03ba3bca5f5878","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-72489","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:22:23.190","lastModified":"2026-08-15T06:22:23.190","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nstaging: nvec: fix use-after-free in nvec_rx_completed()\n\nIn nvec_rx_completed(), when an incomplete RX transfer is detected,\nnvec_msg_free() is called to return the message back to the pool by\nclearing its 'used' atomic flag. Immediately after this, the code\naccesses nvec->rx->data[0] to check the message type.\n\nSince nvec_msg_free() marks the pool slot as available via atomic_set(),\nany concurrent or subsequent call to nvec_msg_alloc() could claim that\nsame slot and overwrite its data[] array. Reading nvec->rx->data[0] after\nfreeing the message is therefore a use-after-free.\n\nFix this by saving the message type byte before calling nvec_msg_free(),\nthen using the saved value for the battery quirk check."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/staging/nvec/nvec.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"d6bdcf2e1019351cbc176e963b7756766bdd8721","lessThan":"6b2ea886ebdae44a2394029844a4e78f58e1587d","versionType":"git","status":"affected"},{"version":"d6bdcf2e1019351cbc176e963b7756766bdd8721","lessThan":"a37625c7b688fcf68a54263528eccbabfd7fa17a","versionType":"git","status":"affected"},{"version":"d6bdcf2e1019351cbc176e963b7756766bdd8721","lessThan":"9f7fe4165a1f1014bdadc8e744c0fd3c2d8c0b89","versionType":"git","status":"affected"},{"version":"d6bdcf2e1019351cbc176e963b7756766bdd8721","lessThan":"08626fcfe12308ca3f8b22c538ba7dee0b2dce7a","versionType":"git","status":"affected"},{"version":"d6bdcf2e1019351cbc176e963b7756766bdd8721","lessThan":"f19a5bc059051143c489dd6f79a0f9c3bfd13aea","versionType":"git","status":"affected"},{"version":"d6bdcf2e1019351cbc176e963b7756766bdd8721","lessThan":"bb3d592c7d6c4ec8ac6640c690ca13298e7e8e90","versionType":"git","status":"affected"},{"version":"d6bdcf2e1019351cbc176e963b7756766bdd8721","lessThan":"5de04caa46b635e180cecbd164e333eca535db94","versionType":"git","status":"affected"},{"version":"d6bdcf2e1019351cbc176e963b7756766bdd8721","lessThan":"26813881181deb3a32fbb59eadb2599cbe8423f6","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/staging/nvec/nvec.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"3.2","status":"affected"},{"version":"0","lessThan":"3.2","versionType":"semver","status":"unaffected"},{"version":"5.10.261","lessThanOrEqual":"5.10.*","versionType":"semver","status":"unaffected"},{"version":"5.15.212","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.178","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.97","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/08626fcfe12308ca3f8b22c538ba7dee0b2dce7a","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/26813881181deb3a32fbb59eadb2599cbe8423f6","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/5de04caa46b635e180cecbd164e333eca535db94","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/6b2ea886ebdae44a2394029844a4e78f58e1587d","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/9f7fe4165a1f1014bdadc8e744c0fd3c2d8c0b89","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/a37625c7b688fcf68a54263528eccbabfd7fa17a","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/bb3d592c7d6c4ec8ac6640c690ca13298e7e8e90","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/f19a5bc059051143c489dd6f79a0f9c3bfd13aea","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-72490","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:22:23.307","lastModified":"2026-08-15T06:22:23.307","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nstaging: rtl8723bs: fix stainfo check in rtw_aes_decrypt\n\nThe null-pointer-guard was incorrect, returning _FAIL on valid pointer.\nInvert the guard, so it returns _FAIL on invalid pointer."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/staging/rtl8723bs/core/rtw_security.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"e23ad15700284b63ab5d8ae1370e93f7c1723863","lessThan":"fde2296f87b72ccd72460ce13ad56e8652b321d4","versionType":"git","status":"affected"},{"version":"e23ad15700284b63ab5d8ae1370e93f7c1723863","lessThan":"9a3f9b3c47d8f071b0eb9e63906ac0448058278d","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/staging/rtl8723bs/core/rtw_security.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"7.1","status":"affected"},{"version":"0","lessThan":"7.1","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/9a3f9b3c47d8f071b0eb9e63906ac0448058278d","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/fde2296f87b72ccd72460ce13ad56e8652b321d4","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-72491","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:22:23.400","lastModified":"2026-08-15T06:22:23.400","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nnet/9p: fix race condition on rdma->state in trans_rdma.c\n\nThe rdma->state field is modified without holding req_lock in both\nrecv_done() and p9_cm_event_handler(), while rdma_request() accesses\nthe same field under the req_lock spinlock. This inconsistent locking\ncreates a race condition:\n\n- recv_done() running in softirq completion context sets\n  rdma->state = P9_RDMA_FLUSHING without acquiring req_lock\n\n- p9_cm_event_handler() modifies rdma->state at multiple points\n  (ADDR_RESOLVED, ROUTE_RESOLVED, ESTABLISHED, CLOSED) without\n  req_lock\n\n- rdma_request() uses spin_lock_irqsave(&rdma->req_lock, flags) to\n  protect the read-modify-write of rdma->state\n\nThe race can cause lost state transitions: recv_done() or the CM\nevent handler could set state to FLUSHING/CLOSED while rdma_request()\nis concurrently checking or modifying state under the lock, leading to\nthe FLUSHING transition being silently overwritten by CLOSING. This\ncorrupts the connection state machine and can cause use-after-free on\nRDMA request objects during teardown.\n\nFix by adding req_lock protection to all rdma->state modifications in\nrecv_done() and p9_cm_event_handler(), matching the pattern already\nused in rdma_request(). Use spin_lock_irqsave/spin_unlock_irqrestore\nin the CM event handler since it can race with recv_done() which runs\nin softirq context.\n\nTested with a kernel module that races two threads (simulating\nrdma_request and recv_done/CM handler) on rdma->state with proper\nlocking: 5.5M+ FLUSHING writes over 27M iterations with 0 lost\ntransitions."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["net/9p/trans_rdma.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"473c7dd1d7b59ff8f88a5154737e3eac78a96e5b","lessThan":"4cee2b8766045059d5e0b8114837b4a8efe827ac","versionType":"git","status":"affected"},{"version":"473c7dd1d7b59ff8f88a5154737e3eac78a96e5b","lessThan":"5424138848eb7d7d8a7196676e90a2cbf2142454","versionType":"git","status":"affected"},{"version":"473c7dd1d7b59ff8f88a5154737e3eac78a96e5b","lessThan":"3970a19a80de530b801b6256354d4a529a9a2d6c","versionType":"git","status":"affected"},{"version":"473c7dd1d7b59ff8f88a5154737e3eac78a96e5b","lessThan":"8aadc136d8e8d8fc95d7982d213cfe2234dfcf2b","versionType":"git","status":"affected"},{"version":"473c7dd1d7b59ff8f88a5154737e3eac78a96e5b","lessThan":"151f8cf5b23d8a534d884432a82a6d54d5a61989","versionType":"git","status":"affected"},{"version":"473c7dd1d7b59ff8f88a5154737e3eac78a96e5b","lessThan":"13bf9879b778b2f4b260b45bed18f31806120d1e","versionType":"git","status":"affected"},{"version":"473c7dd1d7b59ff8f88a5154737e3eac78a96e5b","lessThan":"ebbcbe5c0db215feecc17def06178da443f4eea6","versionType":"git","status":"affected"},{"version":"473c7dd1d7b59ff8f88a5154737e3eac78a96e5b","lessThan":"7d54894a1ee265a72d70f7cae1da6cc774cccc71","versionType":"git","status":"affected"},{"version":"3479b3c35e82ed10aa0ca2ee9e78c4eded06ba62","versionType":"git","status":"affected"},{"version":"c01ddaa54d7411e964ffd250c018d8469c5852f2","versionType":"git","status":"affected"},{"version":"9e69c673fe077b8dc491cd8406c9bdcb1f76dee2","versionType":"git","status":"affected"},{"version":"e48e7e27e4dfd00c81e0381e7cee610cce021452","versionType":"git","status":"affected"},{"version":"4.4.185","lessThan":"4.5","versionType":"semver","status":"affected"},{"version":"4.9.185","lessThan":"4.10","versionType":"semver","status":"affected"},{"version":"4.14.132","lessThan":"4.15","versionType":"semver","status":"affected"},{"version":"4.19.57","lessThan":"4.20","versionType":"semver","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["net/9p/trans_rdma.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"4.20","status":"affected"},{"version":"0","lessThan":"4.20","versionType":"semver","status":"unaffected"},{"version":"5.10.261","lessThanOrEqual":"5.10.*","versionType":"semver","status":"unaffected"},{"version":"5.15.212","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.178","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.97","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/13bf9879b778b2f4b260b45bed18f31806120d1e","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/151f8cf5b23d8a534d884432a82a6d54d5a61989","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/3970a19a80de530b801b6256354d4a529a9a2d6c","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/4cee2b8766045059d5e0b8114837b4a8efe827ac","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/5424138848eb7d7d8a7196676e90a2cbf2142454","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/7d54894a1ee265a72d70f7cae1da6cc774cccc71","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/8aadc136d8e8d8fc95d7982d213cfe2234dfcf2b","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/ebbcbe5c0db215feecc17def06178da443f4eea6","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-72492","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:22:23.533","lastModified":"2026-08-15T06:22:23.533","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nksmbd: fix use-after-free in same_client_has_lease()\n\nsame_client_has_lease() returns an opinfo pointer from ci->m_op_list\nafter dropping ci->m_lock without taking a reference.\n\nsmb_grant_oplock() then dereferences that pointer in copy_lease() and\nwhen checking breaking_cnt. A concurrent close can remove the old lease\nfrom ci->m_op_list and drop the last reference before the caller uses\nthe returned pointer, leading to a use-after-free.\n\nTake a reference when same_client_has_lease() selects an existing lease,\ndrop any previous match while scanning, and release the returned\nreference in smb_grant_oplock() after copying the lease state."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["fs/smb/server/oplock.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"e2f34481b24db2fd634b5edb0a5bd0e4d38cc6e9","lessThan":"aaa3bb2bbf2ccbfea9e4e0b9dabf3afc60b50cd0","versionType":"git","status":"affected"},{"version":"e2f34481b24db2fd634b5edb0a5bd0e4d38cc6e9","lessThan":"09634cd055d9bd8dd167995ea52bcd8028dd5dac","versionType":"git","status":"affected"},{"version":"e2f34481b24db2fd634b5edb0a5bd0e4d38cc6e9","lessThan":"7c3264d273d524aa6adcce23c01087271f13586f","versionType":"git","status":"affected"},{"version":"e2f34481b24db2fd634b5edb0a5bd0e4d38cc6e9","lessThan":"79c7c59bb519db6f5a2a151965e825ec725614cc","versionType":"git","status":"affected"},{"version":"e2f34481b24db2fd634b5edb0a5bd0e4d38cc6e9","lessThan":"35d3d6ff2bc1e7aaecb15d5377ebbd6227acae0d","versionType":"git","status":"affected"},{"version":"e2f34481b24db2fd634b5edb0a5bd0e4d38cc6e9","lessThan":"0ff82a9cf9312678d8bc4edeef0b6e82659ac12a","versionType":"git","status":"affected"},{"version":"e2f34481b24db2fd634b5edb0a5bd0e4d38cc6e9","lessThan":"65b655f65c3ca1ab5d598d3832bb0ff531725858","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["fs/smb/server/oplock.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"5.15","status":"affected"},{"version":"0","lessThan":"5.15","versionType":"semver","status":"unaffected"},{"version":"5.15.212","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.178","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.97","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/09634cd055d9bd8dd167995ea52bcd8028dd5dac","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/0ff82a9cf9312678d8bc4edeef0b6e82659ac12a","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/35d3d6ff2bc1e7aaecb15d5377ebbd6227acae0d","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/65b655f65c3ca1ab5d598d3832bb0ff531725858","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/79c7c59bb519db6f5a2a151965e825ec725614cc","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/7c3264d273d524aa6adcce23c01087271f13586f","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/aaa3bb2bbf2ccbfea9e4e0b9dabf3afc60b50cd0","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-72493","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:22:23.643","lastModified":"2026-08-15T06:22:23.643","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nnet: serialize netif_running() check in enqueue_to_backlog()\n\nSyzbot reported a KASAN slab-use-after-free in fib_rules_lookup().\n\nThe root cause is a race condition where packets can escape the backlog\nflushing during device unregistration (e.g., during netns exit).\n\nCommit e9e4dd3267d0 (\"net: do not process device backlog during unregistration\")\nintroduced a lockless netif_running() check in enqueue_to_backlog() to\nprevent queuing packets to an unregistering device.\n\nHowever, this creates a TOCTOU race window.\n\nA lockless transmitter (like veth_xmit) can pass\nthe check before dev_close() clears IFF_UP. If the transmitter is then\ndelayed, flush_all_backlogs() can run and finish before the transmitter\ngrabs the backlog lock and queues the packet. The packet then escapes\nthe flush and triggers UAF later when processed.\n\nFix this by moving the netif_running() check inside the backlog lock.\nThis serializes the check with the flush work (which also grabs the lock).\nWe then either queue the packet before the flush runs (so it gets flushed),\nor check netif_running() after the flush/close completes (so it gets dropped)."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["net/core/dev.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"e9e4dd3267d0c5234c5c0f47440456b10875dec9","lessThan":"2fface6e0bbd6314d1d9d071abf2c4d67548511c","versionType":"git","status":"affected"},{"version":"e9e4dd3267d0c5234c5c0f47440456b10875dec9","lessThan":"46762cefe7f4e5bffc1eb467810a7bbb02e461d7","versionType":"git","status":"affected"},{"version":"78b6803a1961369d0b8350ff1f99b7375bbd7a8f","versionType":"git","status":"affected"},{"version":"b5d73d9cdd6be22795499890ea928a6f57ef829c","versionType":"git","status":"affected"},{"version":"f6533fed1bfa842e391ee50f9a9c5e963c71e579","versionType":"git","status":"affected"},{"version":"2095ab2456da766174cda8bc105d7a7b1bc70e16","versionType":"git","status":"affected"},{"version":"f1fdb184aefa8447560e3ea0e605171592ffee41","versionType":"git","status":"affected"},{"version":"f75c8a3015422128ca150e81c730bc2a471b5f4a","versionType":"git","status":"affected"},{"version":"3.2.71","lessThan":"3.3","versionType":"semver","status":"affected"},{"version":"3.4.111","lessThan":"3.5","versionType":"semver","status":"affected"},{"version":"3.12.48","lessThan":"3.13","versionType":"semver","status":"affected"},{"version":"3.14.54","lessThan":"3.15","versionType":"semver","status":"affected"},{"version":"3.18.22","lessThan":"3.19","versionType":"semver","status":"affected"},{"version":"4.1.9","lessThan":"4.2","versionType":"semver","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["net/core/dev.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"4.2","status":"affected"},{"version":"0","lessThan":"4.2","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/2fface6e0bbd6314d1d9d071abf2c4d67548511c","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/46762cefe7f4e5bffc1eb467810a7bbb02e461d7","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-72494","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:22:23.747","lastModified":"2026-08-15T06:22:23.747","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nRDMA/irdma: Replace waitqueue and flag with completion\n\nThe driver previously used a waitqueue along with an explicit\nrequest_done flag, but without proper barriers around request_done.\n\nAn earlier patch by Gui-Dong Han <hanguidong02@gmail.com> attempted\nto fix this by adding the missing memory barriers. Rather than\nadding the barriers, this patch replaces the waitqueue+flag with\na completion, which is designed for this exact purpose."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/infiniband/hw/irdma/hw.c","drivers/infiniband/hw/irdma/main.h","drivers/infiniband/hw/irdma/utils.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"44d9e52977a1b90b0db1c7f8b197c218e9226520","lessThan":"bde37aed0724c0139dea177f3aae8d989b6babb1","versionType":"git","status":"affected"},{"version":"44d9e52977a1b90b0db1c7f8b197c218e9226520","lessThan":"d9c8c45e6d2f438a3c8e643ae78b59454fa0fadd","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/infiniband/hw/irdma/hw.c","drivers/infiniband/hw/irdma/main.h","drivers/infiniband/hw/irdma/utils.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"5.14","status":"affected"},{"version":"0","lessThan":"5.14","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/bde37aed0724c0139dea177f3aae8d989b6babb1","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/d9c8c45e6d2f438a3c8e643ae78b59454fa0fadd","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-72495","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:22:23.840","lastModified":"2026-08-15T06:22:23.840","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nRDMA/bnxt_re: Avoid repeated requests to allocate WC pages\n\nApplications can request multiple WC pages for the same ucontext.\nAs of now, only 1 WC page per ucontext is supported. Add a lock to\navoid concurrent access and a check to fail repeated requests.\nAlso, if the mmap entry insert fails for the WC, free the Doorbell\npage index mapped for the WC page."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/infiniband/hw/bnxt_re/ib_verbs.c","drivers/infiniband/hw/bnxt_re/ib_verbs.h","drivers/infiniband/hw/bnxt_re/uapi.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"360da60d6c6edb9740de7a8e6d8969d62ceff956","lessThan":"478c4d24193fe3e6aa2accd4874ae43000e4a217","versionType":"git","status":"affected"},{"version":"360da60d6c6edb9740de7a8e6d8969d62ceff956","lessThan":"da406b8b49c1dfe661a497483940d7ee781430db","versionType":"git","status":"affected"},{"version":"360da60d6c6edb9740de7a8e6d8969d62ceff956","lessThan":"441baa79043431807115fd030d7d0bb14ed441a0","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/infiniband/hw/bnxt_re/ib_verbs.c","drivers/infiniband/hw/bnxt_re/ib_verbs.h","drivers/infiniband/hw/bnxt_re/uapi.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.5","status":"affected"},{"version":"0","lessThan":"6.5","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/441baa79043431807115fd030d7d0bb14ed441a0","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/478c4d24193fe3e6aa2accd4874ae43000e4a217","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/da406b8b49c1dfe661a497483940d7ee781430db","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-72496","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:22:23.940","lastModified":"2026-08-15T06:22:23.940","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nRDMA/bnxt_re: Proper rollback if the ioremap fails\n\nbnxt_qplib_alloc_dpi returns success even if ioremap fails.\nAdd the proper rollback when the ioremap fails and return\n-ENOMEM status."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/infiniband/hw/bnxt_re/qplib_res.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"0ac20faf5d837b59fb4c041ea320932ed47fd67f","lessThan":"303f6fef95df5e5316970746d861cf6daeeca77f","versionType":"git","status":"affected"},{"version":"0ac20faf5d837b59fb4c041ea320932ed47fd67f","lessThan":"87267803a8c824616eb147c5dad7030a5db6f878","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/infiniband/hw/bnxt_re/qplib_res.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.5","status":"affected"},{"version":"0","lessThan":"6.5","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/303f6fef95df5e5316970746d861cf6daeeca77f","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/87267803a8c824616eb147c5dad7030a5db6f878","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-72497","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:22:24.037","lastModified":"2026-08-15T06:22:24.037","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nRDMA/bnxt_re: Add a max slot check for SQ\n\nThe variable WQE mode must be validated against\nthe maximum slots supported by HW. The max supported\nvalue is 64K. Adding a max and min check and fail if user\nsupplied value is more than the max supported and zero."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/infiniband/hw/bnxt_re/ib_verbs.c","drivers/infiniband/hw/bnxt_re/qplib_sp.h"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"d8ea645d6984c84a87032063a0941f15a323831f","lessThan":"a59d815cbe667929b693b5fa6716a074e6a31c5b","versionType":"git","status":"affected"},{"version":"d8ea645d6984c84a87032063a0941f15a323831f","lessThan":"dc95931b7e1326dacae547874bf38c092e5960d8","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/infiniband/hw/bnxt_re/ib_verbs.c","drivers/infiniband/hw/bnxt_re/qplib_sp.h"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.12","status":"affected"},{"version":"0","lessThan":"6.12","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/a59d815cbe667929b693b5fa6716a074e6a31c5b","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/dc95931b7e1326dacae547874bf38c092e5960d8","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-72498","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:22:24.127","lastModified":"2026-08-15T06:22:24.127","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nRDMA/bnxt_re: Avoid displaying the kernel pointer\n\nWhile dumping the info on MR using the rdma tool, we\ndump the mr_hwq which is a kernel pointer. There is\nno need to expose this value for end user. So avoid\nit."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/infiniband/hw/bnxt_re/main.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"7363eb76b7f3b860ecfb8fcaf537e143bfd725bd","lessThan":"95d46a8d3ba9fdbe356fe7ed0117bc78dac9d557","versionType":"git","status":"affected"},{"version":"7363eb76b7f3b860ecfb8fcaf537e143bfd725bd","lessThan":"0c403e0786768d88cabe0ccf4e45425da2fd8841","versionType":"git","status":"affected"},{"version":"7363eb76b7f3b860ecfb8fcaf537e143bfd725bd","lessThan":"7d70c704a06f620d5d421ab76bac5e225bfb4308","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/infiniband/hw/bnxt_re/main.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.13","status":"affected"},{"version":"0","lessThan":"6.13","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/0c403e0786768d88cabe0ccf4e45425da2fd8841","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/7d70c704a06f620d5d421ab76bac5e225bfb4308","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/95d46a8d3ba9fdbe356fe7ed0117bc78dac9d557","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-72499","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:22:24.220","lastModified":"2026-08-15T06:22:24.220","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nRDMA/bnxt_re: Free CQ toggle page after firmware teardown\n\nFree the toggle page only after firmware teardown completes so that\nan NQ interrupt arriving during bnxt_qplib_destroy_cq() won't write\nthe toggle value to an already-freed page. Move free_page() after\nbnxt_qplib_destroy_cq."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/infiniband/hw/bnxt_re/ib_verbs.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"e275919d96693c5ca964b20d73a33d52a7e57f04","lessThan":"b193854675ecad43b4d69c304c1b6a90b206cc99","versionType":"git","status":"affected"},{"version":"e275919d96693c5ca964b20d73a33d52a7e57f04","lessThan":"bb45e06f9914ca64ac95341a80a0c20bb8dd46a9","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/infiniband/hw/bnxt_re/ib_verbs.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.8","status":"affected"},{"version":"0","lessThan":"6.8","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/b193854675ecad43b4d69c304c1b6a90b206cc99","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/bb45e06f9914ca64ac95341a80a0c20bb8dd46a9","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-72500","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:22:24.320","lastModified":"2026-08-15T06:22:24.320","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nRDMA/bnxt_re: Free SRQ toggle page after firmware teardown\n\nFree the toggle page only after firmware teardown completes so that\nan NQ interrupt arriving during bnxt_qplib_destroy_srq() won't write\nthe toggle values to an already-freed page. Move free_page() after\nbnxt_qplib_destroy_srq()."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/infiniband/hw/bnxt_re/ib_verbs.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"181028a0d84cdcc7ac86d05cc49eaa416ce85c8b","lessThan":"104a7ff382a58a83cae018925e3574c784e8274c","versionType":"git","status":"affected"},{"version":"181028a0d84cdcc7ac86d05cc49eaa416ce85c8b","lessThan":"0adcd67f3d6f84835be682da0153f57f5c2f8036","versionType":"git","status":"affected"},{"version":"181028a0d84cdcc7ac86d05cc49eaa416ce85c8b","lessThan":"131e2918b9b0529687e67e2e58047304027f095a","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/infiniband/hw/bnxt_re/ib_verbs.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.12","status":"affected"},{"version":"0","lessThan":"6.12","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/0adcd67f3d6f84835be682da0153f57f5c2f8036","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/104a7ff382a58a83cae018925e3574c784e8274c","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/131e2918b9b0529687e67e2e58047304027f095a","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-72501","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:22:24.417","lastModified":"2026-08-15T06:22:24.417","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nRDMA/bnxt_re: Initialize dpi variable to zero\n\ndpi is initialized only for BNXT_RE_ALLOC_WC_PAGE, but copied\nfor all the cases. So initialize the dpi to 0."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/infiniband/hw/bnxt_re/uapi.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"360da60d6c6edb9740de7a8e6d8969d62ceff956","lessThan":"b87cbd4d198ae377be4815d8102fa9dfefb91dcc","versionType":"git","status":"affected"},{"version":"360da60d6c6edb9740de7a8e6d8969d62ceff956","lessThan":"3d00b375853fbbf4157ad092884b4ed9a49429c1","versionType":"git","status":"affected"},{"version":"360da60d6c6edb9740de7a8e6d8969d62ceff956","lessThan":"978b27d6ce538bb832ccd69e45802824e4301c4b","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/infiniband/hw/bnxt_re/uapi.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.5","status":"affected"},{"version":"0","lessThan":"6.5","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/3d00b375853fbbf4157ad092884b4ed9a49429c1","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/978b27d6ce538bb832ccd69e45802824e4301c4b","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/b87cbd4d198ae377be4815d8102fa9dfefb91dcc","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-72502","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:22:24.510","lastModified":"2026-08-15T06:22:24.510","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\ntcp: ipv6: clamp default adverting MSS to avoid GSO_BY_FRAGS (0xFFFF)\n\nWhen MTU is large, ip6_default_advmss() can return IPV6_MAXPLEN (65535).\nThis is interpreted by TCP as mss_clamp, allowing the MSS to reach 65535.\n\nHowever, 0xFFFF is also used as a magic value GSO_BY_FRAGS in the kernel.\nIf a TCP packet with gso_size=0xFFFF is passed to skb_segment(), it will\nbe mistakenly treated as GSO_BY_FRAGS, leading to a NULL pointer\ndereference because local TCP packets do not use frag_list.\n\nFix this by returning min(IPV6_MAXPLEN, GSO_BY_FRAGS - 1) (65534) from\nip6_default_advmss() when MTU is large.\n\nAlso update the stale comment in ip6_default_advmss() which suggested\nthat IPV6_MAXPLEN is returned to mean \"any MSS\"."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["net/ipv6/route.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"3953c46c3ac7eef31a9935427371c6f54a22f1ba","lessThan":"560b33b434e922ef97f9ff23aa2e909ef7aacd5c","versionType":"git","status":"affected"},{"version":"3953c46c3ac7eef31a9935427371c6f54a22f1ba","lessThan":"21f69ac1879bb970588d5e7c12a96e6542f7c1a7","versionType":"git","status":"affected"},{"version":"3953c46c3ac7eef31a9935427371c6f54a22f1ba","lessThan":"c0db3dc2ac323b6c4b76adede3b355a9daa6dea8","versionType":"git","status":"affected"},{"version":"3953c46c3ac7eef31a9935427371c6f54a22f1ba","lessThan":"572fff10819dfc359298d1f774839e76a4d96f93","versionType":"git","status":"affected"},{"version":"3953c46c3ac7eef31a9935427371c6f54a22f1ba","lessThan":"8e6214a530c03e341dc1b0a846c8f2b716b3551a","versionType":"git","status":"affected"},{"version":"3953c46c3ac7eef31a9935427371c6f54a22f1ba","lessThan":"d774cdbda6634a78d0f2baf201ee5a8c57f3bc0e","versionType":"git","status":"affected"},{"version":"3953c46c3ac7eef31a9935427371c6f54a22f1ba","lessThan":"a210791f33345aa87187f7d7a9f3b9b7f4a28e6d","versionType":"git","status":"affected"},{"version":"3953c46c3ac7eef31a9935427371c6f54a22f1ba","lessThan":"2bf43d0e2e6a27d52a7d624e2d6b9116972e8a22","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["net/ipv6/route.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"4.8","status":"affected"},{"version":"0","lessThan":"4.8","versionType":"semver","status":"unaffected"},{"version":"5.10.261","lessThanOrEqual":"5.10.*","versionType":"semver","status":"unaffected"},{"version":"5.15.212","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.178","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.97","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/21f69ac1879bb970588d5e7c12a96e6542f7c1a7","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/2bf43d0e2e6a27d52a7d624e2d6b9116972e8a22","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/560b33b434e922ef97f9ff23aa2e909ef7aacd5c","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/572fff10819dfc359298d1f774839e76a4d96f93","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/8e6214a530c03e341dc1b0a846c8f2b716b3551a","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/a210791f33345aa87187f7d7a9f3b9b7f4a28e6d","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/c0db3dc2ac323b6c4b76adede3b355a9daa6dea8","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/d774cdbda6634a78d0f2baf201ee5a8c57f3bc0e","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-74255","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:22:24.627","lastModified":"2026-08-15T06:22:24.627","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\ntipc: fix UAF in tipc_l2_send_msg()\n\nSyzbot reported a slab-use-after-free in ipvlan_hard_header() when\ncalled from tipc_l2_send_msg().\n\nThe root cause is that tipc_disable_l2_media() calls synchronize_net()\nwhile b->media_ptr is still valid. This allows concurrent RCU readers\nto obtain the device pointer after synchronize_net() has finished.\nThe pointer is cleared later in bearer_disable(), but without any\nsubsequent synchronization, allowing the device to be freed while\nstill in use by readers.\n\nFix this by clearing b->media_ptr in tipc_disable_l2_media() before\ncalling synchronize_net().\n\nThis is safe to do now because the call order in bearer_disable()\nwas reversed in 0d051bf93c06 (\"tipc: make bearer packet filtering generic\")\nto call tipc_node_delete_links() (which needs the pointer) before\ndisable_media().\n\nhttps: //lore.kernel.org/netdev/6a2c1007.428ffe26.258b27.015d.GAE@google.com/T/#u"}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["net/tipc/bearer.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"282b3a056225b35024246f63feb91d769d714dad","lessThan":"609ced2301be1df7e7ed2ef47d1d916674e6ba3b","versionType":"git","status":"affected"},{"version":"282b3a056225b35024246f63feb91d769d714dad","lessThan":"71aafa16d79b107b33837f60b6cbc7d0cb8c5708","versionType":"git","status":"affected"},{"version":"282b3a056225b35024246f63feb91d769d714dad","lessThan":"f4002f1c669cc02e3763f479fc25ff1dfa9e2420","versionType":"git","status":"affected"},{"version":"282b3a056225b35024246f63feb91d769d714dad","lessThan":"50ff092633b06382e5091dd5b093ce943d4ac2f9","versionType":"git","status":"affected"},{"version":"282b3a056225b35024246f63feb91d769d714dad","lessThan":"aef12b5ce793dea6b3a97a58fd0f946000ae8945","versionType":"git","status":"affected"},{"version":"282b3a056225b35024246f63feb91d769d714dad","lessThan":"0d8a12d7143126afdf9fbe2e3d438650dd6603ed","versionType":"git","status":"affected"},{"version":"282b3a056225b35024246f63feb91d769d714dad","lessThan":"35e0297a93c3c34a3924eeef816c03504e3ab5c5","versionType":"git","status":"affected"},{"version":"282b3a056225b35024246f63feb91d769d714dad","lessThan":"f4c3d89fc986b0da196ddfc6cfe0ea5d5d08bec6","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["net/tipc/bearer.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"4.4","status":"affected"},{"version":"0","lessThan":"4.4","versionType":"semver","status":"unaffected"},{"version":"5.10.261","lessThanOrEqual":"5.10.*","versionType":"semver","status":"unaffected"},{"version":"5.15.212","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.178","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.97","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/0d8a12d7143126afdf9fbe2e3d438650dd6603ed","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/35e0297a93c3c34a3924eeef816c03504e3ab5c5","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/50ff092633b06382e5091dd5b093ce943d4ac2f9","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/609ced2301be1df7e7ed2ef47d1d916674e6ba3b","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/71aafa16d79b107b33837f60b6cbc7d0cb8c5708","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/aef12b5ce793dea6b3a97a58fd0f946000ae8945","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/f4002f1c669cc02e3763f479fc25ff1dfa9e2420","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/f4c3d89fc986b0da196ddfc6cfe0ea5d5d08bec6","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-74256","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:22:24.743","lastModified":"2026-08-15T06:22:24.743","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nbpf, sockmap: fix integer overflow in bpf_msg_pop_data() bounds check\n\nstart and len are u32, so\n\n\tu64 last = start + len;\n\nevaluates start + len in 32-bit and wraps before storing it in last.\nThe bounds check\n\n\tif (start >= offset + l || last > msg->sg.size)\n\t\treturn -EINVAL;\n\ncan then be passed with an out-of-range start/len, after which the pop\nloop runs off the end of the scatterlist and sk_msg_shift_left() calls\nput_page() on the empty msg->sg.end slot:\n\n  Oops: general protection fault, probably for non-canonical address\n  0xdffffc0000000001: 0000 [#1] SMP KASAN PTI\n  KASAN: null-ptr-deref in range [0x0000000000000008-0x000000000000000f]\n  RIP: 0010:sk_msg_shift_left net/core/filter.c:2957 [inline]\n  RIP: 0010:____bpf_msg_pop_data net/core/filter.c:3103 [inline]\n  RIP: 0010:bpf_msg_pop_data+0x753/0x1a10 net/core/filter.c:2984\n  Call Trace:\n   <TASK>\n   bpf_prog_4cc92c278f4d5d56+0x1b1/0x1e8\n   bpf_prog_run_pin_on_cpu+0x107/0x320 include/linux/filter.h:746\n   sk_psock_msg_verdict+0x357/0x7f0 net/core/skmsg.c:934\n   tcp_bpf_send_verdict net/ipv4/tcp_bpf.c:420 [inline]\n   tcp_bpf_sendmsg+0x766/0x1ae0 net/ipv4/tcp_bpf.c:583\n   __sock_sendmsg+0x153/0x1c0 net/socket.c:802\n   __sys_sendto+0x326/0x430 net/socket.c:2265\n   __x64_sys_sendto+0xe3/0x100 net/socket.c:2268\n   do_syscall_64+0x14c/0x480\n   entry_SYSCALL_64_after_hwframe+0x77/0x7f\n   </TASK>\n\nWiden the addition with a (u64) cast so the bound is evaluated in\n64-bit and a len near U32_MAX no longer wraps below msg->sg.size.\n\nWhile here, change pop from int to u32. It counts bytes against the\nunsigned scatterlist lengths and can never be negative, so the signed\ntype only invites sign-confusion in the pop loop."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["net/core/filter.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"7246d8ed4dcce23f7509949a77be15fa9f0e3d28","lessThan":"9ef44ed6fb0c1db01cfcc3de432a33e719713eb5","versionType":"git","status":"affected"},{"version":"7246d8ed4dcce23f7509949a77be15fa9f0e3d28","lessThan":"d693c5ed67dabe1ccbf8dcea93075bdc9ffd4ca0","versionType":"git","status":"affected"},{"version":"7246d8ed4dcce23f7509949a77be15fa9f0e3d28","lessThan":"ba5cc05dae8fce237d191c7ea96b1107a791e548","versionType":"git","status":"affected"},{"version":"7246d8ed4dcce23f7509949a77be15fa9f0e3d28","lessThan":"c05a0ec1cdced622a1a0c7d85679fe02f31033ec","versionType":"git","status":"affected"},{"version":"7246d8ed4dcce23f7509949a77be15fa9f0e3d28","lessThan":"17eb9832a10db2f7a80cb429ca2bc5038445a943","versionType":"git","status":"affected"},{"version":"7246d8ed4dcce23f7509949a77be15fa9f0e3d28","lessThan":"fe09dd288722f1c749b7506c0b3e7841a7d85027","versionType":"git","status":"affected"},{"version":"7246d8ed4dcce23f7509949a77be15fa9f0e3d28","lessThan":"e09f7bd7273928b4089e6b71f8e992f2b356ca1b","versionType":"git","status":"affected"},{"version":"7246d8ed4dcce23f7509949a77be15fa9f0e3d28","lessThan":"a48802fb2cd2d1e23651989f8ff4d15e9d5dad54","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["net/core/filter.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"5.0","status":"affected"},{"version":"0","lessThan":"5.0","versionType":"semver","status":"unaffected"},{"version":"5.10.261","lessThanOrEqual":"5.10.*","versionType":"semver","status":"unaffected"},{"version":"5.15.212","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.178","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.97","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/17eb9832a10db2f7a80cb429ca2bc5038445a943","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/9ef44ed6fb0c1db01cfcc3de432a33e719713eb5","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/a48802fb2cd2d1e23651989f8ff4d15e9d5dad54","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/ba5cc05dae8fce237d191c7ea96b1107a791e548","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/c05a0ec1cdced622a1a0c7d85679fe02f31033ec","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/d693c5ed67dabe1ccbf8dcea93075bdc9ffd4ca0","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/e09f7bd7273928b4089e6b71f8e992f2b356ca1b","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/fe09dd288722f1c749b7506c0b3e7841a7d85027","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-74257","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:22:24.870","lastModified":"2026-08-15T06:22:24.870","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nsockmap: Fix use-after-free in udp_bpf_recvmsg()\n\nsyzbot reported use-after-free of struct sk_msg in sk_msg_recvmsg(). [0]\n\nsk_msg_recvmsg() peeks sk_msg from psock->ingress_msg under a lock,\nbut its processing is lockless.\n\nThus, sk_msg_recvmsg() must be serialised by callers, otherwise\nmultiple threads could touch the same sk_msg.\n\nFor example, TCP uses lock_sock(), and AF_UNIX uses unix_sk(sk)->iolock.\n\nInitially, udp_bpf_recvmsg() had used lock_sock(), but the cited\ncommit removed it.\n\nLet's serialise sk_msg_recvmsg() with lock_sock() in udp_bpf_recvmsg().\n\nNote that holding spin_lock_bh(&sk->sk_receive_queue.lock) is not\nan option due to copy_page_to_iter() in sk_msg_recvmsg().\n\n[0]:\nBUG: KASAN: slab-use-after-free in sk_msg_recvmsg+0xb54/0xc30 net/core/skmsg.c:428\nRead of size 4 at addr ffff88814cdcf000 by task syz.0.24/6020\n\nCPU: 1 UID: 0 PID: 6020 Comm: syz.0.24 Not tainted syzkaller #0 PREEMPT(full)\nHardware name: Google Compute Engine/Google Compute Engine, BIOS Google 01/13/2026\nCall Trace:\n <TASK>\n dump_stack_lvl+0xe8/0x150 lib/dump_stack.c:120\n print_address_description mm/kasan/report.c:378 [inline]\n print_report+0xba/0x230 mm/kasan/report.c:482\n kasan_report+0x117/0x150 mm/kasan/report.c:595\n sk_msg_recvmsg+0xb54/0xc30 net/core/skmsg.c:428\n udp_bpf_recvmsg+0x4bd/0xe00 net/ipv4/udp_bpf.c:84\n inet_recvmsg+0x260/0x270 net/ipv4/af_inet.c:891\n sock_recvmsg_nosec net/socket.c:1078 [inline]\n sock_recvmsg+0x1a8/0x270 net/socket.c:1100\n ____sys_recvmsg+0x1e6/0x4a0 net/socket.c:2812\n ___sys_recvmsg+0x215/0x590 net/socket.c:2854\n do_recvmmsg+0x334/0x800 net/socket.c:2949\n __sys_recvmmsg net/socket.c:3023 [inline]\n __do_sys_recvmmsg net/socket.c:3046 [inline]\n __se_sys_recvmmsg net/socket.c:3039 [inline]\n __x64_sys_recvmmsg+0x198/0x250 net/socket.c:3039\n do_syscall_x64 arch/x86/entry/syscall_64.c:63 [inline]\n do_syscall_64+0xe2/0xf80 arch/x86/entry/syscall_64.c:94\n entry_SYSCALL_64_after_hwframe+0x77/0x7f\nRIP: 0033:0x7fb319f9aeb9\nCode: ff c3 66 2e 0f 1f 84 00 00 00 00 00 0f 1f 44 00 00 48 89 f8 48 89 f7 48 89 d6 48 89 ca 4d 89 c2 4d 89 c8 4c 8b 4c 24 08 0f 05 <48> 3d 01 f0 ff ff 73 01 c3 48 c7 c1 e8 ff ff ff f7 d8 64 89 01 48\nRSP: 002b:00007fb31ad97028 EFLAGS: 00000246 ORIG_RAX: 000000000000012b\nRAX: ffffffffffffffda RBX: 00007fb31a216090 RCX: 00007fb319f9aeb9\nRDX: 0000000000000001 RSI: 0000200000000400 RDI: 0000000000000004\nRBP: 00007fb31a008c1f R08: 0000000000000000 R09: 0000000000000000\nR10: 0000000040000021 R11: 0000000000000246 R12: 0000000000000000\nR13: 00007fb31a216128 R14: 00007fb31a216090 R15: 00007ffe21dd0a98\n </TASK>\n\nAllocated by task 6019:\n kasan_save_stack mm/kasan/common.c:57 [inline]\n kasan_save_track+0x3e/0x80 mm/kasan/common.c:78\n poison_kmalloc_redzone mm/kasan/common.c:398 [inline]\n __kasan_kmalloc+0x93/0xb0 mm/kasan/common.c:415\n kasan_kmalloc include/linux/kasan.h:263 [inline]\n __kmalloc_cache_noprof+0x3d1/0x6e0 mm/slub.c:5780\n kmalloc_noprof include/linux/slab.h:957 [inline]\n kzalloc_noprof include/linux/slab.h:1094 [inline]\n alloc_sk_msg net/core/skmsg.c:510 [inline]\n sk_psock_skb_ingress_self+0x60/0x350 net/core/skmsg.c:612\n sk_psock_verdict_apply net/core/skmsg.c:1038 [inline]\n sk_psock_verdict_recv+0x7d9/0x8d0 net/core/skmsg.c:1236\n udp_read_skb+0x73e/0x7e0 net/ipv4/udp.c:2045\n sk_psock_verdict_data_ready+0x12d/0x550 net/core/skmsg.c:1257\n __udp_enqueue_schedule_skb+0xc54/0x10b0 net/ipv4/udp.c:1789\n __udp_queue_rcv_skb net/ipv4/udp.c:2346 [inline]\n udp_queue_rcv_one_skb+0xac5/0x19c0 net/ipv4/udp.c:2475\n __udp4_lib_mcast_deliver+0xc06/0xcf0 net/ipv4/udp.c:2585\n __udp4_lib_rcv+0x10f6/0x2620 net/ipv4/udp.c:2724\n ip_protocol_deliver_rcu+0x282/0x440 net/ipv4/ip_input.c:207\n ip_local_deliver_finish+0x3bb/0x6f0 net/ipv4/ip_input.c:241\n NF_HOOK+0x336/0x3c0 include/linux/netfilter.h:318\n dst_input include/net/dst.h:474 [inline]\n ip_sublist_rcv_finish+0x221/0x2a0 net/ipv4/ip_input.c:584\n ip_list_rcv_finish net/ipv4/ip_inp\n---truncated---"}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["net/ipv4/udp_bpf.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"9f2470fbc4cb4583c080bb729a998933ba61aca4","lessThan":"81567d2b3f4dc4fc32f8b61433738bce2cafd4a1","versionType":"git","status":"affected"},{"version":"9f2470fbc4cb4583c080bb729a998933ba61aca4","lessThan":"39d44ed6904bfa9a1c6d0538672dd50c7b85520e","versionType":"git","status":"affected"},{"version":"9f2470fbc4cb4583c080bb729a998933ba61aca4","lessThan":"c010995b29c8939c6aa69e3cb26f8dbee163d156","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["net/ipv4/udp_bpf.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"5.14","status":"affected"},{"version":"0","lessThan":"5.14","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/39d44ed6904bfa9a1c6d0538672dd50c7b85520e","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/81567d2b3f4dc4fc32f8b61433738bce2cafd4a1","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/c010995b29c8939c6aa69e3cb26f8dbee163d156","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-74258","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:22:24.993","lastModified":"2026-08-15T06:22:24.993","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nbpf: Guard __get_user acesss with access_ok for uprobe_multi data\n\nAs reported by sashiko [1] we need to use access_ok to check the user\nspace data bounds before we use __get-user to get it.\n\n[1] https://lore.kernel.org/bpf/20260610145235.CB1441F00893@smtp.kernel.org/"}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["kernel/trace/bpf_trace.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"89ae89f53d201143560f1e9ed4bfa62eee34f88e","lessThan":"c6d51ad36490013ee9df94a372d3bf794bd304d1","versionType":"git","status":"affected"},{"version":"89ae89f53d201143560f1e9ed4bfa62eee34f88e","lessThan":"4d87a251d45b4a95eb4c0abcfab809c9f231258a","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["kernel/trace/bpf_trace.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.6","status":"affected"},{"version":"0","lessThan":"6.6","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/4d87a251d45b4a95eb4c0abcfab809c9f231258a","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/c6d51ad36490013ee9df94a372d3bf794bd304d1","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-74259","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:22:25.090","lastModified":"2026-08-15T06:22:25.090","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\ncifs: remove all cifs files before kill super\n\nCifs files may be put into fileinfo_put_wq during umounting cifs.\nAfter umount done, cifsFileInfo_put_final is called, which cause\nfollowing BUG:\n\nBUG: kernel NULL pointer dereference, address: 0000000000000000\n...\n[  134.222152]  list_lru_add+0x64/0x1a0\n[  134.222399]  ? cifs_put_tcon+0x171/0x340 [cifs]\n[  134.222772]  d_lru_add+0x44/0x60\n[  134.222997]  dput+0x1fc/0x210\n[  134.223213]  cifsFileInfo_put_final+0x11a/0x140 [cifs]\n[  134.223576]  process_one_work+0x17c/0x320\n[  134.223843]  worker_thread+0x188/0x280\n[  134.224084]  ? __pfx_worker_thread+0x10/0x10\n[  134.224366]  kthread+0xcc/0x100\n[  134.224576]  ? __pfx_kthread+0x10/0x10\n[  134.224827]  ret_from_fork+0x30/0x50\n[  134.225063]  ? __pfx_kthread+0x10/0x10\n[  134.225328]  ret_from_fork_asm+0x1b/0x30\n\nThis can be reproduce by following:\nunshare -n bash -c \"\nmkdir -p ${CIFS_MNT}\nip netns attach root 1\nip link add eth0 type veth peer veth0 netns root\nip link set eth0 up\nip -n root link set veth0 up\nip addr add 192.168.0.2/24 dev eth0\nip -n root addr add 192.168.0.1/24 dev veth0\nip route add default via 192.168.0.1 dev eth0\nip netns exec root sysctl net.ipv4.ip_forward=1\nip netns exec root iptables -t nat -A POSTROUTING -s 192.168.0.2 -o\n${DEV} -j MASQUERADE\nmount -t cifs ${CIFS_PATH} ${CIFS_MNT} -o\nvers=3.0,sec=ntlmssp,credentials=${CIFS_CRED},rsize=65536,wsize=65536,cache=none,echo_interval=1\ntouch ${CIFS_MNT}/a.txt\nip netns exec root iptables -t nat -D POSTROUTING -s 192.168.0.2 -o\n${DEV} -j MASQUERADE\n\"\numount ${CIFS_MNT}"}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["fs/smb/client/connect.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"708c276f516d27beaded7f372ac8111cee43926c","lessThan":"55fb9581986141659002264fdc75cef307811eb8","versionType":"git","status":"affected"},{"version":"0629a1a187e424373364d681b42b101894bdb548","lessThan":"4465ebe67d89345954bb3622b25dd13e06f9d367","versionType":"git","status":"affected"},{"version":"0e4b8faaaebe3137bec5723ef2b3cb0437fb38fd","lessThan":"3baedc9b2f53e6a6ac57b16fdff0f9b954d9ca71","versionType":"git","status":"affected"},{"version":"f655467a9973f964b267871e5fef533ad5014494","lessThan":"21303c4a2b7275e626c6b67de0f45f2d5b9bb3e7","versionType":"git","status":"affected"},{"version":"340cea84f691c5206561bb2e0147158fe02070be","lessThan":"7839f1817a0cb6c4ed5cfe25d04845c43380a129","versionType":"git","status":"affected"},{"version":"340cea84f691c5206561bb2e0147158fe02070be","lessThan":"6d9a4aaaa8b2612b5ef9d581e2f286a458b71ee1","versionType":"git","status":"affected"},{"version":"30afc6ea72cc6cf7c8d579e79b64232801c38d08","versionType":"git","status":"affected"},{"version":"6.1.167","lessThan":"6.1.178","versionType":"semver","status":"affected"},{"version":"6.6.130","lessThan":"6.6.145","versionType":"semver","status":"affected"},{"version":"6.12.78","lessThan":"6.12.97","versionType":"semver","status":"affected"},{"version":"6.18.20","lessThan":"6.18.40","versionType":"semver","status":"affected"},{"version":"6.19.10","lessThan":"6.20","versionType":"semver","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["fs/smb/client/connect.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"7.0","status":"affected"},{"version":"0","lessThan":"7.0","versionType":"semver","status":"unaffected"},{"version":"6.1.178","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.97","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/21303c4a2b7275e626c6b67de0f45f2d5b9bb3e7","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/3baedc9b2f53e6a6ac57b16fdff0f9b954d9ca71","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/4465ebe67d89345954bb3622b25dd13e06f9d367","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/55fb9581986141659002264fdc75cef307811eb8","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/6d9a4aaaa8b2612b5ef9d581e2f286a458b71ee1","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/7839f1817a0cb6c4ed5cfe25d04845c43380a129","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-74260","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:22:25.210","lastModified":"2026-08-15T06:22:25.210","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nnetfilter: nf_dup_netdev: add nf_dev_xmit_recursion*() helpers and use them\n\nUpdate nft_dup and nft_fwd to use the nf_dev_xmit_recursion() helpers.\nThis patch also disables BH when transmitting the skb to address a\npossible migration to different CPU leading to imbalanced decrementation\nof the recursion counters.\n\nThis is modeled after Florian Westphal's dev_xmit_recursion*() API\navailable since commit 97cdcf37b57e (\"net: place xmit recursion in\nsoftnet data\") according to its current state in the tree."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["include/net/netfilter/nf_dup_netdev.h","net/netfilter/nf_dup_netdev.c","net/netfilter/nft_fwd_netdev.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"f37ad91270397a6d053e8623bdb3cf79859691d2","lessThan":"edf234f71fb327792196f813048ab8f5bd3bb712","versionType":"git","status":"affected"},{"version":"f37ad91270397a6d053e8623bdb3cf79859691d2","lessThan":"2354e975932dabb06fad239f07a3b68fd1809737","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["include/net/netfilter/nf_dup_netdev.h","net/netfilter/nf_dup_netdev.c","net/netfilter/nft_fwd_netdev.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.16","status":"affected"},{"version":"0","lessThan":"6.16","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/2354e975932dabb06fad239f07a3b68fd1809737","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/edf234f71fb327792196f813048ab8f5bd3bb712","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-74261","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:22:25.307","lastModified":"2026-08-15T06:22:25.307","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nALSA: seq: avoid stale FIFO cells during resize\n\nsnd_seq_fifo_resize() still needs to publish the replacement pool\nbefore it waits for FIFO users. A blocking snd_seq_read() holds\nf->use_lock while it sleeps, so concurrent senders must be able to\nqueue to the new pool and wake that reader instead of failing against a\nclosing old pool.\n\nHowever, snd_seq_fifo_event_in() duplicates an event before it takes\nf->lock, and snd_seq_read() can dequeue a cell and later call\nsnd_seq_fifo_cell_putback() if copy_to_user() or\nsnd_seq_expand_var_event() fails. If resize swaps f->pool and detaches\noldhead in between, either path can relink an old-pool cell after the\nsnapshot. That stale cell sits outside the drained oldhead list, keeps\noldpool->counter elevated, and can leave snd_seq_pool_delete() waiting\nfor the retired pool to drain.\n\nKeep the existing swap-before-wait ordering in snd_seq_fifo_resize(),\nbut reject stale cells before any FIFO relink. Revalidate event-in cells\nunder f->lock and retry them against the published replacement pool, and\nfree stale putback cells instead of linking them back into the FIFO.\n\nThe buggy scenario involves two paths, with each column showing the\norder within that path:\n\nresize path:                    relink path:\n1. Allocate newpool.             1. Take f->use_lock.\n2. Swap f->pool to newpool and   2. Duplicate or dequeue an old-pool\n   detach oldhead.                  cell before oldpool closes.\n3. Mark oldpool closing and      3. Reach a later relink point after\n   wait for FIFO users.             resize published newpool.\n4. Free oldhead and delete       4. Relink the old-pool cell after\n   oldpool.                         resize detached oldhead.\n                                 5. Drop f->use_lock.\n\nThe reproducer reports a resize ioctl blocked in the expected pool\nteardown path:\n\nsignal: resize iteration=98 target_pool=4 exceeded 250ms\n        (elapsed=251ms)\ndiagnostic: resize_tid=651 wchan=snd_seq_pool_done\ndiagnostic: resize_tid=651 stack=\n  snd_seq_pool_done+0x5b/0x140\n  snd_seq_pool_delete+0x7a/0x90\n  snd_seq_fifo_resize+0x193/0x1e0\n  snd_seq_ioctl_set_client_pool+0x214/0x260\n  snd_seq_ioctl+0x119/0x540\n  __x64_sys_ioctl+0xd1/0x120\n  do_syscall_64+0xbb/0x2f0\n  entry_SYSCALL_64_after_hwframe+0x77/0x7f\n\nA second run with larger pools hit the same target path:\n\nsignal: resize iteration=32 target_pool=64 exceeded 250ms\n        (elapsed=251ms)\ndiagnostic: resize_tid=663 wchan=snd_seq_pool_done\ndiagnostic: resize_tid=663 stack=\n  snd_seq_pool_done+0x5b/0x140\n  snd_seq_pool_delete+0x7a/0x90\n  snd_seq_fifo_resize+0x193/0x1e0\n  snd_seq_ioctl_set_client_pool+0x214/0x260\n  snd_seq_ioctl+0x119/0x540\n  __x64_sys_ioctl+0xd1/0x120\n  do_syscall_64+0xbb/0x2f0\n  entry_SYSCALL_64_after_hwframe+0x77/0x7f"}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["sound/core/seq/seq_fifo.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"2d7d54002e396c180db0c800c1046f0a3c471597","lessThan":"98a965cb1e767b54b6bbd831b6cea26f521a8f51","versionType":"git","status":"affected"},{"version":"2d7d54002e396c180db0c800c1046f0a3c471597","lessThan":"1c4c35fb68d520241f7d9f1c356b5e2370fd8364","versionType":"git","status":"affected"},{"version":"2d7d54002e396c180db0c800c1046f0a3c471597","lessThan":"e546128291f8d688dcb931827e2efd2aa6c0734d","versionType":"git","status":"affected"},{"version":"df7a2d0af9f7ab73cf22a7b62bbc0bad93a02110","versionType":"git","status":"affected"},{"version":"28e0ebdd57cd3287ac821068364b74c70af3861c","versionType":"git","status":"affected"},{"version":"d4b8e8a32d74052fe292618ae19f794944ddc673","versionType":"git","status":"affected"},{"version":"e91325f27c4d98d1088e9e86b3ab475f752eeb80","versionType":"git","status":"affected"},{"version":"9ebfed203c0d93449a074c5c2fd5bb3e58518f0d","versionType":"git","status":"affected"},{"version":"3492352e1f34673708fa7409b4b1d97545aa2f1c","versionType":"git","status":"affected"},{"version":"a90d7447e4a154ad26e3b9e09a0878680be49339","versionType":"git","status":"affected"},{"version":"74a2c1ff88a4e0960623d17f7db56ac5a60bb0cf","versionType":"git","status":"affected"},{"version":"c36ef6467420f8982e6d4d6f93d0634a85a5ee45","versionType":"git","status":"affected"},{"version":"3.2.91","lessThan":"3.3","versionType":"semver","status":"affected"},{"version":"3.10.107","lessThan":"3.11","versionType":"semver","status":"affected"},{"version":"3.12.73","lessThan":"3.13","versionType":"semver","status":"affected"},{"version":"3.16.46","lessThan":"3.17","versionType":"semver","status":"affected"},{"version":"3.18.50","lessThan":"3.19","versionType":"semver","status":"affected"},{"version":"4.1.40","lessThan":"4.2","versionType":"semver","status":"affected"},{"version":"4.4.60","lessThan":"4.5","versionType":"semver","status":"affected"},{"version":"4.9.21","lessThan":"4.10","versionType":"semver","status":"affected"},{"version":"4.10.9","lessThan":"4.11","versionType":"semver","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["sound/core/seq/seq_fifo.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"4.11","status":"affected"},{"version":"0","lessThan":"4.11","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/1c4c35fb68d520241f7d9f1c356b5e2370fd8364","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/98a965cb1e767b54b6bbd831b6cea26f521a8f51","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/e546128291f8d688dcb931827e2efd2aa6c0734d","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-74262","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:22:25.450","lastModified":"2026-08-15T06:22:25.450","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nkcm: use WRITE_ONCE() when changing lower socket callbacks\n\nkcm_attach() replaces a live lower TCP socket's sk_data_ready and\nsk_write_space callbacks with KCM handlers, and kcm_unattach() restores\nthem later. Those callback-pointer updates are still plain stores even\nthough the same fields can be read and invoked concurrently on other\nCPUs.\n\nIf another CPU observes an older callback snapshot after the live field\nhas already been restored, callback execution can run with a mismatched\ntarget and sk_user_data state, leading to stale or misdirected wakeups.\n\nUse WRITE_ONCE() for the callback replacement and restore operations so\nthese shared callback fields follow the same visibility contract already\nestablished by the earlier 4022 fixes."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["net/kcm/kcmsock.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"ab7ac4eb9832e32a09f4e8042705484d2fb0aad3","lessThan":"0cb3e2f40679032c1aa2186280a86e5ead0161ee","versionType":"git","status":"affected"},{"version":"ab7ac4eb9832e32a09f4e8042705484d2fb0aad3","lessThan":"fa26e4606aed0f7fe793c325506adeda1d847a43","versionType":"git","status":"affected"},{"version":"ab7ac4eb9832e32a09f4e8042705484d2fb0aad3","lessThan":"b4ccd6eef671d7c44a30123cd29f3acf3de8468e","versionType":"git","status":"affected"},{"version":"ab7ac4eb9832e32a09f4e8042705484d2fb0aad3","lessThan":"b8c90823cdfb5f3d22f261aeb3e9066612853c36","versionType":"git","status":"affected"},{"version":"ab7ac4eb9832e32a09f4e8042705484d2fb0aad3","lessThan":"11faefd11ce2448bac7279ab302dd1954a6547fe","versionType":"git","status":"affected"},{"version":"ab7ac4eb9832e32a09f4e8042705484d2fb0aad3","lessThan":"f01fb6138f8eb606b56ce9158e2d8b72352c53f4","versionType":"git","status":"affected"},{"version":"ab7ac4eb9832e32a09f4e8042705484d2fb0aad3","lessThan":"9684fff87124b201e11dea01ded9173025359a0f","versionType":"git","status":"affected"},{"version":"ab7ac4eb9832e32a09f4e8042705484d2fb0aad3","lessThan":"47186409c092cd7dd70350999186c700233e854d","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["net/kcm/kcmsock.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"4.6","status":"affected"},{"version":"0","lessThan":"4.6","versionType":"semver","status":"unaffected"},{"version":"5.10.261","lessThanOrEqual":"5.10.*","versionType":"semver","status":"unaffected"},{"version":"5.15.212","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.178","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.97","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/0cb3e2f40679032c1aa2186280a86e5ead0161ee","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/11faefd11ce2448bac7279ab302dd1954a6547fe","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/47186409c092cd7dd70350999186c700233e854d","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/9684fff87124b201e11dea01ded9173025359a0f","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/b4ccd6eef671d7c44a30123cd29f3acf3de8468e","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/b8c90823cdfb5f3d22f261aeb3e9066612853c36","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/f01fb6138f8eb606b56ce9158e2d8b72352c53f4","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/fa26e4606aed0f7fe793c325506adeda1d847a43","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-74263","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:22:25.570","lastModified":"2026-08-15T06:22:25.570","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nnet: wwan: t7xx: check skb_clone in control TX\n\nt7xx_port_ctrl_tx() clones each skb fragment before passing it to the\nport transmit path. The clone is used immediately to set cloned->len, so\nan skb_clone() failure results in a NULL pointer dereference.\n\nCheck the clone before using it. If previous fragments were already\nqueued, preserve the driver's existing partial-write behavior by\nreturning the number of bytes submitted so far."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/net/wwan/t7xx/t7xx_port_wwan.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"36bd28c1cb0dbf48645cfe43159907fb3253b33a","lessThan":"7edd4db82f9429591de10be4c904c817f12ba029","versionType":"git","status":"affected"},{"version":"36bd28c1cb0dbf48645cfe43159907fb3253b33a","lessThan":"112490467586146d323cb7230b1d72137e36900c","versionType":"git","status":"affected"},{"version":"36bd28c1cb0dbf48645cfe43159907fb3253b33a","lessThan":"f7aebaee2961bfcb86f282202d3dbd9b69db1a7c","versionType":"git","status":"affected"},{"version":"36bd28c1cb0dbf48645cfe43159907fb3253b33a","lessThan":"4c1b25d85f4c9a0f85f3f8c39988ad266a3f3095","versionType":"git","status":"affected"},{"version":"36bd28c1cb0dbf48645cfe43159907fb3253b33a","lessThan":"05f789fa90d95d5771230e78453cedff2486039d","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/net/wwan/t7xx/t7xx_port_wwan.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.4","status":"affected"},{"version":"0","lessThan":"6.4","versionType":"semver","status":"unaffected"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.97","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/05f789fa90d95d5771230e78453cedff2486039d","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/112490467586146d323cb7230b1d72137e36900c","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/4c1b25d85f4c9a0f85f3f8c39988ad266a3f3095","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/7edd4db82f9429591de10be4c904c817f12ba029","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/f7aebaee2961bfcb86f282202d3dbd9b69db1a7c","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-74264","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:22:25.670","lastModified":"2026-08-15T06:22:25.670","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nnet: watchdog: fix refcount tracking races\n\nBlamed commit converted the untracked dev_hold()/dev_put() calls\nin the watchdog code to use the tracked dev_hold_track()/dev_put_track()\n(which were later renamed/interfaced to netdev_hold() and netdev_put()).\n\nBy introducing dev->watchdog_dev_tracker to store the\nreference tracking information without adding synchronization\nbetween netdev_watchdog_up() and dev_watchdog(), it enabled the\nrace condition where this pointer could be overwritten or freed\nconcurrently, leading to the list corruption crash syzbot reported:\n\nlist_del corruption, ffff888114a18c00->next is NULL\n kernel BUG at lib/list_debug.c:52 !\nOops: invalid opcode: 0000 [#1] SMP KASAN PTI\nCPU: 1 UID: 0 PID: 91 Comm: kworker/u8:5 Not tainted syzkaller #0 PREEMPT(lazy)\nHardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 05/09/2026\nWorkqueue: events_unbound linkwatch_event\n RIP: 0010:__list_del_entry_valid_or_report.cold+0x22/0x2a lib/list_debug.c:52\nCall Trace:\n <TASK>\n  __list_del_entry_valid include/linux/list.h:132 [inline]\n  __list_del_entry include/linux/list.h:246 [inline]\n  list_move_tail include/linux/list.h:341 [inline]\n  ref_tracker_free+0x1a7/0x6c0 lib/ref_tracker.c:329\n  netdev_tracker_free include/linux/netdevice.h:4491 [inline]\n  netdev_put include/linux/netdevice.h:4508 [inline]\n  netdev_put include/linux/netdevice.h:4504 [inline]\n  netdev_watchdog_down net/sched/sch_generic.c:600 [inline]\n  dev_deactivate_many+0x28c/0xfe0 net/sched/sch_generic.c:1363\n  dev_deactivate+0x109/0x1d0 net/sched/sch_generic.c:1397\n  linkwatch_do_dev net/core/link_watch.c:184 [inline]\n  linkwatch_do_dev+0xd3/0x120 net/core/link_watch.c:166\n  __linkwatch_run_queue+0x3a5/0x810 net/core/link_watch.c:240\n  linkwatch_event+0x8f/0xc0 net/core/link_watch.c:314\n  process_one_work+0xa0e/0x1980 kernel/workqueue.c:3314\n  process_scheduled_works kernel/workqueue.c:3397 [inline]\n  worker_thread+0x5ef/0xe50 kernel/workqueue.c:3478\n  kthread+0x370/0x450 kernel/kthread.c:436\n  ret_from_fork+0x69a/0xc80 arch/x86/kernel/process.c:158\n  ret_from_fork_asm+0x1a/0x30 arch/x86/entry/entry_64.S:245\n\nThis patch has three coordinated parts:\n\n1) Add dev->watchdog_lock and dev->watchdog_ref_held to serialize watchdog operations.\n\n2) Remove netdev_watchdog_up() call from netif_carrier_on():\n   This ensures netdev_watchdog_up() is only called from process/BH context\n   (via linkwatch workqueue dev_activate()), allowing us to use\n   spin_lock_bh() for synchronization.\n\n3) Synchronize watchdog up and watchdog timer:\n   Protect netdev_watchdog_up() with tx_global_lock and watchdog_lock.\n   Only allocate a new tracker in netdev_watchdog_up() if one is\n   not already present.\n   In dev_watchdog(), ensure we don't release the tracker if the\n   timer was rescheduled either by dev_watchdog() itself or concurrently\n   by netdev_watchdog_up()."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["include/linux/netdevice.h","net/core/dev.c","net/sched/sch_generic.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"f12bf6f3f942b37de65eeea8be25903587fec930","lessThan":"446fe8ce699ce0a4d702f7b0fcdb50de340b9260","versionType":"git","status":"affected"},{"version":"f12bf6f3f942b37de65eeea8be25903587fec930","lessThan":"7ce2b00ff058ec4cafc9b447e1f0a6d6f49275d9","versionType":"git","status":"affected"},{"version":"f12bf6f3f942b37de65eeea8be25903587fec930","lessThan":"8eed5519e496b7a07f441a0f579cb228a33189f7","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["include/linux/netdevice.h","net/core/dev.c","net/sched/sch_generic.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"5.17","status":"affected"},{"version":"0","lessThan":"5.17","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/446fe8ce699ce0a4d702f7b0fcdb50de340b9260","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/7ce2b00ff058ec4cafc9b447e1f0a6d6f49275d9","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/8eed5519e496b7a07f441a0f579cb228a33189f7","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-74265","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:22:25.803","lastModified":"2026-08-15T06:22:25.803","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nnet: mana: initialize gdma queue id to INVALID_QUEUE_ID\n\nmana_gd_create_mana_wq_cq() leaves queue->id as 0 (from kzalloc_obj())\nuntil mana_create_wq_obj() assigns the firmware-returned id. If creation\nfails before that, cleanup calls mana_gd_destroy_cq() with id 0, NULLing\ngc->cq_table[0] and silently breaking whichever real CQ owns that slot.\n\nInitialize queue->id to INVALID_QUEUE_ID right after allocation, matching\nmana_gd_create_eq(). The existing (id >= max_num_cqs) guard then\nshort-circuits cleanly."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/net/ethernet/microsoft/mana/gdma_main.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"ca9c54d2d6a5ab2430c4eda364c77125d62e5e0f","lessThan":"372e7318af379eee29ab6e60848ce7d7db76c85a","versionType":"git","status":"affected"},{"version":"ca9c54d2d6a5ab2430c4eda364c77125d62e5e0f","lessThan":"c6662f3ad1c7c3549a1c39545651833220b0de89","versionType":"git","status":"affected"},{"version":"ca9c54d2d6a5ab2430c4eda364c77125d62e5e0f","lessThan":"8e52a247d9aa979d43eb9ff1e445b9b3bf229d4d","versionType":"git","status":"affected"},{"version":"ca9c54d2d6a5ab2430c4eda364c77125d62e5e0f","lessThan":"a493cbb6b11acd4adc93397a4b12bd460d47620d","versionType":"git","status":"affected"},{"version":"ca9c54d2d6a5ab2430c4eda364c77125d62e5e0f","lessThan":"62ce489acb428a936bdf243e7b92b3eb341447cf","versionType":"git","status":"affected"},{"version":"ca9c54d2d6a5ab2430c4eda364c77125d62e5e0f","lessThan":"150590d9ab0dbeb0087193058363819d4c82a00f","versionType":"git","status":"affected"},{"version":"ca9c54d2d6a5ab2430c4eda364c77125d62e5e0f","lessThan":"5985474e1cb4034680fac2145497a94b0860be50","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/net/ethernet/microsoft/mana/gdma_main.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"5.13","status":"affected"},{"version":"0","lessThan":"5.13","versionType":"semver","status":"unaffected"},{"version":"5.15.212","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.178","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.97","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/150590d9ab0dbeb0087193058363819d4c82a00f","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/372e7318af379eee29ab6e60848ce7d7db76c85a","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/5985474e1cb4034680fac2145497a94b0860be50","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/62ce489acb428a936bdf243e7b92b3eb341447cf","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/8e52a247d9aa979d43eb9ff1e445b9b3bf229d4d","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/a493cbb6b11acd4adc93397a4b12bd460d47620d","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/c6662f3ad1c7c3549a1c39545651833220b0de89","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-74266","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:22:25.920","lastModified":"2026-08-15T06:22:25.920","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nnet/sched: sch_dualpi2: Do not call qdisc_tree_reduce_backlog during peek before restoring qlen\n\nWhenever dualpi2 drops packets during peek, it calls\nqdisc_tree_reduce_backlog. An issue arises because it calls\nqdisc_tree_reduce_backlog before it reincrements the qlen. If qlen drops\nto zero, but peek returns an skb, the parent's qlen_notify callback will be\nexecuted even though dualpi2 still has 1 packet on the queue and, thus,\nmistakenly deactivates the parent's class which leads to a null-ptr-deref:\n\n[  101.427314][  T599] Oops: general protection fault, probably for non-canonical address 0xdffffc0000000009: 0000 [#1] SMP KASAN NOPTI\n[  101.427755][  T599] KASAN: null-ptr-deref in range [0x0000000000000048-0x000000000000004f]\n[  101.428048][  T599] CPU: 2 UID: 0 PID: 599 Comm: ping Not tainted 7.1.0-rc5-00284-gbce53c430ed7 #102 PREEMPT(full)\n[  101.428400][  T599] Hardware name: Bochs Bochs, BIOS Bochs 01/01/2011\n[  101.428608][  T599] RIP: 0010:qfq_dequeue (net/sched/sch_qfq.c:1150) sch_qfq\n[  101.428821][  T599] Code: 00 fc ff df 80 3c 02 00 0f 85 46 0c 00 00 4c 8d 73 48 48 89 9d b8 02 00 00 48 b8 00 00 00 00 00 fc ff df 4c 89 f2 48 c1 ea 03 <80> 3c 02 00 0f 85 2d 0c 00 00 48 b8 00 00 00 00 00 fc ff df 4c 8b\nAll code\n[  101.429348][  T599] RSP: 0018:ffff8881110df4f0 EFLAGS: 00010216\n[  101.429541][  T599] RAX: dffffc0000000000 RBX: 0000000000000000 RCX: dffffc0000000000\n[  101.429763][  T599] RDX: 0000000000000009 RSI: 00000024c0000000 RDI: ffff88811436c2b0\n[  101.429985][  T599] RBP: ffff88811436c000 R08: ffff88811436c280 R09: 1ffff11021277523\n[  101.430206][  T599] R10: 1ffff11021277526 R11: 1ffff11021277527 R12: 00000024c0000000\n[  101.430423][  T599] R13: ffff88811436c2b8 R14: 0000000000000048 R15: 0000000020000000\n[  101.430642][  T599] FS:  00007f61813e1c40(0000) GS:ffff8881691ef000(0000) knlGS:0000000000000000\n[  101.430913][  T599] CS:  0010 DS: 0000 ES: 0000 CR0: 0000000080050033\n[  101.431100][  T599] CR2: 00005651650850a8 CR3: 000000010ca0b000 CR4: 0000000000750ef0\n[  101.431320][  T599] PKRU: 55555554\n[  101.431433][  T599] Call Trace:\n[  101.431544][  T599]  <TASK>\n[  101.431628][  T599]  __qdisc_run (net/sched/sch_generic.c:322 net/sched/sch_generic.c:427 net/sched/sch_generic.c:445)\n[  101.431792][  T599]  ? dev_qdisc_enqueue (./include/trace/events/qdisc.h:49 (discriminator 22) net/core/dev.c:4176 (discriminator 22))\n[  101.431941][  T599]  __dev_queue_xmit (./include/net/pkt_sched.h:120 ./include/net/pkt_sched.h:117 net/core/dev.c:4292 net/core/dev.c:4831)\n\nFix this by only calling qdisc_tree_reduce_backlog in peek after the\nqlen is restored."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["net/sched/sch_dualpi2.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"8f9516daedd67097a0c6e463fcb7a42b5ee9d477","lessThan":"bd851b10daee7199a658458b8ce250e95a334500","versionType":"git","status":"affected"},{"version":"8f9516daedd67097a0c6e463fcb7a42b5ee9d477","lessThan":"466f29477cae2bd1982a066d518a9b20c5a37924","versionType":"git","status":"affected"},{"version":"8f9516daedd67097a0c6e463fcb7a42b5ee9d477","lessThan":"15cd0c93bf4f892d66bc7a93667e2357b5673365","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["net/sched/sch_dualpi2.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.17","status":"affected"},{"version":"0","lessThan":"6.17","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/15cd0c93bf4f892d66bc7a93667e2357b5673365","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/466f29477cae2bd1982a066d518a9b20c5a37924","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/bd851b10daee7199a658458b8ce250e95a334500","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-74267","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:22:26.030","lastModified":"2026-08-15T06:22:26.030","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nnet/sched: sch_codel: Do not call qdisc_tree_reduce_backlog during peek before restoring qlen\n\nWhenever codel drops packets during peek, it calls\nqdisc_tree_reduce_backlog. An issue arises because it calls\nqdisc_tree_reduce_backlog before it reincrements the qlen. If qlen drops\nto zero, but peek returns an skb, the parent's qlen_notify callback will\nbe executed even though codel still has 1 packet on the queue and, thus,\nwill mistakenly deactivate the parent's class causing issues like a wild\nmemory access when qfq has codel as a child:\n\n[   36.339843][  T370] Oops: general protection fault, probably for non-canonical address 0xfbd59c0000000024: 0000 [#1] SMP KASAN NOPTI\n[   36.340408][  T370] KASAN: maybe wild-memory-access in range [0xdead000000000120-0xdead000000000127]\n[   36.340737][  T370] CPU: 2 UID: 0 PID: 370 Comm: tc Not tainted 7.1.0-rc5-00287-g66e13b626592 #87 PREEMPT(full)\n[   36.341113][  T370] Hardware name: Bochs Bochs, BIOS Bochs 01/01/2011\n[   36.341357][  T370] RIP: 0010:qfq_deactivate_agg (include/linux/list.h:1029 (discriminator 2) include/linux/list.h:1043 (discriminator 2) net/sched/sch_qfq.c:1369 (discriminator 2) net/sched/sch_qfq.c:1395 (discriminator 2)) sch_qfq\n[   36.342221][  T370] RSP: 0018:ffff8881100ef370 EFLAGS: 00010216\n[   36.342422][  T370] RAX: 0000000000000000 RBX: ffff8881058a9568 RCX: dffffc0000000000\n[   36.342664][  T370] RDX: 1ffff11021064dc3 RSI: ffff888108326e00 RDI: dffffc0000000000\n[   36.342905][  T370] RBP: ffff8881058a8280 R08: dead000000000122 R09: 1bd5a00000000024\n[   36.343140][  T370] R10: fffffbfff2940329 R11: fffffbfff2940329 R12: 0000000000000000\n[   36.343383][  T370] R13: dead000000000100 R14: ffff8881058a9580 R15: ffff8881058a9578\n[   36.343631][  T370] FS:  00007fc04b0ca780(0000) GS:ffff888184fef000(0000) knlGS:0000000000000000\n[   36.343911][  T370] CS:  0010 DS: 0000 ES: 0000 CR0: 0000000080050033\n[   36.344116][  T370] CR2: 0000557c02c02000 CR3: 000000010e0ba000 CR4: 0000000000750ef0\n[   36.344359][  T370] PKRU: 55555554\n[   36.344481][  T370] Call Trace:\n...\n[   36.345054][  T370] qfq_reset_qdisc (net/sched/sch_qfq.c:357 net/sched/sch_qfq.c:1487) sch_qfq\n[   36.345222][  T370]  qdisc_reset (net/sched/sch_generic.c:1057)\n[   36.345503][  T370]  __qdisc_destroy (net/sched/sch_generic.c:1096)\n[   36.345677][  T370]  qdisc_graft (net/sched/sch_api.c:1062 net/sched/sch_api.c:1053 net/sched/sch_api.c:1159)\n[   36.346335][  T370]  tc_get_qdisc (net/sched/sch_api.c:1528 net/sched/sch_api.c:1556)\n\nFix this by only calling qdisc_tree_reduce_backlog in peek after the\nqlen is restored."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["net/sched/sch_codel.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"cc71a757da78dd4aa1b4a9b19cb011833730ccf2","lessThan":"bb9cfd874ee884117b33e92a002b9a45b48202f4","versionType":"git","status":"affected"},{"version":"eda741fe155ddf5ecd2dd3bfbd4fc3c0c7dbb450","lessThan":"7a05af7f58566682b73578b72ca8e53a268c43bd","versionType":"git","status":"affected"},{"version":"829c49b6b2ff45b043739168fd1245e4e1a91a30","lessThan":"eba49fd85995a3851c597fa2d214f8d21736e1d8","versionType":"git","status":"affected"},{"version":"2f9761a94bae33d26e6a81b31b36e7d776d93dc1","lessThan":"e8c6dbadf139cb14ea6ed14add6ed6e88504dedd","versionType":"git","status":"affected"},{"version":"4d55144b12e742404bb3f8fee6038bafbf45619d","lessThan":"e4615aa6bb7802944ae790cb4b3ef8c1b7491af3","versionType":"git","status":"affected"},{"version":"342debc12183b51773b3345ba267e9263bdfaaef","lessThan":"755108bb7a5083e911294c416cfea605dc75632f","versionType":"git","status":"affected"},{"version":"342debc12183b51773b3345ba267e9263bdfaaef","lessThan":"91e0a793a72374c20ab31a40ccec21373e82e973","versionType":"git","status":"affected"},{"version":"342debc12183b51773b3345ba267e9263bdfaaef","lessThan":"52f1da34c9f4d5bdc1e8b44242da5c7ba8db85f3","versionType":"git","status":"affected"},{"version":"7a742a9506849d1c1aa71e36c89855ceddc7d58e","versionType":"git","status":"affected"},{"version":"e73c838c80dccb9e4f19becc11d9f3cb4a27d483","versionType":"git","status":"affected"},{"version":"a57fe60ef4cf96bfbb6b58397ec28bdb5a5c6b31","versionType":"git","status":"affected"},{"version":"5.10.241","lessThan":"5.10.261","versionType":"semver","status":"affected"},{"version":"5.15.190","lessThan":"5.15.212","versionType":"semver","status":"affected"},{"version":"6.1.135","lessThan":"6.1.178","versionType":"semver","status":"affected"},{"version":"6.6.88","lessThan":"6.6.145","versionType":"semver","status":"affected"},{"version":"6.12.24","lessThan":"6.12.97","versionType":"semver","status":"affected"},{"version":"5.4.297","lessThan":"5.5","versionType":"semver","status":"affected"},{"version":"6.13.12","lessThan":"6.14","versionType":"semver","status":"affected"},{"version":"6.14.3","lessThan":"6.15","versionType":"semver","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["net/sched/sch_codel.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.15","status":"affected"},{"version":"0","lessThan":"6.15","versionType":"semver","status":"unaffected"},{"version":"5.10.261","lessThanOrEqual":"5.10.*","versionType":"semver","status":"unaffected"},{"version":"5.15.212","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.178","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.97","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/52f1da34c9f4d5bdc1e8b44242da5c7ba8db85f3","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/755108bb7a5083e911294c416cfea605dc75632f","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/7a05af7f58566682b73578b72ca8e53a268c43bd","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/91e0a793a72374c20ab31a40ccec21373e82e973","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/bb9cfd874ee884117b33e92a002b9a45b48202f4","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/e4615aa6bb7802944ae790cb4b3ef8c1b7491af3","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/e8c6dbadf139cb14ea6ed14add6ed6e88504dedd","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/eba49fd85995a3851c597fa2d214f8d21736e1d8","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-74268","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:22:26.183","lastModified":"2026-08-15T06:22:26.183","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\ntcp: clear sock_ops cb flags before force-closing a child socket\n\nA child socket inherits the listener's bpf_sock_ops_cb_flags via\nsk_clone_lock(). If its setup fails in tcp_v4_syn_recv_sock() /\ntcp_v6_syn_recv_sock(), the child is freed through put_and_exit, where\ninet_csk_prepare_forced_close() drops the socket lock and tcp_done() runs\nwithout it.\n\nIf BPF_SOCK_OPS_STATE_CB_FLAG was inherited, tcp_done() -> tcp_set_state()\ncalls tcp_call_bpf(), which expects the lock and trips sock_owned_by_me():\n\n  WARNING: include/net/sock.h:1799 at tcp_set_state+0x433/0x550\n  RIP: 0010:tcp_set_state+0x433/0x550 include/net/sock.h:1799\n  Call Trace:\n   <IRQ>\n   tcp_done+0xba/0x250 net/ipv4/tcp.c:5095\n   tcp_v4_syn_recv_sock+0x850/0xa50 net/ipv4/tcp_ipv4.c:1787\n   tcp_check_req+0xf30/0x1360 net/ipv4/tcp_minisocks.c:926\n   tcp_v4_rcv+0x1047/0x1b50 net/ipv4/tcp_ipv4.c:2164\n   </IRQ>\n\nThe child is freed before it is ever established, so it should run no\nsock_ops callback. Clear its cb flags in inet_csk_prepare_for_destroy_sock(),\nthe common point for the IPv4, IPv6 and chtls forced-close paths and for the\nMPTCP ->syn_recv_sock() failure path (dispose_child), which reaches tcp_done()\non a child that was never established too."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["include/net/tcp.h","net/ipv4/inet_connection_sock.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"d44874910a26f3a8f81edf873a2473363f07f660","lessThan":"ce311bd2e36596f0aa2c92ca86fb3e019ac57eae","versionType":"git","status":"affected"},{"version":"d44874910a26f3a8f81edf873a2473363f07f660","lessThan":"8874dafc9099bc49c2e5ebba030f85d276421f92","versionType":"git","status":"affected"},{"version":"d44874910a26f3a8f81edf873a2473363f07f660","lessThan":"990348e5bb457697c2f1f7f7b65154a3334d9d2b","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["include/net/tcp.h","net/ipv4/inet_connection_sock.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"4.16","status":"affected"},{"version":"0","lessThan":"4.16","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/8874dafc9099bc49c2e5ebba030f85d276421f92","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/990348e5bb457697c2f1f7f7b65154a3334d9d2b","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/ce311bd2e36596f0aa2c92ca86fb3e019ac57eae","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-74269","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:22:26.280","lastModified":"2026-08-15T06:22:26.280","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nbnxt: fix head underflow on XDP head-grow\n\nThe xdp.py test test_xdp_native_adjst_head_grow_data crashes when run on\na bnxt machine (and also crashes in NIPA).\n\nIt seems that the bug is an underflow in bnxt_rx_multi_page_skb, which\nbuilds the skb head:\n\n  napi_build_skb(data_ptr - bp->rx_offset, rxr->rx_page_size);\n\nThe problem with this expression is that in page mode, rx_offset is:\n\n  bp->rx_offset = NET_IP_ALIGN + XDP_PACKET_HEADROOM;\n\nWhich evaluates (at least on x86_64) to 258.\n\nThe test test_xdp_native_adjst_head_grow_data tests a case where the\nhead is adjusted by -256.\n\nWhen this test runs, data_ptr is shifted to frag_start + 2 (where\nfrag_start = page_address(page) + offset).\n\nThen, bnxt_rx_multi_page_skb is invoked and the napi_build_skb\nexpression subtracts 258, landing at an address before frag_start. This\ncould be either the previous fragment or the previous physical page when\nthe offset is < 256 (e.g. if the fragment started at offset 0).\n\nWhen the skb is freed, the page pool fragment reference is dropped on\neither the wrong page or the wrong frag of the right page. In either\ncase, the corrupted reference count can lead to the page being\nprematurely recycled while still in use. Once (incorrectly) recycled, it\ncan be handed out again and on driver teardown this would result in a\ndouble free.\n\nThe commit under fixes updated this code to handle the case where the\nnative page size is >= 64k, but it unintentionally broke the head grow\ncase.\n\nTo fix this, add an offset field to struct bnxt_sw_rx_bd, mirroring the\nexisting offset field in struct bnxt_sw_rx_agg_bd. Populate it on\nallocation and preserve it on reuse.\n\nIn bnxt_rx_multi_page_skb, use the newly added offset field to compute\nthe fragment start and pass that to napi_build_skb. Adjust the layout\nwith skb_reserve.\n\nThere are two cases, the non-adjustment case and the adjustment case.\n\nIn both cases, the skb is built at page_address(page) + offset to\naccount for the case where the native page size >= 64K and skb_reserve\nis called with data_ptr - (page_address(page) + offset). That\ndifference equals bp->rx_offset when data_ptr was not moved, or\nbp->rx_offset + xdp_adjust when XDP adjusted the head.\n\nRe-running the failing test with this commit applied causes the test to\nrun successfully to completion.\n\nThe other rx_skb_func implementations don't have this issue."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/net/ethernet/broadcom/bnxt/bnxt.c","drivers/net/ethernet/broadcom/bnxt/bnxt.h"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"f6974b4c2d8e1062b5a52228ee47293c15b4ee1e","lessThan":"bb72b1c6755631c74b7e0878ee55bb81c06776c0","versionType":"git","status":"affected"},{"version":"f6974b4c2d8e1062b5a52228ee47293c15b4ee1e","lessThan":"e26657fe3b85c068b01f42bb0c602f242d643ba9","versionType":"git","status":"affected"},{"version":"e9f11bfc03fb0d3c86f91b8ae945bb10f7e19c16","versionType":"git","status":"affected"},{"version":"ae0e135dc900827687ecc684c2bbb57aae48d318","versionType":"git","status":"affected"},{"version":"6.1.45","lessThan":"6.2","versionType":"semver","status":"affected"},{"version":"6.4.10","lessThan":"6.5","versionType":"semver","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/net/ethernet/broadcom/bnxt/bnxt.c","drivers/net/ethernet/broadcom/bnxt/bnxt.h"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.5","status":"affected"},{"version":"0","lessThan":"6.5","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/bb72b1c6755631c74b7e0878ee55bb81c06776c0","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/e26657fe3b85c068b01f42bb0c602f242d643ba9","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-74270","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:22:26.390","lastModified":"2026-08-15T06:22:26.390","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nhandshake: Require admin permission for DONE command\n\nACCEPT and DONE are the two downcalls of the handshake genl\nfamily, both intended for use by the trusted handshake agent\n(tlshd). ACCEPT already requires GENL_ADMIN_PERM; DONE has\nno privilege check at all.\n\nThe fd-lookup in handshake_nl_done_doit() only confirms that\nsome pending handshake request exists for the supplied sockfd;\nit does not authenticate the sender. An unprivileged process\nthat guesses or observes a valid sockfd can therefore submit\na DONE with HANDSHAKE_A_DONE_STATUS == 0, leaving the kernel\nconsumer to proceed as if the handshake succeeded. A non-zero\nstatus on a forged DONE tears down a legitimate in-flight\nhandshake before tlshd can report its real result."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["Documentation/netlink/specs/handshake.yaml","net/handshake/genl.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"3b3009ea8abb713b022d94fba95ec270cf6e7eae","lessThan":"25fb53e43ec006ac69b9e825a7e8a11d63a6083e","versionType":"git","status":"affected"},{"version":"3b3009ea8abb713b022d94fba95ec270cf6e7eae","lessThan":"b6557f912509abe8e70223373dd7a44d1d4a0d6c","versionType":"git","status":"affected"},{"version":"3b3009ea8abb713b022d94fba95ec270cf6e7eae","lessThan":"67cec2f1eb9e58719d622e92e2278ceda72dbd85","versionType":"git","status":"affected"},{"version":"3b3009ea8abb713b022d94fba95ec270cf6e7eae","lessThan":"4dafc411948469277b276724c3b2b4408c02c04c","versionType":"git","status":"affected"},{"version":"3b3009ea8abb713b022d94fba95ec270cf6e7eae","lessThan":"81246a65303d9635266b1334490142caaf86a11f","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["Documentation/netlink/specs/handshake.yaml","net/handshake/genl.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.4","status":"affected"},{"version":"0","lessThan":"6.4","versionType":"semver","status":"unaffected"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.97","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/25fb53e43ec006ac69b9e825a7e8a11d63a6083e","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/4dafc411948469277b276724c3b2b4408c02c04c","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/67cec2f1eb9e58719d622e92e2278ceda72dbd85","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/81246a65303d9635266b1334490142caaf86a11f","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/b6557f912509abe8e70223373dd7a44d1d4a0d6c","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-74271","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:22:26.497","lastModified":"2026-08-15T06:22:26.497","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\npower: supply: core: fix supplied_from allocations\n\nIf dts property power-supplies has multiple values, then accessing to\npsy->supplied_from[i-1] in __power_supply_populate_supplied_from will\noverrun supplied_from array."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/power/supply/power_supply_core.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"f6e0b081fb300a4601b064346963cf6bb163f437","lessThan":"ae55e4bf18ee0c4c170797dd65e17dbdf644fcf2","versionType":"git","status":"affected"},{"version":"f6e0b081fb300a4601b064346963cf6bb163f437","lessThan":"23a29ee1d9de38b7d6226b27653bc736b28ff05a","versionType":"git","status":"affected"},{"version":"f6e0b081fb300a4601b064346963cf6bb163f437","lessThan":"fefc9dad30d545be288d50a0b10d00465015fcfe","versionType":"git","status":"affected"},{"version":"f6e0b081fb300a4601b064346963cf6bb163f437","lessThan":"d0503357653ee62188987a26baa2d7f3689f367e","versionType":"git","status":"affected"},{"version":"f6e0b081fb300a4601b064346963cf6bb163f437","lessThan":"14357ba006e1586e4b4e809c074b21baf0aa4c4b","versionType":"git","status":"affected"},{"version":"f6e0b081fb300a4601b064346963cf6bb163f437","lessThan":"ba61aed9a34671222d1149acfc2f0179a9ce7e80","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/power/supply/power_supply_core.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"3.10","status":"affected"},{"version":"0","lessThan":"3.10","versionType":"semver","status":"unaffected"},{"version":"6.1.178","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.97","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/14357ba006e1586e4b4e809c074b21baf0aa4c4b","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/23a29ee1d9de38b7d6226b27653bc736b28ff05a","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/ae55e4bf18ee0c4c170797dd65e17dbdf644fcf2","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/ba61aed9a34671222d1149acfc2f0179a9ce7e80","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/d0503357653ee62188987a26baa2d7f3689f367e","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/fefc9dad30d545be288d50a0b10d00465015fcfe","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-74272","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:22:26.597","lastModified":"2026-08-15T06:22:26.597","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\ncxl/region: Resolve region deletion races\n\nSungwoo noticed that the sysfs trigger to delete a region may try to delete\na region multiple times. It also has no exclusion relative to the kernel\nreleasing the region via CXL root device teardown.\n\nInstead of installing new cxl root devres actions per region, use the\nexisting root decoder unregistration event to remove all remaining regions.\nAn xarray of regions replaces a devres list of regions.\n\nThis handles 3 separate issues with the old approach:\n\n1/ sysfs users racing to delete the same region: no longer possible now\n   that the regions_lock is held over the lookup and deletion.\n\n2/ multiple actions triggering deletion of the same region: solved by\n   erasing regions while holding @regions_lock, and only proceeding on\n   successful erasure.\n\n3/ userspace racing devres_release_all() to trigger the devres not found\n   warning: solved by sysfs unregistration not requiring a release action"}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/cxl/core/core.h","drivers/cxl/core/port.c","drivers/cxl/core/region.c","drivers/cxl/cxl.h"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"779dd20cfb56c510f89877cca45529fa9f8bc450","lessThan":"be44c1c04f85d7b7ac1c597a30b443bbd346acbd","versionType":"git","status":"affected"},{"version":"779dd20cfb56c510f89877cca45529fa9f8bc450","lessThan":"4dd86ca99ffcc413cbf79063fd9956ef54e0ca91","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/cxl/core/core.h","drivers/cxl/core/port.c","drivers/cxl/core/region.c","drivers/cxl/cxl.h"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.0","status":"affected"},{"version":"0","lessThan":"6.0","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/4dd86ca99ffcc413cbf79063fd9956ef54e0ca91","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/be44c1c04f85d7b7ac1c597a30b443bbd346acbd","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-74273","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:22:26.697","lastModified":"2026-08-15T06:22:26.697","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\ncxl/region: Block region delete during region creation\n\nExpand the range lock, rename it \"regions_lock\", to disable region deletion\nin the critical period between construct_region() and attach_target(), as\nwell as the period between device_add() and registering the remove actions.\n\nOtherwise, userspace can confuse the kernel. It can violate the assumption\nthe region stays registered through the completion of cxl_add_to_region().\nIt can violate the assumption that devm_add_action_or_reset() is working\nwith a live 'struct cxl_region'.\n\nIt is ok for the region to disappear outside of those windows as that\nmirrors device hotplug flows where the proper locks are held."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/cxl/core/port.c","drivers/cxl/core/region.c","drivers/cxl/cxl.h"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"a32320b71f085f8d82afedcf285f1682c8c00aed","lessThan":"b0b6a9c65cb72c901fdcc6ae83d7afd70cdca1b8","versionType":"git","status":"affected"},{"version":"a32320b71f085f8d82afedcf285f1682c8c00aed","lessThan":"d91feb88692e81b00cd22f0125cfcd04970b4a0b","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/cxl/core/port.c","drivers/cxl/core/region.c","drivers/cxl/cxl.h"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.3","status":"affected"},{"version":"0","lessThan":"6.3","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/b0b6a9c65cb72c901fdcc6ae83d7afd70cdca1b8","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/d91feb88692e81b00cd22f0125cfcd04970b4a0b","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-74274","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:22:26.793","lastModified":"2026-08-15T06:22:26.793","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\ncxl/region: Fill first free targets[] slot during auto-discovery\n\nAny invalid endpoint decoder pointer in the target array of an active\nregion is not allowed by cxl driver. This means cxl driver always\nassumes the first p->nr_targets entries of the target array in an\nauto-assembly region are valid. However, there are scenarios that could\nleave NULL endpoint decoder pointer holes in the target array.\n\n1. When cxl_cancel_auto_attach() removes an endpoint decoder from a\n   target array, the target slot is set to NULL. If the removed endpoint\n   decoder is not the last element in the target array, the target array\n   will contain a NULL hole.\n\n2. When a auto-assembly region removes an assigned endpoint decoder, if\n   the removed endpoint decoder is not the last element in the target\n   array, always remains a NULL hole in the target array.\n\nWhen a NULL pointer hole exists in a region's target array, it\nintroduces two potential problems:\n1. Access an endpoint decoder via a NULL pointer. it always trigger\n   calltrace like that.\n    Oops: general protection fault, probably for non-canonical address 0xdffffc0000000008: 0000 [#1] SMP KASAN PTI\n    RIP: 0010:cxl_calc_interleave_pos+0x26/0x810 [cxl_core]\n    Call Trace:\n      <TASK>\n      cxl_region_attach+0xc50/0x2140 [cxl_core]\n      cxl_add_to_region+0x321/0x2330 [cxl_core]\n      discover_region+0x92/0x150 [cxl_port]\n      device_for_each_child+0xf3/0x170\n      cxl_port_probe+0x150/0x200 [cxl_port]\n      cxl_bus_probe+0x4f/0xa0 [cxl_core]\n      really_probe+0x1c8/0x960\n      __driver_probe_device+0x323/0x450\n      driver_probe_device+0x45/0x120\n      __device_attach_driver+0x15d/0x280\n      bus_for_each_drv+0x10f/0x190\n\n2. Not having enough valid endpoint decoders attached to an\n   auto-assembly region. if an auto-assembly region is created with lock\n   flag or assigned endpoint decoder with lock flag, which means\n   assigned endpoint decoder will not be reset during detaching, they\n   could re-attach to the auto-assembly region again. But cxl region\n   driver relies on p->nr_targets to verify whether the required number\n   of endpoint decoders has been attached, and NULL endpoint decoder\n   pointers are still counted in that case.\n\nTo fix above issues, adjust cxl_region_attach_auto() logic to find the\nfirst free target slot for endpoint decoder attachment, this ensures\nNULL holes in the target array are filled, rather than adding new\nendpoint decoders at the tail of the target array."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/cxl/core/region.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"2230c4bdc4120417799c74326ade3123da226d54","lessThan":"6fde3fcdfec438ba0df26e25a8ac7c3707211799","versionType":"git","status":"affected"},{"version":"2230c4bdc4120417799c74326ade3123da226d54","lessThan":"aa8a76711c15041ec1e42c3a74c15c2df0bd31f6","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/cxl/core/region.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.19","status":"affected"},{"version":"0","lessThan":"6.19","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/6fde3fcdfec438ba0df26e25a8ac7c3707211799","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/aa8a76711c15041ec1e42c3a74c15c2df0bd31f6","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-74275","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:22:26.897","lastModified":"2026-08-15T06:22:26.897","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\ncxl/region: Fix out-of-bounds access in cxl_cancel_auto_attach()\n\nIn cxl_cancel_auto_attach(), it assumes cxled->pos is a valid index for\naccessing p->targets[]. However, cxled->pos can be set to negative errno\nin cxl_region_sort_targets() if cxl_calc_interleave_pos() fails. This\ncauses the driver to use a negative index to access p->targets[],\nresulting in out-of-bounds access.\n\nFix it by walking p->targets[] instead of using cxled->pos directly."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/cxl/core/region.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"87805c32e6ad7b5ce2d9f7f47e76081857a4a335","lessThan":"44b2397eb67b7f728640989a22d062e41f94ab64","versionType":"git","status":"affected"},{"version":"87805c32e6ad7b5ce2d9f7f47e76081857a4a335","lessThan":"cbda6a2c2bec2a5fb30a2ce85baeab15b5fc7db3","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/cxl/core/region.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"7.1","status":"affected"},{"version":"0","lessThan":"7.1","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/44b2397eb67b7f728640989a22d062e41f94ab64","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/cbda6a2c2bec2a5fb30a2ce85baeab15b5fc7db3","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-74276","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:22:26.993","lastModified":"2026-08-15T06:22:26.993","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nspi: xilinx: use FIFO occupancy register to determine buffer size\n\nThe method the driver uses to determine the size of the FIFO has a\nproblem. What it currently does is this:\nIt stops the SPI hardware and writes to the TX FIFO register until TX\nFIFO FULL asserts in the status register. But the hardware does not only\nhave the FIFO, it also has a shift register which can hold a byte. This\ncan be seen, when writing a byte to the FIFO (while the SPI hardware is\nstopped,) the TX FIFO EMPTY is still empty. So, if we have a FIFO size\nof 16 for example, the current method returns a 17.\nThis is a problem, at least when using the driver in irq mode. The same\nsize determined for the TX FIFO is also assumed for the RX FIFO. When a\nSPI transaction wants to write the amount of the FIFO size or more\nbytes, the following happens, for example with 16 bytes FIFO size:\nThe driver stops the SPI hardware and writes 17 bytes to the TX FIFO and\nstarts the SPI hardware and goes sleep.\nThe hardware then shifts out 17 bytes (FIFO + shift register) and\nsimultaneously reads bytes into the RX FIFO, but it only has 16 places,\nso it looses one byte. Then TX FIFO empty asserts, wakes the driver\nagain, which has a fast path and reads 16 bytes from the RX FIFO, but\nbefore reading the last 17th byte (which is lost) it does this:\n\n\tsr = xspi->read_fn(xspi->regs + XSPI_SR_OFFSET);\n\tif (!(sr & XSPI_SR_RX_EMPTY_MASK)) {\n\t\txilinx_spi_rx(xspi);\n\t\trx_words--;\n\t}\n\nIt reads the status register and checks if the RX FIFO is not empty.\nBut it is empty in our case. So this check spins in a while loop\nforever locking the driver.\n\nThis patch fixes the logic to determine the FIFO size."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/spi/spi-xilinx.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"4c9a761402d780b86b9b068aba4ef8e29ed15e99","lessThan":"4ee65558a7fda463222f5edc631b6d7862218725","versionType":"git","status":"affected"},{"version":"4c9a761402d780b86b9b068aba4ef8e29ed15e99","lessThan":"e98f589d54068dfcc7da42d9b730e47b84e2991a","versionType":"git","status":"affected"},{"version":"4c9a761402d780b86b9b068aba4ef8e29ed15e99","lessThan":"1fc6a6c0cc7796b0c1cf4eec3f0720f422f09273","versionType":"git","status":"affected"},{"version":"4c9a761402d780b86b9b068aba4ef8e29ed15e99","lessThan":"dfab0d4698a642bab9b895e2e6d240838cfe2cc6","versionType":"git","status":"affected"},{"version":"4c9a761402d780b86b9b068aba4ef8e29ed15e99","lessThan":"d7ccd8736b67550eca746ed7fa39a36016ff114b","versionType":"git","status":"affected"},{"version":"4c9a761402d780b86b9b068aba4ef8e29ed15e99","lessThan":"1c9246a199e19b2fd36e94feed60e55f27103a4f","versionType":"git","status":"affected"},{"version":"4c9a761402d780b86b9b068aba4ef8e29ed15e99","lessThan":"d1944b71c18e7494756bff1a6f80c25be99eaecb","versionType":"git","status":"affected"},{"version":"4c9a761402d780b86b9b068aba4ef8e29ed15e99","lessThan":"47f3b5365536e8c38f264824ab15fdb74454e066","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/spi/spi-xilinx.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"4.0","status":"affected"},{"version":"0","lessThan":"4.0","versionType":"semver","status":"unaffected"},{"version":"5.10.261","lessThanOrEqual":"5.10.*","versionType":"semver","status":"unaffected"},{"version":"5.15.212","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.178","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.97","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/1c9246a199e19b2fd36e94feed60e55f27103a4f","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/1fc6a6c0cc7796b0c1cf4eec3f0720f422f09273","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/47f3b5365536e8c38f264824ab15fdb74454e066","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/4ee65558a7fda463222f5edc631b6d7862218725","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/d1944b71c18e7494756bff1a6f80c25be99eaecb","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/d7ccd8736b67550eca746ed7fa39a36016ff114b","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/dfab0d4698a642bab9b895e2e6d240838cfe2cc6","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/e98f589d54068dfcc7da42d9b730e47b84e2991a","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-74277","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:22:27.120","lastModified":"2026-08-15T06:22:27.120","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\niommu/dma-iommu: Fix wrong scatterlist length assignment in P2PDMA path\n\nIn iommu_dma_map_sg(), when handling PCI P2PDMA cases, the DMA length\nof the current scatterlist segment `s` is incorrectly assigned from the\nhead entry `sg->length` instead of the current entry `s->length`.\n\nThis typo causes all P2PDMA segments in the scatterlist to inherit the\nlength of the first segment, leading to corrupted DMA lengths for multi-\nsegment scatterlists.\n\nFix this by using `s->length` instead of `sg->length`."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/iommu/dma-iommu.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"a25e7962db0d79882c9d32fd2a67a02e79129c0e","lessThan":"8646f00ce021e49f4f05bc1d4060a0c27b25d0e1","versionType":"git","status":"affected"},{"version":"a25e7962db0d79882c9d32fd2a67a02e79129c0e","lessThan":"db50fb87015b955a5a0c155293b2dd40d63a3b9e","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/iommu/dma-iommu.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.16","status":"affected"},{"version":"0","lessThan":"6.16","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/8646f00ce021e49f4f05bc1d4060a0c27b25d0e1","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/db50fb87015b955a5a0c155293b2dd40d63a3b9e","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-74278","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:22:27.213","lastModified":"2026-08-15T06:22:27.213","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nALSA: seq: Fix kernel heap address leak in bounce_error_event()\n\nThe comment above bounce_error_event() documents that user clients\nshould receive SNDRV_SEQ_EVENT_BOUNCE with the original event embedded\nas variable-length data, while kernel clients should receive\nSNDRV_SEQ_EVENT_KERNEL_ERROR with a quoted kernel pointer.\n\nHowever, the implementation unconditionally uses\nSNDRV_SEQ_EVENT_KERNEL_ERROR with data.quote.event set to the raw\nstruct snd_seq_event pointer for all clients.  When a bounce error\nevent is delivered to a USER_CLIENT via snd_seq_read(), the kernel\nheap address in data.quote.event is exposed to userspace through\ncopy_to_user() in the fixed-length branch.\n\nThis is a distinct leak path from the one addressed by commit\n705dd6dcbc0e (\"ALSA: seq: Clear variable event pointer on read\"),\nwhich sanitizes data.ext.ptr in the variable-length branch of\nsnd_seq_read().  The bounce_error_event() leak uses fixed-length\nevents that take the else branch where no sanitization occurs.\n\nDifferentiate the bounce event by client type.  For USER_CLIENT,\nsend SNDRV_SEQ_EVENT_BOUNCE with SNDRV_SEQ_EVENT_LENGTH_VARIABLE\nand data.ext pointing to the original event.  The variable-length\npath in snd_seq_event_dup() copies the event data into chained\ncells, and snd_seq_expand_var_event() copies only the content --\nnever the pointer -- to userspace.  For KERNEL_CLIENT, keep the\nexisting SNDRV_SEQ_EVENT_KERNEL_ERROR behavior with the quoted\npointer."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["sound/core/seq/seq_clientmgr.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"93d260ce43a81df579c98bee92b91316df9c1c57","versionType":"git","status":"affected"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"dae23c545eb5a2be3b27a82fd0f611894fb8ab69","versionType":"git","status":"affected"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"0527a56cb327021cb73167cfddf0e49efa043500","versionType":"git","status":"affected"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"efc86691e4d8083d9e380ea95042c2cf679f65fd","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["sound/core/seq/seq_clientmgr.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"2.6.12","status":"affected"},{"version":"0","lessThan":"2.6.12","versionType":"semver","status":"unaffected"},{"version":"6.12.97","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/0527a56cb327021cb73167cfddf0e49efa043500","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/93d260ce43a81df579c98bee92b91316df9c1c57","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/dae23c545eb5a2be3b27a82fd0f611894fb8ab69","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/efc86691e4d8083d9e380ea95042c2cf679f65fd","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-74279","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:22:27.317","lastModified":"2026-08-15T06:22:27.317","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\ncrypto: cavium/cpt - fix DMA cleanup using wrong loop index\n\nThe sg_cleanup error path used list[i] instead of list[j] when unmapping\nDMA buffers, leaking successfully mapped entries and repeatedly unmapping\nthe failed one."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/crypto/cavium/cpt/cptvf_reqmanager.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"c694b233295b99c33dd5ac28aede9f171f5a6862","lessThan":"23c6174e48f66fc10b998b0acdb406cb0caf5c80","versionType":"git","status":"affected"},{"version":"c694b233295b99c33dd5ac28aede9f171f5a6862","lessThan":"23d3a7e896a1fe2d7a6bcb42f093948b79f8a198","versionType":"git","status":"affected"},{"version":"c694b233295b99c33dd5ac28aede9f171f5a6862","lessThan":"28141f95ae93b18f9bfde953cb787fcb151fb9da","versionType":"git","status":"affected"},{"version":"c694b233295b99c33dd5ac28aede9f171f5a6862","lessThan":"8afd1007ef79898a6e010eaade97097e49405fce","versionType":"git","status":"affected"},{"version":"c694b233295b99c33dd5ac28aede9f171f5a6862","lessThan":"3b8a1e1f4e4071a62b20374028744e8cc8310d48","versionType":"git","status":"affected"},{"version":"c694b233295b99c33dd5ac28aede9f171f5a6862","lessThan":"fb4d57b83356d4bd411b45ede3024e0ff42c9b5e","versionType":"git","status":"affected"},{"version":"c694b233295b99c33dd5ac28aede9f171f5a6862","lessThan":"d319b83b97b3585550d9ae592dfa78c755b6129e","versionType":"git","status":"affected"},{"version":"c694b233295b99c33dd5ac28aede9f171f5a6862","lessThan":"9dbf173bd32d5f81b005008b682bfb50aa093455","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/crypto/cavium/cpt/cptvf_reqmanager.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"4.11","status":"affected"},{"version":"0","lessThan":"4.11","versionType":"semver","status":"unaffected"},{"version":"5.10.261","lessThanOrEqual":"5.10.*","versionType":"semver","status":"unaffected"},{"version":"5.15.212","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.178","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.97","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/23c6174e48f66fc10b998b0acdb406cb0caf5c80","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/23d3a7e896a1fe2d7a6bcb42f093948b79f8a198","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/28141f95ae93b18f9bfde953cb787fcb151fb9da","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/3b8a1e1f4e4071a62b20374028744e8cc8310d48","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/8afd1007ef79898a6e010eaade97097e49405fce","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/9dbf173bd32d5f81b005008b682bfb50aa093455","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/d319b83b97b3585550d9ae592dfa78c755b6129e","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/fb4d57b83356d4bd411b45ede3024e0ff42c9b5e","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-74280","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:22:27.430","lastModified":"2026-08-15T06:22:27.430","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\ncrypto: marvell/octeontx - fix DMA cleanup using wrong loop index\n\nThe sg_cleanup path used list[i] instead of list[j] when unmapping DMA\nbuffers, leaking successfully mapped entries and repeatedly unmapping\nthe failed one."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/crypto/marvell/octeontx/otx_cptvf_reqmgr.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"10b4f09491bfeb0b298cb2f49df585510ee6189a","lessThan":"97f150ba3e372256eabb93bd80c2cf3740077fb5","versionType":"git","status":"affected"},{"version":"10b4f09491bfeb0b298cb2f49df585510ee6189a","lessThan":"8a0db9fad3c97e6447a92417cb95d7c55eaa9530","versionType":"git","status":"affected"},{"version":"10b4f09491bfeb0b298cb2f49df585510ee6189a","lessThan":"8d301e5a51173ba56ce4f632a2a33bf6b14b0fcf","versionType":"git","status":"affected"},{"version":"10b4f09491bfeb0b298cb2f49df585510ee6189a","lessThan":"ed374dbc70c10c4a864414b3d9c257faec8fd485","versionType":"git","status":"affected"},{"version":"10b4f09491bfeb0b298cb2f49df585510ee6189a","lessThan":"6c721a3e43344f8560ee4ef506fc1f72b4646dcd","versionType":"git","status":"affected"},{"version":"10b4f09491bfeb0b298cb2f49df585510ee6189a","lessThan":"5f99a396f706afc749448659d1565991330e4f71","versionType":"git","status":"affected"},{"version":"10b4f09491bfeb0b298cb2f49df585510ee6189a","lessThan":"acff30cfc0d72465b51b0bfdf019f1cb54e15314","versionType":"git","status":"affected"},{"version":"10b4f09491bfeb0b298cb2f49df585510ee6189a","lessThan":"7891c64c0520519782470ba29bac8a5761e295d8","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/crypto/marvell/octeontx/otx_cptvf_reqmgr.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"5.7","status":"affected"},{"version":"0","lessThan":"5.7","versionType":"semver","status":"unaffected"},{"version":"5.10.261","lessThanOrEqual":"5.10.*","versionType":"semver","status":"unaffected"},{"version":"5.15.212","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.178","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.97","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/5f99a396f706afc749448659d1565991330e4f71","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/6c721a3e43344f8560ee4ef506fc1f72b4646dcd","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/7891c64c0520519782470ba29bac8a5761e295d8","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/8a0db9fad3c97e6447a92417cb95d7c55eaa9530","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/8d301e5a51173ba56ce4f632a2a33bf6b14b0fcf","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/97f150ba3e372256eabb93bd80c2cf3740077fb5","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/acff30cfc0d72465b51b0bfdf019f1cb54e15314","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/ed374dbc70c10c4a864414b3d9c257faec8fd485","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-74281","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:22:27.547","lastModified":"2026-08-15T06:22:27.547","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\ntipc: reject inverted service ranges from peer bindings\n\ntipc_update_nametbl() inserts a binding advertised by a peer node using\nthe lower and upper service-range bounds taken directly from the wire,\nwithout checking that lower <= upper. The local bind path validates the\nordering (tipc_uaddr_valid()), but the name-distribution path does not.\n\nA binding with lower > upper is inserted at the far end of the\nservice-range rbtree (keyed on lower) where no lookup or withdrawal can\never match it (service_range_foreach_match() requires sr->lower <= end).\nThe publication, its service_range node and the augmented rbtree entry\nare then leaked for the lifetime of the namespace, and there is no\nper-peer cap equivalent to TIPC_MAX_PUBL on locally created bindings.\n\nReject inverted ranges in the network path as well. A peer node can\notherwise leak unbounded binding-table memory by sending PUBLICATION\nitems with lower > upper."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["net/tipc/name_distr.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"37922ea4a3105176357c8d565a9d982c4a08714a","lessThan":"cd1955f81bd8ebeef51b324989ac871ad1947fb6","versionType":"git","status":"affected"},{"version":"37922ea4a3105176357c8d565a9d982c4a08714a","lessThan":"f683200b83a0085d4e11abea8c1fdd9fdfb95b0b","versionType":"git","status":"affected"},{"version":"37922ea4a3105176357c8d565a9d982c4a08714a","lessThan":"f1715d92ee3095d9215b493a8603a81f646fcf61","versionType":"git","status":"affected"},{"version":"37922ea4a3105176357c8d565a9d982c4a08714a","lessThan":"581ef56e5c34d475056ce086dc2ba0e872ba6857","versionType":"git","status":"affected"},{"version":"37922ea4a3105176357c8d565a9d982c4a08714a","lessThan":"7e401233f9bb74a626e70698d0d62f3a94ac0676","versionType":"git","status":"affected"},{"version":"37922ea4a3105176357c8d565a9d982c4a08714a","lessThan":"973bf0ed896b9898668dbadb82ed849d7d573010","versionType":"git","status":"affected"},{"version":"37922ea4a3105176357c8d565a9d982c4a08714a","lessThan":"2afb648f7b99216c687db1f89739c995e1144153","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["net/tipc/name_distr.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"4.17","status":"affected"},{"version":"0","lessThan":"4.17","versionType":"semver","status":"unaffected"},{"version":"5.15.212","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.178","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.97","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/2afb648f7b99216c687db1f89739c995e1144153","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/581ef56e5c34d475056ce086dc2ba0e872ba6857","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/7e401233f9bb74a626e70698d0d62f3a94ac0676","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/973bf0ed896b9898668dbadb82ed849d7d573010","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/cd1955f81bd8ebeef51b324989ac871ad1947fb6","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/f1715d92ee3095d9215b493a8603a81f646fcf61","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/f683200b83a0085d4e11abea8c1fdd9fdfb95b0b","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-74282","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:22:27.660","lastModified":"2026-08-15T06:22:27.660","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\ntipc: prevent snt_unacked underflow on CONN_ACK\n\ntipc_sk_conn_proto_rcv() subtracts the peer-supplied connection ack count\nfrom the unsigned 16-bit send counter snt_unacked without checking that it\ndoes not exceed the number of messages actually outstanding:\n\n\ttsk->snt_unacked -= msg_conn_ack(hdr);\n\nmsg_conn_ack() is read straight from a received CONN_MANAGER/CONN_ACK\nmessage. If the ack count is larger than snt_unacked, the subtraction\nwraps to a near-maximum value, leaving tsk_conn_cong() permanently true\nand starving the connection of further transmits.\n\nValidate the ACK count at the start of the CONN_ACK block and drop the\nmessage if it acknowledges more messages than are outstanding. A peer (or,\nfor a local connection, the connected peer socket) can otherwise wedge a\nTIPC connection's send side by sending an oversized connection ack."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["net/tipc/socket.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"10724cc7bb7832b482df049c20fd824d928c5eaa","lessThan":"3388145d258cf2c4c98278e3987296007d30672e","versionType":"git","status":"affected"},{"version":"10724cc7bb7832b482df049c20fd824d928c5eaa","lessThan":"67e55b054bf8025658dc0e255057f2a6236416bd","versionType":"git","status":"affected"},{"version":"10724cc7bb7832b482df049c20fd824d928c5eaa","lessThan":"96f91b8ae1a489b3eca137e7acf42cf985fb8939","versionType":"git","status":"affected"},{"version":"10724cc7bb7832b482df049c20fd824d928c5eaa","lessThan":"47ed873e4ceda34098bd46d8e96b4bb13cad3a04","versionType":"git","status":"affected"},{"version":"10724cc7bb7832b482df049c20fd824d928c5eaa","lessThan":"b44bebdd32c9ff66ee2aebfc317ced44bedd9335","versionType":"git","status":"affected"},{"version":"10724cc7bb7832b482df049c20fd824d928c5eaa","lessThan":"3cfa3d8e0dc167850edeb5bf5a07757db83fd54e","versionType":"git","status":"affected"},{"version":"10724cc7bb7832b482df049c20fd824d928c5eaa","lessThan":"1e2c956745777e6ffdee7f30da5935741c03ee1e","versionType":"git","status":"affected"},{"version":"10724cc7bb7832b482df049c20fd824d928c5eaa","lessThan":"ab3e10b44ba5411779aac7afd2477917dd77750f","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["net/tipc/socket.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"4.7","status":"affected"},{"version":"0","lessThan":"4.7","versionType":"semver","status":"unaffected"},{"version":"5.10.261","lessThanOrEqual":"5.10.*","versionType":"semver","status":"unaffected"},{"version":"5.15.212","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.178","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.97","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/1e2c956745777e6ffdee7f30da5935741c03ee1e","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/3388145d258cf2c4c98278e3987296007d30672e","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/3cfa3d8e0dc167850edeb5bf5a07757db83fd54e","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/47ed873e4ceda34098bd46d8e96b4bb13cad3a04","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/67e55b054bf8025658dc0e255057f2a6236416bd","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/96f91b8ae1a489b3eca137e7acf42cf985fb8939","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/ab3e10b44ba5411779aac7afd2477917dd77750f","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/b44bebdd32c9ff66ee2aebfc317ced44bedd9335","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-74283","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:22:27.780","lastModified":"2026-08-15T06:22:27.780","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\ntipc: require net admin for TIPCv2 netlink mutators\n\nTIPCv2 registers mutating generic-netlink operations without admin\npermission flags. Generic netlink only checks CAP_NET_ADMIN when an\noperation sets GENL_ADMIN_PERM or GENL_UNS_ADMIN_PERM, so a local\nunprivileged process can currently change TIPC state through commands\nsuch as TIPC_NL_NET_SET, TIPC_NL_KEY_SET, TIPC_NL_KEY_FLUSH, and\nbearer enable/disable.\n\nThe legacy TIPC netlink API already checks netlink_net_capable(...,\nCAP_NET_ADMIN) for administrative commands. Give the TIPCv2 mutators\nthe equivalent generic-netlink gate. Use GENL_UNS_ADMIN_PERM, which\nmaps to the same namespace-aware CAP_NET_ADMIN check that\nnetlink_net_capable() performs, so the behaviour matches the legacy\npath and keeps working for CAP_NET_ADMIN holders in a non-initial user\nnamespace (containers).\n\nA QEMU/KASAN repro run as uid/gid 65534 with zero effective\ncapabilities previously succeeded in changing the network id and node\nidentity, setting and flushing key material, and enabling/disabling a\nUDP bearer. With this patch applied the same operations fail with\n-EPERM."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["net/tipc/netlink.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"0655f6a8635b1b66f2434d5556b1044c14b1ccaf","lessThan":"b06fb5f78a9af0929aaa47c92d0b7bca0617fb25","versionType":"git","status":"affected"},{"version":"0655f6a8635b1b66f2434d5556b1044c14b1ccaf","lessThan":"52864c6c13dcc292481eabfeb3c31a86c3ec06f2","versionType":"git","status":"affected"},{"version":"0655f6a8635b1b66f2434d5556b1044c14b1ccaf","lessThan":"e87dcc1a644d087de0bb6c94c6dd28c29b89597f","versionType":"git","status":"affected"},{"version":"0655f6a8635b1b66f2434d5556b1044c14b1ccaf","lessThan":"9b937de4b3ded62a24da6e8d9d623cdb2748fa74","versionType":"git","status":"affected"},{"version":"0655f6a8635b1b66f2434d5556b1044c14b1ccaf","lessThan":"c9668a4adb2264625daeeabc7466b783badd4614","versionType":"git","status":"affected"},{"version":"0655f6a8635b1b66f2434d5556b1044c14b1ccaf","lessThan":"cebaefe1aceb650d5c99a4c0e1a4dde09e211818","versionType":"git","status":"affected"},{"version":"0655f6a8635b1b66f2434d5556b1044c14b1ccaf","lessThan":"56f0a2e0a1d004e025cd031c3a801ab73959269f","versionType":"git","status":"affected"},{"version":"0655f6a8635b1b66f2434d5556b1044c14b1ccaf","lessThan":"86b0c540e2ea397cde021eecd24145f7c16a3d4e","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["net/tipc/netlink.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"3.19","status":"affected"},{"version":"0","lessThan":"3.19","versionType":"semver","status":"unaffected"},{"version":"5.10.261","lessThanOrEqual":"5.10.*","versionType":"semver","status":"unaffected"},{"version":"5.15.212","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.178","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.97","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/52864c6c13dcc292481eabfeb3c31a86c3ec06f2","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/56f0a2e0a1d004e025cd031c3a801ab73959269f","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/86b0c540e2ea397cde021eecd24145f7c16a3d4e","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/9b937de4b3ded62a24da6e8d9d623cdb2748fa74","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/b06fb5f78a9af0929aaa47c92d0b7bca0617fb25","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/c9668a4adb2264625daeeabc7466b783badd4614","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/cebaefe1aceb650d5c99a4c0e1a4dde09e211818","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/e87dcc1a644d087de0bb6c94c6dd28c29b89597f","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-74284","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:22:27.903","lastModified":"2026-08-15T06:22:27.903","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nnet/sched: sch_hfsc: Don't make class passive twice\n\nupdate_vf() is called from two places for the same class during a single\ndequeue when the class's child qdisc (e.g. codel/fq_codel) drops its last\npackets while dequeuing:\n\n1. The child calls qdisc_tree_reduce_backlog(), which, now that the child\n   is empty, invokes hfsc_qlen_notify() -> update_vf(cl, 0, 0) and turns\n   the class passive (cl_nactive is decremented up the hierarchy).\n\n2. hfsc_dequeue() then calls update_vf(cl, qdisc_pkt_len(skb), cur_time)\n   to charge the dequeued bytes.\n\nOn the second call the class is already passive, but its child qdisc is\nstill empty, so update_vf() arms go_passive again:\n\n      if (cl->qdisc->q.qlen == 0 && cl->cl_flags & HFSC_FSC)\n              go_passive = 1;\n\nThe leaf is then skipped by the cl_nactive == 0 check inside the loop,\nwhich does not clear go_passive, so the stale go_passive propagates to the\nparent and decrements its cl_nactive a second time. A parent that still\nhas other active children is driven to cl_nactive == 0 and removed from\nthe vttree, even though those siblings are still backlogged. They are\nnever dequeued again and the qdisc stalls.\n\nFix this by only arming go_passive when the class is actually active, so an\nalready-passive class no longer triggers a second passive transition. The\nbyte accounting (cl->cl_total += len) still runs for every ancestor, so\ndequeued bytes continue to be counted exactly once."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["net/sched/sch_hfsc.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"72c61ffbeeb8c50f6d4d70c65d3283aa1bac57a7","lessThan":"a425c82ff06cda5165e0de3de8c2a445ec1f863e","versionType":"git","status":"affected"},{"version":"a5efc95a33bd4fcb879250852828cc58c7862970","lessThan":"fc973ecd1a079b9a87c360478542f3a56dea085b","versionType":"git","status":"affected"},{"version":"0475c85426b18eccdcb7f9fb58d8f8e9c6c58c87","lessThan":"15720cd8fa3fc625146128f89a8e11b0449a20a7","versionType":"git","status":"affected"},{"version":"9030a91235ae4845ec71902c3e0cecfc9ed1f2df","lessThan":"b2a017bfcf565721918ec7355a373911d2f2a227","versionType":"git","status":"affected"},{"version":"d06476714d2819b550e0cc39222347e2c8941c9d","lessThan":"9221a594c72a1446137926d4c2aa04e345f798dc","versionType":"git","status":"affected"},{"version":"51eb3b65544c9efd6a1026889ee5fb5aa62da3bb","lessThan":"66dbb13eeb2fc339f8f548a9076be4c1a94857b0","versionType":"git","status":"affected"},{"version":"51eb3b65544c9efd6a1026889ee5fb5aa62da3bb","lessThan":"3a49bbae676fef1ffe548971e6229ae2adeb9d10","versionType":"git","status":"affected"},{"version":"51eb3b65544c9efd6a1026889ee5fb5aa62da3bb","lessThan":"90b662ea25f5e83bb3b8ccec5b93ced810b92fb8","versionType":"git","status":"affected"},{"version":"9a5fd5c2f4d4afdd5e405083ee53e0789ce76956","versionType":"git","status":"affected"},{"version":"c1175c4ad01dbc9c979d099861fa90a754f72059","versionType":"git","status":"affected"},{"version":"5.10.241","lessThan":"5.10.261","versionType":"semver","status":"affected"},{"version":"5.15.190","lessThan":"5.15.212","versionType":"semver","status":"affected"},{"version":"6.1.138","lessThan":"6.1.178","versionType":"semver","status":"affected"},{"version":"6.6.90","lessThan":"6.6.145","versionType":"semver","status":"affected"},{"version":"6.12.28","lessThan":"6.12.97","versionType":"semver","status":"affected"},{"version":"5.4.297","lessThan":"5.5","versionType":"semver","status":"affected"},{"version":"6.14.6","lessThan":"6.15","versionType":"semver","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["net/sched/sch_hfsc.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.15","status":"affected"},{"version":"0","lessThan":"6.15","versionType":"semver","status":"unaffected"},{"version":"5.10.261","lessThanOrEqual":"5.10.*","versionType":"semver","status":"unaffected"},{"version":"5.15.212","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.178","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.97","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/15720cd8fa3fc625146128f89a8e11b0449a20a7","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/3a49bbae676fef1ffe548971e6229ae2adeb9d10","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/66dbb13eeb2fc339f8f548a9076be4c1a94857b0","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/90b662ea25f5e83bb3b8ccec5b93ced810b92fb8","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/9221a594c72a1446137926d4c2aa04e345f798dc","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/a425c82ff06cda5165e0de3de8c2a445ec1f863e","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/b2a017bfcf565721918ec7355a373911d2f2a227","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/fc973ecd1a079b9a87c360478542f3a56dea085b","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-74285","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:22:28.037","lastModified":"2026-08-15T06:22:28.037","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nnet: Stop leased rxq before uninstalling its memory provider\n\nnetif_rxq_cleanup_unlease() tears down the memory provider that was\ninstalled on a physical RX queue through a netkit queue lease. It\ncurrently revokes the provider's DMA mappings before stopping the\nphysical queue:\n\n  __netif_mp_uninstall_rxq(virt_rxq, p);            /* DMA unmap */\n  __netif_mp_close_rxq(phys_rxq->dev, rxq_idx, p);  /* queue stop */\n\nThis inverts the ordering used by the regular teardown paths (normal\ndevice unregister and the io_uring zcrx close path), which stop the\nqueue before revoking the provider's mappings.\n\nWith the physical queue still live, its NAPI can keep consuming\nnet_iov entries from the page_pool alloc cache after the\n__netif_mp_uninstall_rxq() has already cleared their dma_addr,\nopening a window for the device to DMA to a stale or zero address.\n\nFix it by swapping the two calls so the queue is stopped (and its\nNAPI quiesced) before the provider is uninstalled. No functional\nregression was observed across repeated runs of the nk_qlease.py\nHW selftest, which exercises the lease teardown path; this was\ntested against fbnic QEMU emulation."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["net/core/netdev_rx_queue.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"5602ad61ebee99c83081fba1aaf5814736edc3e7","lessThan":"03f4c6ed3cffbfce0b85a3a0193d08a46692a9f8","versionType":"git","status":"affected"},{"version":"5602ad61ebee99c83081fba1aaf5814736edc3e7","lessThan":"37314c9dbe95b4d924c7b61aaf563cec4f4e4133","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["net/core/netdev_rx_queue.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"7.1","status":"affected"},{"version":"0","lessThan":"7.1","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/03f4c6ed3cffbfce0b85a3a0193d08a46692a9f8","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/37314c9dbe95b4d924c7b61aaf563cec4f4e4133","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-74286","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:22:28.127","lastModified":"2026-08-15T06:22:28.127","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nnet: pfcp: allocate per-cpu tstats for PFCP netdevs\n\nPFCP uses dev_get_tstats64() as its ndo_get_stats64 callback, but\npfcp_link_setup() does not request NETDEV_PCPU_STAT_TSTATS.  The net\ncore therefore leaves dev->tstats NULL for PFCP devices.\n\nCreating a PFCP rtnetlink device can immediately ask the new netdev for\nstats while building the RTM_NEWLINK notification.  That reaches\ndev_get_tstats64() and dereferences the NULL dev->tstats pointer.\n\nSet pcpu_stat_type to NETDEV_PCPU_STAT_TSTATS during PFCP link setup so\nthe net core allocates the storage expected by dev_get_tstats64()."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/net/pfcp.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"76c8764ef36a5d37ea2e551bda28ac7f028383ba","lessThan":"56b4ad500fd1282ef04db3c4beae5b54ab093a53","versionType":"git","status":"affected"},{"version":"76c8764ef36a5d37ea2e551bda28ac7f028383ba","lessThan":"51a1d9836acc76a1bd16170b2f4b35f11036593f","versionType":"git","status":"affected"},{"version":"76c8764ef36a5d37ea2e551bda28ac7f028383ba","lessThan":"67e4b283de36d9eebf95acdea5d6674b6ef4b2f4","versionType":"git","status":"affected"},{"version":"76c8764ef36a5d37ea2e551bda28ac7f028383ba","lessThan":"24041543da8cd84eb5d8ae738c534372fff54820","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/net/pfcp.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.10","status":"affected"},{"version":"0","lessThan":"6.10","versionType":"semver","status":"unaffected"},{"version":"6.12.97","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/24041543da8cd84eb5d8ae738c534372fff54820","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/51a1d9836acc76a1bd16170b2f4b35f11036593f","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/56b4ad500fd1282ef04db3c4beae5b54ab093a53","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/67e4b283de36d9eebf95acdea5d6674b6ef4b2f4","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-74287","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:22:28.220","lastModified":"2026-08-15T06:22:28.220","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nsctp: validate embedded address parameter length\n\nsctp_verify_asconf() and sctp_verify_param() only validate ADD_IP, DEL_IP,\nand SET_PRIMARY parameters against a fixed minimum size of sizeof(struct\nsctp_addip_param) + sizeof(struct sctp_paramhdr). This ensures the outer\nparameter is large enough to contain an embedded address parameter header,\nbut does not verify that the embedded address parameter's declared length\nfits within the bounds of the outer parameter.\n\nLater, sctp_process_param() and sctp_process_asconf_param() extract the\nembedded address parameter and pass it to af->from_addr_param(), which uses\nthe address parameter length to parse the variable-length address payload.\nA malformed peer can therefore advertise an embedded address parameter\nlength that exceeds the remaining bytes in the enclosing parameter.\n\nValidate that addr_param->p.length does not exceed the space available\nafter the sctp_addip_param header before processing the embedded address\nparameter. Reject malformed parameters when the embedded address length\nextends beyond the enclosing parameter bounds.\n\nThis prevents out-of-bounds reads when parsing malformed parameters carried\nin INIT or ASCONF processing paths."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["net/sctp/sm_make_chunk.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"06c8bf48505f2fef265931db82d5003d302a347b","versionType":"git","status":"affected"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"28ba1d3c956604a89168adfb4c97cfc6c509bba5","versionType":"git","status":"affected"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"3a44b2602d57e11e2eb85958d4cd500d14a27d9e","versionType":"git","status":"affected"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"85f54cf589163a75fa06e37d8c2a4a72824c6dd1","versionType":"git","status":"affected"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"92e4adfee56f32a963ebb105c6cd9a1ed707262a","versionType":"git","status":"affected"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"ed8605c6f39b9b84f9a4631db6deb25e7f1e973c","versionType":"git","status":"affected"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"0c674b20c9cdb54f8a46c88b4d00cadf82b8f0c0","versionType":"git","status":"affected"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"e9361d0ca55c4af12aac09e2572852fa91046229","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["net/sctp/sm_make_chunk.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"2.6.12","status":"affected"},{"version":"0","lessThan":"2.6.12","versionType":"semver","status":"unaffected"},{"version":"5.10.261","lessThanOrEqual":"5.10.*","versionType":"semver","status":"unaffected"},{"version":"5.15.212","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.178","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.97","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/06c8bf48505f2fef265931db82d5003d302a347b","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/0c674b20c9cdb54f8a46c88b4d00cadf82b8f0c0","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/28ba1d3c956604a89168adfb4c97cfc6c509bba5","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/3a44b2602d57e11e2eb85958d4cd500d14a27d9e","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/85f54cf589163a75fa06e37d8c2a4a72824c6dd1","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/92e4adfee56f32a963ebb105c6cd9a1ed707262a","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/e9361d0ca55c4af12aac09e2572852fa91046229","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/ed8605c6f39b9b84f9a4631db6deb25e7f1e973c","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-74288","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:22:28.343","lastModified":"2026-08-15T06:22:28.343","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nnet: fib_rules: Don't dump dying fib_rule in fib_rules_dump().\n\nrocker_router_fib_event() calls fib_rule_get() during RCU dump.\n\nIf the fib_rule is dying, refcount_inc() will complain about it.\n\nLet's call refcount_inc_not_zero() in fib_rules_dump()."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["include/net/fib_rules.h","net/core/fib_rules.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"5d7bfd141924a5ece21eb612ad3c56612f041c1e","lessThan":"0f929b59f4cd0e05bb1ecefe12b77e85911d4be2","versionType":"git","status":"affected"},{"version":"5d7bfd141924a5ece21eb612ad3c56612f041c1e","lessThan":"4b7ae30c81c2ee10a644749a3704a5c797ccc308","versionType":"git","status":"affected"},{"version":"5d7bfd141924a5ece21eb612ad3c56612f041c1e","lessThan":"2dfdc210d240bd48bb2ea746430b02b5571b6db9","versionType":"git","status":"affected"},{"version":"5d7bfd141924a5ece21eb612ad3c56612f041c1e","lessThan":"a7ef30753353ba6a95d693b1863a0214222a199a","versionType":"git","status":"affected"},{"version":"5d7bfd141924a5ece21eb612ad3c56612f041c1e","lessThan":"1fbc6c6efe78f4454a51afa0587efb6826f60f00","versionType":"git","status":"affected"},{"version":"5d7bfd141924a5ece21eb612ad3c56612f041c1e","lessThan":"bb4a5b3c91af3c8d705bb2e9f6f8069a70db26fc","versionType":"git","status":"affected"},{"version":"5d7bfd141924a5ece21eb612ad3c56612f041c1e","lessThan":"3af0bc1bd9039e2e50abf3e2d7fee411f38bce4e","versionType":"git","status":"affected"},{"version":"5d7bfd141924a5ece21eb612ad3c56612f041c1e","lessThan":"2821e85c058f81c9948a2fb1a634f7b47457d51c","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["include/net/fib_rules.h","net/core/fib_rules.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"4.12","status":"affected"},{"version":"0","lessThan":"4.12","versionType":"semver","status":"unaffected"},{"version":"5.10.261","lessThanOrEqual":"5.10.*","versionType":"semver","status":"unaffected"},{"version":"5.15.212","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.178","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.97","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/0f929b59f4cd0e05bb1ecefe12b77e85911d4be2","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/1fbc6c6efe78f4454a51afa0587efb6826f60f00","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/2821e85c058f81c9948a2fb1a634f7b47457d51c","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/2dfdc210d240bd48bb2ea746430b02b5571b6db9","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/3af0bc1bd9039e2e50abf3e2d7fee411f38bce4e","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/4b7ae30c81c2ee10a644749a3704a5c797ccc308","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/a7ef30753353ba6a95d693b1863a0214222a199a","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/bb4a5b3c91af3c8d705bb2e9f6f8069a70db26fc","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-74289","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:22:28.457","lastModified":"2026-08-15T06:22:28.457","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nipv4: fib: Don't dump dying fib_info in fib_leaf_notify().\n\nsyzbot reported use-after-free in nsim_fib4_prepare_event(). [0]\n\nThe problem is that the following functions call fib_info_hold() /\nrefcount_inc() while dumping fib_info under RCU, which is unsafe.\n\n  * mlxsw_sp_router_fib4_event()\n  * rocker_router_fib_event()\n  * nsim_fib4_prepare_event()\n\nrefcount_inc_not_zero() must be used, but it would be too late\nthere.\n\nLet's guarantee the lifetime of fib_info in fib_leaf_notify().\n\nNote that IPv6 does not need the corresponding change since\nfib6_table_dump() holds fib6_table.tb6_lock.\n\n[0]:\nrefcount_t: addition on 0; use-after-free.\nWARNING: lib/refcount.c:25 at refcount_warn_saturate+0x9f/0x110 lib/refcount.c:25, CPU#0: kworker/u8:15/3420\nModules linked in:\nCPU: 0 UID: 0 PID: 3420 Comm: kworker/u8:15 Not tainted syzkaller #0 PREEMPT_{RT,(full)}\nHardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 04/18/2026\nWorkqueue: netns cleanup_net\nRIP: 0010:refcount_warn_saturate+0x9f/0x110 lib/refcount.c:25\nCode: eb 66 85 db 74 3e 83 fb 01 75 4c e8 1b f1 22 fd 48 8d 3d 84 cb f1 0a 67 48 0f b9 3a eb 4a e8 08 f1 22 fd 48 8d 3d 81 cb f1 0a <67> 48 0f b9 3a eb 37 e8 f5 f0 22 fd 48 8d 3d 7e cb f1 0a 67 48 0f\nRSP: 0018:ffffc9000f2c7270 EFLAGS: 00010293\nRAX: ffffffff84a18858 RBX: 0000000000000002 RCX: ffff888032ff9ec0\nRDX: 0000000000000000 RSI: 0000000000000000 RDI: ffffffff8f9353e0\nRBP: 0000000000000000 R08: ffff888032ff9ec0 R09: 0000000000000005\nR10: 0000000000000100 R11: 0000000000000004 R12: ffff8880570cc000\nR13: dffffc0000000000 R14: ffff88802b40563c R15: ffff8880570cc000\nFS:  0000000000000000(0000) GS:ffff888126173000(0000) knlGS:0000000000000000\nCS:  0010 DS: 0000 ES: 0000 CR0: 0000000080050033\nCR2: 00007fb1f4d5d000 CR3: 000000006072a000 CR4: 00000000003526f0\nCall Trace:\n <TASK>\n __refcount_add include/linux/refcount.h:-1 [inline]\n __refcount_inc include/linux/refcount.h:366 [inline]\n refcount_inc include/linux/refcount.h:383 [inline]\n fib_info_hold include/net/ip_fib.h:629 [inline]\n nsim_fib4_prepare_event drivers/net/netdevsim/fib.c:930 [inline]\n nsim_fib_event_schedule_work drivers/net/netdevsim/fib.c:1000 [inline]\n nsim_fib_event_nb+0x1055/0x1240 drivers/net/netdevsim/fib.c:1043\n call_fib_notifier+0x45/0x80 net/core/fib_notifier.c:25\n call_fib_entry_notifier net/ipv4/fib_trie.c:90 [inline]\n fib_leaf_notify net/ipv4/fib_trie.c:2176 [inline]\n fib_table_notify net/ipv4/fib_trie.c:2194 [inline]\n fib_notify+0x36b/0x5e0 net/ipv4/fib_trie.c:2217\n fib_net_dump net/core/fib_notifier.c:70 [inline]\n register_fib_notifier+0x184/0x360 net/core/fib_notifier.c:108\n nsim_fib_create+0x85d/0x9f0 drivers/net/netdevsim/fib.c:1596\n nsim_dev_reload_create drivers/net/netdevsim/dev.c:1604 [inline]\n nsim_dev_reload_up+0x374/0x7c0 drivers/net/netdevsim/dev.c:1058\n devlink_reload+0x501/0x8d0 net/devlink/dev.c:475\n devlink_pernet_pre_exit+0x1ff/0x420 net/devlink/core.c:558\n ops_pre_exit_list net/core/net_namespace.c:161 [inline]\n ops_undo_list+0x187/0x940 net/core/net_namespace.c:234\n cleanup_net+0x56e/0x800 net/core/net_namespace.c:702\n process_one_work kernel/workqueue.c:3314 [inline]\n process_scheduled_works+0xb5d/0x1860 kernel/workqueue.c:3397\n worker_thread+0xa53/0xfc0 kernel/workqueue.c:3478\n kthread+0x388/0x470 kernel/kthread.c:436\n ret_from_fork+0x514/0xb70 arch/x86/kernel/process.c:158\n ret_from_fork_asm+0x1a/0x30 arch/x86/entry/entry_64.S:245\n </TASK>"}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["include/net/ip_fib.h","net/ipv4/fib_trie.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"c3852ef7f2f8f75a9f85a864bec1f6f5a3068eea","lessThan":"676482da8d938ea72c26da0fc86af2d2ec238ab2","versionType":"git","status":"affected"},{"version":"c3852ef7f2f8f75a9f85a864bec1f6f5a3068eea","lessThan":"06b693d2eb6651a63ad85bad8673de3b7d4edd6d","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["include/net/ip_fib.h","net/ipv4/fib_trie.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"4.10","status":"affected"},{"version":"0","lessThan":"4.10","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/06b693d2eb6651a63ad85bad8673de3b7d4edd6d","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/676482da8d938ea72c26da0fc86af2d2ec238ab2","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-74290","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:22:28.570","lastModified":"2026-08-15T06:22:28.570","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nnet/sched: cls_flow: Dont expose folded kernel pointers\n\nThe flow classifier falls back to addr_fold() for fields that are missing\nfrom packet headers. In map mode, userspace controls mask, xor, rshift,\naddend and divisor, and can observe the resulting classid through class\nstatistics. This allows a tc classifier in a user/network namespace to\nrecover the 32-bit folded value of skb->sk, skb_dst() or skb_nfct().\n\nAlign with standard kernel practices for pointer hashing and replace the\nXOR folding with a keyed siphash (which is cryptographically secure)"}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["net/sched/cls_flow.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"e5dfb815181fcb186d6080ac3a091eadff2d98fe","lessThan":"19f2ecf8ea564562c7e7a919cf38068dd9aa1c96","versionType":"git","status":"affected"},{"version":"e5dfb815181fcb186d6080ac3a091eadff2d98fe","lessThan":"3d054001860270748405a3f9270c5fa0bf7ffc19","versionType":"git","status":"affected"},{"version":"e5dfb815181fcb186d6080ac3a091eadff2d98fe","lessThan":"fb31fbe51c233f3bf47021121f63d2e42cac2d08","versionType":"git","status":"affected"},{"version":"e5dfb815181fcb186d6080ac3a091eadff2d98fe","lessThan":"0a8b5b74f0e6b6b9ce453bcfa4baa502c4c7577a","versionType":"git","status":"affected"},{"version":"e5dfb815181fcb186d6080ac3a091eadff2d98fe","lessThan":"6151159618198675e01c391676e579738286c135","versionType":"git","status":"affected"},{"version":"e5dfb815181fcb186d6080ac3a091eadff2d98fe","lessThan":"f294fc71c4a0fa4964f6428a1b4e7929c1d83125","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["net/sched/cls_flow.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"2.6.25","status":"affected"},{"version":"0","lessThan":"2.6.25","versionType":"semver","status":"unaffected"},{"version":"6.1.178","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.97","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/0a8b5b74f0e6b6b9ce453bcfa4baa502c4c7577a","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/19f2ecf8ea564562c7e7a919cf38068dd9aa1c96","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/3d054001860270748405a3f9270c5fa0bf7ffc19","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/6151159618198675e01c391676e579738286c135","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/f294fc71c4a0fa4964f6428a1b4e7929c1d83125","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/fb31fbe51c233f3bf47021121f63d2e42cac2d08","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-74291","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:22:28.670","lastModified":"2026-08-15T06:22:28.670","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nASoC: topology: Check PCM and DAI name strings before use\n\nTopology objects store several PCM and DAI names in fixed-size UAPI\narrays. Other topology parser paths validate these fields with bounded\nstrnlen() checks before using them as C strings, but the PCM and DAI\npaths still pass some fixed-size arrays directly to strlen(),\ndevm_kstrdup(), DAI lookup, and diagnostic prints.\n\nA malformed topology blob with a non-NUL-terminated PCM, DAI, or stream\ncapability name can therefore make the parser read past the end of the\nfixed-size field.\n\nReject unterminated PCM and DAI name fields before consuming them as C\nstrings."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["sound/soc/soc-topology.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"64527e8a352968bda529f01df1c9dd5fe581ff04","lessThan":"ba37b62ed0a443b8e23f53a7477e7f2537fd34c7","versionType":"git","status":"affected"},{"version":"64527e8a352968bda529f01df1c9dd5fe581ff04","lessThan":"b7e44d1986d6671342c19b82192189ca5db5dab7","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["sound/soc/soc-topology.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"4.6","status":"affected"},{"version":"0","lessThan":"4.6","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/b7e44d1986d6671342c19b82192189ca5db5dab7","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/ba37b62ed0a443b8e23f53a7477e7f2537fd34c7","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-74292","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:22:28.760","lastModified":"2026-08-15T06:22:28.760","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nASoC: tegra: tegra210_ahub: Validate written enum value\n\ntegra_ahub_put_value_enum() reads e->values[item[0]] before\nchecking whether item[0] is within the enum item range. The existing\ncheck therefore happens too late to prevent an out-of-range read of the\nvalues array.\n\nMove the check before the array access."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["sound/soc/tegra/tegra210_ahub.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"16e1bcc2caf446fa3e1daa040b59fd6f6272a766","lessThan":"4e45e4c2015519a39c40eb575c03b77807fb5080","versionType":"git","status":"affected"},{"version":"16e1bcc2caf446fa3e1daa040b59fd6f6272a766","lessThan":"964f8f9015fb117402d8d2186593397cd93388e9","versionType":"git","status":"affected"},{"version":"16e1bcc2caf446fa3e1daa040b59fd6f6272a766","lessThan":"2ec7d16fe21c68b0879873a2abf9aac854c96134","versionType":"git","status":"affected"},{"version":"16e1bcc2caf446fa3e1daa040b59fd6f6272a766","lessThan":"4bcb23635d5059ee71f3fb89719ea14aada6fd59","versionType":"git","status":"affected"},{"version":"16e1bcc2caf446fa3e1daa040b59fd6f6272a766","lessThan":"f67d63628fe158b3a6e6b33a2b8c83ff118699d1","versionType":"git","status":"affected"},{"version":"16e1bcc2caf446fa3e1daa040b59fd6f6272a766","lessThan":"e098c9c6477dfa3cb363282100108484ceba5cc5","versionType":"git","status":"affected"},{"version":"16e1bcc2caf446fa3e1daa040b59fd6f6272a766","lessThan":"226d93b65f4f99b35fb7a03bdb24acb577364ebc","versionType":"git","status":"affected"},{"version":"16e1bcc2caf446fa3e1daa040b59fd6f6272a766","lessThan":"1d8aabb413b5638670dfd1162169edc0ba276a2e","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["sound/soc/tegra/tegra210_ahub.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"5.9","status":"affected"},{"version":"0","lessThan":"5.9","versionType":"semver","status":"unaffected"},{"version":"5.10.261","lessThanOrEqual":"5.10.*","versionType":"semver","status":"unaffected"},{"version":"5.15.212","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.178","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.97","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/1d8aabb413b5638670dfd1162169edc0ba276a2e","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/226d93b65f4f99b35fb7a03bdb24acb577364ebc","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/2ec7d16fe21c68b0879873a2abf9aac854c96134","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/4bcb23635d5059ee71f3fb89719ea14aada6fd59","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/4e45e4c2015519a39c40eb575c03b77807fb5080","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/964f8f9015fb117402d8d2186593397cd93388e9","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/e098c9c6477dfa3cb363282100108484ceba5cc5","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/f67d63628fe158b3a6e6b33a2b8c83ff118699d1","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-74293","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:22:28.877","lastModified":"2026-08-15T06:22:28.877","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nASoC: fsl: fsl_audmix: Validate written enum values\n\nfsl_audmix_put_mix_clk_src() and fsl_audmix_put_out_src()\nconvert the user-provided enum item with snd_soc_enum_item_to_val()\nbefore checking whether the item is within the enum's item count.\n\nThe generic snd_soc_put_enum_double() helper performs that\nvalidation, but these callbacks use the converted value first: the\nclock-source path tests it with BIT(), and the output-source path\nindexes the prms transition table with it.\n\nReject out-of-range enum items before converting them."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["sound/soc/fsl/fsl_audmix.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"be1df61cf06efb355c90702e46b8d46f055acb4e","lessThan":"7513831b90a38d55fa089e3e1b49691e467afee6","versionType":"git","status":"affected"},{"version":"be1df61cf06efb355c90702e46b8d46f055acb4e","lessThan":"b4774a7da12b14fc37219ab4368d1907f9b5aca4","versionType":"git","status":"affected"},{"version":"be1df61cf06efb355c90702e46b8d46f055acb4e","lessThan":"8fb4364eb494b926d009bfaf3c98f07c3aa5d9f3","versionType":"git","status":"affected"},{"version":"be1df61cf06efb355c90702e46b8d46f055acb4e","lessThan":"0b10c6203e62d9e7337cc401568b201f9bac79ec","versionType":"git","status":"affected"},{"version":"be1df61cf06efb355c90702e46b8d46f055acb4e","lessThan":"b36d6d48faa6b1bb723b8f4e527c531a1a68520e","versionType":"git","status":"affected"},{"version":"be1df61cf06efb355c90702e46b8d46f055acb4e","lessThan":"0f1510e84d7bfc3eb9538efa65c6ea0aadf1078c","versionType":"git","status":"affected"},{"version":"be1df61cf06efb355c90702e46b8d46f055acb4e","lessThan":"5b7a23c1ed04e794ef3b31e452ef5c93e1e34b4a","versionType":"git","status":"affected"},{"version":"be1df61cf06efb355c90702e46b8d46f055acb4e","lessThan":"3cd17e4e2871114d5579fa7bc8da66faf7fc1930","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["sound/soc/fsl/fsl_audmix.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"5.2","status":"affected"},{"version":"0","lessThan":"5.2","versionType":"semver","status":"unaffected"},{"version":"5.10.261","lessThanOrEqual":"5.10.*","versionType":"semver","status":"unaffected"},{"version":"5.15.212","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.178","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.97","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/0b10c6203e62d9e7337cc401568b201f9bac79ec","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/0f1510e84d7bfc3eb9538efa65c6ea0aadf1078c","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/3cd17e4e2871114d5579fa7bc8da66faf7fc1930","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/5b7a23c1ed04e794ef3b31e452ef5c93e1e34b4a","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/7513831b90a38d55fa089e3e1b49691e467afee6","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/8fb4364eb494b926d009bfaf3c98f07c3aa5d9f3","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/b36d6d48faa6b1bb723b8f4e527c531a1a68520e","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/b4774a7da12b14fc37219ab4368d1907f9b5aca4","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-74294","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:22:28.990","lastModified":"2026-08-15T06:22:28.990","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nASoC: meson: aiu: Validate written enum values\n\nThe AIU HDMI and internal codec mux put callbacks use the written enum\nvalue with snd_soc_enum_item_to_val() before checking whether the value is\nvalid for the enumeration.\n\nReject out-of-range values before converting the enum item, matching the\nvalidation already done by the G12A HDMI and internal codec mux controls."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["sound/soc/meson/aiu-acodec-ctrl.c","sound/soc/meson/aiu-codec-ctrl.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"b82b734c0e9a75e1b956214ac523a8eb590f51f3","lessThan":"0965892cc486ca554d72eeb62d85ccf8d0137a5a","versionType":"git","status":"affected"},{"version":"b82b734c0e9a75e1b956214ac523a8eb590f51f3","lessThan":"d65adf85477247be04ac86886f8edfaa047b5d4a","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["sound/soc/meson/aiu-acodec-ctrl.c","sound/soc/meson/aiu-codec-ctrl.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"5.7","status":"affected"},{"version":"0","lessThan":"5.7","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/0965892cc486ca554d72eeb62d85ccf8d0137a5a","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/d65adf85477247be04ac86886f8edfaa047b5d4a","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-74295","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:22:29.097","lastModified":"2026-08-15T06:22:29.097","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nASoC: codecs: hdac_hdmi: Validate written enum value\n\nhdac_hdmi_set_pin_port_mux() uses the written enum value to index the\ntexts array before calling snd_soc_dapm_put_enum_double(), which validates\nthat the value is within the enum item range.\n\nAn out-of-range value can therefore make the driver read past the texts\narray before the helper rejects the write. Move the lookup after the helper\nhas accepted the value."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["sound/soc/codecs/hdac_hdmi.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"4a3478debf36c0aa0cf0860daec245b13cd4448f","lessThan":"216336418c007c4b44c650acf2fd3d2de5bb81e8","versionType":"git","status":"affected"},{"version":"4a3478debf36c0aa0cf0860daec245b13cd4448f","lessThan":"bc464a6a9e352daa17b1636c090cf3185710b9a0","versionType":"git","status":"affected"},{"version":"4a3478debf36c0aa0cf0860daec245b13cd4448f","lessThan":"8cbf24714d6b3f553fc959632c9781176a73a9a7","versionType":"git","status":"affected"},{"version":"4a3478debf36c0aa0cf0860daec245b13cd4448f","lessThan":"7f02e9064b6f84e7f93c72f134306271eb4f7de4","versionType":"git","status":"affected"},{"version":"4a3478debf36c0aa0cf0860daec245b13cd4448f","lessThan":"9131e4b023e0db5764680034bdc94aeae0b0f33d","versionType":"git","status":"affected"},{"version":"4a3478debf36c0aa0cf0860daec245b13cd4448f","lessThan":"d8961b5c7889b6ecc00f1409d36826df1665df27","versionType":"git","status":"affected"},{"version":"4a3478debf36c0aa0cf0860daec245b13cd4448f","lessThan":"0b08baeccdcf52fad328ad645f5b4fbee04eea34","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["sound/soc/codecs/hdac_hdmi.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"4.6","status":"affected"},{"version":"0","lessThan":"4.6","versionType":"semver","status":"unaffected"},{"version":"5.15.212","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.178","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.97","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/0b08baeccdcf52fad328ad645f5b4fbee04eea34","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/216336418c007c4b44c650acf2fd3d2de5bb81e8","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/7f02e9064b6f84e7f93c72f134306271eb4f7de4","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/8cbf24714d6b3f553fc959632c9781176a73a9a7","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/9131e4b023e0db5764680034bdc94aeae0b0f33d","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/bc464a6a9e352daa17b1636c090cf3185710b9a0","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/d8961b5c7889b6ecc00f1409d36826df1665df27","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-74296","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:22:29.203","lastModified":"2026-08-15T06:22:29.203","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nRDMA/mlx5: Release the HW‑provided UAR index rather than the SW one\n\nFree the UAR index returned by the hardware."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/infiniband/hw/mlx5/main.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"4ed131d0bb1597ce12fff22d9d7fc9720a6e8cf0","lessThan":"80f1f49f53a42733e60c90e0ec545e647969214d","versionType":"git","status":"affected"},{"version":"4ed131d0bb1597ce12fff22d9d7fc9720a6e8cf0","lessThan":"aabfc845838ef453f1d22d7665596f9cc48be7dd","versionType":"git","status":"affected"},{"version":"4ed131d0bb1597ce12fff22d9d7fc9720a6e8cf0","lessThan":"6f83de384ca582fa87b4c2b0d03bd1ed3bf9a2ee","versionType":"git","status":"affected"},{"version":"4ed131d0bb1597ce12fff22d9d7fc9720a6e8cf0","lessThan":"d3ff718c0c7153e2641e6a09507bace14fc5c402","versionType":"git","status":"affected"},{"version":"4ed131d0bb1597ce12fff22d9d7fc9720a6e8cf0","lessThan":"ef369446f62903ea079e8a7954b5bf8bb8300fe3","versionType":"git","status":"affected"},{"version":"4ed131d0bb1597ce12fff22d9d7fc9720a6e8cf0","lessThan":"449ae7927152e46acbe5f19f97eafdae6d3a96b1","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/infiniband/hw/mlx5/main.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"4.16","status":"affected"},{"version":"0","lessThan":"4.16","versionType":"semver","status":"unaffected"},{"version":"6.1.178","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.97","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/449ae7927152e46acbe5f19f97eafdae6d3a96b1","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/6f83de384ca582fa87b4c2b0d03bd1ed3bf9a2ee","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/80f1f49f53a42733e60c90e0ec545e647969214d","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/aabfc845838ef453f1d22d7665596f9cc48be7dd","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/d3ff718c0c7153e2641e6a09507bace14fc5c402","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/ef369446f62903ea079e8a7954b5bf8bb8300fe3","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-74297","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:22:29.307","lastModified":"2026-08-15T06:22:29.307","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nRDMA/mlx5: Fix undefined shift of user RQ WQE size\n\nset_rq_size() computes the RQ WQE size as \"1 << rq_wqe_shift\" based on\nthe user-provided rq_wqe_shift, which is only checked to be greater than\n32, so shifts of 32 are still accepted. A shift of 31 also overflows a\nsigned integer, leading to undefined behavior.\n\nUse check_shl_overflow() to compute the RQ WQE size and reject any\ninvalid values."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/infiniband/hw/mlx5/qp.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"e126ba97dba9edeb6fafa3665b5f8497fc9cdf8c","lessThan":"9fff54929cc00849d738faa99f06c32399aeb026","versionType":"git","status":"affected"},{"version":"e126ba97dba9edeb6fafa3665b5f8497fc9cdf8c","lessThan":"b746f949c2ac2b041102836095d6d4a2ef21fa75","versionType":"git","status":"affected"},{"version":"e126ba97dba9edeb6fafa3665b5f8497fc9cdf8c","lessThan":"c1dbf52d24a8cb1aa56780ba51b72e7d495f258c","versionType":"git","status":"affected"},{"version":"e126ba97dba9edeb6fafa3665b5f8497fc9cdf8c","lessThan":"6fc874fdfb366bfb11c62e6af9a831c8be59ddda","versionType":"git","status":"affected"},{"version":"e126ba97dba9edeb6fafa3665b5f8497fc9cdf8c","lessThan":"42f3d2c8c18b92ea33e506a38b64f1a8986c2823","versionType":"git","status":"affected"},{"version":"e126ba97dba9edeb6fafa3665b5f8497fc9cdf8c","lessThan":"4b87a2497276a72fd63028e7419abf0fb7ed837b","versionType":"git","status":"affected"},{"version":"e126ba97dba9edeb6fafa3665b5f8497fc9cdf8c","lessThan":"b732db02a2b04cde393638df19de6251ce62a74e","versionType":"git","status":"affected"},{"version":"e126ba97dba9edeb6fafa3665b5f8497fc9cdf8c","lessThan":"d881d60223aac8fdc12b227d89c76e131e92a9cd","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/infiniband/hw/mlx5/qp.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"3.11","status":"affected"},{"version":"0","lessThan":"3.11","versionType":"semver","status":"unaffected"},{"version":"5.10.261","lessThanOrEqual":"5.10.*","versionType":"semver","status":"unaffected"},{"version":"5.15.212","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.178","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.97","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/42f3d2c8c18b92ea33e506a38b64f1a8986c2823","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/4b87a2497276a72fd63028e7419abf0fb7ed837b","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/6fc874fdfb366bfb11c62e6af9a831c8be59ddda","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/9fff54929cc00849d738faa99f06c32399aeb026","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/b732db02a2b04cde393638df19de6251ce62a74e","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/b746f949c2ac2b041102836095d6d4a2ef21fa75","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/c1dbf52d24a8cb1aa56780ba51b72e7d495f258c","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/d881d60223aac8fdc12b227d89c76e131e92a9cd","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-74298","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:22:29.420","lastModified":"2026-08-15T06:22:29.420","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nRDMA/core: Fix FRMR set pinned push error path\n\nAdd destruction of FRMR handles in case the push to the pool fails.\nThis prevents resources leak in case pool page allocation fails."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/infiniband/core/frmr_pools.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"020d189d16a62ed56115cce7e255459cf0eeb4e6","lessThan":"a487c14dda02a649d84c8303772430d32bd76eb9","versionType":"git","status":"affected"},{"version":"020d189d16a62ed56115cce7e255459cf0eeb4e6","lessThan":"41a707d0275cdec9ac125e826dd6836fa9623cbc","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/infiniband/core/frmr_pools.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"7.1","status":"affected"},{"version":"0","lessThan":"7.1","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/41a707d0275cdec9ac125e826dd6836fa9623cbc","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/a487c14dda02a649d84c8303772430d32bd76eb9","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-74299","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:22:29.517","lastModified":"2026-08-15T06:22:29.517","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nRDMA/core: Fix FRMR aging push to queue error flow\n\nAging pools with pinned handles requires moving handles from the\nactive queue to a non-empty inactive queue that might fail on new page\nallocation, we are currently not handling the fault and leaking any mkey\nthat fails the push.\n\nFix by Introducing push_queue_to_queue_locked() that fills the\ndestination's partial tail page from the source and then splices the\nremaining source pages onto the destination, performing no allocation.\n\nReplace the per-handle move loop in age_pinned_pool() and the\nopen-coded splice in pool_aging_work() with calls to the helper.\nAs the helper cannot fail under memory pressure, removing a class of\nGFP_ATOMIC allocations under the pool lock and simplifying the error\nflow."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/infiniband/core/frmr_pools.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"020d189d16a62ed56115cce7e255459cf0eeb4e6","lessThan":"edf133d28fc43f7f8b0da43a8d5b93fdf8073d35","versionType":"git","status":"affected"},{"version":"020d189d16a62ed56115cce7e255459cf0eeb4e6","lessThan":"c6936506ed556ce3ccad36ab999baf2764dd7d25","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/infiniband/core/frmr_pools.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"7.1","status":"affected"},{"version":"0","lessThan":"7.1","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/c6936506ed556ce3ccad36ab999baf2764dd7d25","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/edf133d28fc43f7f8b0da43a8d5b93fdf8073d35","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-74300","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:22:29.610","lastModified":"2026-08-15T06:22:29.610","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nBluetooth: hci: validate codec capability element length\n\nRead Local Codec Capabilities returns a sequence of capability elements.\nEach element starts with a one-byte length followed by that many payload\nbytes.\n\nhci_read_codec_capabilities() checks that the skb contains the length\nbyte, but then validates only caps->len against the remaining skb\nlength.  A malformed controller response with one remaining byte and\ncaps->len set to one passes that check even though the element needs two\nbytes.  The parser then records a two-byte capability and copies one\nbyte beyond the advertised response payload into the codec list.\n\nValidate the full element size, including the length byte, before adding\nit to the accumulated capability length.  This preserves all well-formed\ncapability elements and drops only truncated controller responses."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["net/bluetooth/hci_codec.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"8961987f3f5fa2f2618e72304d013c8dd5e604a6","lessThan":"fc97fc8cf7f53fd3619db63e09050d20a3a0c4b1","versionType":"git","status":"affected"},{"version":"8961987f3f5fa2f2618e72304d013c8dd5e604a6","lessThan":"290b36f9d1eb9b2f72b40d826f26b4a182ab15f7","versionType":"git","status":"affected"},{"version":"8961987f3f5fa2f2618e72304d013c8dd5e604a6","lessThan":"f2ad01f55e07f9531efcea736087e6b8658a3440","versionType":"git","status":"affected"},{"version":"8961987f3f5fa2f2618e72304d013c8dd5e604a6","lessThan":"ec4d352747a62c1082f16c11a74b37d6eb85a5a3","versionType":"git","status":"affected"},{"version":"8961987f3f5fa2f2618e72304d013c8dd5e604a6","lessThan":"4bc16db0f11918e07edf9fdcda4a30cf4c9df45c","versionType":"git","status":"affected"},{"version":"8961987f3f5fa2f2618e72304d013c8dd5e604a6","lessThan":"c38fbcdc407925c7088f7e5f11c1fff73d2d35a2","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["net/bluetooth/hci_codec.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"5.16","status":"affected"},{"version":"0","lessThan":"5.16","versionType":"semver","status":"unaffected"},{"version":"6.1.178","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.97","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/290b36f9d1eb9b2f72b40d826f26b4a182ab15f7","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/4bc16db0f11918e07edf9fdcda4a30cf4c9df45c","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/c38fbcdc407925c7088f7e5f11c1fff73d2d35a2","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/ec4d352747a62c1082f16c11a74b37d6eb85a5a3","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/f2ad01f55e07f9531efcea736087e6b8658a3440","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/fc97fc8cf7f53fd3619db63e09050d20a3a0c4b1","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-74301","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:22:29.720","lastModified":"2026-08-15T06:22:29.720","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nBluetooth: btmtk: fix URB leak in alloc_mtk_intr_urb error path\n\nWhen btmtk_isopkt_pad() fails, the previously allocated URB is not freed,\nleaking the urb structure. Add usb_free_urb() before returning the error."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/bluetooth/btmtk.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"ceac1cb0259de682d78f5c784ef8e0b13022e9d9","lessThan":"2643524743b9cc3c6f5f34cde2a8c627d793f21c","versionType":"git","status":"affected"},{"version":"ceac1cb0259de682d78f5c784ef8e0b13022e9d9","lessThan":"7f206a8d8d82296aa2d30bf5f3e5bb73fc44591d","versionType":"git","status":"affected"},{"version":"ceac1cb0259de682d78f5c784ef8e0b13022e9d9","lessThan":"4e354991da5890d5ce7bfea3f66fb897ae301756","versionType":"git","status":"affected"},{"version":"ceac1cb0259de682d78f5c784ef8e0b13022e9d9","lessThan":"f396f4005180928cd9e15e352a6512865d3bc908","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/bluetooth/btmtk.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.11","status":"affected"},{"version":"0","lessThan":"6.11","versionType":"semver","status":"unaffected"},{"version":"6.12.97","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/2643524743b9cc3c6f5f34cde2a8c627d793f21c","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/4e354991da5890d5ce7bfea3f66fb897ae301756","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/7f206a8d8d82296aa2d30bf5f3e5bb73fc44591d","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/f396f4005180928cd9e15e352a6512865d3bc908","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-74302","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:22:29.813","lastModified":"2026-08-15T06:22:29.813","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nBluetooth: hci_core: Fix UAF in hci_unregister_dev()\n\nhci_unregister_dev() does not disable cmd_timer and ncmd_timer\nbefore the hci_dev structure is freed. If a timeout fires\nduring device teardown, the callback dereferences freed memory\n(including the hdev->reset function pointer), leading to a\nuse-after-free.\n\nAdd disable_delayed_work_sync() calls alongside the existing\ndisable_work_sync() calls to ensure both timers are fully\nquiesced before teardown proceeds."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["net/bluetooth/hci_core.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"0d151a103775dd9645c78c97f77d6e2a5298d913","lessThan":"48c7ad6afcc58c2cda11fed39791708103b6a644","versionType":"git","status":"affected"},{"version":"0d151a103775dd9645c78c97f77d6e2a5298d913","lessThan":"a0fd1086a57b982f8c24ae4ab165c2af39fe1735","versionType":"git","status":"affected"},{"version":"0d151a103775dd9645c78c97f77d6e2a5298d913","lessThan":"672d52d9412252e61b8de8d773ccdf5a277cf540","versionType":"git","status":"affected"},{"version":"0d151a103775dd9645c78c97f77d6e2a5298d913","lessThan":"5edcc018fa6e80b2c478454a4a8229c23d67c181","versionType":"git","status":"affected"},{"version":"48542881997e17b49dc16b93fe910e0cfcf7a9f9","versionType":"git","status":"affected"},{"version":"9cfc84b1d464cc024286f42a090718f9067b80ed","versionType":"git","status":"affected"},{"version":"ddeda6ca5f218b668b560d90fc31ae469adbfd92","versionType":"git","status":"affected"},{"version":"d2ce562a5aff1dcd0c50d9808ea825ef90da909f","versionType":"git","status":"affected"},{"version":"96600c2e5ee8213dbab5df1617293d8e847bb4fa","versionType":"git","status":"affected"},{"version":"d6cbce18370641a21dd889e8613d8153df15eb39","versionType":"git","status":"affected"},{"version":"3f939bd73fed12dddc2a32a76116c19ca47c7678","versionType":"git","status":"affected"},{"version":"4.19.319","lessThan":"4.20","versionType":"semver","status":"affected"},{"version":"5.4.281","lessThan":"5.5","versionType":"semver","status":"affected"},{"version":"5.10.223","lessThan":"5.11","versionType":"semver","status":"affected"},{"version":"5.15.164","lessThan":"5.16","versionType":"semver","status":"affected"},{"version":"6.1.101","lessThan":"6.2","versionType":"semver","status":"affected"},{"version":"6.6.42","lessThan":"6.7","versionType":"semver","status":"affected"},{"version":"6.9.11","lessThan":"6.10","versionType":"semver","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["net/bluetooth/hci_core.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.10","status":"affected"},{"version":"0","lessThan":"6.10","versionType":"semver","status":"unaffected"},{"version":"6.12.97","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/48c7ad6afcc58c2cda11fed39791708103b6a644","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/5edcc018fa6e80b2c478454a4a8229c23d67c181","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/672d52d9412252e61b8de8d773ccdf5a277cf540","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/a0fd1086a57b982f8c24ae4ab165c2af39fe1735","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-74303","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:22:29.930","lastModified":"2026-08-15T06:22:29.930","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nBluetooth: hci_qca: fix NULL pointer dereference in qca_dmp_hdr() for non-serdev device\n\nhu->serdev is NULL for hci_uart attached via non-serdev paths, but\nqca_dmp_hdr() unconditionally dereferences hu->serdev->dev.driver->name,\ncausing a NULL pointer dereference.\n\nFix by guarding the dereference with a NULL check and falling back to\n\"hci_ldisc_qca\" for the non-serdev case."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/bluetooth/hci_qca.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"06d3fdfcdf5cefb06f2024b9d3dad356779399cf","lessThan":"809230cc25dde1d6bb00de2a1eeb5f3199402fbe","versionType":"git","status":"affected"},{"version":"06d3fdfcdf5cefb06f2024b9d3dad356779399cf","lessThan":"a209744230f9ce3d7a7e9a0839944f5cb5fa02a4","versionType":"git","status":"affected"},{"version":"06d3fdfcdf5cefb06f2024b9d3dad356779399cf","lessThan":"e284bb94ad4512ec0bcd9b91bda99e67c507f7f8","versionType":"git","status":"affected"},{"version":"06d3fdfcdf5cefb06f2024b9d3dad356779399cf","lessThan":"d54a5fb7d821b88c7c5569d450af59dafccaf414","versionType":"git","status":"affected"},{"version":"06d3fdfcdf5cefb06f2024b9d3dad356779399cf","lessThan":"6b8cbcf08de0db62254d1981f83db0f94681ccd9","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/bluetooth/hci_qca.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.6","status":"affected"},{"version":"0","lessThan":"6.6","versionType":"semver","status":"unaffected"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.97","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/6b8cbcf08de0db62254d1981f83db0f94681ccd9","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/809230cc25dde1d6bb00de2a1eeb5f3199402fbe","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/a209744230f9ce3d7a7e9a0839944f5cb5fa02a4","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/d54a5fb7d821b88c7c5569d450af59dafccaf414","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/e284bb94ad4512ec0bcd9b91bda99e67c507f7f8","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-74304","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:22:30.037","lastModified":"2026-08-15T06:22:30.037","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nBluetooth: hci_qca: fix NULL pointer dereference in qca_setup() for non-serdev device\n\nhu->serdev is NULL for hci_uart attached via non-serdev paths, but\nqca_setup() unconditionally calls serdev_device_get_drvdata(hu->serdev)\nand dereferences the result, causing a NULL pointer dereference.\n\nFix by guarding the dereference with a NULL check, consistent with the\nrest of qca_setup()."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/bluetooth/hci_qca.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"22d893eec0d52fa97d25d3de248285648f26ef68","lessThan":"0704c04769ccc1a0939682db35d816dfa5fe75dc","versionType":"git","status":"affected"},{"version":"22d893eec0d52fa97d25d3de248285648f26ef68","lessThan":"3ec629fee178d429f01ae843e4ea888de93012bf","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/bluetooth/hci_qca.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"7.0","status":"affected"},{"version":"0","lessThan":"7.0","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/0704c04769ccc1a0939682db35d816dfa5fe75dc","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/3ec629fee178d429f01ae843e4ea888de93012bf","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-74305","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:22:30.190","lastModified":"2026-08-15T06:22:30.190","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nbpf: Tighten cgroup storage cookie checks for prog arrays\n\nThe fix in commit abad3d0bad72 (\"bpf: Fix oob access in cgroup local\nstorage\") is still incomplete. The prog-array compatibility check\ntreats a program with no cgroup storage as compatible with any stored\nstorage cookie. This allows a storage-less program to bridge a tail\ncall chain between an entry program and a storage-using callee even\nthough cgroup local storage at runtime still follows the caller's\ncontext, that is, A -> B(no storage) -> C(storage) path.\n\nRequiring exact cookie equality would break the legitimate case of a\nstorage-less leaf program being tail called from a storage-using one.\nInstead, only accept a zero storage cookie if the program cannot\nperform tail calls itself. This keeps A -> B(no storage) working\nwhile rejecting the A -> B(no storage) -> C(storage) bridge."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["kernel/bpf/core.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"c1c74584b9b4043c52e41fec415226e582d266a3","lessThan":"87177497cca90bf4fcfb759eb898560eb5b46a10","versionType":"git","status":"affected"},{"version":"66da7cee78590259b400e51a70622ccd41da7bb2","lessThan":"1c762d28698483ce7c372091f34d86e4d4828652","versionType":"git","status":"affected"},{"version":"7acfa07c585e3d7a64654d38f0a5c762877d0b9b","lessThan":"eb73056ce2a6f101ddd3bdba89af6b24ebffff85","versionType":"git","status":"affected"},{"version":"41688d1fc5d163a6c2c0e95c0419e2cb31a44648","lessThan":"9ca06849c4239aa2d580c54651f8588c51cb398b","versionType":"git","status":"affected"},{"version":"abad3d0bad72a52137e0c350c59542d75ae4f513","lessThan":"46fbafe3d2d569d828e8d24a7dbe1659f63685cf","versionType":"git","status":"affected"},{"version":"abad3d0bad72a52137e0c350c59542d75ae4f513","lessThan":"cb22dc79528eb26a46d346c3118dbd6b14c70609","versionType":"git","status":"affected"},{"version":"abad3d0bad72a52137e0c350c59542d75ae4f513","lessThan":"10627ddc0167aab5c1c390a10ef461e9937aba08","versionType":"git","status":"affected"},{"version":"19341d5c59e8c7e8528e40f8663e99d67810473c","versionType":"git","status":"affected"},{"version":"5.15.192","lessThan":"5.15.212","versionType":"semver","status":"affected"},{"version":"6.1.151","lessThan":"6.1.178","versionType":"semver","status":"affected"},{"version":"6.6.105","lessThan":"6.6.145","versionType":"semver","status":"affected"},{"version":"6.12.46","lessThan":"6.12.97","versionType":"semver","status":"affected"},{"version":"6.16.1","lessThan":"6.17","versionType":"semver","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["kernel/bpf/core.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.17","status":"affected"},{"version":"0","lessThan":"6.17","versionType":"semver","status":"unaffected"},{"version":"5.15.212","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.178","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.97","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/10627ddc0167aab5c1c390a10ef461e9937aba08","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/1c762d28698483ce7c372091f34d86e4d4828652","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/46fbafe3d2d569d828e8d24a7dbe1659f63685cf","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/87177497cca90bf4fcfb759eb898560eb5b46a10","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/9ca06849c4239aa2d580c54651f8588c51cb398b","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/cb22dc79528eb26a46d346c3118dbd6b14c70609","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/eb73056ce2a6f101ddd3bdba89af6b24ebffff85","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-74306","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:22:30.357","lastModified":"2026-08-15T06:22:30.357","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nvfio/qat: fix f_pos race in qat_vf_resume_write()\n\nqat_vf_resume_write() checks filp->f_pos before taking migf->lock, but\ncopies into the migration-state buffer after taking the lock and\nre-reading the shared file position.\n\nTwo concurrent writers could therefore pass the bounds check with the\nold offset, then have the second writer copy after the first advanced\nf_pos, writing past the end of the migration-state buffer.\n\nTake migf->lock before doing the boundary checks."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/vfio/pci/qat/main.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"bb208810b1abf1c84870cfbe1cc9cf1a1d35c607","lessThan":"6465af0004dc1b067129a26ef44f19cdf13bbce6","versionType":"git","status":"affected"},{"version":"bb208810b1abf1c84870cfbe1cc9cf1a1d35c607","lessThan":"d416dcefdbac90d96b22485fd93f28229ad9984b","versionType":"git","status":"affected"},{"version":"bb208810b1abf1c84870cfbe1cc9cf1a1d35c607","lessThan":"b6fd7a40a66485c8aa8156d8fcf50b95cb8ba281","versionType":"git","status":"affected"},{"version":"bb208810b1abf1c84870cfbe1cc9cf1a1d35c607","lessThan":"4ec5e932e636896e97e4c6a8205b0ac76d52421a","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/vfio/pci/qat/main.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.10","status":"affected"},{"version":"0","lessThan":"6.10","versionType":"semver","status":"unaffected"},{"version":"6.12.97","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/4ec5e932e636896e97e4c6a8205b0ac76d52421a","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/6465af0004dc1b067129a26ef44f19cdf13bbce6","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/b6fd7a40a66485c8aa8156d8fcf50b95cb8ba281","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/d416dcefdbac90d96b22485fd93f28229ad9984b","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-74307","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:22:30.500","lastModified":"2026-08-15T06:22:30.500","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\next4: validate donor file superblock early in EXT4_IOC_MOVE_EXT\n\nReject the EXT4_IOC_MOVE_EXT ioctl early if the donor file does not\nbelong to the same superblock as the original file.  Currently, this\nvalidation is performed inside ext4_move_extents() by\nmext_check_validity(), but only after lock_two_nondirectories() has\nalready acquired the inode locks.  When the donor fd refers to a file\non a different filesystem (e.g., overlayfs), this late validation\ncreates a circular lock dependency:\n\n  CPU0 (overlayfs write)            CPU1 (ext4 ioctl)\n  ----                              ----\n  inode_lock(ovl_inode)\n                                    mnt_want_write_file(filp)\n                                      sb_start_write(ext4_sb)   [sb_writers]\n    backing_file_write_iter()\n      vfs_iter_write(real_file)\n        file_start_write(real_file)\n          sb_start_write(ext4_sb)   [blocked by freeze]\n                                    lock_two_nondirectories()\n                                      inode_lock(ovl_inode)     [blocked]\n\nWith a concurrent freeze operation holding sb_writers write side, this\nforms a deadlock cycle: CPU0 waits for freeze to complete, freeze waits\nfor CPU1's sb_writers reader to exit, CPU1 waits for CPU0's inode lock.\n\nSince EXT4_IOC_MOVE_EXT exchanges physical extents between two files,\nit fundamentally requires both files to reside on the same ext4\nfilesystem.  Moving the superblock check before any lock acquisition\nis both semantically correct and eliminates the circular dependency\nby ensuring that cross-filesystem donor fds are rejected before\nsb_writers or inode locks are taken."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["fs/ext4/ioctl.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"fcf6b1b729bcd23f2b49a84fb33ffbb44712ee6a","lessThan":"74796e886ca39fcb0d3fd36ea6a39c62784ab6fb","versionType":"git","status":"affected"},{"version":"fcf6b1b729bcd23f2b49a84fb33ffbb44712ee6a","lessThan":"fb52013cad9e9b7d3a6a14ea1bcd841e41da7c6c","versionType":"git","status":"affected"},{"version":"fcf6b1b729bcd23f2b49a84fb33ffbb44712ee6a","lessThan":"c143957520c6c9b5cd72e0de8b52b814f0c576fe","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["fs/ext4/ioctl.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"3.18","status":"affected"},{"version":"0","lessThan":"3.18","versionType":"semver","status":"unaffected"},{"version":"6.12.97","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/74796e886ca39fcb0d3fd36ea6a39c62784ab6fb","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/c143957520c6c9b5cd72e0de8b52b814f0c576fe","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/fb52013cad9e9b7d3a6a14ea1bcd841e41da7c6c","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-74308","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:22:30.653","lastModified":"2026-08-15T06:22:30.653","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\next4: fix kernel BUG in ext4_write_inline_data_end\n\nWhen the data=journal mount option is used, the ext4_journalled_write_end()\nfunction incorrectly calls ext4_write_inline_data_end() without checking\nif the EXT4_STATE_MAY_INLINE_DATA flag is still set on the inode.\n\nIf a previous attempt to convert the inline data to an extent failed (e.g.\ndue to ENOSPC), the EXT4_STATE_MAY_INLINE_DATA flag is cleared, but\nthe EXT4_INODE_INLINE_DATA flag remains set. In this scenario, the next\ncall to ext4_write_begin() will not prepare the inline data xattr for\nwriting, but ext4_journalled_write_end() will incorrectly attempt to write\nto it, triggering a BUG_ON(pos + len > EXT4_I(inode)->i_inline_size) in\next4_write_inline_data() since i_inline_size was not expanded.\n\nFix this by ensuring that ext4_journalled_write_end() only calls\next4_write_inline_data_end() if the EXT4_STATE_MAY_INLINE_DATA flag is\nset, mirroring the behavior of ext4_write_end() and ext4_da_write_end()."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["fs/ext4/inode.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"3fdcfb668fd78ec92d9bc2daddf1d41e2a8a30bb","lessThan":"260830a9a706f5d335398236fc788ce32f220de1","versionType":"git","status":"affected"},{"version":"3fdcfb668fd78ec92d9bc2daddf1d41e2a8a30bb","lessThan":"9808ae9fae996afa942bd963a39c9b1cdeebd0bd","versionType":"git","status":"affected"},{"version":"3fdcfb668fd78ec92d9bc2daddf1d41e2a8a30bb","lessThan":"f00f5c0dd55319bc33b76f72c853bda0e0a32eda","versionType":"git","status":"affected"},{"version":"3fdcfb668fd78ec92d9bc2daddf1d41e2a8a30bb","lessThan":"0ae42b51607240990614e0843f0d3529aaff62cc","versionType":"git","status":"affected"},{"version":"3fdcfb668fd78ec92d9bc2daddf1d41e2a8a30bb","lessThan":"ad09aa45965d3fafaf9963bc78109b73c0f9ac8d","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["fs/ext4/inode.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"3.8","status":"affected"},{"version":"0","lessThan":"3.8","versionType":"semver","status":"unaffected"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.97","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/0ae42b51607240990614e0843f0d3529aaff62cc","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/260830a9a706f5d335398236fc788ce32f220de1","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/9808ae9fae996afa942bd963a39c9b1cdeebd0bd","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/ad09aa45965d3fafaf9963bc78109b73c0f9ac8d","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/f00f5c0dd55319bc33b76f72c853bda0e0a32eda","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-74309","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:22:30.823","lastModified":"2026-08-15T06:22:30.823","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nvdpa/octeon_ep: fix IRQ-to-ring mapping in interrupt handler\n\nLook up the IRQ index in oct_hw->irqs instead of assuming\nirq - irqs[0]. This supports non-contiguous IRQ numbers and\navoids incorrect ring indexing when irqs[0] is not the base."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/vdpa/octeon_ep/octep_vdpa_main.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"26f8ce06af6475b33b0bc60261e9f5027f9af58f","lessThan":"3ef0cfa77a3d526591be069850d186c255e3f0cc","versionType":"git","status":"affected"},{"version":"26f8ce06af6475b33b0bc60261e9f5027f9af58f","lessThan":"c6c7eae5de798442987619434171ac886035d57c","versionType":"git","status":"affected"},{"version":"26f8ce06af6475b33b0bc60261e9f5027f9af58f","lessThan":"0d21a1d6375a05274291e32c1ab7cd57dbb69513","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/vdpa/octeon_ep/octep_vdpa_main.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.14","status":"affected"},{"version":"0","lessThan":"6.14","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/0d21a1d6375a05274291e32c1ab7cd57dbb69513","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/3ef0cfa77a3d526591be069850d186c255e3f0cc","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/c6c7eae5de798442987619434171ac886035d57c","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-74310","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:22:30.987","lastModified":"2026-08-15T06:22:30.987","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nvhost/net: complete zerocopy ubufs only once\n\nvhost-net initializes one ubuf_info per outstanding zerocopy TX\ndescriptor and hands it to the backend socket.  The networking stack may\nthen clone a zerocopy skb before all skb references are released.  For\nexample, batman-adv fragmentation reaches skb_split(), which calls\nskb_zerocopy_clone() and increments the same ubuf_info refcount.\n\nvhost_zerocopy_complete() currently treats every ubuf callback as a\ncompleted vhost descriptor.  It dereferences ubuf->ctx, writes the\ndescriptor completion state, and drops the vhost_net_ubuf_ref even when\nthe callback only releases a cloned skb reference.  A backend reset can\ntherefore wait for and free the vhost_net_ubuf_ref while another cloned\nskb still carries the same ubuf_info.  A later completion then\ndereferences the freed ubufs pointer.\n\nKASAN reports the stale completion as:\n\n  BUG: KASAN: slab-use-after-free in vhost_zerocopy_complete+0x1d7/0x1f0\n  BUG: KASAN: slab-use-after-free in vhost_zerocopy_complete+0x101/0x1f0\n  vhost_zerocopy_complete\n  skb_copy_ubufs\n  __dev_forward_skb2\n  veth_xmit\n\nThe freed object was allocated from vhost_net_ioctl() while setting the\nbackend and freed through kfree_rcu()/kvfree_rcu_bulk after backend\nremoval, while delayed skb completion still reached\nvhost_zerocopy_complete().\n\nHonor the generic ubuf_info refcount before touching vhost state, and run\nthe vhost descriptor completion only for the final ubuf reference.  This\nmatches the msg_zerocopy_complete() ownership rule for cloned zerocopy\nskbs."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/vhost/net.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"bab632d69ee48a106e779b60cc01adfe80a72807","lessThan":"ea71f873423fb73e66ad88936d6759ac0ad4aa53","versionType":"git","status":"affected"},{"version":"bab632d69ee48a106e779b60cc01adfe80a72807","lessThan":"6445b945024f4c7675ae5352b2d5885cb1deea71","versionType":"git","status":"affected"},{"version":"bab632d69ee48a106e779b60cc01adfe80a72807","lessThan":"a9f8a1d2e3ff511eafd4c5462481950c2f4d2b5d","versionType":"git","status":"affected"},{"version":"bab632d69ee48a106e779b60cc01adfe80a72807","lessThan":"321c73baf54d971ce3771fea275c98a247f7ee35","versionType":"git","status":"affected"},{"version":"bab632d69ee48a106e779b60cc01adfe80a72807","lessThan":"c069437924663539a93a1e5afe90838d9ccee284","versionType":"git","status":"affected"},{"version":"bab632d69ee48a106e779b60cc01adfe80a72807","lessThan":"8f6898fe80794f2d7c3d38c1158c806e4074a1c4","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/vhost/net.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"3.1","status":"affected"},{"version":"0","lessThan":"3.1","versionType":"semver","status":"unaffected"},{"version":"6.1.178","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.97","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/321c73baf54d971ce3771fea275c98a247f7ee35","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/6445b945024f4c7675ae5352b2d5885cb1deea71","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/8f6898fe80794f2d7c3d38c1158c806e4074a1c4","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/a9f8a1d2e3ff511eafd4c5462481950c2f4d2b5d","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/c069437924663539a93a1e5afe90838d9ccee284","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/ea71f873423fb73e66ad88936d6759ac0ad4aa53","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-74311","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:22:31.173","lastModified":"2026-08-15T06:22:31.173","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nvirtio: rtc: tear down old virtqueues before restore\n\nvirtio_device_restore() resets the device and restores the negotiated\nfeatures before calling ->restore(). viortc_freeze() intentionally\nleaves the existing virtqueues in place so the alarm queue can still\nwake the system, but viortc_restore() immediately calls\nviortc_init_vqs() without first deleting those old queues.\n\nIf virtqueue reinitialization fails on virtio-pci, the transport error\npath can run vp_del_vqs() against a newly allocated vp_dev->vqs array\nwhile vdev->vqs still contains the old virtqueues. vp_del_vqs() then\nlooks up queue state through the new array and can dereference a NULL\ninfo pointer in vp_del_vq(), crashing the guest kernel during restore.\n\nThis can also happen during a non-faulty reinitialization, when one of\nthe vp_find_vqs_msix() attempts is unsuccessful before a later attempt\nwould succeed.\n\nDelete the stale virtqueues before rebuilding them. If restore fails\nbefore virtio_device_ready(), reuse the remove path to stop the device.\nOnce the device is ready, return errors directly instead of deleting the\nvirtqueues again."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/virtio/virtio_rtc_driver.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"0623c759276885c3ae88197ba6fb5c9c6ba8612f","lessThan":"79366023aa891ca31376021a7bccff6384ca1ff1","versionType":"git","status":"affected"},{"version":"0623c759276885c3ae88197ba6fb5c9c6ba8612f","lessThan":"aebebd1e9d70b650fc9e877082e0134edcf511da","versionType":"git","status":"affected"},{"version":"0623c759276885c3ae88197ba6fb5c9c6ba8612f","lessThan":"548d2208455f14e6121404c6e30e997bfe0cd264","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/virtio/virtio_rtc_driver.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.16","status":"affected"},{"version":"0","lessThan":"6.16","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/548d2208455f14e6121404c6e30e997bfe0cd264","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/79366023aa891ca31376021a7bccff6384ca1ff1","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/aebebd1e9d70b650fc9e877082e0134edcf511da","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-74312","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:22:31.310","lastModified":"2026-08-15T06:22:31.310","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nvhost/vdpa: validate virtqueue index in mmap and fault paths\n\nvhost_vdpa_mmap() and vhost_vdpa_fault() use vma->vm_pgoff as a\nvirtqueue index for get_vq_notification(), but they do not validate\nthat the index is smaller than v->nvqs.\n\nThe ioctl path already performs both a bounds check and\narray_index_nospec(), but the mmap/fault path only checks that the\nindex fits in u16. This allows an out-of-range queue index to reach\ndriver-specific get_vq_notification() callbacks.\n\nFix this by extracting a unified vhost_vdpa_get_vq_notification()\nhelper that validates the queue index against v->nvqs and applies\narray_index_nospec() before calling the driver callback. Both the\nmmap and fault paths use this helper, and the bounds checking is\nconsolidated into a single location.\n\nFrom source inspection, the most defensible impact is out-of-bounds\naccess in the callback path, potentially leading to invalid PFN\nremaps and crash/DoS."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/vhost/vdpa.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"ddd89d0a059d8e9740c75a97e0efe9bf07ee51f9","lessThan":"0f310bac6db9bd3bb1655707d692d9d2a86eeb17","versionType":"git","status":"affected"},{"version":"ddd89d0a059d8e9740c75a97e0efe9bf07ee51f9","lessThan":"4bf5a51963ff816f7443702dc536b9327cf5e550","versionType":"git","status":"affected"},{"version":"ddd89d0a059d8e9740c75a97e0efe9bf07ee51f9","lessThan":"55a644031e610ea93fbde2702c7b8f267476552f","versionType":"git","status":"affected"},{"version":"ddd89d0a059d8e9740c75a97e0efe9bf07ee51f9","lessThan":"2b3f79b90b231a682315fe2191bb71925650e183","versionType":"git","status":"affected"},{"version":"ddd89d0a059d8e9740c75a97e0efe9bf07ee51f9","lessThan":"bbba4f92515238d76018e9b75e41b16d83df52c8","versionType":"git","status":"affected"},{"version":"ddd89d0a059d8e9740c75a97e0efe9bf07ee51f9","lessThan":"1f5f94c6c6b2e4eaa5b45815509e21d0c6cfa81e","versionType":"git","status":"affected"},{"version":"ddd89d0a059d8e9740c75a97e0efe9bf07ee51f9","lessThan":"32ac9097aa2463fcfc12f61cc4a9ebc3579cba7d","versionType":"git","status":"affected"},{"version":"ddd89d0a059d8e9740c75a97e0efe9bf07ee51f9","lessThan":"929e4f044621c8cc30b612fb74e1410bef09e41b","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/vhost/vdpa.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"5.8","status":"affected"},{"version":"0","lessThan":"5.8","versionType":"semver","status":"unaffected"},{"version":"5.10.261","lessThanOrEqual":"5.10.*","versionType":"semver","status":"unaffected"},{"version":"5.15.212","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.178","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.97","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/0f310bac6db9bd3bb1655707d692d9d2a86eeb17","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/1f5f94c6c6b2e4eaa5b45815509e21d0c6cfa81e","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/2b3f79b90b231a682315fe2191bb71925650e183","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/32ac9097aa2463fcfc12f61cc4a9ebc3579cba7d","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/4bf5a51963ff816f7443702dc536b9327cf5e550","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/55a644031e610ea93fbde2702c7b8f267476552f","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/929e4f044621c8cc30b612fb74e1410bef09e41b","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/bbba4f92515238d76018e9b75e41b16d83df52c8","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-74313","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:22:31.460","lastModified":"2026-08-15T06:22:31.460","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nvduse: hold vduse_lock across IDR lookup in open path\n\nvduse_dev_open() looks up struct vduse_dev through the IDR and then\nacquires dev->lock only after vduse_lock has been dropped.\n\nThis leaves a window where a concurrent VDUSE_DESTROY_DEV can remove the\nsame object from the IDR and free it before the open path locks the\ndevice, leading to a use-after-free.\n\nClose this race by keeping vduse_lock held until dev->lock has been\nacquired in the open path, matching the lock ordering already used by\nthe destroy path."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/vdpa/vdpa_user/vduse_dev.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"c8a6153b6c59d95c0e091f053f6f180952ade91e","lessThan":"35483c5306e09b3190ff937089d404a78012695c","versionType":"git","status":"affected"},{"version":"c8a6153b6c59d95c0e091f053f6f180952ade91e","lessThan":"5c1560be8aa6849356455af67518d35c551cbd95","versionType":"git","status":"affected"},{"version":"c8a6153b6c59d95c0e091f053f6f180952ade91e","lessThan":"93ed4692f2299a40346025979f40e4a9b7b33af7","versionType":"git","status":"affected"},{"version":"c8a6153b6c59d95c0e091f053f6f180952ade91e","lessThan":"d94e2947203aead590fd63f667d316d4475d65af","versionType":"git","status":"affected"},{"version":"c8a6153b6c59d95c0e091f053f6f180952ade91e","lessThan":"a2d0a57538fd0b3b3ab75d64bb64f4cd2fab13a2","versionType":"git","status":"affected"},{"version":"c8a6153b6c59d95c0e091f053f6f180952ade91e","lessThan":"79e12c891940b0c4c75881b7fd82a8cbb8ac97be","versionType":"git","status":"affected"},{"version":"c8a6153b6c59d95c0e091f053f6f180952ade91e","lessThan":"e440e077748939839d9f76e24383b76b785f80ce","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/vdpa/vdpa_user/vduse_dev.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"5.15","status":"affected"},{"version":"0","lessThan":"5.15","versionType":"semver","status":"unaffected"},{"version":"5.15.212","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.178","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.97","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/35483c5306e09b3190ff937089d404a78012695c","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/5c1560be8aa6849356455af67518d35c551cbd95","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/79e12c891940b0c4c75881b7fd82a8cbb8ac97be","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/93ed4692f2299a40346025979f40e4a9b7b33af7","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/a2d0a57538fd0b3b3ab75d64bb64f4cd2fab13a2","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/d94e2947203aead590fd63f667d316d4475d65af","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/e440e077748939839d9f76e24383b76b785f80ce","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-74314","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:22:31.617","lastModified":"2026-08-15T06:22:31.617","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nbpf: Cancel special fields on map value recycle\n\nMap update and delete paths currently call bpf_obj_free_fields() when a\nvalue is being replaced or recycled. That makes field destruction depend\non the context of the update/delete operation. For tracing programs this\ncan include NMI context, where referenced kptr destructors, uptr\nunpinning, and graph root destruction are not generally safe.\n\nIntroduce bpf_obj_cancel_fields() for the reusable-value path. It only\nperforms NMI-safe cleanup for timer, workqueue, and task_work fields.\nFields that need full destruction are left attached to the recycled value\nand are destroyed by the final cleanup path instead.\n\nSwitch array and hashtab update/delete/recycle paths to this cancel\nhelper. Keep bpf_obj_free_fields() for final map destruction and for\nbpf_mem_alloc destructors. Preallocated hashtabs do not have allocator\ndestructors, so teardown continues to walk the normal and extra elements\nand fully destroy their fields.\n\nThis deliberately relaxes the eager-free semantics of map update/delete\nfor special fields. Programs that relied on a recycled map slot becoming\nempty immediately after update/delete were relying on behavior that\ncannot be implemented safely from every BPF execution context without\noffloading arbitrary destructors.\n\nThere is a chance this change breaks programs making assumptions\nregarding the eager freeing of fields. If so, we can relax semantics to\ncancellation only when irqs_disabled() is true in the future. However,\ntheoretically, map values that get reused eagerly already have weaker\nguarantees as parallel users can recreate freed fields before the new\nelement becomes visible again."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["include/linux/bpf.h","kernel/bpf/arraymap.c","kernel/bpf/hashtab.c","kernel/bpf/syscall.c","tools/testing/selftests/bpf/prog_tests/htab_update.c","tools/testing/selftests/bpf/prog_tests/linked_list.c","tools/testing/selftests/bpf/prog_tests/map_kptr.c","tools/testing/selftests/bpf/prog_tests/refcounted_kptr.c","tools/testing/selftests/bpf/progs/htab_update.c","tools/testing/selftests/bpf/progs/linked_list.c","tools/testing/selftests/bpf/progs/refcounted_kptr.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"14a324f6a67ef6a53e04362a70160a47eb8afffa","lessThan":"9ea734e2cc0143d7429ab7dc0b20c85e5836183c","versionType":"git","status":"affected"},{"version":"14a324f6a67ef6a53e04362a70160a47eb8afffa","lessThan":"a3a81d247651218e47153f2d2afd7aee236726fd","versionType":"git","status":"affected"},{"version":"f0462d38589422bc9e27fd3c6343dfeb6b3db2f9","versionType":"git","status":"affected"},{"version":"5.18.18","lessThan":"5.19","versionType":"semver","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["include/linux/bpf.h","kernel/bpf/arraymap.c","kernel/bpf/hashtab.c","kernel/bpf/syscall.c","tools/testing/selftests/bpf/prog_tests/htab_update.c","tools/testing/selftests/bpf/prog_tests/linked_list.c","tools/testing/selftests/bpf/prog_tests/map_kptr.c","tools/testing/selftests/bpf/prog_tests/refcounted_kptr.c","tools/testing/selftests/bpf/progs/htab_update.c","tools/testing/selftests/bpf/progs/linked_list.c","tools/testing/selftests/bpf/progs/refcounted_kptr.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"5.19","status":"affected"},{"version":"0","lessThan":"5.19","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/9ea734e2cc0143d7429ab7dc0b20c85e5836183c","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/a3a81d247651218e47153f2d2afd7aee236726fd","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-74315","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:22:31.763","lastModified":"2026-08-15T06:22:31.763","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nlockd: Avoid hashing uninitialized bytes in nlm4svc_lookup_file()\n\nfile_hash() digests the first LOCKD_FH_HASH_SIZE bytes of\nnfs_fh.data when bucketing nlm_files[], independent of fh.size.\nCommit 3de744ee4e45 (\"lockd: Use xdrgen XDR functions for the\nNLMv4 TEST procedure\") set .pc_argzero to zero for the converted\nprocedures and moved file-handle population into\nnlm4svc_lookup_file(), which copies only xdr_lock->fh.len bytes\ninto lock->fh.data.\n\nWhen an NLMv4 client presents a file handle shorter than\nLOCKD_FH_HASH_SIZE, bytes fh.len..31 retain whatever the argument\nbuffer held from an earlier request.  The same wire handle then\nhashes to different buckets across calls; nlm_lookup_file() misses\nthe existing nlm_file entry, and lock-state lookups fail.\n\nZero only the tail bytes that file_hash() would otherwise consume.\nHandles of LOCKD_FH_HASH_SIZE or larger already populate every byte\nthat file_hash() reads."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["fs/lockd/lockd.h","fs/lockd/svc4proc.c","fs/lockd/svcsubs.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"3de744ee4e4557da0d63be8a97ad44b4dad58912","lessThan":"686c2434f9f16b87aeed18d76cc562df9f2695ab","versionType":"git","status":"affected"},{"version":"3de744ee4e4557da0d63be8a97ad44b4dad58912","lessThan":"6e4c62caecf792e8a15ad9bc7f371e57c17e3302","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["fs/lockd/lockd.h","fs/lockd/svc4proc.c","fs/lockd/svcsubs.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"7.1","status":"affected"},{"version":"0","lessThan":"7.1","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/686c2434f9f16b87aeed18d76cc562df9f2695ab","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/6e4c62caecf792e8a15ad9bc7f371e57c17e3302","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-74316","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:22:31.890","lastModified":"2026-08-15T06:22:31.890","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nNFSD: Handle layout stid in nfsd4_drop_revoked_stid()\n\nnfsd4_drop_revoked_stid() has no SC_TYPE_LAYOUT case, so when a\nclient sends FREE_STATEID for an admin-revoked layout stid, the\ndefault branch releases cl_lock and returns without unhashing or\nreleasing the stid.  The stid remains in the IDR and on the\nper-client list until the client is destroyed.\n\nRemove the layout stid from the per-client list and call\nnfs4_put_stid() to drop the creation reference.  When the\nrefcount reaches zero, nfsd4_free_layout_stateid() handles the\nremaining cleanup: cancelling the fence worker, removing from\nthe per-file list, and freeing the slab object."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["fs/nfsd/nfs4state.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"1e33e1414bec54a4feafa9e67e2617031be0afe2","lessThan":"7ed62f7040ee182cf7dea5798f9e114235b31dae","versionType":"git","status":"affected"},{"version":"1e33e1414bec54a4feafa9e67e2617031be0afe2","lessThan":"da6f86ff4f2dd490bea52419a49e19680efd5847","versionType":"git","status":"affected"},{"version":"1e33e1414bec54a4feafa9e67e2617031be0afe2","lessThan":"8024028ef91616cf91cc669f2446a0406bc0ba19","versionType":"git","status":"affected"},{"version":"1e33e1414bec54a4feafa9e67e2617031be0afe2","lessThan":"86b9898920a6d02b4149f4fef9efd77b8aa3b9ca","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["fs/nfsd/nfs4state.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.9","status":"affected"},{"version":"0","lessThan":"6.9","versionType":"semver","status":"unaffected"},{"version":"6.12.97","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/7ed62f7040ee182cf7dea5798f9e114235b31dae","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/8024028ef91616cf91cc669f2446a0406bc0ba19","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/86b9898920a6d02b4149f4fef9efd77b8aa3b9ca","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/da6f86ff4f2dd490bea52419a49e19680efd5847","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-74317","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:22:32.033","lastModified":"2026-08-15T06:22:32.033","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nixgbe: do not configure xps for XDP queues\n\nnetif_set_xps_queue() should not be called for an XDP Tx queue, since such\nqueues are not netdev-exposed. On systems with number of CPUs >=64, on E610\nadapter, netdev is configured with maximum number queue pairs being 63\n(due to MSI-X assignment), but configuring XDP results in 64 XDP queues.\n\nSo, during XDP program load, when netif_set_xps_queue() is called for the\nlast XDP queue, we get a WARNING with a call trace and KASAN report\nafterwards (if enabled).\n\n[ 2012.699800] WARNING: net/core/dev.c:2854 at __netif_set_xps_queue+0x116a/0x1e40, CPU#36: xdpsock/103668\n[...]\n[ 2012.700029] RIP: 0010:__netif_set_xps_queue+0x116a/0x1e40\n[ 2012.700035] Code: b6 34 06 48 89 f8 83 e0 07 83 c0 01 40 38 f0 7c 09 40 84 f6 0f 85 03 0a 00 00 0f b7 44 24 40 66 43 89 44 6a 18 e9 01 fb ff ff <0f> 0b e9 f2 ee ff ff 44 8b 44 24 44 45 85 c0 74 50 4d 85 e4 0f 84\n[ 2012.700040] RSP: 0018:ffff8882369aeb28 EFLAGS: 00010246\n[ 2012.700046] RAX: 0000000000000000 RBX: 000000000000003f RCX: 0000000000000000\n[ 2012.700050] RDX: 1ffff1111da3d891 RSI: ffff888120e34250 RDI: ffff8888ed1ec488\n[ 2012.700054] RBP: ffff888913281560 R08: 0000000000000000 R09: ffff8888ed1ec000\n[ 2012.700058] R10: ffff8888a2e83180 R11: 0000000000000000 R12: 0000000000007fa8\n[ 2012.700061] R13: 000000000000003f R14: ffff888120e34854 R15: ffff8889132817c8\n[ 2012.700065] FS:  00007fc8ea9ff740(0000) GS:ffff88884cefe000(0000) knlGS:0000000000000000\n[ 2012.700069] CS:  0010 DS: 0000 ES: 0000 CR0: 0000000080050033\n[ 2012.700073] CR2: 00007f81c8000020 CR3: 00000002299f8006 CR4: 00000000007726f0\n[ 2012.700077] PKRU: 55555554\n[ 2012.700080] Call Trace:\n[ 2012.700084]  <TASK>\n[ 2012.700087]  ? ktime_get+0x61/0x150\n[ 2012.700097]  ? usleep_range_state+0x133/0x1b0\n[ 2012.700108]  ? __pfx_usleep_range_state+0x10/0x10\n[ 2012.700114]  netif_set_xps_queue+0x31/0x50\n[ 2012.700119]  ixgbe_configure_tx_ring+0x472/0x920 [ixgbe]\n[...]\n[ 2012.700486]  ixgbe_xdp+0x38f/0x750 [ixgbe]\n\n[...]\n\n[ 2012.701094] BUG: KASAN: slab-out-of-bounds in __netif_set_xps_queue+0x1ac5/0x1e40\n[ 2012.701100] Write of size 4 at addr ffff88888d43cff8 by task xdpsock/103668\n\nSkip XPS configuration for XDP Tx queues."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/net/ethernet/intel/ixgbe/ixgbe_main.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"33fdc82f08835de4c39a00657742f5b11db00d32","lessThan":"a2a224f5e344ccb1ec3693a0735822db9214e2ca","versionType":"git","status":"affected"},{"version":"33fdc82f08835de4c39a00657742f5b11db00d32","lessThan":"7bd4355272de34c2e90e34b72c5613736d03c32b","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/net/ethernet/intel/ixgbe/ixgbe_main.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"4.12","status":"affected"},{"version":"0","lessThan":"4.12","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/7bd4355272de34c2e90e34b72c5613736d03c32b","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/a2a224f5e344ccb1ec3693a0735822db9214e2ca","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-74318","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:22:32.177","lastModified":"2026-08-15T06:22:32.177","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nbtrfs: fix deadlock cloning inline extent when using flushoncommit\n\nIn commit b48c980b6a7e (\"btrfs: fix deadlock between reflink and\ntransaction commit when using flushoncommit\") a deadlock was fixed\nbetween reflinks and transaction commits when the fs is mounted with the\nflushoncommit option. This happened when we had to copy an inline extent's\ndata to the destination file. However the issue was fixed only for the\ncase where the destination offset is 0, it missed the case when the offset\nis greater than zero.\n\nFix this by ensuring we get i_size update whenever we copied an inline\nextent's data into the destination file.\n\nSyzbot reported this with the following trace:\n\n   INFO: task kworker/u8:3:57 blocked for more than 143 seconds.\n         Not tainted syzkaller #0\n   \"echo 0 > /proc/sys/kernel/hung_task_timeout_secs\" disables this message.\n   task:kworker/u8:3    state:D stack:21600 pid:57    tgid:57    ppid:2      task_flags:0x4208160 flags:0x00080000\n   Workqueue: writeback wb_workfn (flush-btrfs-129)\n   Call Trace:\n    <TASK>\n    context_switch kernel/sched/core.c:5402 [inline]\n    __schedule+0x16f9/0x5500 kernel/sched/core.c:7204\n    __schedule_loop kernel/sched/core.c:7283 [inline]\n    schedule+0x164/0x360 kernel/sched/core.c:7298\n    wait_extent_bit fs/btrfs/extent-io-tree.c:905 [inline]\n    btrfs_lock_extent_bits+0x59c/0x700 fs/btrfs/extent-io-tree.c:2008\n    btrfs_lock_extent fs/btrfs/extent-io-tree.h:152 [inline]\n    btrfs_invalidate_folio+0x440/0xc00 fs/btrfs/inode.c:7718\n    extent_writepage fs/btrfs/extent_io.c:1848 [inline]\n    extent_write_cache_pages fs/btrfs/extent_io.c:2552 [inline]\n    btrfs_writepages+0x12f3/0x2410 fs/btrfs/extent_io.c:2684\n    do_writepages+0x32e/0x550 mm/page-writeback.c:2571\n    __writeback_single_inode+0x133/0x10e0 fs/fs-writeback.c:1764\n    writeback_sb_inodes+0x97f/0x1980 fs/fs-writeback.c:2056\n    wb_writeback+0x445/0xb00 fs/fs-writeback.c:2241\n    wb_do_writeback fs/fs-writeback.c:2388 [inline]\n    wb_workfn+0x3fd/0xf20 fs/fs-writeback.c:2428\n    process_one_work+0x98b/0x1630 kernel/workqueue.c:3318\n    process_scheduled_works kernel/workqueue.c:3401 [inline]\n    worker_thread+0xb49/0x1140 kernel/workqueue.c:3482\n    kthread+0x388/0x470 kernel/kthread.c:436\n    ret_from_fork+0x514/0xb70 arch/x86/kernel/process.c:158\n    ret_from_fork_asm+0x1a/0x30 arch/x86/entry/entry_64.S:245\n    </TASK>\n   INFO: task syz.0.145:8523 blocked for more than 143 seconds.\n         Not tainted syzkaller #0\n   \"echo 0 > /proc/sys/kernel/hung_task_timeout_secs\" disables this message.\n   task:syz.0.145       state:D stack:22752 pid:8523  tgid:8522  ppid:5850   task_flags:0x400140 flags:0x00080002\n   Call Trace:\n    <TASK>\n    context_switch kernel/sched/core.c:5402 [inline]\n    __schedule+0x16f9/0x5500 kernel/sched/core.c:7204\n    __schedule_loop kernel/sched/core.c:7283 [inline]\n    schedule+0x164/0x360 kernel/sched/core.c:7298\n    wb_wait_for_completion+0x3e8/0x790 fs/fs-writeback.c:227\n    __writeback_inodes_sb_nr+0x24c/0x2d0 fs/fs-writeback.c:2847\n    try_to_writeback_inodes_sb+0x9a/0xc0 fs/fs-writeback.c:2895\n    btrfs_start_delalloc_flush fs/btrfs/transaction.c:2182 [inline]\n    btrfs_commit_transaction+0x813/0x2fc0 fs/btrfs/transaction.c:2371\n    btrfs_sync_file+0xdf4/0x1230 fs/btrfs/file.c:1822\n    generic_write_sync include/linux/fs.h:2663 [inline]\n    btrfs_do_write_iter+0x6a9/0x840 fs/btrfs/file.c:1473\n    new_sync_write fs/read_write.c:595 [inline]\n    vfs_write+0x629/0xba0 fs/read_write.c:688\n    ksys_write+0x156/0x270 fs/read_write.c:740\n    do_syscall_x64 arch/x86/entry/syscall_64.c:63 [inline]\n    do_syscall_64+0x15f/0x560 arch/x86/entry/syscall_64.c:94\n    entry_SYSCALL_64_after_hwframe+0x77/0x7f\n   RIP: 0033:0x7f5a0bdece59\n   RSP: 002b:00007f5a0b446028 EFLAGS: 00000246 ORIG_RAX: 0000000000000001\n   RAX: ffffffffffffffda RBX: 00007f5a0c065fa0 RCX: 00007f5a0bdece59\n   RDX: 000000000000029f RSI: 0000200000\n---truncated---"}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["fs/btrfs/reflink.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"05a5a7621ce66c142e081ffc24dd6ade6e912061","lessThan":"06283034cec0fa357cbd85784ef7d3f5b2ce0790","versionType":"git","status":"affected"},{"version":"05a5a7621ce66c142e081ffc24dd6ade6e912061","lessThan":"2aa37c8ef1092c6f088e23a90bffefc672831c09","versionType":"git","status":"affected"},{"version":"05a5a7621ce66c142e081ffc24dd6ade6e912061","lessThan":"ea3452726ccb6bcaa732f43cc57bb928eca3dd59","versionType":"git","status":"affected"},{"version":"05a5a7621ce66c142e081ffc24dd6ade6e912061","lessThan":"532085d00eb54c074bdeae648b194765239f4d11","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["fs/btrfs/reflink.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"5.7","status":"affected"},{"version":"0","lessThan":"5.7","versionType":"semver","status":"unaffected"},{"version":"6.12.97","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/06283034cec0fa357cbd85784ef7d3f5b2ce0790","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/2aa37c8ef1092c6f088e23a90bffefc672831c09","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/532085d00eb54c074bdeae648b194765239f4d11","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/ea3452726ccb6bcaa732f43cc57bb928eca3dd59","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-74319","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:22:32.333","lastModified":"2026-08-15T06:22:32.333","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nbtrfs: zoned: fix deadlock waiting for ticket during data relocation\n\nWhen performing data relocation on a zoned filesystem, BTRFS can deadlock\nin handle_reserve_tickets(). The relocation process is waiting on a space\nreservation ticket that can never be fulfilled, because the relocation\nitself is the operation responsible for freeing up that space.\n\nFix this by introducing a new flush state,\nBTRFS_RESERVE_FLUSH_ZONED_RELOCATION, specifically for data chunk\nallocation during zoned relocation. Like\nBTRFS_RESERVE_FLUSH_FREE_SPACE_INODE, this state uses\npriority_reclaim_data_space() instead of the normal flushing path, which\navoids re-entering the relocation code and breaking the deadlock cycle.\n\nIn btrfs_alloc_data_chunk_ondemand(), select this new flush state when the\ninode belongs to a data relocation root on a zoned filesystem."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["fs/btrfs/delalloc-space.c","fs/btrfs/space-info.c","fs/btrfs/space-info.h"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"e2a7fd22378f6500bcf979edc71e6837271eacfd","lessThan":"f84dbbaa988e1344634a20ddf6c7d51a99f12477","versionType":"git","status":"affected"},{"version":"e2a7fd22378f6500bcf979edc71e6837271eacfd","lessThan":"814c3b4ea357297c507158bceb07bcdc5fbe9808","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["fs/btrfs/delalloc-space.c","fs/btrfs/space-info.c","fs/btrfs/space-info.h"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"7.1","status":"affected"},{"version":"0","lessThan":"7.1","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/814c3b4ea357297c507158bceb07bcdc5fbe9808","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/f84dbbaa988e1344634a20ddf6c7d51a99f12477","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-74320","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:22:32.457","lastModified":"2026-08-15T06:22:32.457","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nfbdev: sm501fb: Fix buffer errors in OF binding code\n\nThe code that gets the frame buffer mode from OF has 'use after free',\n'buffer overrun' and memory leaks.\n\ninfo->edid_data isn't free if the probe functions fail or if\npd->def_mode is set.\n\nIf both the CRT and PANEL are enabled info->edid_data is used after\nbeing freed and is freed twice.\n\nThe string returned by of_get_property(np, \"mode\", &len) is just\nwritten over either the static \"640x480-16@60\" or the module parameter\nstring without any regard for the length (which is most likely longer).\n\nUse kstrump() for the OF mode and free everything before freeing 'info."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/video/fbdev/sm501fb.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"4295f9bf74a885da390abc49a3b42a011c1bb890","lessThan":"0bc3d909a49e1fd8b8c3f2160d526e672c40621d","versionType":"git","status":"affected"},{"version":"4295f9bf74a885da390abc49a3b42a011c1bb890","lessThan":"47008d59c60ed896085da95f8d4dd40e1677dd3a","versionType":"git","status":"affected"},{"version":"4295f9bf74a885da390abc49a3b42a011c1bb890","lessThan":"d374f76e1257ecc5d691a765c512ed2c29a44741","versionType":"git","status":"affected"},{"version":"4295f9bf74a885da390abc49a3b42a011c1bb890","lessThan":"b2ff450f7f5cfc7143cab57c3ad70293ba8b822a","versionType":"git","status":"affected"},{"version":"4295f9bf74a885da390abc49a3b42a011c1bb890","lessThan":"9057e3f5db39f0ef0dac2f59f2bc59bf17e36c31","versionType":"git","status":"affected"},{"version":"4295f9bf74a885da390abc49a3b42a011c1bb890","lessThan":"de590cdf7efec8a0b6da90ae2ab5fc5df26810b9","versionType":"git","status":"affected"},{"version":"4295f9bf74a885da390abc49a3b42a011c1bb890","lessThan":"48cf0f4c6581ec90104cec9c5bf794a8bf347e30","versionType":"git","status":"affected"},{"version":"4295f9bf74a885da390abc49a3b42a011c1bb890","lessThan":"d8421e09382cfe0bd2a044c8b0a822f64855dd4e","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/video/fbdev/sm501fb.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"2.6.39","status":"affected"},{"version":"0","lessThan":"2.6.39","versionType":"semver","status":"unaffected"},{"version":"5.10.261","lessThanOrEqual":"5.10.*","versionType":"semver","status":"unaffected"},{"version":"5.15.212","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.178","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.97","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/0bc3d909a49e1fd8b8c3f2160d526e672c40621d","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/47008d59c60ed896085da95f8d4dd40e1677dd3a","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/48cf0f4c6581ec90104cec9c5bf794a8bf347e30","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/9057e3f5db39f0ef0dac2f59f2bc59bf17e36c31","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/b2ff450f7f5cfc7143cab57c3ad70293ba8b822a","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/d374f76e1257ecc5d691a765c512ed2c29a44741","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/d8421e09382cfe0bd2a044c8b0a822f64855dd4e","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/de590cdf7efec8a0b6da90ae2ab5fc5df26810b9","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-74321","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:22:32.600","lastModified":"2026-08-15T06:22:32.600","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nbtrfs: fix invalid pointer dereference in __btrfs_run_delayed_refs()\n\nIn the beginning of the loop, we try to obtain a locked delayed ref head,\nif 'locked_ref' is currently NULL, by calling btrfs_select_ref_head(),\nwhich can return an error pointer. If the error pointer is -EAGAIN we do\na continue and go back to the beginning of the loop, which will not try\nagain to call btrfs_select_ref_head() since 'locked_ref' is no longer\nNULL but it's ERR_PTR(-EAGAIN), and then we do:\n\n   spin_lock(&locked_ref->lock);\n\nagainst a ERR_PTR(-EAGAIN) value, generating an invalid pointer\ndereference.\n\nFix this by ensuring that 'locked_ref' is set to NULL when\nbtrfs_select_ref_head() returns ERR_PTR(-EAGAIN) and incrementing 'count'\nas well, to prevent infinite looping. We do this by doing a goto to the\nbottom of the loop that already sets 'locked_ref' to NULL and does a\ncond_resched(), with an increment to 'count' right before the goto.\nThese measures were in place before the refactoring in commit 0110a4c43451\n(\"btrfs: refactor __btrfs_run_delayed_refs loop\") but were unintentionally\nlost afterwards."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["fs/btrfs/extent-tree.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"0110a4c43451533de1ea1bbdc57b5d452f9d8b25","lessThan":"c372ca227e16bace86f1df1fa4ae6849e2fcfa28","versionType":"git","status":"affected"},{"version":"0110a4c43451533de1ea1bbdc57b5d452f9d8b25","lessThan":"a71143590ce9764dbcb47617647592ff8b4d48bc","versionType":"git","status":"affected"},{"version":"0110a4c43451533de1ea1bbdc57b5d452f9d8b25","lessThan":"65770111a2d47c2b15e20b2ba92bb12198f289d4","versionType":"git","status":"affected"},{"version":"0110a4c43451533de1ea1bbdc57b5d452f9d8b25","lessThan":"015dc4a1e0c2cba551d4620eba13d26d5081dc34","versionType":"git","status":"affected"},{"version":"0110a4c43451533de1ea1bbdc57b5d452f9d8b25","lessThan":"ba9fa2ff5981589bb49094d3358c339b37c47f53","versionType":"git","status":"affected"},{"version":"0110a4c43451533de1ea1bbdc57b5d452f9d8b25","lessThan":"3b15d02be05e74321adb1e0ae0cb4ccfba7c6cb1","versionType":"git","status":"affected"},{"version":"0110a4c43451533de1ea1bbdc57b5d452f9d8b25","lessThan":"9faa6b69ad73f03c7bde53e07d75a28822dc9a1a","versionType":"git","status":"affected"},{"version":"0110a4c43451533de1ea1bbdc57b5d452f9d8b25","lessThan":"486f8298b6188ff11ef1f4be7f1d5d2e4d1b1fae","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["fs/btrfs/extent-tree.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"4.20","status":"affected"},{"version":"0","lessThan":"4.20","versionType":"semver","status":"unaffected"},{"version":"5.10.261","lessThanOrEqual":"5.10.*","versionType":"semver","status":"unaffected"},{"version":"5.15.212","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.178","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.97","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/015dc4a1e0c2cba551d4620eba13d26d5081dc34","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/3b15d02be05e74321adb1e0ae0cb4ccfba7c6cb1","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/486f8298b6188ff11ef1f4be7f1d5d2e4d1b1fae","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/65770111a2d47c2b15e20b2ba92bb12198f289d4","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/9faa6b69ad73f03c7bde53e07d75a28822dc9a1a","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/a71143590ce9764dbcb47617647592ff8b4d48bc","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/ba9fa2ff5981589bb49094d3358c339b37c47f53","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/c372ca227e16bace86f1df1fa4ae6849e2fcfa28","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-74322","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:22:32.757","lastModified":"2026-08-15T06:22:32.757","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: mt76: mt7996: Fix possible NULL pointer dereference in mt7996_mac_write_txwi_80211()\n\nFor injected frames (e.g. via radiotap), mac80211 can pass\ninfo->control.vif = NULL, as explicitly noted in struct ieee80211_tx_info.\nCheck vif pointer before executing ieee80211_vif_is_mld() in\nmt7996_mac_write_txwi_80211 routine in order to avoid a possible NULL\npointer dereference."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/net/wireless/mediatek/mt76/mt7996/mac.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"f0b0b239b8f36cdc55cf0bc1bac75ec07fc9fef1","lessThan":"dfb27e5dd9e4d34fbb74fa834c644dcef0be2be9","versionType":"git","status":"affected"},{"version":"f0b0b239b8f36cdc55cf0bc1bac75ec07fc9fef1","lessThan":"63e6151b9791b31877a88ff62806e7c407683955","versionType":"git","status":"affected"},{"version":"f0b0b239b8f36cdc55cf0bc1bac75ec07fc9fef1","lessThan":"61370e6674b5253de5686813ceeceebc35a7d3e5","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/net/wireless/mediatek/mt76/mt7996/mac.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.15","status":"affected"},{"version":"0","lessThan":"6.15","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/61370e6674b5253de5686813ceeceebc35a7d3e5","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/63e6151b9791b31877a88ff62806e7c407683955","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/dfb27e5dd9e4d34fbb74fa834c644dcef0be2be9","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-74323","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:22:32.877","lastModified":"2026-08-15T06:22:32.877","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: mt76: mt7996: Fix possible token leak in mt7996_tx_prepare_skb()\n\nIf link_conf or link_sta lookup fails in mt7996_tx_prepare_skb routine,\nmt7996 driver leaks an already allocated tx token. Fix the issue\nreleasing the token in case of error."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/net/wireless/mediatek/mt76/mt7996/mac.c","drivers/net/wireless/mediatek/mt76/tx.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"7ef0c7ad735b0c38140259519a3f165bee2b857c","lessThan":"06e65d6cf80490bc0457d339595d1ed5a89e8899","versionType":"git","status":"affected"},{"version":"7ef0c7ad735b0c38140259519a3f165bee2b857c","lessThan":"fa0e9aa92a7bc97fc42014c5efaaf1278fa92723","versionType":"git","status":"affected"},{"version":"7ef0c7ad735b0c38140259519a3f165bee2b857c","lessThan":"831074096d0450308357271fc0ffd3f600a2487e","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/net/wireless/mediatek/mt76/mt7996/mac.c","drivers/net/wireless/mediatek/mt76/tx.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.18","status":"affected"},{"version":"0","lessThan":"6.18","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/06e65d6cf80490bc0457d339595d1ed5a89e8899","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/831074096d0450308357271fc0ffd3f600a2487e","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/fa0e9aa92a7bc97fc42014c5efaaf1278fa92723","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-74324","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:22:33.000","lastModified":"2026-08-15T06:22:33.000","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: mt76: mt7925: validate skb length in testmode query\n\nIn mt7925_tm_query(), the response skb from mt76_mcu_send_and_get_msg()\nis used in a memcpy without validating its length:\n\n  memcpy(evt_resp, skb->data + 8, MT7925_EVT_RSP_LEN);\n\nwhere MT7925_EVT_RSP_LEN is 512. If the firmware returns a response\nshorter than 520 bytes (8 + 512), this reads beyond the skb data\nbuffer. The over-read data is then returned to userspace via nla_put()\nin mt7925_testmode_dump().\n\nAdd a length check before the memcpy to ensure the skb contains\nsufficient data."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/net/wireless/mediatek/mt76/mt7925/testmode.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"c948b5da6bbec742b433138e3e3f9537a85af2e5","lessThan":"c386e90a7ce8ddec9f038e9437661a2821b0ce89","versionType":"git","status":"affected"},{"version":"c948b5da6bbec742b433138e3e3f9537a85af2e5","lessThan":"e8b214b6d6e1902025452db0a0af73dc9693e4ba","versionType":"git","status":"affected"},{"version":"c948b5da6bbec742b433138e3e3f9537a85af2e5","lessThan":"c7369a00860a0704461d440e7c3bf9b49bfdbaee","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/net/wireless/mediatek/mt76/mt7925/testmode.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.7","status":"affected"},{"version":"0","lessThan":"6.7","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/c386e90a7ce8ddec9f038e9437661a2821b0ce89","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/c7369a00860a0704461d440e7c3bf9b49bfdbaee","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/e8b214b6d6e1902025452db0a0af73dc9693e4ba","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-74325","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:22:33.130","lastModified":"2026-08-15T06:22:33.130","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: mt76: use kfree_rcu for offchannel link in mt76_put_vif_phy_link\n\nmt76_put_vif_phy_link() frees the offchannel mlink with plain kfree()\nafter rcu_assign_pointer(NULL). However, rcu_assign_pointer only prevents\nfuture RCU readers from obtaining the pointer -- it does not wait for\nexisting readers that already hold it via rcu_dereference.\n\nThe TX datapath (e.g. mt7996_mac_write_txwi) dereferences mlink->wcid\nand mlink->idx under rcu_read_lock. If a TX softirq obtained the pointer\nvia rcu_dereference just before the NULL assignment, it will dereference\nfreed memory after the kfree.\n\nstruct mt76_vif_link already contains an rcu_head field that is unused at\nthis free site -- a developer oversight, since the adjacent\nkfree_rcu_mightsleep call for rx_sc in the same function shows the\npattern was understood.\n\nReplace kfree(mlink) with kfree_rcu(mlink, rcu_head)."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/net/wireless/mediatek/mt76/channel.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"a8f424c1287cc79a06c21816658feea87dfcb83f","lessThan":"c7a83899203ed36696a2d35ddd03c0f522874a63","versionType":"git","status":"affected"},{"version":"a8f424c1287cc79a06c21816658feea87dfcb83f","lessThan":"50e700ac0edce72dee5c3a9755865d9423696ac7","versionType":"git","status":"affected"},{"version":"a8f424c1287cc79a06c21816658feea87dfcb83f","lessThan":"7fae097aa9a56c30febf539d72ef3773165d3aa3","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/net/wireless/mediatek/mt76/channel.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.14","status":"affected"},{"version":"0","lessThan":"6.14","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/50e700ac0edce72dee5c3a9755865d9423696ac7","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/7fae097aa9a56c30febf539d72ef3773165d3aa3","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/c7a83899203ed36696a2d35ddd03c0f522874a63","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-74326","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:22:33.260","lastModified":"2026-08-15T06:22:33.260","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: mt76: mt7921: fix resource leak in probe error path\n\nWhen pcim_iomap_region() or devm_kmemdup() fail, the code returns\ndirectly without cleaning up previously allocated resources:\n  - mt76_device allocated by mt76_alloc_device()\n  - pci irq vectors allocated by pci_alloc_irq_vectors()\nFix this by jumping to the existing error cleanup path instead of\nreturning directly."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/net/wireless/mediatek/mt76/mt7921/pci.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"ee5bb35d2b83fadc6920aa2478326fb50ea653a9","lessThan":"79a307b2730e4b4e060cf3e19a6c21b87116ee78","versionType":"git","status":"affected"},{"version":"ee5bb35d2b83fadc6920aa2478326fb50ea653a9","lessThan":"346dac35b1384af9338b34b6835e82e634ea4d2c","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/net/wireless/mediatek/mt76/mt7921/pci.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"7.1","status":"affected"},{"version":"0","lessThan":"7.1","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/346dac35b1384af9338b34b6835e82e634ea4d2c","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/79a307b2730e4b4e060cf3e19a6c21b87116ee78","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-74327","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:22:33.383","lastModified":"2026-08-15T06:22:33.383","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nvmalloc: fix NULL pointer dereference in is_vm_area_hugepages()\n\nfind_vm_area() can return NULL if the given address is not a valid vmalloc\narea.  Check the return value before dereferencing it to avoid a kernel\ncrash."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["include/linux/vmalloc.h"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"121e6f3258fe393e22c36f61a319be8a4f2c05ae","lessThan":"c741485fa09bf5900f76d95424d86316d0a00331","versionType":"git","status":"affected"},{"version":"121e6f3258fe393e22c36f61a319be8a4f2c05ae","lessThan":"b86f98e53df4f5d57259817b8e9a00167b78bae6","versionType":"git","status":"affected"},{"version":"121e6f3258fe393e22c36f61a319be8a4f2c05ae","lessThan":"af71c2b88ccae44418e273bdfe0c96be8515151e","versionType":"git","status":"affected"},{"version":"121e6f3258fe393e22c36f61a319be8a4f2c05ae","lessThan":"a1bca6b69bd934e2731d009e645038e05d57ce59","versionType":"git","status":"affected"},{"version":"121e6f3258fe393e22c36f61a319be8a4f2c05ae","lessThan":"bbd664b7c77f6488cd5652231c0fe01d069a73ea","versionType":"git","status":"affected"},{"version":"121e6f3258fe393e22c36f61a319be8a4f2c05ae","lessThan":"55a44f5259e6a5f1d5b11cb0e19e943c9cc62280","versionType":"git","status":"affected"},{"version":"121e6f3258fe393e22c36f61a319be8a4f2c05ae","lessThan":"c55dd3b46c1208d6d2ea737a8aefef4aa4c70cb8","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["include/linux/vmalloc.h"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"5.13","status":"affected"},{"version":"0","lessThan":"5.13","versionType":"semver","status":"unaffected"},{"version":"5.15.212","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.178","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.97","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/55a44f5259e6a5f1d5b11cb0e19e943c9cc62280","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/a1bca6b69bd934e2731d009e645038e05d57ce59","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/af71c2b88ccae44418e273bdfe0c96be8515151e","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/b86f98e53df4f5d57259817b8e9a00167b78bae6","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/bbd664b7c77f6488cd5652231c0fe01d069a73ea","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/c55dd3b46c1208d6d2ea737a8aefef4aa4c70cb8","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/c741485fa09bf5900f76d95424d86316d0a00331","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-74328","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:22:33.520","lastModified":"2026-08-15T06:22:33.520","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\niommufd: Destroy the pages content after detaching from dmabuf\n\nSashiko points out this has gotten out of order, the mutex could still be\nin use through the dmabuf invalidation callbacks. Don't destroy any of the\npages content until the dmabuf is fully detached."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/iommu/iommufd/pages.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"71db84a092c399f434976d0522e848e9803cd51a","lessThan":"0507fcedbdcc87281ef8639c045fc9980363bbb6","versionType":"git","status":"affected"},{"version":"71db84a092c399f434976d0522e848e9803cd51a","lessThan":"f2d70dbd3dcefa8e3c380beff9c31f5f033a4221","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/iommu/iommufd/pages.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.19","status":"affected"},{"version":"0","lessThan":"6.19","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/0507fcedbdcc87281ef8639c045fc9980363bbb6","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/f2d70dbd3dcefa8e3c380beff9c31f5f033a4221","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-74329","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:22:33.640","lastModified":"2026-08-15T06:22:33.640","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nwatchdog: unregister PM notifier on watchdog unregister\n\nwatchdog_register_device() registers wdd->pm_nb when\nWDOG_NO_PING_ON_SUSPEND is set, but watchdog_unregister_device() does not\nremove it. This leaves an embedded notifier block on the PM notifier chain\nafter the watchdog device has been unregistered.\n\nA later suspend/resume notification can then call watchdog_pm_notifier()\nwith a stale watchdog_device pointer, or at minimum after wdd->wd_data has\nbeen cleared by watchdog_dev_unregister().\n\nUnregister the PM notifier before tearing down the watchdog device."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/watchdog/watchdog_core.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"60bcd91aafd22ef62cef9ae2037fa2e1d4da2fb3","lessThan":"cd2d1b1f99308f7680d75a377daaff363f1cc736","versionType":"git","status":"affected"},{"version":"60bcd91aafd22ef62cef9ae2037fa2e1d4da2fb3","lessThan":"5d9b58ec6f5de5e159a570d419b1b08b3b9f854b","versionType":"git","status":"affected"},{"version":"60bcd91aafd22ef62cef9ae2037fa2e1d4da2fb3","lessThan":"89184909634e50d086d86d8a0c03fc86fe8d889f","versionType":"git","status":"affected"},{"version":"60bcd91aafd22ef62cef9ae2037fa2e1d4da2fb3","lessThan":"e690afea5c876a4abfa2978c6a664460ed7d1217","versionType":"git","status":"affected"},{"version":"60bcd91aafd22ef62cef9ae2037fa2e1d4da2fb3","lessThan":"298821692d447c2f7b1bc9ef41cd88a31bf56436","versionType":"git","status":"affected"},{"version":"60bcd91aafd22ef62cef9ae2037fa2e1d4da2fb3","lessThan":"c70b5bb6f04f77ef90e047d7edc2f476e206909f","versionType":"git","status":"affected"},{"version":"60bcd91aafd22ef62cef9ae2037fa2e1d4da2fb3","lessThan":"a298c7302ee9584a7a1ac1e8acbede8d98ab51a4","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/watchdog/watchdog_core.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"5.15","status":"affected"},{"version":"0","lessThan":"5.15","versionType":"semver","status":"unaffected"},{"version":"5.15.212","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.178","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.97","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/298821692d447c2f7b1bc9ef41cd88a31bf56436","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/5d9b58ec6f5de5e159a570d419b1b08b3b9f854b","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/89184909634e50d086d86d8a0c03fc86fe8d889f","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/a298c7302ee9584a7a1ac1e8acbede8d98ab51a4","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/c70b5bb6f04f77ef90e047d7edc2f476e206909f","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/cd2d1b1f99308f7680d75a377daaff363f1cc736","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/e690afea5c876a4abfa2978c6a664460ed7d1217","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-74330","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:22:33.773","lastModified":"2026-08-15T06:22:33.773","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nconfigfs: fix lockless traversals of ->s_children\n\nHaving the parent directory locked protects entries from removal\nby another thread, but it does *not* protect cursors from being\nmoved around by lseek() - or freed, for that matter."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["fs/configfs/dir.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6f61076406251626be39651d114fac412b1e0c39","lessThan":"77fd6f50f633a52c2db061e7d71d8cb486b0265e","versionType":"git","status":"affected"},{"version":"6f61076406251626be39651d114fac412b1e0c39","lessThan":"91f289728ec706b7ff1ca0ee845dd73ff2253488","versionType":"git","status":"affected"},{"version":"6f61076406251626be39651d114fac412b1e0c39","lessThan":"b166ab78dc3f48e83d2c80bdfde4159b31fdc5fb","versionType":"git","status":"affected"},{"version":"6f61076406251626be39651d114fac412b1e0c39","lessThan":"9e57e2863872e82e7c7237bc32299f67ebebc543","versionType":"git","status":"affected"},{"version":"6f61076406251626be39651d114fac412b1e0c39","lessThan":"459860529c109c5ce08b81c0776ca1200eaaeb4a","versionType":"git","status":"affected"},{"version":"6f61076406251626be39651d114fac412b1e0c39","lessThan":"637ef4961470e04455102b34ac484a34d8eca0a4","versionType":"git","status":"affected"},{"version":"6f61076406251626be39651d114fac412b1e0c39","lessThan":"e6d93108e0a27d7e6f95c7e45017d14ba2900d32","versionType":"git","status":"affected"},{"version":"6f61076406251626be39651d114fac412b1e0c39","lessThan":"9b9e8bb81c41fd27e7b57a1c936fde140548535f","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["fs/configfs/dir.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"2.6.27","status":"affected"},{"version":"0","lessThan":"2.6.27","versionType":"semver","status":"unaffected"},{"version":"5.10.261","lessThanOrEqual":"5.10.*","versionType":"semver","status":"unaffected"},{"version":"5.15.212","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.178","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.97","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/459860529c109c5ce08b81c0776ca1200eaaeb4a","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/637ef4961470e04455102b34ac484a34d8eca0a4","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/77fd6f50f633a52c2db061e7d71d8cb486b0265e","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/91f289728ec706b7ff1ca0ee845dd73ff2253488","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/9b9e8bb81c41fd27e7b57a1c936fde140548535f","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/9e57e2863872e82e7c7237bc32299f67ebebc543","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/b166ab78dc3f48e83d2c80bdfde4159b31fdc5fb","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/e6d93108e0a27d7e6f95c7e45017d14ba2900d32","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-74331","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:22:33.907","lastModified":"2026-08-15T06:22:33.907","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nfirmware_loader: Fix recursive lock in device_cache_fw_images()\n\nA recursive locking deadlock can occur in the firmware loader's power\nmanagement notification handler.\n\nDuring system suspend or hibernation preparation, fw_pm_notify() calls\ndevice_cache_fw_images(). This function acquires fw_lock to set the\nfirmware cache state to FW_LOADER_START_CACHE and then iterates over all\ndevices using dpm_for_each_dev() while still holding the lock.\n\nFor each device, dev_cache_fw_image() schedules asynchronous work to cache\nthe firmware. If memory allocation for the async work entry fails (e.g., in\nout-of-memory conditions), async_schedule_node_domain() falls back to\nexecuting the work function synchronously in the current thread.\n\nThe synchronous execution path (__async_dev_cache_fw_image() ->\ncache_firmware() -> request_firmware() -> assign_fw()) attempts to acquire\nfw_lock again. Since the current thread already holds fw_lock, this results\nin a recursive locking deadlock.\n\nFix this by releasing fw_lock immediately after updating the cache state\nand before calling dpm_for_each_dev(). The lock is only needed to protect\nthe state update. Concurrent firmware requests will correctly see the\nFW_LOADER_START_CACHE state and use the piggyback mechanism, which is\nindependently protected by its own fwc->name_lock."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/base/firmware_loader/main.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"ac39b3ea73aacde876d1d5ee1ca3e2719f771482","lessThan":"806cb8fabfde7f830da5ae87777d52fdf50c4774","versionType":"git","status":"affected"},{"version":"ac39b3ea73aacde876d1d5ee1ca3e2719f771482","lessThan":"7865a1bfd20d10c03b083a5fc392d907ca5099b3","versionType":"git","status":"affected"},{"version":"ac39b3ea73aacde876d1d5ee1ca3e2719f771482","lessThan":"490b0385e4cfac691f7b18dde821c13e77b4770b","versionType":"git","status":"affected"},{"version":"ac39b3ea73aacde876d1d5ee1ca3e2719f771482","lessThan":"38149b57427c736c08d9aa4c7b87deacd53e9e63","versionType":"git","status":"affected"},{"version":"ac39b3ea73aacde876d1d5ee1ca3e2719f771482","lessThan":"a5b2a68a391b05d54552f13548a72a46c65006f7","versionType":"git","status":"affected"},{"version":"ac39b3ea73aacde876d1d5ee1ca3e2719f771482","lessThan":"f25d6e4ec4c257030592bd671f113cf9584c52f0","versionType":"git","status":"affected"},{"version":"ac39b3ea73aacde876d1d5ee1ca3e2719f771482","lessThan":"c0f2dedd41fe14dbe076c1672214802fb42cd8c8","versionType":"git","status":"affected"},{"version":"ac39b3ea73aacde876d1d5ee1ca3e2719f771482","lessThan":"d3ec78f8f8d48a04a9fac38d47275c34645e5103","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/base/firmware_loader/main.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"3.7","status":"affected"},{"version":"0","lessThan":"3.7","versionType":"semver","status":"unaffected"},{"version":"5.10.261","lessThanOrEqual":"5.10.*","versionType":"semver","status":"unaffected"},{"version":"5.15.212","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.178","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.97","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/38149b57427c736c08d9aa4c7b87deacd53e9e63","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/490b0385e4cfac691f7b18dde821c13e77b4770b","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/7865a1bfd20d10c03b083a5fc392d907ca5099b3","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/806cb8fabfde7f830da5ae87777d52fdf50c4774","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/a5b2a68a391b05d54552f13548a72a46c65006f7","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/c0f2dedd41fe14dbe076c1672214802fb42cd8c8","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/d3ec78f8f8d48a04a9fac38d47275c34645e5103","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/f25d6e4ec4c257030592bd671f113cf9584c52f0","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-74332","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:22:34.043","lastModified":"2026-08-15T06:22:34.043","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nASoC: amd: acp-sdw-sof: Bound DAI link iteration\n\ncreate_sdw_dailinks() walks sof_dais until it finds an entry with\ninitialised cleared, but sof_dais is allocated with exactly num_ends\nentries. If all entries are initialised, the loop reads past the end of\nthe array.\n\nPass the allocated entry count to create_sdw_dailinks() and stop before\nreading past the array."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["sound/soc/amd/acp/acp-sdw-sof-mach.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6d8348ddc56ed43ba39d1e8adda13299201f32ed","lessThan":"0a5ff4000dd7a390139dd7823fef1de4963e490a","versionType":"git","status":"affected"},{"version":"6d8348ddc56ed43ba39d1e8adda13299201f32ed","lessThan":"9e82497138abea7d5c6e65015663d907fbcbf6b4","versionType":"git","status":"affected"},{"version":"6d8348ddc56ed43ba39d1e8adda13299201f32ed","lessThan":"86a64c049873fe4d4a6a378e27a333ab5631c4b2","versionType":"git","status":"affected"},{"version":"6d8348ddc56ed43ba39d1e8adda13299201f32ed","lessThan":"4d992e63f52d58f52b724606c60ae7b37a1c582f","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["sound/soc/amd/acp/acp-sdw-sof-mach.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.12","status":"affected"},{"version":"0","lessThan":"6.12","versionType":"semver","status":"unaffected"},{"version":"6.12.97","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/0a5ff4000dd7a390139dd7823fef1de4963e490a","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/4d992e63f52d58f52b724606c60ae7b37a1c582f","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/86a64c049873fe4d4a6a378e27a333ab5631c4b2","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/9e82497138abea7d5c6e65015663d907fbcbf6b4","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-74333","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:22:34.167","lastModified":"2026-08-15T06:22:34.167","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nASoC: amd: acp-sdw-legacy: Bound DAI link iteration\n\ncreate_sdw_dailinks() walks soc_dais until it finds an entry with\ninitialised cleared, but soc_dais is allocated with exactly num_ends\nentries. If all entries are initialised, the loop reads past the end of\nthe array.\n\nThis was reported by KASAN:\n\n  BUG: KASAN: slab-out-of-bounds in mc_probe+0x26b3/0x2774 [snd_acp_sdw_legacy_mach]\n  Read of size 1\n\nPass the allocated entry count to create_sdw_dailinks() and stop before\nreading past the array."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["sound/soc/amd/acp/acp-sdw-legacy-mach.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"2981d9b0789c44b7375e7d599caf71bd843afc9e","lessThan":"1279bdab5fa1f28c168e54215db506e87c6fac1e","versionType":"git","status":"affected"},{"version":"2981d9b0789c44b7375e7d599caf71bd843afc9e","lessThan":"0230471eef5902207516851dcd47c559571dded2","versionType":"git","status":"affected"},{"version":"2981d9b0789c44b7375e7d599caf71bd843afc9e","lessThan":"d49ecdf327cc91062d2f80996a163cf65fda1e60","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["sound/soc/amd/acp/acp-sdw-legacy-mach.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.13","status":"affected"},{"version":"0","lessThan":"6.13","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/0230471eef5902207516851dcd47c559571dded2","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/1279bdab5fa1f28c168e54215db506e87c6fac1e","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/d49ecdf327cc91062d2f80996a163cf65fda1e60","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-74334","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:22:34.280","lastModified":"2026-08-15T06:22:34.280","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nRDMA/nldev: Fix locking when accessing mr->pd\n\nSashiko points out that, due to rereg_mr, the PD is actually variable and\nall the touches in nldev are racy.\n\nUse mr->device instead of mr->pd->device.\n\nGetting the PD restrack ID is more tricky. To avoid disturbing all the\nhappy paths, add an rdma_restrack_sync() operation which is sort of like\nflush_workqueue() or synchronize_irq(): after it returns, all the old\nnldev touches to the mr are gone and everything sees the new PD. This\nmakes it safe to reach into the PD pointer."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/infiniband/core/nldev.c","drivers/infiniband/core/restrack.c","drivers/infiniband/core/restrack.h","drivers/infiniband/core/uverbs_cmd.c","include/rdma/ib_verbs.h"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"da5c8507821573b8ed6e3f47e009f273493ffaf7","lessThan":"1a132ee4e655288d9a0937ea5109a0d038431ae9","versionType":"git","status":"affected"},{"version":"da5c8507821573b8ed6e3f47e009f273493ffaf7","lessThan":"50d5c02ab8e62325548bd3a6e6b758a9dcd6e7c3","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/infiniband/core/nldev.c","drivers/infiniband/core/restrack.c","drivers/infiniband/core/restrack.h","drivers/infiniband/core/uverbs_cmd.c","include/rdma/ib_verbs.h"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"4.18","status":"affected"},{"version":"0","lessThan":"4.18","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/1a132ee4e655288d9a0937ea5109a0d038431ae9","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/50d5c02ab8e62325548bd3a6e6b758a9dcd6e7c3","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-74335","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:22:34.393","lastModified":"2026-08-15T06:22:34.393","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nbpf: Fix NULL pointer dereference in bpf_task_from_vpid()\n\nbpf_task_from_vpid() looks up a task in the pid namespace of the\ncurrent task, via find_task_by_vpid():\n\n  find_task_by_vpid(vpid)\n    find_task_by_pid_ns(vpid, task_active_pid_ns(current))\n      find_pid_ns(nr, ns) -> idr_find(&ns->idr, nr)\n\ncgroup_skb programs run in softirq, which may interrupt a task that is\nitself in do_exit(). Once that task has passed\nexit_notify() -> release_task() -> __unhash_process(), its thread_pid is\ncleared, so task_active_pid_ns(current) returns NULL and find_pid_ns()\ndereferences &NULL->idr:\n\n  BUG: kernel NULL pointer dereference, address: 0000000000000050\n  RIP: 0010:idr_find+0x11/0x30 lib/idr.c:176\n  Call Trace:\n   <IRQ>\n   find_pid_ns kernel/pid.c:370 [inline]\n   find_task_by_pid_ns+0x3b/0xe0 kernel/pid.c:485\n   bpf_task_from_vpid+0x5b/0x200 kernel/bpf/helpers.c:2916\n   bpf_prog_run_array_cg+0x17e/0x530 kernel/bpf/cgroup.c:81\n   __cgroup_bpf_run_filter_skb+0x12b/0x250 kernel/bpf/cgroup.c:1612\n   sk_filter_trim_cap+0x1dc/0x4c0 net/core/filter.c:148\n   tcp_v4_rcv+0x18d1/0x2200 net/ipv4/tcp_ipv4.c:2223\n   </IRQ>\n   <TASK>\n   do_exit+0xa63/0x1270 kernel/exit.c:1010\n   get_signal+0x141c/0x1530 kernel/signal.c:3037\n\nBail out when current has no pid namespace."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["kernel/bpf/helpers.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"675c3596ff32c040d1dd2e28dd57e83e634b9f60","lessThan":"b7474f4432dd9559ada03b01a8cd3472cd02c61d","versionType":"git","status":"affected"},{"version":"675c3596ff32c040d1dd2e28dd57e83e634b9f60","lessThan":"a4c95b6221cb2972a94ed72663c09bd5b0b6dea4","versionType":"git","status":"affected"},{"version":"675c3596ff32c040d1dd2e28dd57e83e634b9f60","lessThan":"50dff00615522f3ec03449680ca23beb4cfc549c","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["kernel/bpf/helpers.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.13","status":"affected"},{"version":"0","lessThan":"6.13","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/50dff00615522f3ec03449680ca23beb4cfc549c","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/a4c95b6221cb2972a94ed72663c09bd5b0b6dea4","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/b7474f4432dd9559ada03b01a8cd3472cd02c61d","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-74336","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:22:34.510","lastModified":"2026-08-15T06:22:34.510","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: mac80211: bound S1G TIM PVB walk to the TIM element\n\nieee80211_s1g_check_tim() parses the S1G Partial Virtual Bitmap (PVB) of a\nreceived TIM element. The TIM is handed in as the element payload:\nieee802_11_parse_elems_full() stores elems->tim = elem->data and\nelems->tim_len = elem->datalen (net/mac80211/parse.c), so the valid bytes\nare [tim, tim + tim_len).\n\nWhen walking the encoded blocks the function passes the walker an end\nsentinel of (const u8 *)tim + tim_len + 2, i.e. two bytes past the end of\nthe element. ieee80211_s1g_find_target_block() loops while (ptr + 1 <= end)\nand dereferences ptr (and the per-mode ieee80211_s1g_len_*() helpers read\n*ptr), so it can read up to two bytes beyond the TIM element -- an\nout-of-bounds read of adjacent skb/heap data when the TIM is the last\nelement in the frame. The +2 appears to account for the element id/len\nheader, but tim already points past that header at the element payload, so\nthe addend is wrong.\n\nPass the correct element end, (const u8 *)tim + tim_len."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["include/linux/ieee80211-s1g.h"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"e0c47c6229c25b54440fe1f84a0ff533942290b1","lessThan":"3abc13ec3ac28c343ad7e7b7496e807b924f0edd","versionType":"git","status":"affected"},{"version":"e0c47c6229c25b54440fe1f84a0ff533942290b1","lessThan":"b224d18b1e5d1cddfc67f63f41d80023b2ec8889","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["include/linux/ieee80211-s1g.h"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.18","status":"affected"},{"version":"0","lessThan":"6.18","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/3abc13ec3ac28c343ad7e7b7496e807b924f0edd","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/b224d18b1e5d1cddfc67f63f41d80023b2ec8889","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-74337","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:22:34.623","lastModified":"2026-08-15T06:22:34.623","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nbpf: Fix NMI/tracepoint re-entry deadlock on lru locks\n\nNMI and tracepoint BPF programs can re-enter the per-CPU or global\nLRU lock that bpf_lru_pop_free()/push_free() already hold on the\nsame CPU, AA-deadlocking. Lockdep reports \"inconsistent\n{INITIAL USE} -> {IN-NMI}\" on &l->lock (syzbot c69a0a2c816716f1e0d5)\nand \"possible recursive locking detected\" on &loc_l->lock (syzbot\n18b26edb69b2e19f3b33).\n\nPrior trylock and rqspinlock based fixes (see links) were nacked\nbecause compromised on reliability.\n\nThis patch converts every LRU lock site to rqspinlock_t and adds a\nrecovery path for some failure windows to avoid node leaks.\n\nFailure recovery:\n\n - *_pop_free top-level: return NULL; prealloc_lru_pop() already\n   treats that as no-free-element (-ENOMEM).\n\n - Cross-CPU steal: skip the victim's locked loc_l, try next CPU.\n\n - Post-steal local lock fail: publish stolen node to lockless\n   per-CPU free_llist; next pop on this CPU picks it up.\n\n - push_free fail: mark node pending_free=1. __local_list_flush(),\n   __local_list_pop_pending() reclaim the node from pending_list.\n   __bpf_lru_list_shrink_inactive() reclaims the node from inactive\n   list. Nodes from active list are reclaimed by __bpf_lru_list_shrink()\n   or after __bpf_lru_list_rotate_active() demotes it to the inactive."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["kernel/bpf/bpf_lru_list.c","kernel/bpf/bpf_lru_list.h"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"3a08c2fd763450a927d1130de078d6f9e74944fb","lessThan":"8b0510cc3a4a000d4ed1a56cd96231f3d3ba94c5","versionType":"git","status":"affected"},{"version":"3a08c2fd763450a927d1130de078d6f9e74944fb","lessThan":"440a2fdbb40608d55a7b11f2be53592a3785131d","versionType":"git","status":"affected"},{"version":"3a08c2fd763450a927d1130de078d6f9e74944fb","lessThan":"89edbdfc5d0308cef57b71359331de5c4ddbf763","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["kernel/bpf/bpf_lru_list.c","kernel/bpf/bpf_lru_list.h"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"4.10","status":"affected"},{"version":"0","lessThan":"4.10","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/440a2fdbb40608d55a7b11f2be53592a3785131d","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/89edbdfc5d0308cef57b71359331de5c4ddbf763","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/8b0510cc3a4a000d4ed1a56cd96231f3d3ba94c5","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-74338","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:22:34.740","lastModified":"2026-08-15T06:22:34.740","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nbpf: Reject sleepable BPF_LSM_CGROUP programs at load time\n\nThe cgroup shim runs under rcu_read_lock_dont_migrate(), so we should\nnot attach any sleepable BPF programs there. Add support to the verifier\nto explicitly reject attempts to load sleepable BPF programs destined\nfor LSM cgroup attachment.\n\nWithout this, we get the following splat from a BPF_LSM_CGROUP\nprogram marked BPF_F_SLEEPABLE attached to file_open when it calls\nbpf_get_dentry_xattr():\n\n  BUG: sleeping function called from invalid context at kernel/locking/rwsem.c:1567\n  in_atomic(): 0, irqs_disabled(): 0, non_block: 0, pid: 34317, name: load\n  preempt_count: 0, expected: 0\n  RCU nest depth: 2, expected: 0\n  Call Trace:\n   down_read+0x76/0x480\n   ext4_xattr_get+0x11f/0x700\n   __vfs_getxattr+0xf0/0x150\n   bpf_get_dentry_xattr+0xbb/0xf0\n   bpf_prog_e76a298dac9218c6_test_open+0x6a/0x85\n   __cgroup_bpf_run_lsm_current+0x326/0x840\n   bpf_trampoline_6442534646+0x62/0x14d\n   security_file_open+0x34/0x60\n   do_dentry_open+0x340/0x1260\n   vfs_open+0x7a/0x440\n   path_openat+0x1bac/0x30a0\n\nlibbpf provides a .s named section variant for every sleepable\nprogram type except lsm_cgroup, reflecting that per-cgroup LSM programs\nare intended to only run in a non-sleepable context.\n\nThe above splat was obtained by bypassing libbpf by using bpf(2)\ndirectly."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["kernel/bpf/verifier.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"69fd337a975c7e690dfe49d9cb4fe5ba1e6db44e","lessThan":"be9eaf2bb5db4ad3de61ef739fd268fd7f135737","versionType":"git","status":"affected"},{"version":"69fd337a975c7e690dfe49d9cb4fe5ba1e6db44e","lessThan":"5b038319be442c620f774e6fc9e9283deeca1c75","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["kernel/bpf/verifier.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.0","status":"affected"},{"version":"0","lessThan":"6.0","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/5b038319be442c620f774e6fc9e9283deeca1c75","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/be9eaf2bb5db4ad3de61ef739fd268fd7f135737","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-74339","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:22:34.850","lastModified":"2026-08-15T06:22:34.850","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nALSA: seq: Clear variable event pointer on read\n\nsnd_seq_read() copies a queued variable-length event header to userspace\nbefore expanding the payload. Queued variable-length events use\nSNDRV_SEQ_EXT_CHAINED internally, and data.ext.ptr points at the first\nextension cell.\n\nThe read side strips SNDRV_SEQ_EXT_* bits from data.ext.len before the\ncopy, but it leaves data.ext.ptr untouched. A userspace sequencer client\ncan therefore write a direct variable event to itself and read back the\nextension-cell kernel address from the returned header.\n\nClear the temporary header pointer before copy_to_user(). The original\nqueued event remains unchanged and is still passed to\nsnd_seq_expand_var_event(), so payload expansion keeps using the\ninternal chain."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["sound/core/seq/seq_clientmgr.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"14fe4f75fd5309d6b75f8e840ada88912b374207","versionType":"git","status":"affected"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"f29243c211928114f8b906e0a3fee77c236f14c8","versionType":"git","status":"affected"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"e0c3edd86414534cfd179fefe45b38c29c01ae7a","versionType":"git","status":"affected"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"6b52211eba213c461f68922708a99d8190c1fcd5","versionType":"git","status":"affected"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"74ac1ce1f4afdb3b80b6742fa28fb86c8c51d31b","versionType":"git","status":"affected"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"c2ac9287e89916da684c2a548798351e63eb59ee","versionType":"git","status":"affected"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"705dd6dcbc0ea87351c660c1a6443f85f1001c76","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["sound/core/seq/seq_clientmgr.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"2.6.12","status":"affected"},{"version":"0","lessThan":"2.6.12","versionType":"semver","status":"unaffected"},{"version":"5.15.212","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.178","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.97","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/14fe4f75fd5309d6b75f8e840ada88912b374207","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/6b52211eba213c461f68922708a99d8190c1fcd5","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/705dd6dcbc0ea87351c660c1a6443f85f1001c76","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/74ac1ce1f4afdb3b80b6742fa28fb86c8c51d31b","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/c2ac9287e89916da684c2a548798351e63eb59ee","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/e0c3edd86414534cfd179fefe45b38c29c01ae7a","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/f29243c211928114f8b906e0a3fee77c236f14c8","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-74340","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:22:34.987","lastModified":"2026-08-15T06:22:34.987","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: wcn36xx: fix OOB read from firmware count in PRINT_REG_INFO indication\n\nThe firmware-controlled rsp->count field is used as the loop bound for\nindexing into the flexible rsp->regs[] array without validation against\nthe message length. A count exceeding the actual data causes out-of-\nbounds reads from the heap-allocated message buffer.\n\nAdd a check that count fits within the received message."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/net/wireless/ath/wcn36xx/smd.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"43efa3c0f241e04862be8e6a68ff765d36cde1ba","lessThan":"22b0b8572a64362531dd0ed499b75e16282aeb2b","versionType":"git","status":"affected"},{"version":"43efa3c0f241e04862be8e6a68ff765d36cde1ba","lessThan":"3cf92b44c4fb88a5e8de8733a4494c0956606bca","versionType":"git","status":"affected"},{"version":"43efa3c0f241e04862be8e6a68ff765d36cde1ba","lessThan":"0907c06dccae9e3c8d5a68eb9014beec73a36e79","versionType":"git","status":"affected"},{"version":"43efa3c0f241e04862be8e6a68ff765d36cde1ba","lessThan":"64228dfc4247aca178c01e5a37af7d8dcc7a6089","versionType":"git","status":"affected"},{"version":"43efa3c0f241e04862be8e6a68ff765d36cde1ba","lessThan":"23d210877968657bd07e1a517e0b516db20a1d80","versionType":"git","status":"affected"},{"version":"43efa3c0f241e04862be8e6a68ff765d36cde1ba","lessThan":"f03782f7f41f2afee5076a1ef08ced5649218771","versionType":"git","status":"affected"},{"version":"43efa3c0f241e04862be8e6a68ff765d36cde1ba","lessThan":"f987efff29a5fe45320ea5991c9d5cb98b676953","versionType":"git","status":"affected"},{"version":"43efa3c0f241e04862be8e6a68ff765d36cde1ba","lessThan":"df2187acfca6c6cca372c5d35f42394d9c270b09","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/net/wireless/ath/wcn36xx/smd.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"4.11","status":"affected"},{"version":"0","lessThan":"4.11","versionType":"semver","status":"unaffected"},{"version":"5.10.261","lessThanOrEqual":"5.10.*","versionType":"semver","status":"unaffected"},{"version":"5.15.212","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.178","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.97","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/0907c06dccae9e3c8d5a68eb9014beec73a36e79","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/22b0b8572a64362531dd0ed499b75e16282aeb2b","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/23d210877968657bd07e1a517e0b516db20a1d80","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/3cf92b44c4fb88a5e8de8733a4494c0956606bca","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/64228dfc4247aca178c01e5a37af7d8dcc7a6089","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/df2187acfca6c6cca372c5d35f42394d9c270b09","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/f03782f7f41f2afee5076a1ef08ced5649218771","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/f987efff29a5fe45320ea5991c9d5cb98b676953","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-74341","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:22:35.127","lastModified":"2026-08-15T06:22:35.127","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: wcn36xx: fix heap overflow from oversized firmware HAL response\n\nThe firmware response dispatcher copies all synchronous HAL responses\ninto the 4096-byte hal_buf without validating the response length. A\nresponse exceeding WCN36XX_HAL_BUF_SIZE causes a heap buffer overflow\nwith firmware-controlled content.\n\nAdd a bounds check on the response length."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/net/wireless/ath/wcn36xx/smd.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"8e84c25821698bdef73c0329fb2022a4673b7adc","lessThan":"dae9cadf0925f1cbfb71306d60490890df3870a6","versionType":"git","status":"affected"},{"version":"8e84c25821698bdef73c0329fb2022a4673b7adc","lessThan":"cfc67aee0c83e7f5d43a1dad3e25c789e9cc1d92","versionType":"git","status":"affected"},{"version":"8e84c25821698bdef73c0329fb2022a4673b7adc","lessThan":"15545ee71301e82d26d9a31b407ed0019eb62a60","versionType":"git","status":"affected"},{"version":"8e84c25821698bdef73c0329fb2022a4673b7adc","lessThan":"1b5d8a248c3afa640bcc99fa95abcd1e36f3ee18","versionType":"git","status":"affected"},{"version":"8e84c25821698bdef73c0329fb2022a4673b7adc","lessThan":"18813b90032bfaafb225906a4d2b51be4dfc02c3","versionType":"git","status":"affected"},{"version":"8e84c25821698bdef73c0329fb2022a4673b7adc","lessThan":"88a240d86d3d64521f9194abe185ac71cc74d0bd","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/net/wireless/ath/wcn36xx/smd.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"3.13","status":"affected"},{"version":"0","lessThan":"3.13","versionType":"semver","status":"unaffected"},{"version":"6.1.178","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.97","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/15545ee71301e82d26d9a31b407ed0019eb62a60","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/18813b90032bfaafb225906a4d2b51be4dfc02c3","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/1b5d8a248c3afa640bcc99fa95abcd1e36f3ee18","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/88a240d86d3d64521f9194abe185ac71cc74d0bd","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/cfc67aee0c83e7f5d43a1dad3e25c789e9cc1d92","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/dae9cadf0925f1cbfb71306d60490890df3870a6","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-74342","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:22:35.253","lastModified":"2026-08-15T06:22:35.253","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nkernfs: link kn to its parent before the LSM init hook\n\nAfter commit 12e9e3cd03b5 (\"simpe_xattr: use per-sb cache\"),\nkernfs_xattr_set() and kernfs_xattr_get() compute the cache via\nkernfs_root(kn) before any other check.  kernfs_root(kn) walks\nkn->__parent first and falls back to kn->dir.root, both of which are\nNULL on a freshly kmem_cache_zalloc()'d kn. kn->__parent was being set\nin kernfs_new_node() after __kernfs_new_node() returned, and kn->dir.root\nis set even later by kernfs_create_dir_ns() / kernfs_create_empty_dir().\n\nThe LSM kernfs_init_security hook is invoked from inside\n__kernfs_new_node(), before either field has been initialized.\nselinux_kernfs_init_security() ends with kernfs_xattr_set(kn,\nXATTR_NAME_SELINUX, ...).  kernfs_root(kn) then returns NULL, and\n&((struct kernfs_root *)NULL)->xa_cache evaluates to\noffsetof(struct kernfs_root, xa_cache) which faults:\n\n  BUG: kernel NULL pointer dereference, address: 00000000000000e0\n  RIP: 0010:simple_xattr_set+0x27/0x8b0\n  Call Trace:\n   kernfs_xattr_set+0x63/0xb0\n   selinux_kernfs_init_security+0x13b/0x270\n   security_kernfs_init_security+0x36/0xc0\n   __kernfs_new_node+0x182/0x290\n   kernfs_new_node+0x80/0xc0\n   kernfs_create_dir_ns+0x2b/0xa0\n   cgroup_create+0x116/0x380\n   cgroup_mkdir+0x7c/0x1a0\n\nReproduces deterministically at PID 1 (systemd) on an SELinux-enabled\ndistro. The first cgroup mkdir under /sys/fs/cgroup with a labelled\nparent panics the kernel.\n\nThe LSM hook's contract is that the kn_dir argument is the parent of\nthe new kn, so kn->__parent should already point at kn_dir when the\nhook runs.  Move kernfs_get(parent) and rcu_assign_pointer of\nkn->__parent from kernfs_new_node() into __kernfs_new_node() right\nbefore the security hook, and unwind the parent reference on the\nerr_out4 path.  kernfs_root(kn) then takes its parent branch during\nthe hook and returns parent->dir.root, which is the correct root.\n\nThis also closes the same-shape latent bug in kernfs_xattr_get() (which\ntoday is hidden only by kernfs_iattrs_noalloc() returning NULL on a\nfresh kn)."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["fs/kernfs/dir.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"319b82e8b46edaf557436ad858e734e583f78ec9","versionType":"git","status":"affected"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"6cccc49b027c7551ffc1d2532f2ef1922661f3da","versionType":"git","status":"affected"},{"version":"0","lessThan":"7.1.5","versionType":"semver","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["fs/kernfs/dir.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/319b82e8b46edaf557436ad858e734e583f78ec9","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/6cccc49b027c7551ffc1d2532f2ef1922661f3da","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-74343","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:22:35.370","lastModified":"2026-08-15T06:22:35.370","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nkernfs: fix xattr race condition with multiple superblocks\n\nMultiple superblocks with different namespaces can share the same\nkernfs_node when kernfs_test_super() finds a matching root but\ndifferent namespace. This means multiple inodes from different\nsuperblocks can reference the same kernfs_node->iattr->xattrs\nstructure.\n\nThe VFS layer only holds per-inode locks during xattr operations,\nwhich is insufficient to serialize concurrent xattr modifications on\nthe shared kernfs_node. This can lead to race conditions in\nsimple_xattr_set() where the lookup->replace/remove sequence is not\natomic with respect to operations from other superblocks.\n\nFix this by protecting xattr operations with the existing hashed\nkernfs_locks->open_file_mutex[] array, which is already used to\nprotect per-node open file data. The hashed mutex array provides\nscalable per-node serialization (scaled by CPU count, up to 1024 locks\non 32+ CPU systems) with zero memory overhead.\n\nChanges:\n- Rename open_file_mutex[] to node_mutex[] to reflect dual purpose\n- Add kernfs_node_lock_ptr() and kernfs_node_lock() helpers\n- Protect simple_xattr_set() calls in kernfs_xattr_set() and\n  kernfs_vfs_user_xattr_set() with the hashed mutex\n- Update file.c to use new helpers via compatibility wrappers\n- Update documentation to explain the extended lock usage"}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["fs/kernfs/file.c","fs/kernfs/inode.c","fs/kernfs/kernfs-internal.h","fs/kernfs/mount.c","include/linux/kernfs.h"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"b32c4a213698ab351b44da2fd1b2a5976c7fa033","lessThan":"bf53db51359939755084d08156684ed649489592","versionType":"git","status":"affected"},{"version":"b32c4a213698ab351b44da2fd1b2a5976c7fa033","lessThan":"6a07814ff643b5c8e1353d8c6229f52fde205cde","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["fs/kernfs/file.c","fs/kernfs/inode.c","fs/kernfs/kernfs-internal.h","fs/kernfs/mount.c","include/linux/kernfs.h"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"7.1","status":"affected"},{"version":"0","lessThan":"7.1","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/6a07814ff643b5c8e1353d8c6229f52fde205cde","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/bf53db51359939755084d08156684ed649489592","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-74344","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:22:35.487","lastModified":"2026-08-15T06:22:35.487","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nbpf: Clear rb node linkage when freeing bpf_rb_root\n\nbpf_rb_root_free() detaches the root by copying the current rb_root_cached\nand then replacing the live root with RB_ROOT_CACHED. It then walks the\ncopied root and drops each object contained in the tree.\n\nThis leaves the rb node state intact while dropping the object. If the\nobject is refcounted and survives the drop, its bpf_rb_node_kern still\ncontains an owner pointer to the freed root and stale rb tree linkage. If\na later bpf_rb_root allocation reuses the same address, bpf_rbtree_remove()\ncan incorrectly pass the owner check and call rb_erase_cached() on a node\nwhose rb pointers belong to the old tree.\n\nMirror the list draining behavior by marking nodes as busy while the root\nis being detached, then clear the rb node and release the owner before\ndropping the containing object. This makes surviving nodes unowned and\nsafe to reject from remove or accept for a later add."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["kernel/bpf/helpers.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"9c395c1b99bd23f74bc628fa000480c49593d17f","lessThan":"2eb39de4962f842d653e96818ae372665cd481fd","versionType":"git","status":"affected"},{"version":"9c395c1b99bd23f74bc628fa000480c49593d17f","lessThan":"574612793bed416f6c05fe7c9b50e9eb0441997e","versionType":"git","status":"affected"},{"version":"9c395c1b99bd23f74bc628fa000480c49593d17f","lessThan":"4a7910ee060d8ce55612f5b3cc267f3a265a3cec","versionType":"git","status":"affected"},{"version":"1d0675957d35ac5e514073481beda62e4e1e2ec5","versionType":"git","status":"affected"},{"version":"6.2.15","lessThan":"6.3","versionType":"semver","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["kernel/bpf/helpers.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.3","status":"affected"},{"version":"0","lessThan":"6.3","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/2eb39de4962f842d653e96818ae372665cd481fd","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/4a7910ee060d8ce55612f5b3cc267f3a265a3cec","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/574612793bed416f6c05fe7c9b50e9eb0441997e","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-74345","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:22:35.607","lastModified":"2026-08-15T06:22:35.607","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nRDMA/siw: Fix endpoint/socket association handling\n\nDisassociating a socket from an endpoint via siw_socket_disassoc() may\nrelease the last reference on that endpoint and free it. Therefore, don't\nclear the endpoints socket pointer after calling that function, but\nwithin.\n\nThis fixes a:\n\n  BUG: KASAN: slab-use-after-free in siw_cm_work_handler (drivers/infiniband/sw/siw/siw_cm.c:1053 drivers/infiniband/sw/siw/siw_cm.c:1075)\n\nwhich occurred after processing a malformed MPA request during connection\nestablishment, causing the new endpoint to be closed."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/infiniband/sw/siw/siw_cm.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6c52fdc244b5ccc468006fd65a504d4ee33743c7","lessThan":"b28d513393f81e2de00f82970487a9d001557e4e","versionType":"git","status":"affected"},{"version":"6c52fdc244b5ccc468006fd65a504d4ee33743c7","lessThan":"f6183983ce1ff254d629a333739082b39d7c5eb6","versionType":"git","status":"affected"},{"version":"6c52fdc244b5ccc468006fd65a504d4ee33743c7","lessThan":"b6cf763eee0a932792bef64ceaca568d324192fc","versionType":"git","status":"affected"},{"version":"6c52fdc244b5ccc468006fd65a504d4ee33743c7","lessThan":"ea4f6f6c53577fb3f05dbd78b15e586772d49831","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/infiniband/sw/siw/siw_cm.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"5.3","status":"affected"},{"version":"0","lessThan":"5.3","versionType":"semver","status":"unaffected"},{"version":"6.12.97","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/b28d513393f81e2de00f82970487a9d001557e4e","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/b6cf763eee0a932792bef64ceaca568d324192fc","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/ea4f6f6c53577fb3f05dbd78b15e586772d49831","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/f6183983ce1ff254d629a333739082b39d7c5eb6","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-74346","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:22:35.720","lastModified":"2026-08-15T06:22:35.720","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nRDMA/irdma: Fix OOB read during CQ MR registration\n\nSashiko pointed out an unrelated bug during a previous patch:\nhttps://sashiko.dev/#/patchset/20260512183852.614045-1-jmoroni%40google.com\n\nThis change fixes the bug by eliminating the cqmr->split field which\nwas not being set properly and instead just checks the CQ resize\nfeature flag directly.\n\nThe cqmr->split field essentially tracks whether IRDMA_FEATURE_CQ_RESIZE\nis set, but it was not being set until CQ creation time, which is _after_\nCQ memory registration (the only other place where it is referenced).\n\nAs a result, it would always be false during MR registration and would\ntherefore cause irdma_handle_q_mem to populate cqmr->shadow even for GEN_2\nHW and beyond:\n\n    cqmr->shadow = (dma_addr_t)arr[req->cq_pages];\n\nThe issue is that for GEN_2 and beyond, req->cq_pages may be exactly equal\nto iwmr->page_cnt and therefore equal to the size of arr, which would cause\nan OOB read by one."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/infiniband/hw/irdma/verbs.c","drivers/infiniband/hw/irdma/verbs.h"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"b48c24c2d710cf34810c555dcef883a3d35a9c08","lessThan":"a80b3b13786e9ab1c52b31a1f16c7d6708fa9220","versionType":"git","status":"affected"},{"version":"b48c24c2d710cf34810c555dcef883a3d35a9c08","lessThan":"3159c6fac43dc24b34d31971884d98a7a1bf4c4b","versionType":"git","status":"affected"},{"version":"b48c24c2d710cf34810c555dcef883a3d35a9c08","lessThan":"ad360a31092a870633ec255b96f50181628b4de0","versionType":"git","status":"affected"},{"version":"b48c24c2d710cf34810c555dcef883a3d35a9c08","lessThan":"d566002de555b18cc395012c5c1cb8682fc6d2a9","versionType":"git","status":"affected"},{"version":"b48c24c2d710cf34810c555dcef883a3d35a9c08","lessThan":"54cab78df0375196aaec4e3109191653d21751df","versionType":"git","status":"affected"},{"version":"b48c24c2d710cf34810c555dcef883a3d35a9c08","lessThan":"d5aa82da8f65562da996d184686db9d0ea718b91","versionType":"git","status":"affected"},{"version":"b48c24c2d710cf34810c555dcef883a3d35a9c08","lessThan":"4385ddd654d90245eeb83b3cb539670ab5c85ba4","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/infiniband/hw/irdma/verbs.c","drivers/infiniband/hw/irdma/verbs.h"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"5.14","status":"affected"},{"version":"0","lessThan":"5.14","versionType":"semver","status":"unaffected"},{"version":"5.15.212","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.178","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.97","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/3159c6fac43dc24b34d31971884d98a7a1bf4c4b","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/4385ddd654d90245eeb83b3cb539670ab5c85ba4","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/54cab78df0375196aaec4e3109191653d21751df","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/a80b3b13786e9ab1c52b31a1f16c7d6708fa9220","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/ad360a31092a870633ec255b96f50181628b4de0","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/d566002de555b18cc395012c5c1cb8682fc6d2a9","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/d5aa82da8f65562da996d184686db9d0ea718b91","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-74347","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:22:35.860","lastModified":"2026-08-15T06:22:35.860","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nnetfilter: cttimeout: detach dataplane timeout policy and repurpose refcount\n\nAdd a refcount for struct nf_ct_timeout which is used by ct extension to\nset the custom ct timeout policy, this tells us that the ct timeout is\nbeing used by a conntrack entry. When the last conntrack entry drops the\nrefcount on the ct timeout, the ct timeout is released.\n\nRemove the refcount for control plane which controls if the ruleset\nrefers to the timeout policy. After this update, it is possible to\nremove the ct timeout policy from nfnetlink_cttimeout immediately.\nThis is for simplicity not to handle two refcounts on a single object.\n\nRemove nf_queue_nf_hook_drop(): a packet sitting in nfqueue will just\nhold a reference to the nf_ct_timeout object until packet is reinjected,\nsince this is part of the ct extension, this will be released by the\ntime the conntrack is freed.\n\nnf_ct_untimeout() is still called to clean up in a best effort basis:\nthe ct timeout on existing entries gets removed when the ct timeout goes\naway, but as long as the iptables ruleset still refers to the ct timeout\nthrough a template, new conntracks may keep attaching it and extend its\nlifetime until the rule is removed.\n\nnf_ct_untimeout() is not called anymore from module removal path, this\nis unlikely to find timeouts give module refcount is bumped, and the new\nrefcount already tracks the ct timeout policy use so it is released when\nunused."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["include/net/netfilter/nf_conntrack_timeout.h","net/netfilter/nf_conntrack_core.c","net/netfilter/nf_conntrack_timeout.c","net/netfilter/nfnetlink_cttimeout.c","net/netfilter/nft_ct.c","net/netfilter/xt_CT.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"50978462300f74dc48aea4a38471cb69bdf741a5","lessThan":"9aeb0dcfeb460d33d61d434148b51103ab1d2013","versionType":"git","status":"affected"},{"version":"50978462300f74dc48aea4a38471cb69bdf741a5","lessThan":"7d6a9cdb8d3a51d9cfe546a09a518ab3d2671549","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["include/net/netfilter/nf_conntrack_timeout.h","net/netfilter/nf_conntrack_core.c","net/netfilter/nf_conntrack_timeout.c","net/netfilter/nfnetlink_cttimeout.c","net/netfilter/nft_ct.c","net/netfilter/xt_CT.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"3.4","status":"affected"},{"version":"0","lessThan":"3.4","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/7d6a9cdb8d3a51d9cfe546a09a518ab3d2671549","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/9aeb0dcfeb460d33d61d434148b51103ab1d2013","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-74348","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:22:35.970","lastModified":"2026-08-15T06:22:35.970","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nocfs2/dlm: require a ref for locking_state debugfs open\n\ndebug_lockres_open() copies inode->i_private into struct debug_lockres and\ndebug_lockres_release() later drops that pointer with dlm_put().  That\nonly works if open successfully pins the struct dlm_ctxt.\n\nToday open calls dlm_grab(dlm) but ignores its return value.  Once the\nlast domain unregister has removed the context from dlm_domains,\ndlm_grab() returns NULL, yet open still stores the raw pointer and returns\nsuccess.  The later release path is outside the debugfs removal barrier,\nso it can call dlm_put() after dlm_free_ctxt_mem() has freed the context. \nKASAN reports this as a slab-use-after-free in dlm_put() called from\ndebug_lockres_release().\n\nFail the open when dlm_grab() cannot acquire the reference and unwind the\nseq_file private state before returning.  That keeps locking_state from\nhanding out a file descriptor whose release path does not own the\ndlm_ctxt.\n\nThe buggy scenario involves two paths, with each column showing the order\nwithin that path:\n\nlocking_state debugfs open:          last domain unregister:\n1. debug_lockres_open() reads        1. dlm_unregister_domain() calls\n   inode->i_private.                    dlm_complete_dlm_shutdown().\n2. debug_lockres_open() calls        2. shutdown removes the dlm_ctxt from\n   dlm_grab(dlm) and gets NULL.         dlm_domains.\n3. open still stores the raw dlm     3. final teardown reaches\n   pointer in dl->dl_ctxt and           dlm_free_ctxt_mem() and frees it.\n   returns success.\n4. debug_lockres_release() later\n   calls dlm_put(dl->dl_ctxt).\n\nValidation reproduced this kernel report:\nKASAN slab-use-after-free in dlm_put+0x82/0x200\nRIP: 0033:0x7f4d349bc9e0\nThe buggy address belongs to the object at ffff888103a3c000 which belongs\nto the cache kmalloc-2k of size 2048\nThe buggy address is located 816 bytes inside of freed 2048-byte region\n[ffff888103a3c000, ffff888103a3c800)\nWrite of size 4\nCall trace:\n  dump_stack_lvl+0x66/0xa0 (?:?)\n  print_report+0xd0/0x630 (?:?)\n  dlm_put+0x82/0x200 (?:?)\n  srso_alias_return_thunk+0x5/0xfbef5 (?:?)\n  __virt_addr_valid+0x188/0x2f0 (?:?)\n  kasan_report+0xe4/0x120 (?:?)\n  kasan_check_range+0x105/0x1b0 (?:?)\n  debug_lockres_release+0x53/0x80 (fs/ocfs2/dlm/dlmdebug.c:587)\n  dlm_put+0x9/0x200 (?:?)\n  debug_lockres_release+0x5c/0x80 (fs/ocfs2/dlm/dlmdebug.c:587)\n  full_proxy_release+0x67/0x90 (?:?)\n  __fput+0x1df/0x4b0 (?:?)\n  do_raw_spin_lock+0x10f/0x1b0 (?:?)\n  fput_close_sync+0xd2/0x170 (?:?)\n  __x64_sys_close+0x55/0x90 (?:?)\n  do_syscall_64+0x10c/0x640 (arch/x86/entry/syscall_64.c:87)\n  irqentry_exit+0xac/0x6e0 (?:?)\n  entry_SYSCALL_64_after_hwframe+0x77/0x7f (?:?)\nFreed by task stack:\n  kasan_save_stack+0x33/0x60 (?:?)\n  kasan_save_track+0x14/0x30 (?:?)\n  kasan_save_free_info+0x3b/0x60 (?:?)\n  __kasan_slab_free+0x5f/0x80 (?:?)\n  kfree+0x30f/0x580 (?:?)\n  dlm_put+0x1ce/0x200 (?:?)\n  dlm_unregister_domain+0xf6/0xb30 (?:?)\n  o2cb_cluster_disconnect+0x6b/0x90 (?:?)\n  ocfs2_cluster_disconnect+0x41/0x70 (?:?)\n  ocfs2_dlm_shutdown+0x1c4/0x220 (?:?)\n  ocfs2_dismount_volume+0x38a/0x550 (?:?)\n  generic_shutdown_super+0xc3/0x220 (?:?)\n  kill_block_super+0x29/0x60 (?:?)\n  deactivate_locked_super+0x66/0xe0 (?:?)\n  cleanup_mnt+0x13d/0x210 (?:?)\n  task_work_run+0xfa/0x170 (?:?)\n  exit_to_user_mode_loop+0xd6/0x430 (?:?)\n  do_syscall_64+0x3cb/0x640 (arch/x86/entry/syscall_64.c:87)\n  entry_SYSCALL_64_after_hwframe+0x77/0x7f (?:?)"}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["fs/ocfs2/dlm/dlmdebug.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"4e3d24ed1a1285fe3289653aacc965642706bacb","lessThan":"6cc93dea4078cbcddee63fa2234e382a76600464","versionType":"git","status":"affected"},{"version":"4e3d24ed1a1285fe3289653aacc965642706bacb","lessThan":"90a6512425414098a63fc97b77bed089c75d106b","versionType":"git","status":"affected"},{"version":"4e3d24ed1a1285fe3289653aacc965642706bacb","lessThan":"5bee5d5f67aedd26d2b72e00e49dd93331fbcc30","versionType":"git","status":"affected"},{"version":"4e3d24ed1a1285fe3289653aacc965642706bacb","lessThan":"aa7883b6a3c76301a3299deb34de948e73bb6a08","versionType":"git","status":"affected"},{"version":"4e3d24ed1a1285fe3289653aacc965642706bacb","lessThan":"9c81c1a61a52b6ecf0d14f1dbd95f154a7a9e92a","versionType":"git","status":"affected"},{"version":"4e3d24ed1a1285fe3289653aacc965642706bacb","lessThan":"a087b2d3411e7f9df71ba3293596923ee2c70d65","versionType":"git","status":"affected"},{"version":"4e3d24ed1a1285fe3289653aacc965642706bacb","lessThan":"a09831214912a1f270663d935613910fafd8d883","versionType":"git","status":"affected"},{"version":"4e3d24ed1a1285fe3289653aacc965642706bacb","lessThan":"03ad858ce8064861ea580021976dc19b7aabb549","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["fs/ocfs2/dlm/dlmdebug.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"2.6.26","status":"affected"},{"version":"0","lessThan":"2.6.26","versionType":"semver","status":"unaffected"},{"version":"5.10.261","lessThanOrEqual":"5.10.*","versionType":"semver","status":"unaffected"},{"version":"5.15.212","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.178","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.97","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/03ad858ce8064861ea580021976dc19b7aabb549","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/5bee5d5f67aedd26d2b72e00e49dd93331fbcc30","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/6cc93dea4078cbcddee63fa2234e382a76600464","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/90a6512425414098a63fc97b77bed089c75d106b","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/9c81c1a61a52b6ecf0d14f1dbd95f154a7a9e92a","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/a087b2d3411e7f9df71ba3293596923ee2c70d65","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/a09831214912a1f270663d935613910fafd8d883","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/aa7883b6a3c76301a3299deb34de948e73bb6a08","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-74349","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:22:36.130","lastModified":"2026-08-15T06:22:36.130","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nocfs2: reject FITRIM ranges shorter than a cluster\n\nocfs2_trim_mainbm() trims the global bitmap in cluster units, but its\ntoo-short range validation only checks sb->s_blocksize.\n\nOn filesystems with a cluster size larger than the block size, a FITRIM\nrange that is at least one block but shorter than one cluster is accepted\nand shifted down to len == 0.  The later start + len - 1 and len -= ... \narithmetic then underflows and can drive trimming past the requested\nrange.\n\nReject ranges shorter than s_clustersize instead.  That preserves the\nexisting -EINVAL behavior for requests that cannot discard even one\nallocation unit and keeps zero-cluster trims out of the group walk."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["fs/ocfs2/alloc.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"aa89762c54800208d5afdcd8e6bf124818f17fe0","lessThan":"d903d59c0315f59bdf0214b4f13d71c9feb2c45c","versionType":"git","status":"affected"},{"version":"aa89762c54800208d5afdcd8e6bf124818f17fe0","lessThan":"441abb77222f155e8d931dbabb465466db01cfd7","versionType":"git","status":"affected"},{"version":"aa89762c54800208d5afdcd8e6bf124818f17fe0","lessThan":"e652d0f5108e447b22da4249bcd23dd1b63c73dd","versionType":"git","status":"affected"},{"version":"aa89762c54800208d5afdcd8e6bf124818f17fe0","lessThan":"346314bb0cc2fc52b50b73d6ecc62e0217455c2e","versionType":"git","status":"affected"},{"version":"aa89762c54800208d5afdcd8e6bf124818f17fe0","lessThan":"06c0a0431b9856506fcd9b2c1b0c6136567d756d","versionType":"git","status":"affected"},{"version":"aa89762c54800208d5afdcd8e6bf124818f17fe0","lessThan":"3fa7139b5f42731a61f78c42433adae13f9adc21","versionType":"git","status":"affected"},{"version":"aa89762c54800208d5afdcd8e6bf124818f17fe0","lessThan":"2c13e02592b918be7725ab5965e01ef4e46c4b57","versionType":"git","status":"affected"},{"version":"aa89762c54800208d5afdcd8e6bf124818f17fe0","lessThan":"ca1afd88f5eaaff9168e1466e5401385edf59543","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["fs/ocfs2/alloc.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"3.14","status":"affected"},{"version":"0","lessThan":"3.14","versionType":"semver","status":"unaffected"},{"version":"5.10.261","lessThanOrEqual":"5.10.*","versionType":"semver","status":"unaffected"},{"version":"5.15.212","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.178","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.97","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/06c0a0431b9856506fcd9b2c1b0c6136567d756d","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/2c13e02592b918be7725ab5965e01ef4e46c4b57","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/346314bb0cc2fc52b50b73d6ecc62e0217455c2e","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/3fa7139b5f42731a61f78c42433adae13f9adc21","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/441abb77222f155e8d931dbabb465466db01cfd7","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/ca1afd88f5eaaff9168e1466e5401385edf59543","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/d903d59c0315f59bdf0214b4f13d71c9feb2c45c","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/e652d0f5108e447b22da4249bcd23dd1b63c73dd","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-74350","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:22:36.270","lastModified":"2026-08-15T06:22:36.270","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nocfs2: validate fast symlink target during inode read\n\nocfs2_validate_inode_block() already rejects several inconsistent\nself-contained dinodes before they are exposed to the rest of the\nfilesystem.  Fast symlinks need the same treatment.\n\nA zero-cluster symlink is treated as a fast symlink and later read through\npage_get_link() and ocfs2_fast_symlink_read_folio().  That path uses\nstrnlen() on the inline payload and then copies len + 1 bytes into the\nfolio.  If a corrupt dinode stores an i_size that does not fit the inline\narea or omits the terminating NUL at i_size, that copy reads past the end\nof the inode block buffer.\n\nReject zero-cluster symlink dinodes whose i_size exceeds the inline\nfast-symlink capacity or whose inline payload is not NUL-terminated\nexactly at i_size when the inode block is validated.  This keeps malformed\nfast symlinks from reaching the read path.\n\nValidation reproduced this kernel report:\nKASAN use-after-free in ocfs2_fast_symlink_read_folio+0x12c/0x1f0\nRIP: 0033:0x7f5c6d859aa7\nRead of size 3905\nCall trace:\n  dump_stack_lvl+0x66/0xa0 (?:?)\n  print_report+0xce/0x630 (?:?)\n  ocfs2_fast_symlink_read_folio+0x12c/0x1f0 (fs/ocfs2/inode.c:?)\n  srso_alias_return_thunk+0x5/0xfbef5 (?:?)\n  __virt_addr_valid+0x19f/0x330 (?:?)\n  kasan_report+0xe0/0x110 (?:?)\n  kasan_check_range+0x105/0x1b0 (?:?)\n  __asan_memcpy+0x23/0x60 (?:?)\n  filemap_read_folio+0x27/0xe0 (?:?)\n  filemap_read_folio+0x35/0xe0 (?:?)\n  do_read_cache_folio+0x138/0x230 (?:?)\n  __page_get_link+0x26/0x110 (?:?)\n  page_get_link+0x2e/0x70 (?:?)\n  vfs_readlink+0x15e/0x250 (?:?)\n  touch_atime+0x4d/0x370 (?:?)\n  do_readlinkat+0x186/0x200 (?:?)\n  do_user_addr_fault+0x65a/0x890 (?:?)\n  __x64_sys_readlink+0x46/0x60 (?:?)\n  do_syscall_64+0x115/0x6a0 (arch/x86/entry/syscall_64.c:87)\n  entry_SYSCALL_64_after_hwframe+0x77/0x7f (?:?)"}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["fs/ocfs2/inode.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"ea022dfb3c2a4680483b00eb2fecc9fc4f6091d1","lessThan":"f9e2cb692b77a679b1f4cc2b7b277fa908586533","versionType":"git","status":"affected"},{"version":"ea022dfb3c2a4680483b00eb2fecc9fc4f6091d1","lessThan":"e234973f286ed2e8961a24561ec91594ec3e3ff8","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["fs/ocfs2/inode.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"3.5","status":"affected"},{"version":"0","lessThan":"3.5","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/e234973f286ed2e8961a24561ec91594ec3e3ff8","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/f9e2cb692b77a679b1f4cc2b7b277fa908586533","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-74351","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:22:36.383","lastModified":"2026-08-15T06:22:36.383","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nocfs2: rebase copied fsdlm LVB pointers in locking_state\n\nThe locking_state debugfs iterator snapshots struct ocfs2_lock_res by\nvalue under ocfs2_dlm_tracking_lock and later formats that copy in\nocfs2_dlm_seq_show().  That is fine for the inline fields, but the\nuserspace fsdlm stack stores the LVB through lksb_fsdlm.sb_lvbptr.  Once\nthe iterator drops the tracking lock, a copied non-NULL sb_lvbptr still\npoints into the original lockres owner, so teardown can free that\ncontainer before the debugfs dump walks the raw LVB bytes.\n\nRebase the copied sb_lvbptr to the copied l_lksb before dumping the raw\nLVB.  The seq snapshot already carries the inline LVB storage reserved in\nstruct ocfs2_dlm_lksb, so the debugfs reader can dump the copied bytes\nwithout borrowing the original lockres lifetime.\n\nThe buggy scenario involves two paths, with each column showing the order\nwithin that path:\n\nlocking_state reader:                  lockres teardown:\n1. ocfs2_dlm_seq_start()/next()        1. file release or another owner\n   copies struct ocfs2_lock_res           teardown reaches\n2. ocfs2_dlm_seq_show() formats           ocfs2_lock_res_free()\n   the copied row                      2. the lockres is removed from the\n3. ocfs2_dlm_lvb() follows the            tracking list\n   copied sb_lvbptr                   3. the owner frees the original\n                                          lockres container\n\nValidation reproduced this kernel report:\nKASAN slab-use-after-free in ocfs2_dlm_seq_show+0x1bd/0x430\nRIP: 0033:0x7f8ec4b1e29d\nThe buggy address belongs to the object at ffff88810a1e0800 which belongs\nto the cache kmalloc-1k of size 1024\nThe buggy address is located 368 bytes inside of freed 1024-byte region\n[ffff88810a1e0800, ffff88810a1e0c00)\nRead of size 1\nCall trace:\n  dump_stack_lvl+0x66/0xa0\n  print_report+0xce/0x630\n  ocfs2_dlm_seq_show+0x1bd/0x430 (fs/ocfs2/dlmglue.c:3137)\n  srso_alias_return_thunk+0x5/0xfbef5\n  __virt_addr_valid+0x19f/0x330\n  kasan_report+0xe0/0x110\n  seq_read_iter+0x29d/0x790\n  seq_read+0x20a/0x280\n  find_held_lock+0x2b/0x80\n  rcu_read_unlock+0x18/0x70\n  full_proxy_read+0x9e/0xd0\n  vfs_read+0x12c/0x590\n  ksys_read+0xd2/0x170\n  do_user_addr_fault+0x65a/0x890\n  do_syscall_64+0x115/0x6a0 (arch/x86/entry/syscall_64.c:87)\n  entry_SYSCALL_64_after_hwframe+0x77/0x7f\nAllocated by task stack:\n  kasan_save_stack+0x33/0x60\n  kasan_save_track+0x14/0x30\n  __kasan_kmalloc+0xaa/0xb0\n  ocfs2_file_open+0x13e/0x300\n  do_dentry_open+0x233/0x7f0\n  vfs_open+0x5a/0x1b0\n  path_openat+0x66d/0x1540\n  do_file_open+0x186/0x2b0\n  do_sys_openat2+0xce/0x150\n  __x64_sys_openat+0xd0/0x140\n  do_syscall_64+0x115/0x6a0 (arch/x86/entry/syscall_64.c:87)\n  entry_SYSCALL_64_after_hwframe+0x77/0x7f\nFreed by task stack:\n  kasan_save_stack+0x33/0x60\n  kasan_save_track+0x14/0x30\n  kasan_save_free_info+0x3b/0x60\n  __kasan_slab_free+0x5f/0x80\n  kfree+0x313/0x590\n  ocfs2_file_release+0x138/0x260\n  __fput+0x1df/0x4b0\n  fput_close_sync+0xd2/0x170\n  __x64_sys_close+0x55/0x90\n  do_syscall_64+0x115/0x6a0 (arch/x86/entry/syscall_64.c:87)\n  entry_SYSCALL_64_after_hwframe+0x77/0x7f"}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["fs/ocfs2/dlmglue.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"cf4d8d75d8aba537a19b313a9364fd08ddbd5622","lessThan":"185427b5f7a209254c85c18aad5a4a8e009b2f30","versionType":"git","status":"affected"},{"version":"cf4d8d75d8aba537a19b313a9364fd08ddbd5622","lessThan":"07aa4a8ebacde3d0ba50f60d2964f274ee7629bc","versionType":"git","status":"affected"},{"version":"cf4d8d75d8aba537a19b313a9364fd08ddbd5622","lessThan":"e037c1250cc90e7aacb002357d1b0399fc65ecfc","versionType":"git","status":"affected"},{"version":"cf4d8d75d8aba537a19b313a9364fd08ddbd5622","lessThan":"6b38a5b8ee951e5b244e9a3c3d28d0f5e7c51411","versionType":"git","status":"affected"},{"version":"cf4d8d75d8aba537a19b313a9364fd08ddbd5622","lessThan":"8614a8f7e81edd34c9f67e454e7024fd12a2a341","versionType":"git","status":"affected"},{"version":"cf4d8d75d8aba537a19b313a9364fd08ddbd5622","lessThan":"bb44a7690a4d553da705919cf666a80f5ca9011c","versionType":"git","status":"affected"},{"version":"cf4d8d75d8aba537a19b313a9364fd08ddbd5622","lessThan":"610a0d2a35496738e1472fb0f318d5008a1c634f","versionType":"git","status":"affected"},{"version":"cf4d8d75d8aba537a19b313a9364fd08ddbd5622","lessThan":"93612d48fa42b3d1a637eb9279e15281c611c000","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["fs/ocfs2/dlmglue.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"2.6.26","status":"affected"},{"version":"0","lessThan":"2.6.26","versionType":"semver","status":"unaffected"},{"version":"5.10.261","lessThanOrEqual":"5.10.*","versionType":"semver","status":"unaffected"},{"version":"5.15.212","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.178","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.97","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/07aa4a8ebacde3d0ba50f60d2964f274ee7629bc","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/185427b5f7a209254c85c18aad5a4a8e009b2f30","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/610a0d2a35496738e1472fb0f318d5008a1c634f","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/6b38a5b8ee951e5b244e9a3c3d28d0f5e7c51411","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/8614a8f7e81edd34c9f67e454e7024fd12a2a341","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/93612d48fa42b3d1a637eb9279e15281c611c000","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/bb44a7690a4d553da705919cf666a80f5ca9011c","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/e037c1250cc90e7aacb002357d1b0399fc65ecfc","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-74352","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:22:36.543","lastModified":"2026-08-15T06:22:36.543","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nof: reserved_mem: avoid post-init UAF when alloc_reserved_mem_array() fails\n\nThe global pointer 'reserved_mem' continues to reference the\nreserved_mem_array which lives in __initdata if\nalloc_reserved_mem_array() fails. of_reserved_mem_lookup() is\nexported for post-init use, that would dereference freed memory\nand trigger a use-after-free.\n\nSo reset reserved_mem_count to 0 when alloc_reserved_mem_array()\nfails."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/of/of_reserved_mem.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"b6ae53301eb41f0f59f83c161248b186bca7da70","lessThan":"6d28e6ad3c5c9248577f21057baa9bf16fa9ef3b","versionType":"git","status":"affected"},{"version":"00c9a452a235c61f099504783badd9a7675ff5a5","lessThan":"9af58d10d0d8c08b822de5fc99e61f31a87ede8d","versionType":"git","status":"affected"},{"version":"00c9a452a235c61f099504783badd9a7675ff5a5","lessThan":"cbd3102fe27bc87da244bf4c3ba670ea4698b0a8","versionType":"git","status":"affected"},{"version":"00c9a452a235c61f099504783badd9a7675ff5a5","lessThan":"e1686ca81dbf3edbde589b7daf312b45cbf76e03","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/of/of_reserved_mem.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.13","status":"affected"},{"version":"0","lessThan":"6.13","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/6d28e6ad3c5c9248577f21057baa9bf16fa9ef3b","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/9af58d10d0d8c08b822de5fc99e61f31a87ede8d","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/cbd3102fe27bc87da244bf4c3ba670ea4698b0a8","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/e1686ca81dbf3edbde589b7daf312b45cbf76e03","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-74353","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:22:36.657","lastModified":"2026-08-15T06:22:36.657","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amdkfd: always resume_all after suspend_all\n\nNeed to restore any good queues even if the suspend_all\nfailed for some.  Always run remove_queue as that will\nschedule a GPU reset is removing the queue fails.\n\nv2: move resume_all after remove"}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/gpu/drm/amd/amdkfd/kfd_device_queue_manager.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"eb067d65c33eecd4b81771384183ad42eec259bf","lessThan":"e29da2a4d9a3b1837dec3ce0892835d506c2a85e","versionType":"git","status":"affected"},{"version":"eb067d65c33eecd4b81771384183ad42eec259bf","lessThan":"9a030fcb4b192a508113787ef28fb97e27dcf6f6","versionType":"git","status":"affected"},{"version":"eb067d65c33eecd4b81771384183ad42eec259bf","lessThan":"b5fc19c898e08deb40b671329d99d85d2d575f0b","versionType":"git","status":"affected"},{"version":"eb067d65c33eecd4b81771384183ad42eec259bf","lessThan":"56ae73c92e200e630c2bdf1e98c88b86c8483b37","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/gpu/drm/amd/amdkfd/kfd_device_queue_manager.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.12","status":"affected"},{"version":"0","lessThan":"6.12","versionType":"semver","status":"unaffected"},{"version":"6.12.97","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/56ae73c92e200e630c2bdf1e98c88b86c8483b37","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/9a030fcb4b192a508113787ef28fb97e27dcf6f6","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/b5fc19c898e08deb40b671329d99d85d2d575f0b","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/e29da2a4d9a3b1837dec3ce0892835d506c2a85e","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-74354","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:22:36.773","lastModified":"2026-08-15T06:22:36.773","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nbpf: Take mmap_lock in zap_pages()\n\nzap_vma_range() requires the owning mm's mmap_lock to be held.\n\nTaking mmap_read_lock under arena->lock would AB-BA against\narena_vm_close() and arena_map_mmap(), both of which run with\nmmap_write_lock held and then acquire arena->lock. Instead drop\narena->lock, mmget_not_zero() the vma's mm, take mmap_read_lock, and\nre-resolve the vma via find_vma() since it may have been unmapped or\nreplaced while waiting.\n\nTrack processed vmls with a per-call generation in vml->zap_gen and\nserialize zap_pages() callers with a new arena->zap_mutex so\nconcurrent callers on different uaddr ranges do not mark each other's\nvmls processed before the zap is done."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["kernel/bpf/arena.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"317460317a02a1af512697e6e964298dedd8a163","lessThan":"36b1d997866f6083d33934983aa2ce0a184ed642","versionType":"git","status":"affected"},{"version":"317460317a02a1af512697e6e964298dedd8a163","lessThan":"80b89d0226a05e8b67969de99c31b51fcd54f76a","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["kernel/bpf/arena.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.9","status":"affected"},{"version":"0","lessThan":"6.9","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/36b1d997866f6083d33934983aa2ce0a184ed642","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/80b89d0226a05e8b67969de99c31b51fcd54f76a","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-74355","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:22:36.887","lastModified":"2026-08-15T06:22:36.887","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\niommu/vt-d: Fix RB-tree corruption in probe error path\n\nThe info->node RB-tree member is zero-initialized via kzalloc. If\na device does not support ATS, the device_rbtree_insert() call is\nskipped. If a subsequent probe step fails, the error path jumps to\ndevice_rbtree_remove(), which misinterprets the zeroed node as\na tree root and corrupts the device RB-tree.\n\nFix this by explicitly initializing the RB-node as empty using\nRB_CLEAR_NODE() during initialization and guarding the removal with\nRB_EMPTY_NODE()."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/iommu/intel/iommu.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"4f1492efb495bcef34c9ee8a94af81e6cea5abf4","lessThan":"f5102e0fc3c6dc8685549891a96e4589fdb3e211","versionType":"git","status":"affected"},{"version":"4f1492efb495bcef34c9ee8a94af81e6cea5abf4","lessThan":"d16923a45d4d08367650fdc3451c89299ab6ac5a","versionType":"git","status":"affected"},{"version":"4f1492efb495bcef34c9ee8a94af81e6cea5abf4","lessThan":"43bd9e6d5513cb1edbafdeef146a1edc3aaced56","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/iommu/intel/iommu.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.15","status":"affected"},{"version":"0","lessThan":"6.15","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/43bd9e6d5513cb1edbafdeef146a1edc3aaced56","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/d16923a45d4d08367650fdc3451c89299ab6ac5a","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/f5102e0fc3c6dc8685549891a96e4589fdb3e211","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-74356","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:22:37.007","lastModified":"2026-08-15T06:22:37.007","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nvhost: fix vhost_get_avail_idx for a non empty ring\n\nvhost_get_avail_idx is supposed to report whether it has updated\nvq->avail_idx. Instead, it returns whether all entries have been\nconsumed, which is usually the same. But not always - in\ndrivers/vhost/net.c and when mergeable buffers have been enabled, the\ndriver checks whether the combined entries are big enough to store an\nincoming packet. If not, the driver re-enables notifications with\navailable entries still in the ring. The incorrect return value from\nvhost_get_avail_idx propagates through vhost_enable_notify and causes\nthe host to livelock if the guest is not making progress, as vhost will\nimmediately disable notifications and retry using the available entries.\n\nThis goes back to commit d3bb267bbdcb (\"vhost: cache avail index in\nvhost_enable_notify()\") which changed vhost_enable_notify() to compare\nthe freshly read avail index against vq->last_avail_idx instead of the\npreviously cached vq->avail_idx. Commit 7ad472397667 (\"vhost: move\nsmp_rmb() into vhost_get_avail_idx()\") then carried over the same\ncomparison when refactoring vhost_enable_notify() to call the unified\nvhost_get_avail_idx().\n\nThe obvious fix is to make vhost_get_avail_idx do what the comment\nsays it does and report whether new entries have been added."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/vhost/vhost.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"d3bb267bbdcba199568f1325743d9d501dea0560","lessThan":"e115471008111f894c6528d9ab2ce7d0ce306f35","versionType":"git","status":"affected"},{"version":"d3bb267bbdcba199568f1325743d9d501dea0560","lessThan":"7f229d27bf27c7e589eca690d8612763a7a4801f","versionType":"git","status":"affected"},{"version":"d3bb267bbdcba199568f1325743d9d501dea0560","lessThan":"a9326b652bc7acd748d7a1143573845c7924d847","versionType":"git","status":"affected"},{"version":"d3bb267bbdcba199568f1325743d9d501dea0560","lessThan":"09861858a68342f851f71c669ac0f69865c32151","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/vhost/vhost.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"5.18","status":"affected"},{"version":"0","lessThan":"5.18","versionType":"semver","status":"unaffected"},{"version":"6.12.97","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/09861858a68342f851f71c669ac0f69865c32151","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/7f229d27bf27c7e589eca690d8612763a7a4801f","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/a9326b652bc7acd748d7a1143573845c7924d847","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/e115471008111f894c6528d9ab2ce7d0ce306f35","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-74357","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:22:37.170","lastModified":"2026-08-15T06:22:37.170","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amdgpu: fix KASAN slab-out-of-bounds in amdgpu_coredump ring dump\n\nThe ring content dump in amdgpu_coredump() uses two separate loops over\nadev->rings[]: the first counts rings with unsignalled fences to size\nthe allocation, and the second copies ring data into the allocated\nbuffers.\n\nBoth loops use the same condition to skip rings:\n\n    atomic_read(&ring->fence_drv.last_seq) == ring->fence_drv.sync_seq\n\nBecause last_seq is an atomic that is updated concurrently by the fence\nsignalling path, additional rings may appear unsignalled in the second\nloop that were signalled during the first. When this happens, idx\nexceeds the allocated ring_count and the store to coredump->rings[idx]\nwrites past the end of the kcalloc-ed buffer.\n\nThis was found during IGT stressful test amd_queue_reset which\ntriggers random GPU resets. The OVERSIZE subtest\n(CMD_STREAM_EXEC_INVALID_PACKET_LENGTH_OVERSIZE on GFX ring) provokes\na ring timeout and subsequent coredump, which hits the race between\nthe counting and copying loops. The failure is non-deterministic and\ndepends on fence signalling timing during the reset.\n\nKASAN log:\n\n  BUG: KASAN: slab-out-of-bounds in amdgpu_coredump+0x1274/0x12f0 [amdgpu]\n  Write of size 4 at addr ffff888106154258 by task kworker/u128:5/23625\n  CPU: 16 UID: 0 PID: 23625 Comm: kworker/u128:5 Not tainted 6.19.0+ #35\n  Workqueue: amdgpu-reset-dev drm_sched_job_timedout [gpu_sched]\n  Call Trace:\n   <TASK>\n   dump_stack_lvl+0xa5/0x110\n   print_report+0xd1/0x660\n   kasan_report+0xf3/0x130\n   __asan_report_store4_noabort+0x17/0x30\n   amdgpu_coredump+0x1274/0x12f0 [amdgpu]\n   amdgpu_job_timedout+0xef0/0x16c0 [amdgpu]\n   drm_sched_job_timedout+0x194/0x5c0 [gpu_sched]\n   process_one_work+0x84b/0x1990\n   worker_thread+0x6b8/0x11b0\n   </TASK>\n\n  Allocated by task 23625:\n   kasan_save_stack+0x39/0x70\n   __kasan_kmalloc+0xc3/0xd0\n   __kmalloc_noprof+0x2ec/0x910\n   amdgpu_coredump+0x5c5/0x12f0 [amdgpu]\n   amdgpu_job_timedout+0xef0/0x16c0 [amdgpu]\n\n  The buggy address belongs to the object at ffff888106154200\n   which belongs to the cache kmalloc-rnd-09-96 of size 96\n  The buggy address is located 16 bytes to the right of\n   allocated 72-byte region [ffff888106154200, ffff888106154248)\n\n72 bytes = 3 * sizeof(struct amdgpu_coredump_ring), so ring_count was 3\nbut idx reached 3+, writing ring_index (at struct offset 16) 16 bytes\npast the allocation.\n\nFix by adding an idx < ring_count guard to the copy loop so it cannot\nexceed the allocated count even when the fence state changes between\nthe two passes."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/gpu/drm/amd/amdgpu/amdgpu_dev_coredump.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"eea85914d15bfe3bdf9f8f80a479f0dee0aa7d73","lessThan":"efb1dadaeb897b22b9e118d398d0f41e70e9ccca","versionType":"git","status":"affected"},{"version":"eea85914d15bfe3bdf9f8f80a479f0dee0aa7d73","lessThan":"08ac3a7879d300302a1927ce2038629539a37f8b","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/gpu/drm/amd/amdgpu/amdgpu_dev_coredump.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"7.1","status":"affected"},{"version":"0","lessThan":"7.1","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/08ac3a7879d300302a1927ce2038629539a37f8b","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/efb1dadaeb897b22b9e118d398d0f41e70e9ccca","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-74358","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:22:37.313","lastModified":"2026-08-15T06:22:37.313","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\next4: fix fast commit wait/wake bit mapping on 64-bit\n\nOn 64-bit, ext4 dynamic inode states live in the upper half of i_flags,\nand ext4_test_inode_state() applies the corresponding +32 offset.\n\nThe fast-commit wait and wake paths open-coded the wait key with the raw\nEXT4_STATE_* value. Add small helpers for the state wait word and bit,\nand use them for the FC_COMMITTING and FC_FLUSHING_DATA waits so the wait\nkey follows the same mapping as the state helpers."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["fs/ext4/ext4.h","fs/ext4/fast_commit.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"857d32f2618166765ce9306a246d0745afc76859","lessThan":"e82d515092a0cf2bca92f399d5c330c324879cea","versionType":"git","status":"affected"},{"version":"857d32f2618166765ce9306a246d0745afc76859","lessThan":"d06df6e447a8510f86db44b2522d5375362a9499","versionType":"git","status":"affected"},{"version":"857d32f2618166765ce9306a246d0745afc76859","lessThan":"8b3bc93fee6771775243665a0cf31857d6659775","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["fs/ext4/ext4.h","fs/ext4/fast_commit.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.16","status":"affected"},{"version":"0","lessThan":"6.16","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/8b3bc93fee6771775243665a0cf31857d6659775","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/d06df6e447a8510f86db44b2522d5375362a9499","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/e82d515092a0cf2bca92f399d5c330c324879cea","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-74359","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:22:37.430","lastModified":"2026-08-15T06:22:37.430","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nconfigfs_lookup(): don't leave ->s_dentry dangling on failure\n\nNormally ->s_dentry is cleared when dentry it's pointing to becomes\nnegative (on eviction, realistically).  However, that only happens\nif dentry gets to be positive in the first place; in case of inode\nallocation failure dentry never becomes positive, so ->d_iput()\nis not called at all.\n\nWe do part of what normally would've been done by configfs_d_iput()\n(dropping the reference to configfs_dirent) manually, but we do\nnot clear ->s_dentry there.  Sloppy as it is, it does not matter in\ncase of configfs_create_{dir,link}() - there configfs_dirent does\nnot survive dropping the sole reference to it.\n\nHowever, for configfs_lookup() it *does* survive, with a dangling\npointer to soon to be freed dentry sitting it its ->s_dentry.\n\nSubsequent getdents(2) in that directory will end up dereferencing\nthat pointer in order to pick the inode number.  Use after free...\n\nThis is the minimal fix; the right approach is to set the linkage\nbetween dentry and configfs_dirent only after we know that we have\nan inode, but that takes more surgery and the bug had been there\nsince 2006, so..."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["fs/configfs/dir.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"3d0f89bb169482d26d5aa4e82e763077e7e9bc4d","lessThan":"3e83b2203aa59bd279e4f677ec793d49dc9d019e","versionType":"git","status":"affected"},{"version":"3d0f89bb169482d26d5aa4e82e763077e7e9bc4d","lessThan":"b6e9c82522ddaa3ac0706b295ff4a71975d4f883","versionType":"git","status":"affected"},{"version":"3d0f89bb169482d26d5aa4e82e763077e7e9bc4d","lessThan":"eee07d769da5ac4e4f7bd0bc17828646a318d499","versionType":"git","status":"affected"},{"version":"3d0f89bb169482d26d5aa4e82e763077e7e9bc4d","lessThan":"9c747dcee164ead300de90550ad9e4122f0d1bbb","versionType":"git","status":"affected"},{"version":"3d0f89bb169482d26d5aa4e82e763077e7e9bc4d","lessThan":"c3b073a209a9baa691b744318ac929fecdd8847c","versionType":"git","status":"affected"},{"version":"3d0f89bb169482d26d5aa4e82e763077e7e9bc4d","lessThan":"57088b06109f3222963c639d8d743f42c2899b13","versionType":"git","status":"affected"},{"version":"3d0f89bb169482d26d5aa4e82e763077e7e9bc4d","lessThan":"10da12d352b7b2bb330a8609fdda9a58bf0e9856","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["fs/configfs/dir.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"2.6.16","status":"affected"},{"version":"0","lessThan":"2.6.16","versionType":"semver","status":"unaffected"},{"version":"5.15.212","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.178","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.97","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/10da12d352b7b2bb330a8609fdda9a58bf0e9856","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/3e83b2203aa59bd279e4f677ec793d49dc9d019e","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/57088b06109f3222963c639d8d743f42c2899b13","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/9c747dcee164ead300de90550ad9e4122f0d1bbb","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/b6e9c82522ddaa3ac0706b295ff4a71975d4f883","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/c3b073a209a9baa691b744318ac929fecdd8847c","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/eee07d769da5ac4e4f7bd0bc17828646a318d499","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-74360","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:22:37.567","lastModified":"2026-08-15T06:22:37.567","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nbpf: Reject exclusive maps for bpf_map_elem iterators\n\nExclusive maps (aka excl_prog_hash) are meant to be reachable only\nfrom the single program whose hash matches. This is enforced by\ncheck_map_prog_compatibility() when the map is referenced from a\nprogram such as signed BPF loaders.\n\nA bpf_map_elem iterator, however, binds its target map at attach\ntime in bpf_iter_attach_map() instead of referencing it from the\nprogram, so the exclusivity check is never reached. On top of that,\nthe iterator exposes the map value as a writable buffer."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["kernel/bpf/map_iter.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"baefdbdf6812e120c9fba9cfb101d3656f478026","lessThan":"5cf2c85b1231218a3e3e9f188afb4fe2e17903d5","versionType":"git","status":"affected"},{"version":"baefdbdf6812e120c9fba9cfb101d3656f478026","lessThan":"c3da741d5b2119c61c4498bc936f0fc1dbc3c79b","versionType":"git","status":"affected"},{"version":"baefdbdf6812e120c9fba9cfb101d3656f478026","lessThan":"3c56ee343f9412d81918635c3e25e22a5dd6d87e","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["kernel/bpf/map_iter.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.18","status":"affected"},{"version":"0","lessThan":"6.18","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/3c56ee343f9412d81918635c3e25e22a5dd6d87e","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/5cf2c85b1231218a3e3e9f188afb4fe2e17903d5","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/c3da741d5b2119c61c4498bc936f0fc1dbc3c79b","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-74361","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:22:37.677","lastModified":"2026-08-15T06:22:37.677","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nnvme: fix FDP fdpcidx bounds check\n\nThe fdpcidx bounds check sets n = NUMFDPC + 1 but used > instead of >=,\nincorrectly accepting fdp_idx when it equals n (i.e. NUMFDPC + 1)."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/nvme/host/core.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"30b5f20bb2ddab013035399e5c7e6577da49320a","lessThan":"5e406928404d67a8da8aa3ae21732e1ea1a04118","versionType":"git","status":"affected"},{"version":"30b5f20bb2ddab013035399e5c7e6577da49320a","lessThan":"5d0e7d2af884b91329235abb16652ae4eead8079","versionType":"git","status":"affected"},{"version":"30b5f20bb2ddab013035399e5c7e6577da49320a","lessThan":"0967074f6830718fd2597404ef119bddd0dbfd00","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/nvme/host/core.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.16","status":"affected"},{"version":"0","lessThan":"6.16","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/0967074f6830718fd2597404ef119bddd0dbfd00","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/5d0e7d2af884b91329235abb16652ae4eead8079","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/5e406928404d67a8da8aa3ae21732e1ea1a04118","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-74362","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:22:37.783","lastModified":"2026-08-15T06:22:37.783","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\next2: fix ignored return value of generic_write_sync()\n\nFix ext2_dio_write_iter() to propagate the error returned by\ngeneric_write_sync() instead of silently discarding it, which could\ncause write(2) to return success to userspace on O_SYNC/O_DSYNC files\neven when the sync failed.\n\nThe correct pattern, already used in ext2_dax_write_iter() in the same\nfile and in ext4, xfs, f2fs among others, is:\n    if (ret > 0)\n        ret = generic_write_sync(iocb, ret);\n\nFound by Linux Verification Center (linuxtesting.org) with SVACE.\n\n[JK: Reflect also filemap_write_and_wait() return value]"}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["fs/ext2/file.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"fb5de4358e1aa4753dce73c4dc1aca73ff39cedd","lessThan":"8990dbb7065b0b002b1e58b9091a5b61f5e94dbe","versionType":"git","status":"affected"},{"version":"fb5de4358e1aa4753dce73c4dc1aca73ff39cedd","lessThan":"8d70b3973020e59845c0bdad90e0b9c2295fd493","versionType":"git","status":"affected"},{"version":"fb5de4358e1aa4753dce73c4dc1aca73ff39cedd","lessThan":"ffa974b2f50ad8b911b9066d7aed84ad0afabcdb","versionType":"git","status":"affected"},{"version":"fb5de4358e1aa4753dce73c4dc1aca73ff39cedd","lessThan":"b6bc07e49a5fbb335f56eb90cd63dec6584c77d3","versionType":"git","status":"affected"},{"version":"fb5de4358e1aa4753dce73c4dc1aca73ff39cedd","lessThan":"a4659be0bc7cb1856ffb15b67f903229ae8891ec","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["fs/ext2/file.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.5","status":"affected"},{"version":"0","lessThan":"6.5","versionType":"semver","status":"unaffected"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.97","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/8990dbb7065b0b002b1e58b9091a5b61f5e94dbe","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/8d70b3973020e59845c0bdad90e0b9c2295fd493","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/a4659be0bc7cb1856ffb15b67f903229ae8891ec","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/b6bc07e49a5fbb335f56eb90cd63dec6584c77d3","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/ffa974b2f50ad8b911b9066d7aed84ad0afabcdb","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-74363","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:22:37.900","lastModified":"2026-08-15T06:22:37.900","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nbpf: fix UAF by restoring RCU-delayed inode freeing in bpffs\n\ncommit 4f375ade6aa9 (\"bpf: Avoid RCU context warning when unpinning\nhtab with internal structs\") moved inode cleanup from ->free_inode()\ninto ->destroy_inode() to avoid sleeping in RCU context when calling\nbpf_any_put(). However this removed the RCU delay on freeing the\ninode itself and the cached symlink body (i_link), both of which\ncan be accessed by RCU pathwalk (pick_link, may_lookup etc.).\n\nThis causes a use-after-free when a concurrent unlinkat() drops the\nlast inode reference and destroy_inode() frees the inode immediately,\nwhile another task is still walking the path in RCU mode and reads\ninode->i_opflags (offset +2) inside current_time() -> is_mgtime().\n\nKASAN reports:\n  BUG: KASAN: slab-use-after-free in is_mgtime include/linux/fs.h:2313\n  Read of size 2 at addr ffff8880407e4282 (offset +2 = i_opflags)\n\nThe rules (per Al Viro):\n  ->destroy_inode()  called immediately, can sleep, use for blocking\n                     cleanup e.g. bpf_any_put()\n  ->free_inode()     called after RCU grace period, use for freeing\n                     inode and anything RCU-accessible e.g. i_link\n\nFix: split the two concerns properly:\n  - keep bpf_any_put() in bpf_destroy_inode() since it is blocking\n    and needs to run promptly\n  - introduce bpf_free_inode() to handle kfree(i_link) and\n    free_inode_nonrcu() with proper RCU delay, preventing the UAF"}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["kernel/bpf/inode.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"e28616ca3d67e745ecb2f10eba4a626e1fc9a203","lessThan":"ea1c243c39e32b7fc1c2edfe32081ff7e30a877c","versionType":"git","status":"affected"},{"version":"743a620c661994c7f0938e6dd32fb0883fb1e0ea","lessThan":"5fecb71c10c28aef276ba49c718dc961745fdcf0","versionType":"git","status":"affected"},{"version":"b6e9645be9eb93f7aff3ca887f8edb6f1d63358f","lessThan":"c70d0f9114c3cc156f6029a400c4eb7e6f7c82b2","versionType":"git","status":"affected"},{"version":"ee04cff9ed4d6bb25802f5cecfcd0750500410f3","lessThan":"53649846e0437d1d9b7cb993cfe54c367addf7ae","versionType":"git","status":"affected"},{"version":"4f375ade6aa9f37fd72d7a78682f639772089eed","lessThan":"61f19729728243c82476dee31315143ed3275e7f","versionType":"git","status":"affected"},{"version":"4f375ade6aa9f37fd72d7a78682f639772089eed","lessThan":"0497ff765746d9b2d17445c8f7cc737b36c0152a","versionType":"git","status":"affected"},{"version":"4f375ade6aa9f37fd72d7a78682f639772089eed","lessThan":"b93c55b4932dd7e32dca8cf34a3443cc87a02906","versionType":"git","status":"affected"},{"version":"de2d2baecc84cc7fca52eec2b9b55d89c93e3565","versionType":"git","status":"affected"},{"version":"5.15.195","lessThan":"5.15.212","versionType":"semver","status":"affected"},{"version":"6.1.157","lessThan":"6.1.178","versionType":"semver","status":"affected"},{"version":"6.6.113","lessThan":"6.6.145","versionType":"semver","status":"affected"},{"version":"6.12.54","lessThan":"6.12.97","versionType":"semver","status":"affected"},{"version":"6.17.4","lessThan":"6.18","versionType":"semver","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["kernel/bpf/inode.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.18","status":"affected"},{"version":"0","lessThan":"6.18","versionType":"semver","status":"unaffected"},{"version":"5.15.212","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.178","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.97","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/0497ff765746d9b2d17445c8f7cc737b36c0152a","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/53649846e0437d1d9b7cb993cfe54c367addf7ae","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/5fecb71c10c28aef276ba49c718dc961745fdcf0","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/61f19729728243c82476dee31315143ed3275e7f","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/b93c55b4932dd7e32dca8cf34a3443cc87a02906","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/c70d0f9114c3cc156f6029a400c4eb7e6f7c82b2","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/ea1c243c39e32b7fc1c2edfe32081ff7e30a877c","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-74364","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:22:38.037","lastModified":"2026-08-15T06:22:38.037","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nbpf: Reject exclusive maps as inner maps in map-in-map\n\nAn exclusive map (created with excl_prog_hash) is bound to a single\nprogram by hash: check_map_prog_compatibility() refuses to load any\nprogram whose digest does not match map->excl_prog_sha. That check\nonly runs for maps a program references directly, i.e. its used_maps.\nA map reached at runtime through a map-of-maps is never in used_maps,\nand bpf_map_meta_equal() does not consider excl_prog_sha, so an\nexclusive map can be inserted into a non-exclusive outer map and\nthen looked up and mutated by an unrelated program, bypassing the\nexclusivity guarantee.\n\nFor the signed loader this defeats the metadata map exclusivity check\nadded in the signed loader: the cached map->sha[] is validated against\nthe signed hash while another program on a hostile host rewrites the\nfrozen map's contents through the outer map."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["kernel/bpf/map_in_map.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"baefdbdf6812e120c9fba9cfb101d3656f478026","lessThan":"3a0f73d27a8d379a8852a378b3c3208143e3b3b2","versionType":"git","status":"affected"},{"version":"baefdbdf6812e120c9fba9cfb101d3656f478026","lessThan":"7c58ace08f180f8e249e714d1623388362f9d807","versionType":"git","status":"affected"},{"version":"baefdbdf6812e120c9fba9cfb101d3656f478026","lessThan":"9a3c3c49c333760c8944dadacbe114c1884546ef","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["kernel/bpf/map_in_map.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.18","status":"affected"},{"version":"0","lessThan":"6.18","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/3a0f73d27a8d379a8852a378b3c3208143e3b3b2","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/7c58ace08f180f8e249e714d1623388362f9d807","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/9a3c3c49c333760c8944dadacbe114c1884546ef","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-74365","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:22:38.143","lastModified":"2026-08-15T06:22:38.143","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nnvdimm/btt: Handle preemption in BTT lane acquisition\n\nBTT lanes serialize access to per-lane metadata and workspace state\nduring BTT I/O. The btt-check unit test reports data mismatches during\nBTT writes due to a race in lane acquisition that can lead to silent\ndata corruption.\n\nThe existing lane model uses a spinlock together with a per-CPU\nrecursion count. That recursion model stopped being valid after BTT\nlanes became preemptible: another task can run on the same CPU,\nobserve a non-zero recursion count, bypass locking, and use the same\nlane concurrently.\n\nBTT lanes are also held across arena_write_bytes() calls. That path\nreaches nsio_rw_bytes(), which flushes writes with nvdimm_flush().\nSome provider flush callbacks can sleep, making a spinlock the wrong\nprimitive for the lane lifetime.\n\nReplace the spinlock-based recursion model with a dynamically\nallocated per-lane mutex array and take the lane lock\nunconditionally.\n\nAdd might_sleep() to catch any future atomic-context caller.\n\nFound with the ndctl unit test btt-check.sh."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["Documentation/driver-api/nvdimm/btt.rst","drivers/nvdimm/nd.h","drivers/nvdimm/region_devs.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"f23859748e3d530217b197e146a9ac84faf0a282","lessThan":"fd7a97b2514cfc4b4cc067a27dd39bde2a8b1735","versionType":"git","status":"affected"},{"version":"6f50b414f1a0d790f11a6438a3ad6d0577eb2c18","lessThan":"73e35c1bdfa160b41fdbe204e02325f0687de506","versionType":"git","status":"affected"},{"version":"36c75ce3bd299878fd9b238e9803d3817ddafbf3","lessThan":"417918783bcfe0be135019df16a267b3af442efd","versionType":"git","status":"affected"},{"version":"36c75ce3bd299878fd9b238e9803d3817ddafbf3","lessThan":"5c53406098b599c420b031e6ec5ba8a2f3794c50","versionType":"git","status":"affected"},{"version":"36c75ce3bd299878fd9b238e9803d3817ddafbf3","lessThan":"4eafa810b042d985ec6bbf5b514414e73cee6f6f","versionType":"git","status":"affected"},{"version":"36c75ce3bd299878fd9b238e9803d3817ddafbf3","lessThan":"8d4b989d9c9afe5f185aa5853b666fc4617afe9e","versionType":"git","status":"affected"},{"version":"2577fece583c7c05cda7ad50dde7638c962665e1","versionType":"git","status":"affected"},{"version":"40ba3fa21250e361bdd8f00800b3e2cb6160de95","versionType":"git","status":"affected"},{"version":"b0e7a935739f33ed2bd6868b89f97dd4c2683c26","versionType":"git","status":"affected"},{"version":"66eb7b7f23dd9aec5356e7054dd3596ae7648ff5","versionType":"git","status":"affected"},{"version":"b27751fb1f271bbb78d5993c0b10011628e40e18","versionType":"git","status":"affected"},{"version":"6.1.63","lessThan":"6.1.178","versionType":"semver","status":"affected"},{"version":"6.6.2","lessThan":"6.6.145","versionType":"semver","status":"affected"},{"version":"4.19.299","lessThan":"4.20","versionType":"semver","status":"affected"},{"version":"5.4.261","lessThan":"5.5","versionType":"semver","status":"affected"},{"version":"5.10.201","lessThan":"5.11","versionType":"semver","status":"affected"},{"version":"5.15.139","lessThan":"5.16","versionType":"semver","status":"affected"},{"version":"6.5.12","lessThan":"6.6","versionType":"semver","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["Documentation/driver-api/nvdimm/btt.rst","drivers/nvdimm/nd.h","drivers/nvdimm/region_devs.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.7","status":"affected"},{"version":"0","lessThan":"6.7","versionType":"semver","status":"unaffected"},{"version":"6.1.178","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.97","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/417918783bcfe0be135019df16a267b3af442efd","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/4eafa810b042d985ec6bbf5b514414e73cee6f6f","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/5c53406098b599c420b031e6ec5ba8a2f3794c50","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/73e35c1bdfa160b41fdbe204e02325f0687de506","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/8d4b989d9c9afe5f185aa5853b666fc4617afe9e","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/fd7a97b2514cfc4b4cc067a27dd39bde2a8b1735","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-74366","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:22:38.287","lastModified":"2026-08-15T06:22:38.287","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: ath12k: fix NULL deref in change_sta_links for unready link\n\n_ieee80211_set_active_links() calls _ieee80211_link_use_channel() for\neach newly-added link and WARN_ON_ONCE()s if it fails. The call uses\nassign_on_failure=true, which allows mac80211 to continue despite\ndriver failures, but when a mac80211-level channel validation fails\n(e.g., combinations check, DFS, or no available radio),\ndrv_assign_vif_chanctx() is never reached. Since ath12k_mac_vdev_create()\nis only called from that path, arvif->is_created remains false and\narvif->ar remains NULL for the failed link.\n\nThe subsequent drv_change_sta_links() call reaches\nath12k_mac_op_change_sta_links(), which allocates an arsta and sets\nahsta->links_map |= BIT(link_id) for the broken link before checking\nwhether the link is ready. When the vdev was never created, only\nstation_add() is skipped, but the link remains in links_map.\n\nAny subsequent operation iterating links_map and dereferencing arvif->ar\nwithout a NULL check will crash. Two observed examples are NULL deref in\nath12k_mac_ml_station_remove() on disconnect and in ath12k_mac_op_set_key()\nwhen wpa_supplicant installs PTK keys.\n\n  BUG: Unable to handle kernel NULL pointer dereference at 0x00000000\n  pc : ath12k_mac_station_post_remove+0x40/0xe8 [ath12k]\n  Call trace:\n   ath12k_mac_station_post_remove+0x40/0xe8 [ath12k]\n   ath12k_mac_op_sta_state+0xb60/0x1720 [ath12k]\n   drv_sta_state+0x100/0xbd8 [mac80211]\n   __sta_info_destroy_part2+0x148/0x178 [mac80211]\n   ieee80211_set_disassoc+0x500/0x678 [mac80211]\n\n  BUG: Unable to handle kernel NULL pointer dereference at 0x00000000\n  pc : ath12k_mac_op_set_key+0x1f8/0x2c0 [ath12k]\n  Call trace:\n   ath12k_mac_op_set_key+0x1f8/0x2c0 [ath12k]\n   drv_set_key+0x70/0x100 [mac80211]\n   ieee80211_key_enable_hw_accel+0x78/0x260 [mac80211]\n   ieee80211_add_key+0x16c/0x2ac [mac80211]\n   nl80211_new_key+0x138/0x280 [cfg80211]\n\nFix this by checking arvif->is_created before calling\nath12k_mac_alloc_assign_link_sta(). This prevents the broken link from\nentering links_map, so all subsequent operations iterating the bitmap\nare protected. The reliability of arvif->is_created across all error\npaths is ensured by the preceding patch.\n\nTested-on: WCN7850 hw2.0 PCI WLAN.HMT.1.1.c5-00302-QCAHMTSWPL_V1.0_V2.0_SILICONZ-1.115823.3"}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/net/wireless/ath/ath12k/mac.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"a27fa6148dacc79451e523c2694bc0a673b1be05","lessThan":"cfcea221db933295bf2cd75a7f80d441c7a51e28","versionType":"git","status":"affected"},{"version":"a27fa6148dacc79451e523c2694bc0a673b1be05","lessThan":"5f5be2aa3b6d730c51dd4f8b432f2ad72823e63f","versionType":"git","status":"affected"},{"version":"a27fa6148dacc79451e523c2694bc0a673b1be05","lessThan":"47809a7c8348bc4a332ccc26a37c7145a5f609f8","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/net/wireless/ath/ath12k/mac.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.14","status":"affected"},{"version":"0","lessThan":"6.14","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/47809a7c8348bc4a332ccc26a37c7145a5f609f8","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/5f5be2aa3b6d730c51dd4f8b432f2ad72823e63f","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/cfcea221db933295bf2cd75a7f80d441c7a51e28","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-74367","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:22:38.407","lastModified":"2026-08-15T06:22:38.407","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: ath12k: fix inconsistent arvif state in vdev_create error paths\n\nath12k_mac_vdev_create() has three error path issues that leave arvif\nin an inconsistent state:\n\n1. When ath12k_wmi_vdev_create() fails, the function returns directly\n   without clearing arvif->ar, which was already set before the WMI\n   call. Subsequent code checking arvif->ar to determine vdev readiness\n   will see a non-NULL value despite no vdev existing in firmware.\n\n2. When ath12k_wmi_send_peer_delete_cmd() fails in err_peer_del, the\n   code jumped to err: skipping the DP peer cleanup and vdev rollback,\n   leaving num_created_vdevs, vdev maps and arvif list membership live.\n\n3. When ath12k_wait_for_peer_delete_done() fails, the code jumped to\n   err_vdev_del: skipping the DP peer cleanup.\n\nFix by changing the ath12k_wmi_vdev_create() failure to goto err instead\nof returning directly, routing both err_peer_del failure paths through\nerr_dp_peer_del: for proper DP peer and vdev rollback, and consolidating\nthe arvif state cleanup at err:.\n\nTested-on: WCN7850 hw2.0 PCI WLAN.HMT.1.1.c5-00302-QCAHMTSWPL_V1.0_V2.0_SILICONZ-1.115823.3"}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/net/wireless/ath/ath12k/mac.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"477cabfdb776b571fab425813c074f30c02a5cf6","lessThan":"e0140e094b196d92f2a4ce167ee73cbfab000290","versionType":"git","status":"affected"},{"version":"477cabfdb776b571fab425813c074f30c02a5cf6","lessThan":"c972636efc63f0f43d725b59805dd1ae5bc4b31e","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/net/wireless/ath/ath12k/mac.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.13","status":"affected"},{"version":"0","lessThan":"6.13","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/c972636efc63f0f43d725b59805dd1ae5bc4b31e","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/e0140e094b196d92f2a4ce167ee73cbfab000290","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-74368","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:22:38.530","lastModified":"2026-08-15T06:22:38.530","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: ath12k: fix memory leak in ath12k_wifi7_dp_rx_h_verify_tkip_mic()\n\nIn ath12k_wifi7_dp_rx_h_verify_tkip_mic(), the call to\nath12k_dp_rx_check_nwifi_hdr_len_valid() may return false when the\nNWIFI header length is invalid, causing the function to abort early with\n-EINVAL.\n\nWhen this happens, the error propagates to\nath12k_wifi7_dp_rx_h_defrag(), which clears first_frag by setting it\nto NULL. As a result, the corresponding MSDU is no longer referenced\nby the defragmentation path and is never freed.\n\nThis leads to a memory leak for the affected MSDU on this error path.\nProper cleanup is required to ensure the MSDU is released when header\nvalidation fails during TKIP MIC verification.\n\nTested-on: WCN7850 hw2.0 PCI WLAN.HMT.1.1.c5-00302-QCAHMTSWPL_V1.0_V2.0_SILICONZ-1.115823.3"}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/net/wireless/ath/ath12k/wifi7/dp_rx.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"9a0dddfb30f120db3851627935851d262e4e7acb","lessThan":"5187a92099778501f21af76ed6c8415d128e7298","versionType":"git","status":"affected"},{"version":"9a0dddfb30f120db3851627935851d262e4e7acb","lessThan":"98d4f92ab6a1af2ea2ab590d7e2801b203110981","versionType":"git","status":"affected"},{"version":"7f1d986da5c6abb75ffe4d0d325fc9b341c41a1c","versionType":"git","status":"affected"},{"version":"3abe15e756481c45f6acba3d476cb3ca4afc3b61","versionType":"git","status":"affected"},{"version":"6ee653194ddb83674913fd2727b8ecfae0597ade","versionType":"git","status":"affected"},{"version":"50be1fb76556e80af9f5da80f28168b6c71bce58","versionType":"git","status":"affected"},{"version":"6.6.88","lessThan":"6.7","versionType":"semver","status":"affected"},{"version":"6.12.24","lessThan":"6.13","versionType":"semver","status":"affected"},{"version":"6.13.12","lessThan":"6.14","versionType":"semver","status":"affected"},{"version":"6.14.3","lessThan":"6.15","versionType":"semver","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/net/wireless/ath/ath12k/wifi7/dp_rx.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.15","status":"affected"},{"version":"0","lessThan":"6.15","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/5187a92099778501f21af76ed6c8415d128e7298","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/98d4f92ab6a1af2ea2ab590d7e2801b203110981","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-74369","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:22:38.640","lastModified":"2026-08-15T06:22:38.640","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nliveupdate: fix u-a-f in luo_file_unpreserve_files() and luo_file_finish()\n\nIn luo_file_unpreserve_files() and luo_file_finish(), reorder\nmodule_put() and xa_erase() to ensure the file handler module remains\npinned while its operations are being accessed.\n\nSpecifically, luo_get_id() dereferences fh->ops->get_id, so the module\nreference must be held until after xa_erase() (which calls luo_get_id)\ncompletes.\n\nFor luo_file_finish(), this requires moving the module_put() call out of\nthe luo_file_finish_one() helper and into the main loop of\nluo_file_finish() itself."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["kernel/liveupdate/luo_file.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"00d0b372374f2528394aabf7b1f53f8dafe294de","lessThan":"f7fca3db635022429382cf26e5b08b33558e375d","versionType":"git","status":"affected"},{"version":"00d0b372374f2528394aabf7b1f53f8dafe294de","lessThan":"291dcd37c8c8f8f8e1bccc92228f44bf371762a8","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["kernel/liveupdate/luo_file.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"7.1","status":"affected"},{"version":"0","lessThan":"7.1","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/291dcd37c8c8f8f8e1bccc92228f44bf371762a8","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/f7fca3db635022429382cf26e5b08b33558e375d","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-74370","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:22:38.750","lastModified":"2026-08-15T06:22:38.750","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nliveupdate: fix TOCTOU race in luo_session_retrieve()\n\nExtend the scope of the rwsem_read lock in luo_session_retrieve() to\noverlap with the acquisition of the session mutex. This prevents a\nconcurrent thread from releasing and freeing the session between the\nlookup and the mutex lock."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["kernel/liveupdate/luo_session.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"0153094d03df5a2e834a19c59b255649a258ae46","lessThan":"d944170607b872a1f93713c555ad3f0efde3a9b8","versionType":"git","status":"affected"},{"version":"0153094d03df5a2e834a19c59b255649a258ae46","lessThan":"d3ae9e7fddb4036f50003d7fa1ef52801fdb961b","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["kernel/liveupdate/luo_session.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.19","status":"affected"},{"version":"0","lessThan":"6.19","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/d3ae9e7fddb4036f50003d7fa1ef52801fdb961b","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/d944170607b872a1f93713c555ad3f0efde3a9b8","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-74371","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:22:38.857","lastModified":"2026-08-15T06:22:38.857","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nbpf: fix BPF_PROG_QUERY OOB write and cgroup backward compat\n\nBPF_PROG_QUERY writes back the 'query.revision' field unconditionally to\nuserspace. If userspace passes a smaller 'bpf_attr' structure (e.g. 40\nbytes, which was the layout before the addition of 'query.revision'),\nthe kernel performs an out-of-bounds write.\n\nFix this by propagating the user-provided attribute size 'uattr_size'\ndown to the cgroup query handlers, and conditionally skipping writing\nthe revision field to userspace when the provided buffer size is\ninsufficient.\n\nquery.revision in bpf_mprog_query is structurally identical to the\ncgroup case: a late tail field, written unconditionally.\n\nBut the backward-compat hazard is not the same.\n\nThe min-historical-size test is per command, and bpf_mprog_query only\nserves attach types that were born with revision in the struct:\n\n- tcx_prog_query -> BPF_TCX_INGRESS/EGRESS\n- netkit_prog_query -> BPF_NETKIT_PRIMARY/PEER\n\ntcx, netkit, the revision field, and bpf_mprog_query itself all landed in\nthe same v6.6 merge window (053c8e1f235d added the mprog query API +\nrevision; tcx in e420bed02507, netkit in 35dfaad7188c). There has never\nbeen a tcx/netkit BPF_PROG_QUERY userspace that doesn't know about\nrevision. So for these commands the minimum legitimate struct already\ncovers offset 56-64 — no old binary can be broken here.\n\nContrast with cgroup: BPF_PROG_QUERY on cgroup attach types shipped in\n2017; revision write-back was bolted on years later (120933984460). That\npath has a real population of pre-revision callers."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["include/linux/bpf-cgroup.h","kernel/bpf/cgroup.c","kernel/bpf/syscall.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"1209339844601ec1766f4ff430673fbcfe42bb51","lessThan":"a7131340d0f95df9a541257dccab5d85e6bcdd2b","versionType":"git","status":"affected"},{"version":"1209339844601ec1766f4ff430673fbcfe42bb51","lessThan":"d3d630e8a7f3421bc2d204b87bdff35b4432a8e3","versionType":"git","status":"affected"},{"version":"1209339844601ec1766f4ff430673fbcfe42bb51","lessThan":"21c4b99b27f3f85b89256e81b3e997dec0a460d0","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["include/linux/bpf-cgroup.h","kernel/bpf/cgroup.c","kernel/bpf/syscall.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.17","status":"affected"},{"version":"0","lessThan":"6.17","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/21c4b99b27f3f85b89256e81b3e997dec0a460d0","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/a7131340d0f95df9a541257dccab5d85e6bcdd2b","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/d3d630e8a7f3421bc2d204b87bdff35b4432a8e3","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-74372","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:22:38.967","lastModified":"2026-08-15T06:22:38.967","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nraid1: fix nr_pending leak in REQ_ATOMIC bad-block error path\n\nIn raid1_write_request(), each per-mirror loop iteration begins by\nincrementing rdev->nr_pending. If a REQ_ATOMIC write encounters a\nbadblock within the requested range, the code jumps to err_handle\nwithout dropping the reference taken for the current mirror.\n\nerr_handle's cleanup loop will only decrements for k < i and\nr1_bio->bios[k] is non-NULL. The current slot is therefore skipped,\nleaving its nr_pending reference leaked permanently. The reference\nprevents the rdev from ever being removed, since raid1_remove_conf()\nrefuses to remove an rdev with nr_pending > 0.\n\nFix this by calling rdev_dec_pending() before jumping to err_handle."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/md/raid1.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"f2a38abf5f1c5aeb3be8e9f4d3d815c867fff7ca","lessThan":"5ac9e793ba2583d72740d929e7858a6c82e22ed5","versionType":"git","status":"affected"},{"version":"f2a38abf5f1c5aeb3be8e9f4d3d815c867fff7ca","lessThan":"731485617bf862f1289c3f40ed1f800d0475826f","versionType":"git","status":"affected"},{"version":"f2a38abf5f1c5aeb3be8e9f4d3d815c867fff7ca","lessThan":"909d9dc3b5730c8ed7b764c68bc788342df2a07b","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/md/raid1.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.13","status":"affected"},{"version":"0","lessThan":"6.13","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/5ac9e793ba2583d72740d929e7858a6c82e22ed5","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/731485617bf862f1289c3f40ed1f800d0475826f","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/909d9dc3b5730c8ed7b764c68bc788342df2a07b","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-74373","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:22:39.070","lastModified":"2026-08-15T06:22:39.070","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nmd/raid1,raid10: fix bio accounting for split md cloned bios\n\nUse md_cloned_bio() to control bio accounting instead of relying\non r1bio_existed in raid1 or the io_accounting flag in raid10.\n\nThe previous logic does not reliably reflect whether a bio is an\nmd cloned bio. When a failed bio is split and resubmitted via\nbio_submit_split_bioset() on the error path, this can lead to either\ndouble accounting for md cloned bios, or missing accounting for bios\nreturned from bio_submit_split_bioset()\n\nFix this by using md_cloned_bio() to detect md cloned bios and\nskip accounting accordingly."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/md/raid1.c","drivers/md/raid10.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"bb2a9acefaf9ce5bbc1e70f407e34599233d0243","lessThan":"bb8d7ea74206b419aa05d7773a15a923b668c9f0","versionType":"git","status":"affected"},{"version":"bb2a9acefaf9ce5bbc1e70f407e34599233d0243","lessThan":"ba976e3501111d11c550848b3b7341a73035f582","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/md/raid1.c","drivers/md/raid10.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.6","status":"affected"},{"version":"0","lessThan":"6.6","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/ba976e3501111d11c550848b3b7341a73035f582","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/bb8d7ea74206b419aa05d7773a15a923b668c9f0","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-74374","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:22:39.173","lastModified":"2026-08-15T06:22:39.173","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nmd/raid1,raid10: fix error-path detection with md_cloned_bio()\n\nDetect the error path using md_cloned_bio() instead of relying\non r1_bio in raid1 or r10_bio->read_slot in raid10, which may be\nNULL or -1 after splitting and resubmitting a failed bio.\n\nAs a result, the error path may not be recognized and memory\nallocations can incorrectly use GFP_NOIO instead of\n(GFP_NOIO | __GFP_HIGH), which can lead to a deadlock under\nmemory pressure."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/md/raid1.c","drivers/md/raid10.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"689389a06ce79fdced85b5115717f71c71e623e0","lessThan":"20fb582c92fd64e5c8bd83c6176264b2794603b7","versionType":"git","status":"affected"},{"version":"689389a06ce79fdced85b5115717f71c71e623e0","lessThan":"811545e0926d02a6a0b1a1258bb5544777c164d4","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/md/raid1.c","drivers/md/raid10.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"4.12","status":"affected"},{"version":"0","lessThan":"4.12","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/20fb582c92fd64e5c8bd83c6176264b2794603b7","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/811545e0926d02a6a0b1a1258bb5544777c164d4","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-74375","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:22:39.277","lastModified":"2026-08-15T06:22:39.277","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nmd/raid1,raid10: fix deadlock in read error recovery path\n\nraid1d and raid10d may resubmit a split md cloned bio while handling\na read error. In this case, resubmitting the bio can lead to a deadlock\nif the array is suspended before md_handle_request() acquires an\nactive_io reference via percpu_ref_tryget_live().\n\nSince the cloned bio already holds an active_io reference,\ntrying to acquire another reference via percpu_ref_tryget_live()\ncan lead to a deadlock while the array is suspended.\n\nFix this by using percpu_ref_get() for md cloned bios."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/md/md.c","drivers/md/md.h"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"bb2a9acefaf9ce5bbc1e70f407e34599233d0243","lessThan":"38777f014c37972868f1733a651c85288bb8a757","versionType":"git","status":"affected"},{"version":"bb2a9acefaf9ce5bbc1e70f407e34599233d0243","lessThan":"7b15c24f805339a585cfe7d72f446b7e88b9bcc0","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/md/md.c","drivers/md/md.h"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.6","status":"affected"},{"version":"0","lessThan":"6.6","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/38777f014c37972868f1733a651c85288bb8a757","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/7b15c24f805339a585cfe7d72f446b7e88b9bcc0","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-74376","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:22:39.373","lastModified":"2026-08-15T06:22:39.373","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nmd/raid10: reset read_slot when reusing r10bio for discard\n\nput_all_bios() always drops devs[i].bio, but it only drops\ndevs[i].repl_bio when r10_bio->read_slot < 0. If discard reuses an\nr10bio that was previously used for a read, read_slot can still be\nnon-negative, and discard cleanup can skip bio_put() on repl_bio.\n\nReset read_slot to -1 when preparing an r10bio for discard so the\nreplacement bio is always released correctly."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/md/raid10.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"d30588b2731fb01e1616cf16c3fe79a1443e29aa","lessThan":"3cb2a606ce4902eceabe68338df0653312f861f8","versionType":"git","status":"affected"},{"version":"d30588b2731fb01e1616cf16c3fe79a1443e29aa","lessThan":"561c9711e4f545d6464a023168bdee03b00fa945","versionType":"git","status":"affected"},{"version":"d30588b2731fb01e1616cf16c3fe79a1443e29aa","lessThan":"ce3030e92f14362880055de5fe3c258971118853","versionType":"git","status":"affected"},{"version":"d30588b2731fb01e1616cf16c3fe79a1443e29aa","lessThan":"742e4afd247d9c972695227716b03d432a7e1d26","versionType":"git","status":"affected"},{"version":"d30588b2731fb01e1616cf16c3fe79a1443e29aa","lessThan":"b7313f23ea5a79b199a007bfad64a866cc2c22e7","versionType":"git","status":"affected"},{"version":"d30588b2731fb01e1616cf16c3fe79a1443e29aa","lessThan":"eb04e3e9c14ed15914f5fd2eae8b6435f54f095f","versionType":"git","status":"affected"},{"version":"d30588b2731fb01e1616cf16c3fe79a1443e29aa","lessThan":"6b8a26af065ddc93de2aa5c9f0df98dce9723442","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/md/raid10.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"5.13","status":"affected"},{"version":"0","lessThan":"5.13","versionType":"semver","status":"unaffected"},{"version":"5.15.212","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.178","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.97","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/3cb2a606ce4902eceabe68338df0653312f861f8","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/561c9711e4f545d6464a023168bdee03b00fa945","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/6b8a26af065ddc93de2aa5c9f0df98dce9723442","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/742e4afd247d9c972695227716b03d432a7e1d26","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/b7313f23ea5a79b199a007bfad64a866cc2c22e7","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/ce3030e92f14362880055de5fe3c258971118853","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/eb04e3e9c14ed15914f5fd2eae8b6435f54f095f","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-74377","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:22:39.487","lastModified":"2026-08-15T06:22:39.487","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nRDMA/rxe: Copy WQE to local buffer in non-SRQ receive path\n\nFor non-SRQ QPs, the responder reads WQE fields directly from the\nshared queue buffer mapped into userspace. This allows a malicious\nuser to modify fields like num_sge or sge entries while the kernel\nis processing the WQE, leading to out-of-bounds reads in\nrxe_resp_check_length() and copy_data().\n\nIntroduce get_recv_wqe() that validates num_sge and copies the WQE\nto a kernel-local buffer before processing, matching the approach\nalready used for SRQ WQEs in get_srq_wqe(). The srq_wqe buffer is\nreused since SRQ and non-SRQ paths are mutually exclusive per QP."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/infiniband/sw/rxe/rxe_resp.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"8700e3e7c4857d28ebaa824509934556da0b3e76","lessThan":"2e60378fb3c8b51c94103bb40014c4fe38fa5033","versionType":"git","status":"affected"},{"version":"8700e3e7c4857d28ebaa824509934556da0b3e76","lessThan":"fc72fd61cc8b2e2e3e92ae4c0e9cc30c9a7ecb78","versionType":"git","status":"affected"},{"version":"8700e3e7c4857d28ebaa824509934556da0b3e76","lessThan":"9fa785137303f7109c23dea779b8dedc67c9b531","versionType":"git","status":"affected"},{"version":"8700e3e7c4857d28ebaa824509934556da0b3e76","lessThan":"5420eebf3b3c162bfaf965f30e61cd1d689e5732","versionType":"git","status":"affected"},{"version":"8700e3e7c4857d28ebaa824509934556da0b3e76","lessThan":"a211b7904aed365e4e4f08a48ec6e6dd1ea7b16b","versionType":"git","status":"affected"},{"version":"8700e3e7c4857d28ebaa824509934556da0b3e76","lessThan":"d6ab440240a04b8737ee4c7bb21af9182e451733","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/infiniband/sw/rxe/rxe_resp.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"4.8","status":"affected"},{"version":"0","lessThan":"4.8","versionType":"semver","status":"unaffected"},{"version":"6.1.178","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.97","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/2e60378fb3c8b51c94103bb40014c4fe38fa5033","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/5420eebf3b3c162bfaf965f30e61cd1d689e5732","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/9fa785137303f7109c23dea779b8dedc67c9b531","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/a211b7904aed365e4e4f08a48ec6e6dd1ea7b16b","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/d6ab440240a04b8737ee4c7bb21af9182e451733","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/fc72fd61cc8b2e2e3e92ae4c0e9cc30c9a7ecb78","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-74378","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:22:39.597","lastModified":"2026-08-15T06:22:39.597","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nRDMA/rxe: Fix TOCTOU heap overflow in get_srq_wqe\n\nget_srq_wqe() reads wqe->dma.num_sge from the shared receive queue\nbuffer, which is mapped into userspace. It validates num_sge against\nmax_sge, but then re-reads the same field to calculate the memcpy\nsize. A concurrent userspace thread can modify num_sge between\nvalidation and use, causing a heap buffer overflow when copying the\nWQE into qp->resp.srq_wqe.\n\nRead num_sge into a local variable and use it for both the bounds\ncheck and the size calculation."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/infiniband/sw/rxe/rxe_resp.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"8700e3e7c4857d28ebaa824509934556da0b3e76","lessThan":"3cfa2a3adc51b7c57729961a03446962ff10e3d2","versionType":"git","status":"affected"},{"version":"8700e3e7c4857d28ebaa824509934556da0b3e76","lessThan":"cd19a6345e3727adafafa5954b58b13c92e13b80","versionType":"git","status":"affected"},{"version":"8700e3e7c4857d28ebaa824509934556da0b3e76","lessThan":"3e07ea9579dc9553d2285c26c2823931358aa3b8","versionType":"git","status":"affected"},{"version":"8700e3e7c4857d28ebaa824509934556da0b3e76","lessThan":"02558c86b6b761063e9399e6b939984500327ef1","versionType":"git","status":"affected"},{"version":"8700e3e7c4857d28ebaa824509934556da0b3e76","lessThan":"b9800d7953d119bcc068c74587d48e4ba0313629","versionType":"git","status":"affected"},{"version":"8700e3e7c4857d28ebaa824509934556da0b3e76","lessThan":"22b8fbded65b8c441b634a185f8da67657df6c50","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/infiniband/sw/rxe/rxe_resp.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"4.8","status":"affected"},{"version":"0","lessThan":"4.8","versionType":"semver","status":"unaffected"},{"version":"6.1.178","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.97","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/02558c86b6b761063e9399e6b939984500327ef1","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/22b8fbded65b8c441b634a185f8da67657df6c50","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/3cfa2a3adc51b7c57729961a03446962ff10e3d2","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/3e07ea9579dc9553d2285c26c2823931358aa3b8","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/b9800d7953d119bcc068c74587d48e4ba0313629","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/cd19a6345e3727adafafa5954b58b13c92e13b80","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-74379","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:22:39.703","lastModified":"2026-08-15T06:22:39.703","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\ndax/kmem: account for partial discontiguous resource upon removal\n\nWhen dev_dax_kmem_probe() partially succeeds (at least one range is\nmapped) but a subsequent range fails request_mem_region() or\nadd_memory_driver_managed(), the probe silently continues, ultimately\nreturning success, but with the corresponding range resource NULL'ed out.\n\ndev_dax_kmem_remove() iterates over all dax_device ranges regardless of if\nthe underlying resource exists.  When remove_memory() is called later, it\nreturns 0 because the memory was never added which causes\ndev_dax_kmem_remove() to incorrectly assume the (nonexistent) resource can\nbe removed and attempts cleanup on a NULL pointer.\n\nFix this by skipping these ranges altogether, noting that these cases are\nconsidered success, such that the cleanup is still reached when all\nactually-added ranges are successfully removed."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/dax/kmem.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"60e93dc097f7f13a16a7e4b75b8803eb2adbb721","lessThan":"ef4fc53898bd6c4d0119cc6d419ebef7f2560f31","versionType":"git","status":"affected"},{"version":"60e93dc097f7f13a16a7e4b75b8803eb2adbb721","lessThan":"5d3139abb9d1671fa5e42c3d6d8cb3b05479c5bb","versionType":"git","status":"affected"},{"version":"60e93dc097f7f13a16a7e4b75b8803eb2adbb721","lessThan":"d47b0b8a69a13e06afafa54723f3e8c99b0c788f","versionType":"git","status":"affected"},{"version":"60e93dc097f7f13a16a7e4b75b8803eb2adbb721","lessThan":"799e54c510a03a65a57627018a817838d72f35bd","versionType":"git","status":"affected"},{"version":"60e93dc097f7f13a16a7e4b75b8803eb2adbb721","lessThan":"598ed7393a639c7547b28ff3e14db9f1ac37c132","versionType":"git","status":"affected"},{"version":"60e93dc097f7f13a16a7e4b75b8803eb2adbb721","lessThan":"30ea97affbcce236c57287c82dc6ef7a29c63b76","versionType":"git","status":"affected"},{"version":"60e93dc097f7f13a16a7e4b75b8803eb2adbb721","lessThan":"8aa442cfce79e2d69e72fc8e0c0864ac2971149d","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/dax/kmem.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"5.10","status":"affected"},{"version":"0","lessThan":"5.10","versionType":"semver","status":"unaffected"},{"version":"5.15.212","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.178","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.97","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/30ea97affbcce236c57287c82dc6ef7a29c63b76","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/598ed7393a639c7547b28ff3e14db9f1ac37c132","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/5d3139abb9d1671fa5e42c3d6d8cb3b05479c5bb","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/799e54c510a03a65a57627018a817838d72f35bd","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/8aa442cfce79e2d69e72fc8e0c0864ac2971149d","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/d47b0b8a69a13e06afafa54723f3e8c99b0c788f","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/ef4fc53898bd6c4d0119cc6d419ebef7f2560f31","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-74380","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:22:39.820","lastModified":"2026-08-15T06:22:39.820","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\ngpu: host1x: Fix iommu_map_sgtable() return value check\n\nCommit \"iommu: return full error code from iommu_map_sg[_atomic]()\"\nchanged iommu_map_sgtable() to return an ssize_t and negative values\nin error cases, rather than a size_t and a zero.\n\npin_job() also was incorrectly assigning to 'int', which could cause\noverflows into negative values.\n\nUpdate pin_job() to correctly check for errors from iommu_map_sgtable."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/gpu/host1x/job.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"ad8f36e4b6b1c826a0daa5fda2c5839205b5aa8b","lessThan":"5f3985c2a500df3126cb12a2e0ccf26a40bc495d","versionType":"git","status":"affected"},{"version":"ad8f36e4b6b1c826a0daa5fda2c5839205b5aa8b","lessThan":"3ac173e46ef6fda9c9df8d47cdff4df962df9728","versionType":"git","status":"affected"},{"version":"ad8f36e4b6b1c826a0daa5fda2c5839205b5aa8b","lessThan":"2a68928c445138961e2c451983b473aeb3f5b999","versionType":"git","status":"affected"},{"version":"ad8f36e4b6b1c826a0daa5fda2c5839205b5aa8b","lessThan":"79240eee5a40014d9edfabe19f06b35ffa84e5f8","versionType":"git","status":"affected"},{"version":"ad8f36e4b6b1c826a0daa5fda2c5839205b5aa8b","lessThan":"e024c7993d839503d6c1f0044b8fc537c30300e9","versionType":"git","status":"affected"},{"version":"ad8f36e4b6b1c826a0daa5fda2c5839205b5aa8b","lessThan":"18f74762013a4b6aa6f905c4459e0f506f9c5c7b","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/gpu/host1x/job.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"5.15","status":"affected"},{"version":"0","lessThan":"5.15","versionType":"semver","status":"unaffected"},{"version":"6.1.178","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.97","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/18f74762013a4b6aa6f905c4459e0f506f9c5c7b","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/2a68928c445138961e2c451983b473aeb3f5b999","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/3ac173e46ef6fda9c9df8d47cdff4df962df9728","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/5f3985c2a500df3126cb12a2e0ccf26a40bc495d","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/79240eee5a40014d9edfabe19f06b35ffa84e5f8","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/e024c7993d839503d6c1f0044b8fc537c30300e9","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-74381","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:22:39.927","lastModified":"2026-08-15T06:22:39.927","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\ngpu: host1x: Allow entries in BO caches to be freed\n\nWhen a buffer object is pinned via host1x_bo_pin() with a cache, the\nresulting mapping is kept in the cache so it can be reused on subsequent\npins. Each mapping held a reference to the underlying host1x_bo (taken\nin tegra_bo_pin / gather_bo_pin), so as long as a mapping was cached,\nthe bo itself could not be freed.\n\nHowever, the only way to remove the cached mapping was through the free\npath of the buffer object. This meant that if a bo got cached, it could\nnever get freed again.\n\nResolve the circularity by holding a weak reference to the bo from the\ncache side. This is done by having the .pin callbacks not bump the bo's\nrefcount -- instead the common Host1x bo code does so, except for the\ncache reference.\n\nAlso move the remove-cache-mapping-on-free code into a common function\ninside Host1x code. This is only called from the TegraDRM GEM buffers\nsince those are the only ones that can be cached at the moment."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/gpu/drm/tegra/gem.c","drivers/gpu/drm/tegra/submit.c","drivers/gpu/host1x/bus.c","include/linux/host1x.h"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"1f39b1dfa53c84b56d7ad37fed44afda7004959d","lessThan":"af755456299d44e4ed6af3b7c70a7f03ea37fdf1","versionType":"git","status":"affected"},{"version":"1f39b1dfa53c84b56d7ad37fed44afda7004959d","lessThan":"71c017b3f83ff72638f2a1b1d6d4e7bc61d30231","versionType":"git","status":"affected"},{"version":"1f39b1dfa53c84b56d7ad37fed44afda7004959d","lessThan":"0e9dd7cfb9986b78cc81eca126ccfbf57f4c0602","versionType":"git","status":"affected"},{"version":"1f39b1dfa53c84b56d7ad37fed44afda7004959d","lessThan":"8c0d3cf0d5108c96317e0eca92b60dd368867cef","versionType":"git","status":"affected"},{"version":"1f39b1dfa53c84b56d7ad37fed44afda7004959d","lessThan":"df63c76f9c8d881ca7bce1aecfba512328d0527d","versionType":"git","status":"affected"},{"version":"1f39b1dfa53c84b56d7ad37fed44afda7004959d","lessThan":"3cbf5e3c46e66d9b3b6b91099bb720c6cb1be3bc","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/gpu/drm/tegra/gem.c","drivers/gpu/drm/tegra/submit.c","drivers/gpu/host1x/bus.c","include/linux/host1x.h"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"5.17","status":"affected"},{"version":"0","lessThan":"5.17","versionType":"semver","status":"unaffected"},{"version":"6.1.178","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.97","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/0e9dd7cfb9986b78cc81eca126ccfbf57f4c0602","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/3cbf5e3c46e66d9b3b6b91099bb720c6cb1be3bc","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/71c017b3f83ff72638f2a1b1d6d4e7bc61d30231","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/8c0d3cf0d5108c96317e0eca92b60dd368867cef","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/af755456299d44e4ed6af3b7c70a7f03ea37fdf1","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/df63c76f9c8d881ca7bce1aecfba512328d0527d","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-74382","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:22:40.040","lastModified":"2026-08-15T06:22:40.040","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nnet/sched: cls_bpf: prevent unbounded recursion in offload rollback\n\nQuan Sun reported [1] a stack overflow in cls_bpf_offload_cmd().\n\nReproducer on netdevsim: add a skip_sw cls_bpf filter, set the\nbpf_tc_accept debugfs knob to 0, then `tc filter replace`. The replace\ncalls tc_setup_cb_replace() which fails. cls_bpf_offload_cmd() then\nswaps prog/oldprog and recursively calls itself to roll back. But\nbpf_tc_accept=0 makes the rollback fail too, which triggers yet another\nrollback frame with the same arguments, and so on until the stack is\nexhausted.\n\nbpf_tc_accept is just a convenient knob for the reproducer. Any driver\nwhose tc_setup_cb_replace() fails twice in a row can hit the same loop,\nso this is not a netdevsim-only issue.\n\nTwo ways to fix it:\n\n  1) Have the rollback call tc_setup_cb_add() on oldprog instead of\n     re-entering cls_bpf_offload_cmd().\n  2) Mark the rollback frame with a flag and skip a second-level\n     rollback from inside it.\n\nGo with (2). It is the smaller change and keeps the original behaviour:\nthe rollback still goes through tc_setup_cb_replace(), so the driver\ngets one real chance to restore its state. If that attempt also fails,\nwe just return the original error instead of recursing.\n\n[1]: https://lore.kernel.org/bpf/ce5a6005-3c5e-4696-9e05-eba9461dc860@std.uestc.edu.cn/T/#u"}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["net/sched/cls_bpf.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"102740bd9436a3a6ba129af3a48271d794009fa5","lessThan":"a018f208ab7512380bd4cf670064d48cba00a1b1","versionType":"git","status":"affected"},{"version":"102740bd9436a3a6ba129af3a48271d794009fa5","lessThan":"33373e1f378a501bc51aa73312f74295c84e3101","versionType":"git","status":"affected"},{"version":"102740bd9436a3a6ba129af3a48271d794009fa5","lessThan":"e2d3b7bab3748c811dc5750ce9a8d62bc7f90ed7","versionType":"git","status":"affected"},{"version":"102740bd9436a3a6ba129af3a48271d794009fa5","lessThan":"4a76953c3ed043797e81529b9395e9ca6f4c7609","versionType":"git","status":"affected"},{"version":"102740bd9436a3a6ba129af3a48271d794009fa5","lessThan":"1387f252a242a51bfbb6eace29c8f8db21b457da","versionType":"git","status":"affected"},{"version":"102740bd9436a3a6ba129af3a48271d794009fa5","lessThan":"10753da2d659dd425a6e620f47f86852d604f67f","versionType":"git","status":"affected"},{"version":"102740bd9436a3a6ba129af3a48271d794009fa5","lessThan":"3fa6fb5d771c992ebedbfa7331c6bcc6f33f89b7","versionType":"git","status":"affected"},{"version":"102740bd9436a3a6ba129af3a48271d794009fa5","lessThan":"27db54b90bcc7c37867fe664107fa25ea6a116e4","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["net/sched/cls_bpf.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"4.15","status":"affected"},{"version":"0","lessThan":"4.15","versionType":"semver","status":"unaffected"},{"version":"5.10.261","lessThanOrEqual":"5.10.*","versionType":"semver","status":"unaffected"},{"version":"5.15.212","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.178","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.97","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/10753da2d659dd425a6e620f47f86852d604f67f","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/1387f252a242a51bfbb6eace29c8f8db21b457da","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/27db54b90bcc7c37867fe664107fa25ea6a116e4","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/33373e1f378a501bc51aa73312f74295c84e3101","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/3fa6fb5d771c992ebedbfa7331c6bcc6f33f89b7","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/4a76953c3ed043797e81529b9395e9ca6f4c7609","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/a018f208ab7512380bd4cf670064d48cba00a1b1","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/e2d3b7bab3748c811dc5750ce9a8d62bc7f90ed7","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-74383","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:22:40.170","lastModified":"2026-08-15T06:22:40.170","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nnvme-pci: fix out-of-bounds access in nvme_setup_descriptor_pools\n\nnvme_setup_descriptor_pools() indexes dev->descriptor_pools[] using the\nnuma_node forwarded from hctx->numa_node by its single caller,\nnvme_init_hctx_common().  On a non-NUMA kernel hctx->numa_node is\nNUMA_NO_NODE (-1).  Because the parameter was declared 'unsigned', the\nvalue becomes UINT_MAX and the index walks off the array (sized to\nnr_node_ids), faulting during nvme_alloc_ns() and leaving the namespace\nwithout a /dev node.\n\nReproduces on any NVMe controller probed by a CONFIG_NUMA=n kernel:\n\n  BUG: unable to handle page fault for address: ffff889101603d38\n  RIP: 0010:nvme_init_hctx_common+0x5a/0x190 [nvme]\n  Call Trace:\n   nvme_init_hctx+0x10/0x20 [nvme]\n   nvme_alloc_ns+0x9e/0xa10 [nvme_core]\n   nvme_scan_ns+0x301/0x3b0 [nvme_core]\n   nvme_scan_ns_async+0x23/0x30 [nvme_core]\n\nSwitch the parameter to int and fall back to node 0 when it is\nNUMA_NO_NODE; node 0 is always present."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/nvme/host/pci.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"d977506f8863807129d7a11f4057dfb1b38085ea","lessThan":"3e8aed5edaeeb237f97255d711aac6b5843fc059","versionType":"git","status":"affected"},{"version":"d977506f8863807129d7a11f4057dfb1b38085ea","lessThan":"fa9b6accd1ad7af6914b409c6b003c417724c299","versionType":"git","status":"affected"},{"version":"d977506f8863807129d7a11f4057dfb1b38085ea","lessThan":"a192b8cfa447e1b3701a13434a31c392b2e7ed29","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/nvme/host/pci.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.16","status":"affected"},{"version":"0","lessThan":"6.16","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/3e8aed5edaeeb237f97255d711aac6b5843fc059","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/a192b8cfa447e1b3701a13434a31c392b2e7ed29","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/fa9b6accd1ad7af6914b409c6b003c417724c299","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-74384","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:22:40.270","lastModified":"2026-08-15T06:22:40.270","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nnvme-multipath: fix flex array size in struct nvme_ns_head\n\nstruct nvme_ns_head contains a flexible array member, current_path[],\nwhich is indexed using the NUMA node ID:\nhead->current_path[numa_node_id()]\n\nThe structure is currently allocated as:\nsize = sizeof(struct nvme_ns_head) +\n       (num_possible_nodes() * sizeof(struct nvme_ns *));\nhead = kzalloc(size, GFP_KERNEL);\n\nThis allocation assumes that NUMA node IDs are sequential and densely\npacked from 0 .. num_possible_nodes() - 1. While this assumption holds\non many systems, it is not always true on some architectures such as\npowerpc.\n\nOn some powerpc systems, NUMA node IDs can be sparse. For example:\nNUMA:\n  NUMA node(s):              6\n  NUMA node0 CPU(s):         80-159\n  NUMA node8 CPU(s):         0-79\n  NUMA node252 CPU(s):\n  NUMA node253 CPU(s):\n  NUMA node254 CPU(s):\n  NUMA node255 CPU(s):\n\nThat is, the possible/online NUMA node IDs are: 0, 8, 252, 253, 254, 255\nIn this case: num_possible_nodes() = 6\n\nSo memory is allocated for only 6 entries in current_path[]. However,\nthe array is later indexed using the actual NUMA node ID. As a result,\naccesses such as:\nhead->current_path[8] or\nhead->current_path[252]\ngoes out of bounds, leading to the following KASAN splat:\n\n==================================================================\nBUG: KASAN: slab-out-of-bounds in nvme_mpath_revalidate_paths+0x22c/0x290 [nvme_core]\nWrite of size 8 at addr c00020003bda35b8 by task kworker/u641:2/1997\n\nCPU: 1 UID: 0 PID: 1997 Comm: kworker/u641:2 Not tainted 7.1.0-rc5-dirty #14 PREEMPT(lazy)\nHardware name: 8335-GTH POWER9 0x4e1202 opal:skiboot-v6.5.3-35-g1851b2a06 PowerNV\nWorkqueue: async async_run_entry_fn\nCall Trace:\n[c000200037fa7510] [c0000000021c23d4] dump_stack_lvl+0x88/0xdc (unreliable)\n[c000200037fa7540] [c0000000009fda90] print_report+0x22c/0x67c\n[c000200037fa7630] [c0000000009fd508] kasan_report+0x108/0x220\n[c000200037fa7740] [c0000000009fff48] __asan_store8+0xe8/0x120\n[c000200037fa7760] [c008000018e76474] nvme_mpath_revalidate_paths+0x22c/0x290 [nvme_core]\n[c000200037fa7800] [c008000018e6556c] nvme_update_ns_info+0x4a4/0x5e0 [nvme_core]\n[c000200037fa7a50] [c008000018e66270] nvme_alloc_ns+0x6d8/0x1a70 [nvme_core]\n[c000200037fa7c20] [c008000018e679fc] nvme_scan_ns+0x3f4/0x630 [nvme_core]\n[c000200037fa7d10] [c00000000031f22c] async_run_entry_fn+0x9c/0x3a0\n[c000200037fa7db0] [c0000000002fa544] process_one_work+0x414/0xa10\n[c000200037fa7ec0] [c0000000002fbf00] worker_thread+0x320/0x640\n[c000200037fa7f80] [c00000000030d0f8] kthread+0x278/0x290\n[c000200037fa7fe0] [c00000000000ded8] start_kernel_thread+0x14/0x18\n\nAllocated by task 1997 on cpu 1 at 35.928317s:\n\nThe buggy address belongs to the object at c00020003bda3000\n which belongs to the cache kmalloc-rnd-15-2k of size 2048\nThe buggy address is located 16 bytes to the right of\n allocated 1448-byte region [c00020003bda3000, c00020003bda35a8)\n\nThe buggy address belongs to the physical page:\n\nMemory state around the buggy address:\n c00020003bda3480: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00\n c00020003bda3500: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00\n>c00020003bda3580: 00 00 00 00 00 fc fc fc fc fc fc fc fc fc fc fc\n                                        ^\n c00020003bda3600: fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc\n c00020003bda3680: fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc\n==================================================================\n\nFix this by allocating the flexible array using nr_node_ids instead\nof num_possible_nodes(). Since nr_node_ids represents the maximum\npossible NUMA node IDs, indexing current_path[] using numa_node_id()\nbecomes safe even on systems with sparse node IDs."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/nvme/host/core.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"f333444708f82c4a4d3ccac004da0bfd9cfdfa42","lessThan":"7e7b167e65610dfa7564d449474f4b477f9d4c1c","versionType":"git","status":"affected"},{"version":"f333444708f82c4a4d3ccac004da0bfd9cfdfa42","lessThan":"316b5f1168264844aa125959de1d6da2b1905795","versionType":"git","status":"affected"},{"version":"f333444708f82c4a4d3ccac004da0bfd9cfdfa42","lessThan":"1d4131b5c9823c7d2c86389898ad1b466af7df5e","versionType":"git","status":"affected"},{"version":"f333444708f82c4a4d3ccac004da0bfd9cfdfa42","lessThan":"9ffdd11bd6c961b46b3689850ff6c5d7af5c5fe5","versionType":"git","status":"affected"},{"version":"f333444708f82c4a4d3ccac004da0bfd9cfdfa42","lessThan":"bde4d6eb53f7d3cdae7e62c9ee84345fdd6e70a6","versionType":"git","status":"affected"},{"version":"f333444708f82c4a4d3ccac004da0bfd9cfdfa42","lessThan":"140d6fff4ed266592492a23444043842b4af7a62","versionType":"git","status":"affected"},{"version":"f333444708f82c4a4d3ccac004da0bfd9cfdfa42","lessThan":"7173a741fed73de6247384056fe92e582ba12507","versionType":"git","status":"affected"},{"version":"f333444708f82c4a4d3ccac004da0bfd9cfdfa42","lessThan":"001e57554de81aa79c25c18fd53911d8a415c304","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/nvme/host/core.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"4.20","status":"affected"},{"version":"0","lessThan":"4.20","versionType":"semver","status":"unaffected"},{"version":"5.10.261","lessThanOrEqual":"5.10.*","versionType":"semver","status":"unaffected"},{"version":"5.15.212","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.178","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.97","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/001e57554de81aa79c25c18fd53911d8a415c304","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/140d6fff4ed266592492a23444043842b4af7a62","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/1d4131b5c9823c7d2c86389898ad1b466af7df5e","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/316b5f1168264844aa125959de1d6da2b1905795","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/7173a741fed73de6247384056fe92e582ba12507","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/7e7b167e65610dfa7564d449474f4b477f9d4c1c","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/9ffdd11bd6c961b46b3689850ff6c5d7af5c5fe5","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/bde4d6eb53f7d3cdae7e62c9ee84345fdd6e70a6","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-74385","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:22:40.420","lastModified":"2026-08-15T06:22:40.420","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nnvmet-tcp: check return value of nvmet_tcp_set_queue_sock\n\nThe return value of nvmet_tcp_set_queue_sock() is currently ignored in\nnvmet_tcp_tls_handshake_done(). If it fails (e.g., due to the socket\nnot being in TCP_ESTABLISHED state), the socket callbacks will not be\nproperly set, leading to queue and socket leakage.\n\nFix this by capturing the return value and calling\nnvmet_tcp_schedule_release_queue() on failure to ensure proper cleanup."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/nvme/target/tcp.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"675b453e024154dd547921c6e6d5b58747ba7e0e","lessThan":"cba2ee57fd302727aea7d41e9d9cd0969f5df0fb","versionType":"git","status":"affected"},{"version":"675b453e024154dd547921c6e6d5b58747ba7e0e","lessThan":"22aa70f9a0544643ec37d442b6fcb1833d804462","versionType":"git","status":"affected"},{"version":"675b453e024154dd547921c6e6d5b58747ba7e0e","lessThan":"7ef789703e2b91775dcb36b2efa46325be31a2a0","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/nvme/target/tcp.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.7","status":"affected"},{"version":"0","lessThan":"6.7","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/22aa70f9a0544643ec37d442b6fcb1833d804462","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/7ef789703e2b91775dcb36b2efa46325be31a2a0","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/cba2ee57fd302727aea7d41e9d9cd0969f5df0fb","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-74386","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:22:40.513","lastModified":"2026-08-15T06:22:40.513","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nnvmet-tcp: fix page fragment cache leak in error path\n\nIn nvmet_tcp_alloc_queue(), when a connection is closed during the\nallocation process (e.g., nvmet_tcp_set_queue_sock() returns -ENOTCONN),\nthe error handling jumps to out_destroy_sq and then to out_ida_remove\nwithout draining the page fragment cache.\n\nAlthough nvmet_tcp_free_cmd() is called in some error paths to release\nindividual page fragments, the underlying page cache reference held by\nqueue->pf_cache is never released. The first allocation using pf_cache\nis the call to nvmet_tcp_alloc_cmd() for queue->connect, which happens\nafter ida_alloc() returns successfully. This results in a page leak each\ntime a connection fails during allocation, which could lead to memory\nexhaustion over time if connections are repeatedly opened and closed.\n\nFix this by calling page_frag_cache_drain() before freeing the queue\nstructure in the out_ida_remove label."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/nvme/target/tcp.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"872d26a391da92ed8f0c0f5cb5fef428067b7f30","lessThan":"a43a9abc1ebf663f0aa56a729106f68dd9c77da6","versionType":"git","status":"affected"},{"version":"872d26a391da92ed8f0c0f5cb5fef428067b7f30","lessThan":"ba3209704b3cd46961e4e081af5c52a780785648","versionType":"git","status":"affected"},{"version":"872d26a391da92ed8f0c0f5cb5fef428067b7f30","lessThan":"5fbe83a374f09561a0f0c1f4aa021501ffd681eb","versionType":"git","status":"affected"},{"version":"872d26a391da92ed8f0c0f5cb5fef428067b7f30","lessThan":"4dae393956093c807212918fd91a8fc70df15338","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/nvme/target/tcp.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"5.0","status":"affected"},{"version":"0","lessThan":"5.0","versionType":"semver","status":"unaffected"},{"version":"6.12.97","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/4dae393956093c807212918fd91a8fc70df15338","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/5fbe83a374f09561a0f0c1f4aa021501ffd681eb","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/a43a9abc1ebf663f0aa56a729106f68dd9c77da6","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/ba3209704b3cd46961e4e081af5c52a780785648","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-74387","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:22:40.610","lastModified":"2026-08-15T06:22:40.610","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nALSA: seq: midi: Serialize output teardown with event_input\n\nevent_process_midi() borrows msynth->output_rfile.output and then\npasses the substream to dump_midi() and snd_rawmidi_kernel_write()\nwithout synchronizing with the output open/close transition.\nmidisynth_use() also publishes output_rfile before\nsnd_rawmidi_output_params() has finished.\n\nThe last midisynth_unuse() can therefore release the same rawmidi file\nand free substream->runtime before snd_rawmidi_kernel_write1() takes\nits runtime buffer reference. That leaves the event_input path using a\nstale substream or runtime and can end in a NULL-deref or use-after-free.\n\nFix this with two pieces of synchronization. Keep a short IRQ-safe\nspinlock only for publishing or clearing output_rfile and for pairing\nthe output snapshot with an snd_use_lock_t reference. Once\nevent_process_midi() has taken that in-flight reference, it drops the\nspinlock before calling snd_seq_dump_var_event(), dump_midi(), or\nsnd_rawmidi_kernel_write(). midisynth_unuse() now detaches the visible\nrawmidi file under the same spinlock, waits for the in-flight writers\nto drain, and only then drains and releases the saved file.\nmidisynth_use() likewise opens into a local snd_rawmidi_file and\npublishes it only after snd_rawmidi_output_params() succeeds.\n\nThe buggy scenario involves two paths, with each column showing the\norder within that path:\n\nevent_input path:                     last unuse path:\n1. event_process_midi() snapshots    1. midisynth_unuse() starts\n   output_rfile.output.                 tearing down output_rfile.\n2. dump_midi() reaches               2. snd_rawmidi_kernel_release()\n   snd_rawmidi_kernel_write()           closes the output file.\n   before runtime is pinned.         3. close_substream() frees\n3. The callback keeps using             substream->runtime.\n   the borrowed substream.\n\nValidation reproduced this kernel report:\nKASAN null-ptr-deref in snd_rawmidi_kernel_write1+0x56/0x360\nRIP: 0033:0x7fde7dd0837f\nRIP: 0010:snd_rawmidi_kernel_write1+0x56/0x360"}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["sound/core/seq/seq_midi.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"f5d470b808bc01f70978e22e595c6f7768313406","versionType":"git","status":"affected"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"936641af564c3d92721704b781e36aaf223efdd2","versionType":"git","status":"affected"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"718f6a56b40875f19e6915799044a02df9abfd52","versionType":"git","status":"affected"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"11165fe2c5ea0516debe486d91df67abbe36905e","versionType":"git","status":"affected"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"d6fd2afb137f52bf00c5210cc44d08ed54dcffb4","versionType":"git","status":"affected"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"ef7607ab1c8adc6258fb1b27d08e26aecdc18a58","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["sound/core/seq/seq_midi.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"2.6.12","status":"affected"},{"version":"0","lessThan":"2.6.12","versionType":"semver","status":"unaffected"},{"version":"6.1.178","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.97","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/11165fe2c5ea0516debe486d91df67abbe36905e","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/718f6a56b40875f19e6915799044a02df9abfd52","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/936641af564c3d92721704b781e36aaf223efdd2","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/d6fd2afb137f52bf00c5210cc44d08ed54dcffb4","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/ef7607ab1c8adc6258fb1b27d08e26aecdc18a58","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/f5d470b808bc01f70978e22e595c6f7768313406","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-74388","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:22:40.733","lastModified":"2026-08-15T06:22:40.733","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nALSA: seq: oss: Fix UAF at handling events with embedded SysEx data\n\nThe OSS sequencer processes the input MIDI bytes into a sequencer\nevent to be dispatched later (in snd_seq_oss_midi_putc() called from\nsnd_seq_oss_process_event()).  When it's a SysEx data, the event\nrecord contains data.ext.ptr pointer to the original SysEx bytes, and\nthe referred data is copied into the pool afterwards at dispatching.\nThe problem is that, if the sequencer port gets closed concurrently\nbefore the dispatch, the OSS sequencer core also releases the\nresources (in snd_seq_oss_midi_check_exit_port()), while the pending\nevent may hold a stale pointer, eventually leading to a UAF at a later\ndispatch.\n\nFortunately, there is already a refcounting mechanism (snd_use_lock_t)\nfor the OSS MIDI device access, and for addressing the issue above, we\njust need to extend the refcount until the event gets dispatched.\n\nThis patch extends snd_seq_oss_process_event() to give back the\nrefcount object, which is in turn released after calling the sequencer\ndispatcher with the given event in the caller side.\n\nAccording to the original report, KASAN report as below:\n\nKASAN slab-use-after-free in snd_seq_event_dup+0x40c/0x470\nRIP: 0033:0x7f2cb66a6340\nRead of size 6\nCall trace:\n  dump_stack_lvl+0x73/0xb0 (?:?)\n  print_report+0xd1/0x650 (?:?)\n  srso_alias_return_thunk+0x5/0xfbef5 (?:?)\n  __virt_addr_valid+0x1a7/0x340 (?:?)\n  kasan_complete_mode_report_info+0x64/0x200 (?:?)\n  kasan_report+0xf7/0x130 (?:?)\n  snd_seq_event_dup+0x40c/0x470 (?:?)\n  kasan_check_range+0x10c/0x1c0 (?:?)\n  __asan_memcpy+0x27/0x70 (?:?)\n  snd_seq_event_dup+0x9/0x470 (?:?)\n  snd_seq_client_enqueue_event+0x139/0x240 (?:?)\n  _raw_spin_unlock_irqrestore+0x4b/0x60 (?:?)\n  snd_seq_kernel_client_enqueue+0x102/0x120 (?:?)\n  snd_seq_oss_write+0x416/0x4e0 (?:?)\n  apparmor_file_permission+0x20/0x30 (?:?)\n  odev_write+0x3b/0x60 (?:?)\n  vfs_write+0x1ce/0x850 (?:?)\n  lock_release+0xc8/0x2a0 (?:?)\n  __kasan_check_write+0x18/0x20 (?:?)\n  __mutex_unlock_slowpath+0x129/0x510 (?:?)\n  ksys_write+0xe1/0x180 (?:?)\n  mutex_unlock+0x16/0x20 (?:?)\n  odev_ioctl+0x65/0xc0 (?:?)\n  __x64_sys_write+0x46/0x60 (?:?)\n  x64_sys_call+0x7d/0x20d0 (?:?)\n  do_syscall_64+0xc1/0x360 (arch/x86/entry/syscall_64.c:87)\n  entry_SYSCALL_64_after_hwframe+0x77/0x7f (?:?)"}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["sound/core/seq/oss/seq_oss_event.c","sound/core/seq/oss/seq_oss_event.h","sound/core/seq/oss/seq_oss_ioctl.c","sound/core/seq/oss/seq_oss_midi.c","sound/core/seq/oss/seq_oss_midi.h","sound/core/seq/oss/seq_oss_rw.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"6dc781778b595be94c31395b2cb167f65145d91f","versionType":"git","status":"affected"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"7aad70cabd8f34cf11a9593fcd3f2ac3f5496943","versionType":"git","status":"affected"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"7c349b4f2a603202fb8c363bd2774a22ac2fddf3","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["sound/core/seq/oss/seq_oss_event.c","sound/core/seq/oss/seq_oss_event.h","sound/core/seq/oss/seq_oss_ioctl.c","sound/core/seq/oss/seq_oss_midi.c","sound/core/seq/oss/seq_oss_midi.h","sound/core/seq/oss/seq_oss_rw.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"2.6.12","status":"affected"},{"version":"0","lessThan":"2.6.12","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/6dc781778b595be94c31395b2cb167f65145d91f","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/7aad70cabd8f34cf11a9593fcd3f2ac3f5496943","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/7c349b4f2a603202fb8c363bd2774a22ac2fddf3","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-74389","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:22:40.847","lastModified":"2026-08-15T06:22:40.847","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nRDMA/hns: Fix log flood after cmd_mbox failure\n\nhns_roce_cmd_mbox() is the command interface between driver and\nhardware. When hardware is abnormal, the unlimited error printings\nafter hns_roce_cmd_mbox() failure will cause log flood and even\nsystem crash.\n\nReplace ibdev_err() and ibdev_warn() with their ratelimited versions\nin the error handling path after hns_roce_cmd_mbox() (and its wrappers\nhns_roce_create_hw_ctx/hns_roce_destroy_hw_ctx) fails."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/infiniband/hw/hns/hns_roce_cq.c","drivers/infiniband/hw/hns/hns_roce_hw_v2.c","drivers/infiniband/hw/hns/hns_roce_mr.c","drivers/infiniband/hw/hns/hns_roce_srq.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"9a4435375cd151e07c0c38fa601b00115986091b","lessThan":"7d9fbee252f84de3e6947a40eec01481c9d8afbb","versionType":"git","status":"affected"},{"version":"9a4435375cd151e07c0c38fa601b00115986091b","lessThan":"66f44ec974ab372e4e1ee9eac4245237c94e8f68","versionType":"git","status":"affected"},{"version":"9a4435375cd151e07c0c38fa601b00115986091b","lessThan":"f3c9e84268e9fa613d40d6c138fb6969c35879b5","versionType":"git","status":"affected"},{"version":"9a4435375cd151e07c0c38fa601b00115986091b","lessThan":"bbd97d71e53e551890e4115ad9de46b5f2ac0858","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/infiniband/hw/hns/hns_roce_cq.c","drivers/infiniband/hw/hns/hns_roce_hw_v2.c","drivers/infiniband/hw/hns/hns_roce_mr.c","drivers/infiniband/hw/hns/hns_roce_srq.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"4.9","status":"affected"},{"version":"0","lessThan":"4.9","versionType":"semver","status":"unaffected"},{"version":"6.12.97","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/66f44ec974ab372e4e1ee9eac4245237c94e8f68","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/7d9fbee252f84de3e6947a40eec01481c9d8afbb","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/bbd97d71e53e551890e4115ad9de46b5f2ac0858","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/f3c9e84268e9fa613d40d6c138fb6969c35879b5","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-74390","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:22:40.947","lastModified":"2026-08-15T06:22:40.947","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nRDMA/irdma: Fix out-of-bounds write in irdma_copy_user_pgaddrs\n\nThe irdma_copy_user_pgaddrs function loops through all of the umem DMA\nblocks to populate the PBLEs and will stop when either the last DMA\nblock is reached or palloc->total_cnt is reached. The issue is that\nthe logic for checking palloc->total_cnt would only work for non-zero\nvalues.\n\nWhen irdma_setup_pbles is called with lvl==0, it\ncalls irdma_copy_user_pgaddrs with palloc->total_cnt==0, which means\nthe only way to break out of the loop is to reach the last umem DMA\nblock, which means it could end up going beyond the fixed size of 4\niwmr->pgaddrmem array that is used in the lvl==0 case.\n\nIn the case of QP/CQ/SRQ rings, the value of lvl is determined by a\nseparate input (for example, req.cq_pages in the case of a CQ). So,\nwe must perform explicit checking to ensure we don't overflow the\npgaddrmem array if the user provides a umem that consists of more\nblocks than their provided req.cq_pages."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/infiniband/hw/irdma/verbs.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"b48c24c2d710cf34810c555dcef883a3d35a9c08","lessThan":"4780f58672ee6328accd54a95f9c00683477e499","versionType":"git","status":"affected"},{"version":"b48c24c2d710cf34810c555dcef883a3d35a9c08","lessThan":"79a20a8e201a779224b4bf115250a7713bde72c0","versionType":"git","status":"affected"},{"version":"b48c24c2d710cf34810c555dcef883a3d35a9c08","lessThan":"9f8f0d2099e3de1194e37dc933ae0c4206b09aaf","versionType":"git","status":"affected"},{"version":"b48c24c2d710cf34810c555dcef883a3d35a9c08","lessThan":"192a3be0e3759daa24af2841208b074ca6dbaabc","versionType":"git","status":"affected"},{"version":"b48c24c2d710cf34810c555dcef883a3d35a9c08","lessThan":"424d51d33c7541a86934067c2c0538124687fc90","versionType":"git","status":"affected"},{"version":"b48c24c2d710cf34810c555dcef883a3d35a9c08","lessThan":"abd27a977b419d584efa659488c22d2306987b29","versionType":"git","status":"affected"},{"version":"b48c24c2d710cf34810c555dcef883a3d35a9c08","lessThan":"5ebb3ed757be3e04cf803026004aa0beaeb13e9b","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/infiniband/hw/irdma/verbs.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"5.14","status":"affected"},{"version":"0","lessThan":"5.14","versionType":"semver","status":"unaffected"},{"version":"5.15.212","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.178","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.97","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/192a3be0e3759daa24af2841208b074ca6dbaabc","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/424d51d33c7541a86934067c2c0538124687fc90","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/4780f58672ee6328accd54a95f9c00683477e499","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/5ebb3ed757be3e04cf803026004aa0beaeb13e9b","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/79a20a8e201a779224b4bf115250a7713bde72c0","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/9f8f0d2099e3de1194e37dc933ae0c4206b09aaf","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/abd27a977b419d584efa659488c22d2306987b29","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-74391","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:22:41.067","lastModified":"2026-08-15T06:22:41.067","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\ntracing: Bound synthetic-field strings with seq_buf\n\nThe synthetic field helpers build a prefixed synthetic variable name and\na generated hist command in fixed MAX_FILTER_STR_VAL buffers. The\ncurrent code appends those strings with raw strcat(), so long key lists,\nfield names, or saved filters can run past the end of the staging\nbuffers.\n\nBuild both strings with seq_buf and propagate -E2BIG if either the\nsynthetic variable name or the generated command exceeds\nMAX_FILTER_STR_VAL. This keeps the existing tracing-side limit while\nusing the helper intended for bounded command construction.\n\n[ sdr: Moved struct seq_buf *s for upside-down x-mas tree formatting ]"}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["kernel/trace/trace_events_hist.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"02205a6752f223779a1b0e9e8ffacbea6e717851","lessThan":"0c584c27f6649a93ec12061cc779a4bd8f7c1434","versionType":"git","status":"affected"},{"version":"02205a6752f223779a1b0e9e8ffacbea6e717851","lessThan":"88b901fdc1662b131ff908cbd017333b61e7acc8","versionType":"git","status":"affected"},{"version":"02205a6752f223779a1b0e9e8ffacbea6e717851","lessThan":"baa333b2700a7fa3529d504529c8c10060fd687c","versionType":"git","status":"affected"},{"version":"02205a6752f223779a1b0e9e8ffacbea6e717851","lessThan":"cf334620036ad2250e008c7e7bb6646a3938b7b0","versionType":"git","status":"affected"},{"version":"02205a6752f223779a1b0e9e8ffacbea6e717851","lessThan":"f07883450eb14d1cf020b55d9f3a7ec5683bcd26","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["kernel/trace/trace_events_hist.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"4.17","status":"affected"},{"version":"0","lessThan":"4.17","versionType":"semver","status":"unaffected"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.97","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/0c584c27f6649a93ec12061cc779a4bd8f7c1434","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/88b901fdc1662b131ff908cbd017333b61e7acc8","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/baa333b2700a7fa3529d504529c8c10060fd687c","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/cf334620036ad2250e008c7e7bb6646a3938b7b0","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/f07883450eb14d1cf020b55d9f3a7ec5683bcd26","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-74392","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:22:41.163","lastModified":"2026-08-15T06:22:41.163","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\ndm: limit target bio polling to one shot\n\ndm_poll_bio() is the ->poll_bio() callback for a stacked dm device.\nThe caller only knows about the dm queue, so it may decide to do a\nspinning poll if it thinks a single queue is being polled. Passing those\nflags unchanged to the mapped clone lets blk_mq_poll() spin on a target\nqueue from inside dm_poll_bio().\n\nWith io_uring IOPOLL on a dm-stripe target this can keep a task in\n\n  dm_poll_bio() -> bio_poll() -> blk_mq_poll()\n\nlong enough to trigger an RCU CPU stall, before io_uring gets back to\nio_iopoll_check() and its need_resched() check.\n\nKeep dm's ->poll_bio() bounded by forcing one-shot polling for target\nbios. The caller can invoke dm_poll_bio() again if it wants to keep\npolling, and it also gets a chance to reap completions or reschedule\nbetween passes."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/md/dm.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"f22ecf9c14c12918e30f2179ef516e99eb8b2e49","lessThan":"6c4ede3b771adbb3bf21ad4e8b8f2f6f6120c4f7","versionType":"git","status":"affected"},{"version":"f22ecf9c14c12918e30f2179ef516e99eb8b2e49","lessThan":"5aa0f9231cbacade065cedd8e9b5ebd067231171","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/md/dm.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.19","status":"affected"},{"version":"0","lessThan":"6.19","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/5aa0f9231cbacade065cedd8e9b5ebd067231171","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/6c4ede3b771adbb3bf21ad4e8b8f2f6f6120c4f7","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-74393","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:22:41.257","lastModified":"2026-08-15T06:22:41.257","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/syncobj: Fix memory leak in drm_syncobj_find_fence()\n\nCommit 18226ba52159 (\"drm/syncobj: reject invalid flags in\ndrm_syncobj_find_fence\") forgot to take into account the fact that\ndrm_syncobj_find() takes a reference to syncobj and returns early\nwithout dropping the reference, leading to memory leaks.\n\nReported by: Sam Spencer <sam.spencer@arm.com>"}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/gpu/drm/drm_syncobj.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"18226ba52159257d4c2f777a168cc09adb3c1ac0","lessThan":"e245f3491bf30a758786a4424854f61fee472308","versionType":"git","status":"affected"},{"version":"18226ba52159257d4c2f777a168cc09adb3c1ac0","lessThan":"7471006cd854d159723344be809e8287a2d75502","versionType":"git","status":"affected"},{"version":"18226ba52159257d4c2f777a168cc09adb3c1ac0","lessThan":"5c5994a1204743fa55e4c198ed93a6c36f21cd1f","versionType":"git","status":"affected"},{"version":"18226ba52159257d4c2f777a168cc09adb3c1ac0","lessThan":"e5b93bd6fdb92aa5e4689715d7e8487d9ce66a38","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/gpu/drm/drm_syncobj.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.9","status":"affected"},{"version":"0","lessThan":"6.9","versionType":"semver","status":"unaffected"},{"version":"6.12.97","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/5c5994a1204743fa55e4c198ed93a6c36f21cd1f","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/7471006cd854d159723344be809e8287a2d75502","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/e245f3491bf30a758786a4424854f61fee472308","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/e5b93bd6fdb92aa5e4689715d7e8487d9ce66a38","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-74394","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:22:41.363","lastModified":"2026-08-15T06:22:41.363","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nRDMA/srpt: fix integer overflow in immediate data length check\n\nimm_buf->len is a user-controlled uint32_t received from the network.\nAdding it to imm_data_offset without overflow checking allows a\nmalicious initiator to send len=0xFFFFFFFF, causing req_size to wrap\naround to a small value, bypassing the bounds check, and subsequently\npassing a ~4GB length to sg_init_one().\n\nUse check_add_overflow() to detect wrapping before the comparison."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/infiniband/ulp/srpt/ib_srpt.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"5dabcd0456d7ee17c2c7a17d7c2305444d2b9639","lessThan":"c82c860f8c8e4f4f454c9f14d0ad0c0466965f7d","versionType":"git","status":"affected"},{"version":"5dabcd0456d7ee17c2c7a17d7c2305444d2b9639","lessThan":"3efa5301137140a3ca3677a9098c0a93a0acfd49","versionType":"git","status":"affected"},{"version":"5dabcd0456d7ee17c2c7a17d7c2305444d2b9639","lessThan":"067b9556eeb007f28b7c2033b4dcde5b6d88418f","versionType":"git","status":"affected"},{"version":"5dabcd0456d7ee17c2c7a17d7c2305444d2b9639","lessThan":"dcf7a986f377cce0749ed53f1d64195fbd5fdf91","versionType":"git","status":"affected"},{"version":"5dabcd0456d7ee17c2c7a17d7c2305444d2b9639","lessThan":"07dec3f6dcb6c6cc891162d252b800eb0e6d5e8e","versionType":"git","status":"affected"},{"version":"5dabcd0456d7ee17c2c7a17d7c2305444d2b9639","lessThan":"65572fbd86033ae2370125593d59b8be34253aaf","versionType":"git","status":"affected"},{"version":"5dabcd0456d7ee17c2c7a17d7c2305444d2b9639","lessThan":"72497172a4799119a0282a5eb5e2b8ddcc821921","versionType":"git","status":"affected"},{"version":"5dabcd0456d7ee17c2c7a17d7c2305444d2b9639","lessThan":"eb4ecdf631fe00e8020bf461503cb9b7017ed796","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/infiniband/ulp/srpt/ib_srpt.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"5.0","status":"affected"},{"version":"0","lessThan":"5.0","versionType":"semver","status":"unaffected"},{"version":"5.10.261","lessThanOrEqual":"5.10.*","versionType":"semver","status":"unaffected"},{"version":"5.15.212","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.178","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.97","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/067b9556eeb007f28b7c2033b4dcde5b6d88418f","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/07dec3f6dcb6c6cc891162d252b800eb0e6d5e8e","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/3efa5301137140a3ca3677a9098c0a93a0acfd49","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/65572fbd86033ae2370125593d59b8be34253aaf","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/72497172a4799119a0282a5eb5e2b8ddcc821921","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/c82c860f8c8e4f4f454c9f14d0ad0c0466965f7d","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/dcf7a986f377cce0749ed53f1d64195fbd5fdf91","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/eb4ecdf631fe00e8020bf461503cb9b7017ed796","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-74395","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:22:41.480","lastModified":"2026-08-15T06:22:41.480","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nRDMA/mlx5: Fix devx subscribe-event unwind NULL dereference\n\nMLX5_IB_METHOD_DEVX_SUBSCRIBE_EVENT() links event_sub into sub_list\nbefore initializing the fields used by the shared error path.\n\nIf eventfd_ctx_fdget() then fails, the unwind path dereferences\nevent_sub->ev_file in uverbs_uobject_put() and calls\nsubscribe_event_xa_dealloc() with an unset xa_key_level1.\n\nsubscribe_event_xa_alloc() creates the XA entry exactly once for a given\nkey_level1, on the first occurrence of that key. The unwind path must\ntherefore call subscribe_event_xa_dealloc() exactly once for it as well.\n\nEnforce that by adding devx_key_in_sub_list() and calling\nsubscribe_event_xa_dealloc() only when the last matching pending entry is\nbeing cleaned up."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/infiniband/hw/mlx5/devx.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"7597385371425febdaa8c6a1da3625d4ffff16f5","lessThan":"6e15b770461eeaa0ff73934922cb670a6a9db04e","versionType":"git","status":"affected"},{"version":"7597385371425febdaa8c6a1da3625d4ffff16f5","lessThan":"9be9aca28424228586fe9211c373ebdb826ebb6c","versionType":"git","status":"affected"},{"version":"7597385371425febdaa8c6a1da3625d4ffff16f5","lessThan":"f345e744b6b087188cde2377da5cbe9713b61353","versionType":"git","status":"affected"},{"version":"7597385371425febdaa8c6a1da3625d4ffff16f5","lessThan":"1025dc2f7ba29b04b8687790fa91f9cd1a53141e","versionType":"git","status":"affected"},{"version":"7597385371425febdaa8c6a1da3625d4ffff16f5","lessThan":"7921821fc2b19c01588311f6e7468ae5b68b1f61","versionType":"git","status":"affected"},{"version":"7597385371425febdaa8c6a1da3625d4ffff16f5","lessThan":"5100febf8e9d6c8c5ba8dc6534c6a5e3376e5989","versionType":"git","status":"affected"},{"version":"7597385371425febdaa8c6a1da3625d4ffff16f5","lessThan":"78b9589fda266c71f0f9d0c858d4fa7381a890a5","versionType":"git","status":"affected"},{"version":"7597385371425febdaa8c6a1da3625d4ffff16f5","lessThan":"43f8f7946814c8e5f464518246fdbc69b6e32326","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/infiniband/hw/mlx5/devx.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"5.3","status":"affected"},{"version":"0","lessThan":"5.3","versionType":"semver","status":"unaffected"},{"version":"5.10.261","lessThanOrEqual":"5.10.*","versionType":"semver","status":"unaffected"},{"version":"5.15.212","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.178","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.97","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/1025dc2f7ba29b04b8687790fa91f9cd1a53141e","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/43f8f7946814c8e5f464518246fdbc69b6e32326","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/5100febf8e9d6c8c5ba8dc6534c6a5e3376e5989","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/6e15b770461eeaa0ff73934922cb670a6a9db04e","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/78b9589fda266c71f0f9d0c858d4fa7381a890a5","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/7921821fc2b19c01588311f6e7468ae5b68b1f61","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/9be9aca28424228586fe9211c373ebdb826ebb6c","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/f345e744b6b087188cde2377da5cbe9713b61353","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-74396","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:22:41.600","lastModified":"2026-08-15T06:22:41.600","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nRDMA/mlx5: Fix UMR XLT cleanup on ODP populate failure\n\nmlx5r_umr_update_xlt() allocates and DMA maps an XLT buffer with\nmlx5r_umr_create_xlt(). The buffer is released by the common cleanup path\nthrough mlx5r_umr_unmap_free_xlt().\n\nAfter mlx5_odp_populate_xlt() became fallible, its error path returned\ndirectly and skipped that cleanup. This leaks the XLT DMA mapping and\nbuffer. If the emergency XLT page was used, it also leaves\nxlt_emergency_page_mutex locked.\n\nBreak out of the loop so execution falls through the existing cleanup path."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/infiniband/hw/mlx5/umr.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"1efe8c0670d6a6883faa09c9abc746c741f5664a","lessThan":"ffa85a2c197935ace6f1634ad9eb0a44bc615670","versionType":"git","status":"affected"},{"version":"1efe8c0670d6a6883faa09c9abc746c741f5664a","lessThan":"9619909d4869afe720904c6888a289b9ac3055b8","versionType":"git","status":"affected"},{"version":"1efe8c0670d6a6883faa09c9abc746c741f5664a","lessThan":"1eae35b37923cb71b0cb5136d00671440d488b9f","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/infiniband/hw/mlx5/umr.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.16","status":"affected"},{"version":"0","lessThan":"6.16","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/1eae35b37923cb71b0cb5136d00671440d488b9f","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/9619909d4869afe720904c6888a289b9ac3055b8","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/ffa85a2c197935ace6f1634ad9eb0a44bc615670","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-74397","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:22:41.690","lastModified":"2026-08-15T06:22:41.690","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nIB/mlx5: Fix transport-domain rollback and initialize lb mutex earlier\n\nmlx5_ib_alloc_transport_domain() allocates a transport domain and then\nmay fail in mlx5_ib_enable_lb(). In that case, the allocated TD is leaked.\n\nFix this by deallocating the TD when mlx5_ib_enable_lb() returns an\nerror. Also return 0 explicitly in the no-loopback-capability success\nbranch, and move dev->lb.mutex initialization to mlx5_ib_stage_init_init()."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/infiniband/hw/mlx5/main.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"146d2f1af3245a10b13eef263687e54f4e253d1d","lessThan":"2c3b2667dad69d56774b79db763acb3a1bee0fc0","versionType":"git","status":"affected"},{"version":"146d2f1af3245a10b13eef263687e54f4e253d1d","lessThan":"37fc3cc0f924fd8d0f0cf87b92672dec75a32e57","versionType":"git","status":"affected"},{"version":"146d2f1af3245a10b13eef263687e54f4e253d1d","lessThan":"65e344925fa30abf50c8de8c150b397715fa2066","versionType":"git","status":"affected"},{"version":"146d2f1af3245a10b13eef263687e54f4e253d1d","lessThan":"f88e12c95fc19f719e06ca1e9eb20fdad68ef61a","versionType":"git","status":"affected"},{"version":"146d2f1af3245a10b13eef263687e54f4e253d1d","lessThan":"e79389115b9d27287ff6230a9750675106ed7668","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/infiniband/hw/mlx5/main.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"4.5","status":"affected"},{"version":"0","lessThan":"4.5","versionType":"semver","status":"unaffected"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.97","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/2c3b2667dad69d56774b79db763acb3a1bee0fc0","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/37fc3cc0f924fd8d0f0cf87b92672dec75a32e57","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/65e344925fa30abf50c8de8c150b397715fa2066","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/e79389115b9d27287ff6230a9750675106ed7668","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/f88e12c95fc19f719e06ca1e9eb20fdad68ef61a","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-74398","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:22:41.790","lastModified":"2026-08-15T06:22:41.790","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nipv6: addrconf: bail out of dad_failure when state is no longer POSTDAD\n\naddrconf_dad_failure() transitions ifp->state from DAD to POSTDAD\nvia addrconf_dad_end(), which drops ifp->lock on return.  The lock\nis re-acquired after net_info_ratelimited().  A concurrent\nipv6_del_addr() can take the lock in that window, set ifp->state\nto DEAD and run list_del_rcu(&ifp->if_list).\n\naddrconf_dad_failure() then overwrites DEAD with ERRDAD at errdad:\nand schedules a new dad_work.  The work calls ipv6_del_addr()\nagain, hitting the already-poisoned list entry:\n\n  general protection fault: 0000 [#1] SMP NOPTI\n  CPU: 4 PID: 217 Comm: kworker/4:1\n  Workqueue: ipv6_addrconf addrconf_dad_work\n  RIP: 0010:ipv6_del_addr+0xe9/0x280\n  RAX: dead000000000122\n  Call Trace:\n   addrconf_dad_stop+0x113/0x140\n   addrconf_dad_work+0x28c/0x430\n   process_one_work+0x1eb/0x3b0\n   worker_thread+0x4d/0x400\n   kthread+0x104/0x140\n   ret_from_fork+0x35/0x40\n\nFold the addrconf_dad_end() logic into addrconf_dad_failure() under\na single ifp->lock critical section.  The STABLE_PRIVACY branch\ntemporarily drops ifp->lock around address regeneration, so at\nlock_errdad: verify the state is still POSTDAD before transitioning\nto ERRDAD; bail out otherwise to avoid overwriting a state set by\nanother path while the lock was released."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["net/ipv6/addrconf.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"c15b1ccadb323ea50023e8f1cca2954129a62b51","lessThan":"47b05836705b63dab93d9ac7c69a3a507375ef80","versionType":"git","status":"affected"},{"version":"c15b1ccadb323ea50023e8f1cca2954129a62b51","lessThan":"d21be7d051012c6b572fa4e3334443c250216f7b","versionType":"git","status":"affected"},{"version":"c15b1ccadb323ea50023e8f1cca2954129a62b51","lessThan":"875c284c0f98b042bb97abad460f63a24c977f88","versionType":"git","status":"affected"},{"version":"c15b1ccadb323ea50023e8f1cca2954129a62b51","lessThan":"8ed0ce9ea58d677d1bac92614ee5f60f8ea57363","versionType":"git","status":"affected"},{"version":"c15b1ccadb323ea50023e8f1cca2954129a62b51","lessThan":"3bdc86d89fd6c6523753fa6f42fcfaf30ee699cb","versionType":"git","status":"affected"},{"version":"c15b1ccadb323ea50023e8f1cca2954129a62b51","lessThan":"b61af0268e3d1308c466bf0be5dced844eafc1ef","versionType":"git","status":"affected"},{"version":"c15b1ccadb323ea50023e8f1cca2954129a62b51","lessThan":"e889aa99ad3ed48bb0ddcff6475b17542532d18b","versionType":"git","status":"affected"},{"version":"c15b1ccadb323ea50023e8f1cca2954129a62b51","lessThan":"627ac78f2741e2ebd2225e2e953b6964a8a9182f","versionType":"git","status":"affected"},{"version":"835b474b8f70fa68d68abffad37378e92f661802","versionType":"git","status":"affected"},{"version":"3.10.105","lessThan":"3.11","versionType":"semver","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["net/ipv6/addrconf.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"3.14","status":"affected"},{"version":"0","lessThan":"3.14","versionType":"semver","status":"unaffected"},{"version":"5.10.261","lessThanOrEqual":"5.10.*","versionType":"semver","status":"unaffected"},{"version":"5.15.212","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.178","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.97","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/3bdc86d89fd6c6523753fa6f42fcfaf30ee699cb","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/47b05836705b63dab93d9ac7c69a3a507375ef80","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/627ac78f2741e2ebd2225e2e953b6964a8a9182f","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/875c284c0f98b042bb97abad460f63a24c977f88","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/8ed0ce9ea58d677d1bac92614ee5f60f8ea57363","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/b61af0268e3d1308c466bf0be5dced844eafc1ef","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/d21be7d051012c6b572fa4e3334443c250216f7b","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/e889aa99ad3ed48bb0ddcff6475b17542532d18b","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-74399","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:22:41.917","lastModified":"2026-08-15T06:22:41.917","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nevm: terminate and bound the evm_xattrs read buffer\n\nevm_read_xattrs() allocates size + 1 bytes, fills them from the list of\nenabled xattrs, and then passes strlen(temp) to\nsimple_read_from_buffer(). When no configured xattrs are enabled, the\nfill loop stores nothing and temp[0] remains uninitialized, so strlen()\nreads beyond initialized memory.\n\nExplicitly terminate the buffer after allocation, use snprintf() for\neach formatted line, and pass the accumulated length, without risk of\ntruncation, to simple_read_from_buffer()."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["security/integrity/evm/evm_secfs.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"fa516b66a1bfce1d72f1620c54bdfebc493000d1","lessThan":"8df81954d22a653a8b01d46692cd56f71137269b","versionType":"git","status":"affected"},{"version":"fa516b66a1bfce1d72f1620c54bdfebc493000d1","lessThan":"0b9f8282b40af4a99d6243d2cb939d14ff36b049","versionType":"git","status":"affected"},{"version":"fa516b66a1bfce1d72f1620c54bdfebc493000d1","lessThan":"a36cbfb85f26e6c6fb6529b1a364331b94dc88f3","versionType":"git","status":"affected"},{"version":"fa516b66a1bfce1d72f1620c54bdfebc493000d1","lessThan":"12ad52dc45a0c8c9d25e85b4a84201de4c5420ed","versionType":"git","status":"affected"},{"version":"fa516b66a1bfce1d72f1620c54bdfebc493000d1","lessThan":"a0f64cf8bfcb39e533d9e27aeb763a8d81b7f39d","versionType":"git","status":"affected"},{"version":"fa516b66a1bfce1d72f1620c54bdfebc493000d1","lessThan":"38b7d63b23aa9d2ddde7688040e9426d32be4065","versionType":"git","status":"affected"},{"version":"fa516b66a1bfce1d72f1620c54bdfebc493000d1","lessThan":"11143a19f5b8dc8f414deab87571134f9f447313","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["security/integrity/evm/evm_secfs.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"4.18","status":"affected"},{"version":"0","lessThan":"4.18","versionType":"semver","status":"unaffected"},{"version":"5.15.212","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.178","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.97","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/0b9f8282b40af4a99d6243d2cb939d14ff36b049","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/11143a19f5b8dc8f414deab87571134f9f447313","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/12ad52dc45a0c8c9d25e85b4a84201de4c5420ed","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/38b7d63b23aa9d2ddde7688040e9426d32be4065","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/8df81954d22a653a8b01d46692cd56f71137269b","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/a0f64cf8bfcb39e533d9e27aeb763a8d81b7f39d","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/a36cbfb85f26e6c6fb6529b1a364331b94dc88f3","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-74400","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:22:42.030","lastModified":"2026-08-15T06:22:42.030","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nbpf: fix crash in bpf_[set|remove]_dentry_xattr for negative dentries\n\nbpf_set_dentry_xattr and bpf_remove_dentry_xattr BPF kfuncs attempt to\nlock the inode of the supplied dentry without checking if it is\nNULL. If a negative dentry is passed (e.g. from\nsecurity_inode_create), d_inode(dentry) returns NULL, and\ninode_lock(inode) will cause a NULL pointer dereference.\n\nTrivially fix this by adding a NULL check for inode before attempting\nto lock it, returning -EINVAL if it is NULL.\n\nAdditionally, drop WARN_ON(!inode) in bpf_xattr_read_permission() and\nbpf_xattr_write_permission(). These warnings could be triggered by\npassing a negative dentry to bpf_get_dentry_xattr() or the _locked\nvariants of the xattr kfuncs, potentially causing a Denial of Service\non systems with panic_on_warn enabled. Instead, simply return -EINVAL."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["fs/bpf_fs_kfuncs.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"56467292794b800164df20c076c409ac548e56ec","lessThan":"e003f3a4be738f650e283e92d07017c3fef8da52","versionType":"git","status":"affected"},{"version":"56467292794b800164df20c076c409ac548e56ec","lessThan":"0160edf2af51c5fde742973742c5d10497901b21","versionType":"git","status":"affected"},{"version":"56467292794b800164df20c076c409ac548e56ec","lessThan":"07410646f6ff1d23222f105ccab778957d401bbe","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["fs/bpf_fs_kfuncs.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.15","status":"affected"},{"version":"0","lessThan":"6.15","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/0160edf2af51c5fde742973742c5d10497901b21","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/07410646f6ff1d23222f105ccab778957d401bbe","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/e003f3a4be738f650e283e92d07017c3fef8da52","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-74401","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:22:42.120","lastModified":"2026-08-15T06:22:42.120","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\ndlm: fix add msg handle in send_queue ordered\n\nIn a benchmark scenario triggering a lot of requests that triggers a lot\nof DLM messages on the network it can be that the mh->seq is not ordered\naccording the oldest seq number. This ordering is required by\ndlm_receive_ack as \"before(mh->seq, seq)\" will stop to check for older\nsequence numbers that are ordered in the tail of \"node->send_queue\".\n\nThe side effects of not having it correct ordered regarding\n\"before(mh->seq, seq)\" are refcounting issues and use-after free.\n\nI only was able to reproduce this issue in a experimental DLM branch\nand a user space DLM benchmark that uses io_uring. After changing this I\ndon't experienced any refcounting with the sending buffer issues anymore."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["fs/dlm/midcomms.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"489d8e559c6596eb08e16447d9830bc39afbe54e","lessThan":"ae9e534e502a0f48c12baf83608c5de0ff0eab11","versionType":"git","status":"affected"},{"version":"489d8e559c6596eb08e16447d9830bc39afbe54e","lessThan":"6369619f1b665f12d8c99cc6ff733c64eb08b22e","versionType":"git","status":"affected"},{"version":"489d8e559c6596eb08e16447d9830bc39afbe54e","lessThan":"712714f818d83373847874ab0f8e426be79296cf","versionType":"git","status":"affected"},{"version":"489d8e559c6596eb08e16447d9830bc39afbe54e","lessThan":"4d45250b1d22960f86d83245be188b16e456218b","versionType":"git","status":"affected"},{"version":"489d8e559c6596eb08e16447d9830bc39afbe54e","lessThan":"d2248cb70c070f8f04762872772e155b59016f17","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["fs/dlm/midcomms.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"5.14","status":"affected"},{"version":"0","lessThan":"5.14","versionType":"semver","status":"unaffected"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.97","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/4d45250b1d22960f86d83245be188b16e456218b","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/6369619f1b665f12d8c99cc6ff733c64eb08b22e","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/712714f818d83373847874ab0f8e426be79296cf","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/ae9e534e502a0f48c12baf83608c5de0ff0eab11","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/d2248cb70c070f8f04762872772e155b59016f17","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-74402","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:22:42.220","lastModified":"2026-08-15T06:22:42.220","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\ncrypto: atmel-sha204a - fix blocking and non-blocking rng logic\n\nThe blocking and non-blocking paths were failing to provide valid entropy\ndue to improper buffer management. Reading the buffer starting from byte 1,\nonly fetch the 32 bytes of random data from the return message.\n\nTested on an Atmel SHA204A device.\n\nBefore (here for blocking), tests showed repeatedly reading reduced bytes.\n$ head -c 32 /dev/hwrng | hexdump -C\n00000000  02 28 85 b3 47 40 f2 ee  00 00 00 00 00 00 00 00  |.(..G@..........|\n00000010  00 00 00 00 00 00 00 00  00 00 00 00 00 00 00 00  |................|\n00000020\n\nAfter, the result will be similar to the following:\n$ head -c 32 /dev/hwrng | hexdump -C\n00000000  5a fc 3f 13 14 68 fe 06  68 0a bd 04 83 6e 09 69  |Z.?..h..h....n.i|\n00000010  75 ff cf 87 10 84 3b c9  c1 df ae eb 45 53 4c c3  |u.....;.....ESL.|\n00000020"}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/crypto/atmel-sha204a.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"da001fb651b00e1deeaf24767dd691ae8152a4f5","lessThan":"76269a91fd9560c5f03c3e59421a0329e39a6661","versionType":"git","status":"affected"},{"version":"da001fb651b00e1deeaf24767dd691ae8152a4f5","lessThan":"9039bb4f238474379221fc933c34f19f0cba501b","versionType":"git","status":"affected"},{"version":"da001fb651b00e1deeaf24767dd691ae8152a4f5","lessThan":"d4aa6141ff03ec82eed6fcef814300fb855ce5d8","versionType":"git","status":"affected"},{"version":"da001fb651b00e1deeaf24767dd691ae8152a4f5","lessThan":"e833e865e4944ba75120db534bd931db6cf677d3","versionType":"git","status":"affected"},{"version":"da001fb651b00e1deeaf24767dd691ae8152a4f5","lessThan":"2fa302bbc62dec7cb6339c9494e0e3f2f884afeb","versionType":"git","status":"affected"},{"version":"da001fb651b00e1deeaf24767dd691ae8152a4f5","lessThan":"aac63bbea8fd5a34f1a4305cb73369068f952d32","versionType":"git","status":"affected"},{"version":"da001fb651b00e1deeaf24767dd691ae8152a4f5","lessThan":"938ae1fb4a8f5db43b62b6206d409efbf317f0d9","versionType":"git","status":"affected"},{"version":"da001fb651b00e1deeaf24767dd691ae8152a4f5","lessThan":"319400fc5ee15db5793aa45f854968141326effc","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/crypto/atmel-sha204a.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"5.3","status":"affected"},{"version":"0","lessThan":"5.3","versionType":"semver","status":"unaffected"},{"version":"5.10.261","lessThanOrEqual":"5.10.*","versionType":"semver","status":"unaffected"},{"version":"5.15.212","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.178","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.97","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/2fa302bbc62dec7cb6339c9494e0e3f2f884afeb","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/319400fc5ee15db5793aa45f854968141326effc","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/76269a91fd9560c5f03c3e59421a0329e39a6661","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/9039bb4f238474379221fc933c34f19f0cba501b","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/938ae1fb4a8f5db43b62b6206d409efbf317f0d9","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/aac63bbea8fd5a34f1a4305cb73369068f952d32","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/d4aa6141ff03ec82eed6fcef814300fb855ce5d8","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/e833e865e4944ba75120db534bd931db6cf677d3","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-74403","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:22:42.340","lastModified":"2026-08-15T06:22:42.340","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\ncrypto: ccp - Check for page allocation failure correctly in TIO\n\nSashiko notes:\n\n> if __snp_alloc_firmware_pages() returns NULL under memory pressure, is it\n> safe to pass it directly to page_address()?\n>\n> On architectures without HASHED_PAGE_VIRTUAL, page_address(NULL) might\n> compute a deterministic but invalid, non-zero virtual address. The\n> subsequent if (tio_status) check would then evaluate to true, and\n> sev_tsm_init_locked() would dereference the invalid pointer.\n\nIndeed, page_address(NULL) will return non-NULL garbage here. Fix this by\nchecking the page allocation itself for NULL, not the resulting virtual\naddress."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/crypto/ccp/sev-dev.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"4be423572da1f4c11f45168e3fafda870ddac9f8","lessThan":"17e1aae19a06d9f6da4b46d54fa2aeab77ec0c69","versionType":"git","status":"affected"},{"version":"4be423572da1f4c11f45168e3fafda870ddac9f8","lessThan":"a8d5370eef00eca132a292b1901c9914c817e385","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/crypto/ccp/sev-dev.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.19","status":"affected"},{"version":"0","lessThan":"6.19","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/17e1aae19a06d9f6da4b46d54fa2aeab77ec0c69","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/a8d5370eef00eca132a292b1901c9914c817e385","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-74404","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:22:42.433","lastModified":"2026-08-15T06:22:42.433","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\ncrypto: ccp - Fix snp_filter_reserved_mem_regions() off-by-one\n\nSashiko notes:\n\n> regarding the bounds check in snp_filter_reserved_mem_regions()\n> called via walk_iomem_res_desc(): does the check\n> if ((range_list->num_elements * 16 + 8) > PAGE_SIZE)\n> allow an off-by-one heap buffer overflow?\n>\n> If range_list->num_elements is 255, 255 * 16 + 8 = 4088, which is <= 4096.\n> Writing range->base (8 bytes) fills 4088-4095, but writing range->page_count\n> (4 bytes) would write to 4096-4099, overflowing the kzalloc-allocated\n> PAGE_SIZE buffer.\n\nFix this by accounting for the entry about to be written to, in addition to\nthe entries that are already allocated."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/crypto/ccp/sev-dev.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"1ca5614b84eed5904f65f143e0e7aaab0ac4c6b2","lessThan":"830c1f3e71989448652973375ef5e39b6ede47a3","versionType":"git","status":"affected"},{"version":"1ca5614b84eed5904f65f143e0e7aaab0ac4c6b2","lessThan":"c5c79d92da0f9a09f48be5e2aabed2d6d1a96294","versionType":"git","status":"affected"},{"version":"1ca5614b84eed5904f65f143e0e7aaab0ac4c6b2","lessThan":"af7341616b742ad2c374a90998bd650a035f694d","versionType":"git","status":"affected"},{"version":"1ca5614b84eed5904f65f143e0e7aaab0ac4c6b2","lessThan":"1b864b6cb213bbd7b406e9b2e98c962077f300df","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/crypto/ccp/sev-dev.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.9","status":"affected"},{"version":"0","lessThan":"6.9","versionType":"semver","status":"unaffected"},{"version":"6.12.97","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/1b864b6cb213bbd7b406e9b2e98c962077f300df","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/830c1f3e71989448652973375ef5e39b6ede47a3","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/af7341616b742ad2c374a90998bd650a035f694d","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/c5c79d92da0f9a09f48be5e2aabed2d6d1a96294","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-74405","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:22:42.530","lastModified":"2026-08-15T06:22:42.530","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nOPP: Fix race between OPP addition and lookup\n\nA race exists between dev_pm_opp_add_dynamic() and\ndev_pm_opp_find_freq_exact():\n\n  CPU0 (add)                          CPU1 (lookup)\n  -------------------------------     ------------------------------\n  _opp_add()\n    mutex_lock()\n    list_add(&new_opp->node, head)\n    mutex_unlock()                    _opp_table_find_key()\n                                        mutex_lock()\n                                        dev_pm_opp_get(opp)\n                                          kref_get()\n                                        mutex_unlock()\n    kref_init(&new_opp->kref)\n                                      dev_pm_opp_put()\n                                        kref_put_mutex()\n\nThe newly added OPP is inserted into the list before its kref is\ninitialized. A concurrent lookup can find this OPP and increment its\nreference count while it is still uninitialized, leading to refcount\ncorruption and a potential premature free.\n\nFix this by initializing ->kref and ->opp_table before making the OPP\nvisible via list_add(). This ensures any concurrent lookup observes a\nfully initialized object.\n\n[ Viresh: Updated commit log ]"}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/opp/core.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"7034764a1e4a6edbb60914e89aad8384e3fe5d17","lessThan":"46696b0b2123475d7f95909435c09808fc5ffd23","versionType":"git","status":"affected"},{"version":"7034764a1e4a6edbb60914e89aad8384e3fe5d17","lessThan":"bb75bd7d9ae7672034f73ce67a57e6ac89bb39e5","versionType":"git","status":"affected"},{"version":"7034764a1e4a6edbb60914e89aad8384e3fe5d17","lessThan":"f5e1cc9a284bff2510981643a5bca4bc4c21b81a","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/opp/core.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"4.11","status":"affected"},{"version":"0","lessThan":"4.11","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/46696b0b2123475d7f95909435c09808fc5ffd23","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/bb75bd7d9ae7672034f73ce67a57e6ac89bb39e5","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/f5e1cc9a284bff2510981643a5bca4bc4c21b81a","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-74406","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:22:42.633","lastModified":"2026-08-15T06:22:42.633","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nvxlan: Fix potential null-ptr-deref in vxlan_gro_prepare_receive().\n\nudp_tunnel_sock_release() could set sk->sk_user_data to NULL\nwhile vxlan_gro_prepare_receive() is running.\n\nLet's check if rcu_dereference_sk_user_data() is NULL after\nskb_gro_remcsum_init()."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/net/vxlan/vxlan_core.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"5602c48cf87562c2f95b831d690631935e834295","lessThan":"9c58c729d32e7cea5772cc44929c6cd61e5a31cd","versionType":"git","status":"affected"},{"version":"5602c48cf87562c2f95b831d690631935e834295","lessThan":"f79c80f173fda9545b220c1f094b65fc06c252d0","versionType":"git","status":"affected"},{"version":"5602c48cf87562c2f95b831d690631935e834295","lessThan":"08f40c0d23c67c3aa4224c3311e134999c721fb4","versionType":"git","status":"affected"},{"version":"5602c48cf87562c2f95b831d690631935e834295","lessThan":"4a8cde6f7281ea2c4c290f9ad9923b3631defceb","versionType":"git","status":"affected"},{"version":"5602c48cf87562c2f95b831d690631935e834295","lessThan":"ef44dac2a37f86eeae6b88ed10a6d60b35387dfd","versionType":"git","status":"affected"},{"version":"5602c48cf87562c2f95b831d690631935e834295","lessThan":"30a45c0bffdd62350261e2f2689fdba426a33578","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/net/vxlan/vxlan_core.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"4.7","status":"affected"},{"version":"0","lessThan":"4.7","versionType":"semver","status":"unaffected"},{"version":"6.1.178","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.97","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/08f40c0d23c67c3aa4224c3311e134999c721fb4","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/30a45c0bffdd62350261e2f2689fdba426a33578","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/4a8cde6f7281ea2c4c290f9ad9923b3631defceb","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/9c58c729d32e7cea5772cc44929c6cd61e5a31cd","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/ef44dac2a37f86eeae6b88ed10a6d60b35387dfd","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/f79c80f173fda9545b220c1f094b65fc06c252d0","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-74407","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:22:42.737","lastModified":"2026-08-15T06:22:42.737","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: ath11k: cancel SSR work items during PCI shutdown\n\nA reboot can crash the kernel if it overlaps with WLAN firmware crash\nrecovery (SSR). The crash is a NULL pointer dereference in the MHI teardown\npath while freeing DMA-backed MHI contexts.\n\nSimplified trace:\n  dma_free_attrs\n  mhi_deinit_dev_ctxt [mhi]\n  ath11k_pci_power_down [ath11k_pci]\n  ath11k_pci_shutdown [ath11k_pci]\n  device_shutdown\n  kernel_restart\n\nOn the host side, SSR is driven by the MHI RDDM callback, which queues\nreset_work to perform device recovery. reset_work power-cycles the device\nby calling ath11k_hif_power_down() followed by ath11k_hif_power_up(). The\npower-down phase deinitializes MHI and frees DMA resources.\n\nShutdown/reboot runs fully asynchronously with this RDDM-driven SSR\nrecovery flow. As a result, the shutdown path\n(ath11k_pci_shutdown() -> ath11k_pci_power_down()) can race with the SSR\nrecovery sequence.\n\nFix this by canceling SSR-related work items during PCI shutdown, marking\nthe device as unregistering, and serializing the RDDM callback path that\nchecks and queues reset_work. This ensures that no new SSR recovery work\ncan be queued once teardown has started, and that any in-flight recovery\nwork is fully synchronized before device power-down, preventing MHI\nteardown and DMA resource freeing from running more than once.\n\nNote: This issue only affects PCI/MHI-based devices. AHB-based ath11k\ndevices do not queue reset_work in normal SSR flows.\n\nTested-on: WCN6855 hw2.1 PCI WLAN.HSP.1.1-04866.5-QCAHSPSWPL_V1_V2_SILICONZ_IOE-1"}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/net/wireless/ath/ath11k/mhi.c","drivers/net/wireless/ath/ath11k/pci.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"13da397f884d9c9a3fb6616206eeb6c6ab097287","lessThan":"53dd29e8aeb2a1b5f079178551836b85fc6b53df","versionType":"git","status":"affected"},{"version":"13da397f884d9c9a3fb6616206eeb6c6ab097287","lessThan":"8c79aac429b583301f387374ff37c59be671df87","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/net/wireless/ath/ath11k/mhi.c","drivers/net/wireless/ath/ath11k/pci.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"5.19","status":"affected"},{"version":"0","lessThan":"5.19","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/53dd29e8aeb2a1b5f079178551836b85fc6b53df","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/8c79aac429b583301f387374ff37c59be671df87","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-74408","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:22:42.837","lastModified":"2026-08-15T06:22:42.837","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: ath9k: fix OOB access from firmware tx status queue ID\n\nath_tx_edma_tasklet() accesses sc->tx.txq[ts.qid] where ts.qid is a\n4-bit hardware field (0-15), but the txq array only has\nATH9K_NUM_TX_QUEUES (10) entries. A qid >= 10 causes an OOB array\naccess.\n\nAdd a bounds check on ts.qid before using it as an array index."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/net/wireless/ath/ath9k/xmit.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"fce041beb03f93c7a771f0b4b6c45bb71ef90901","lessThan":"fb11083db9d7d6fb8f98bbba1cbfcf3fb7b4bf54","versionType":"git","status":"affected"},{"version":"fce041beb03f93c7a771f0b4b6c45bb71ef90901","lessThan":"734db72d55ca578a344dfa33e30145032c074b25","versionType":"git","status":"affected"},{"version":"fce041beb03f93c7a771f0b4b6c45bb71ef90901","lessThan":"f5931d06b45ed402572bfe5832fff15864ef5481","versionType":"git","status":"affected"},{"version":"fce041beb03f93c7a771f0b4b6c45bb71ef90901","lessThan":"46ca1451f61b598f45cb5259e066d305444d95fc","versionType":"git","status":"affected"},{"version":"fce041beb03f93c7a771f0b4b6c45bb71ef90901","lessThan":"a9e055ac62cb3fcea262d4b687ec73eed82b3379","versionType":"git","status":"affected"},{"version":"fce041beb03f93c7a771f0b4b6c45bb71ef90901","lessThan":"5435fd3edcb11c7cc4002847c83e9a50b49284dc","versionType":"git","status":"affected"},{"version":"fce041beb03f93c7a771f0b4b6c45bb71ef90901","lessThan":"336d4c8cd9b1646060ee690c881d465dfc09c6c0","versionType":"git","status":"affected"},{"version":"fce041beb03f93c7a771f0b4b6c45bb71ef90901","lessThan":"7ce2f118a2389e8f0a64068c6fe7cc7d40639be0","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/net/wireless/ath/ath9k/xmit.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"3.1","status":"affected"},{"version":"0","lessThan":"3.1","versionType":"semver","status":"unaffected"},{"version":"5.10.261","lessThanOrEqual":"5.10.*","versionType":"semver","status":"unaffected"},{"version":"5.15.212","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.178","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.97","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/336d4c8cd9b1646060ee690c881d465dfc09c6c0","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/46ca1451f61b598f45cb5259e066d305444d95fc","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/5435fd3edcb11c7cc4002847c83e9a50b49284dc","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/734db72d55ca578a344dfa33e30145032c074b25","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/7ce2f118a2389e8f0a64068c6fe7cc7d40639be0","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/a9e055ac62cb3fcea262d4b687ec73eed82b3379","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/f5931d06b45ed402572bfe5832fff15864ef5481","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/fb11083db9d7d6fb8f98bbba1cbfcf3fb7b4bf54","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-74409","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:22:42.950","lastModified":"2026-08-15T06:22:42.950","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: rtw89: add bounds check on firmware mac_id in link lookup\n\nThe mac_id field in RX descriptors is 8 bits wide (0-255), but\nassoc_link_on_macid[] has only RTW89_MAX_MAC_ID_NUM (128) entries.\nWhile the driver currently assigns mac_id values below 128, the\ndescriptor value comes from firmware and is not validated before use\nas an array index. Add a defensive bounds check in\nrtw89_assoc_link_rcu_dereference() to guard against out-of-range\nfirmware values."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/net/wireless/realtek/rtw89/core.h"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"144c6cd24b3556e6e7a14271cee57a42ebf97450","lessThan":"ad445de67359f24088d4305c05fbd7e34c4e35e3","versionType":"git","status":"affected"},{"version":"144c6cd24b3556e6e7a14271cee57a42ebf97450","lessThan":"920101305e7601a33b9e01019f4ca526af2526ae","versionType":"git","status":"affected"},{"version":"144c6cd24b3556e6e7a14271cee57a42ebf97450","lessThan":"6d88244bb129755acca696f9227200f4a2d106a6","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/net/wireless/realtek/rtw89/core.h"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.14","status":"affected"},{"version":"0","lessThan":"6.14","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/6d88244bb129755acca696f9227200f4a2d106a6","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/920101305e7601a33b9e01019f4ca526af2526ae","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/ad445de67359f24088d4305c05fbd7e34c4e35e3","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-74410","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:22:43.043","lastModified":"2026-08-15T06:22:43.043","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: rtw88: fix OOB read from firmware RX descriptor exceeding DMA buffer\n\nIn rtw_pci_rx_napi(), new_len is computed as the sum of pkt_len (14-bit\ndescriptor field, max 16383) and pkt_offset (drv_info_sz + shift, both\nfirmware-controlled). The result can exceed RTK_PCI_RX_BUF_SIZE (11478),\ncausing an out-of-bounds read from the pre-allocated DMA buffer when\nskb_put_data copies new_len bytes. The USB transport already validates\nthis (rtw_usb_rx_data_put checks against RTW_USB_MAX_RECVBUF_SZ); the\nPCIe path does not.\n\nAdd a check that new_len does not exceed the DMA buffer size."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/net/wireless/realtek/rtw88/pci.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"e3037485c68ec1a299ff41160d8fedbd4abc29b9","lessThan":"913bd7d3d3d842b5c1d2b908a0201efa8fc79793","versionType":"git","status":"affected"},{"version":"e3037485c68ec1a299ff41160d8fedbd4abc29b9","lessThan":"45abc14ab3f15da7d689f1a8809c1a01240a94d9","versionType":"git","status":"affected"},{"version":"e3037485c68ec1a299ff41160d8fedbd4abc29b9","lessThan":"08193e733e5d4790e6c937af86d78793b02709be","versionType":"git","status":"affected"},{"version":"e3037485c68ec1a299ff41160d8fedbd4abc29b9","lessThan":"6a3c384393d3f0b41669ed5a2e88744aad9d87c8","versionType":"git","status":"affected"},{"version":"e3037485c68ec1a299ff41160d8fedbd4abc29b9","lessThan":"26c183a86ea4dd1f2ff90c6f783649e7f5722a10","versionType":"git","status":"affected"},{"version":"e3037485c68ec1a299ff41160d8fedbd4abc29b9","lessThan":"01155ded5d4dad61840a9a3c33ab56778ef1f100","versionType":"git","status":"affected"},{"version":"e3037485c68ec1a299ff41160d8fedbd4abc29b9","lessThan":"1554fa522f16ec7c5c342ad33fe734eeb6eb2452","versionType":"git","status":"affected"},{"version":"e3037485c68ec1a299ff41160d8fedbd4abc29b9","lessThan":"6e76e9ed273dfb4b3333a5ebbb94958cc5752ab6","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/net/wireless/realtek/rtw88/pci.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"5.2","status":"affected"},{"version":"0","lessThan":"5.2","versionType":"semver","status":"unaffected"},{"version":"5.10.261","lessThanOrEqual":"5.10.*","versionType":"semver","status":"unaffected"},{"version":"5.15.212","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.178","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.97","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/01155ded5d4dad61840a9a3c33ab56778ef1f100","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/08193e733e5d4790e6c937af86d78793b02709be","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/1554fa522f16ec7c5c342ad33fe734eeb6eb2452","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/26c183a86ea4dd1f2ff90c6f783649e7f5722a10","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/45abc14ab3f15da7d689f1a8809c1a01240a94d9","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/6a3c384393d3f0b41669ed5a2e88744aad9d87c8","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/6e76e9ed273dfb4b3333a5ebbb94958cc5752ab6","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/913bd7d3d3d842b5c1d2b908a0201efa8fc79793","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-74411","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:22:43.197","lastModified":"2026-08-15T06:22:43.197","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: rtw89: Correct data type for scan index to avoid infinite loop\n\nA kernel soft lockup was observed during Wi-Fi scanning on the 6GHz band.\nThe CPU becomes stuck in rtw89_hw_scan_add_chan_ax for over 20 seconds,\nleading to a system panic.\n\nRIP points to 0f b6 c3 (movzbl %bl, %eax), which zero-extends\nthe low 8 bits of RBX into RAX.\nRBX (the counter i) has reached a huge value: 0x137466a1.\n\n  watchdog: BUG: soft lockup - CPU#2 stuck for 26s! [kworker/u16:4:6124]\n  Workqueue: events_unbound cfg80211_wiphy_work [cfg80211]\n  RIP: 0010:rtw89_hw_scan_add_chan_ax+0xb3/0x6e0 [rtw89_core]\n  Code: a0 48 89 45 a8 44 89 6d 9c 44 89 75 98 eb 29 66 66 2e 0f 1f\n  84 00 00 00 00 00 66 66 2e 0f 1f 84 00 00 00 00 00 66 90 83 c3 01\n  <0f> b6 c3 41 3b 44 24 74 0f 83 0b 02 00 00 0f b6 c3 48 8d 14 80 49\n  RSP: 0018:ffffcb48cbaa39f8 EFLAGS: 00000202\n  RAX: 0000000000000005 RBX: 00000000137466a1 RCX: 0000000000000000\n  RDX: ffff89ffc9d851a8 RSI: 0000000000004f0d RDI: 0000000096af0130\n  RBP: ffffcb48cbaa3a60 R08: 0000000000000000 R09: ffff8a00b7502080\n  R10: ffff8a00b75ff600 R11: 0000000000000000 R12: ffff89ffc7553870\n  R13: ffff8a00b7ac8f19 R14: ffff8a00b75020d8 R15: ffff89ffc3d54d80\n  FS:  0000000000000000(0000) GS:ffff8a014f962000(0000)\n  knlGS:0000000000000000\n  CS:  0010 DS: 0000 ES: 0000 CR0: 0000000080050033\n  CR2: 00007558d7f9f4c4 CR3: 0000000178040001 CR4: 00000000001706f0\n  Call Trace:\n   <TASK>\n   rtw89_hw_scan_prep_chan_list_ax+0x8a/0x400 [rtw89_core]\n   rtw89_hw_scan_start+0x546/0x8a0 [rtw89_core]\n   ? rtw89_fw_h2c_default_cmac_tbl+0x13c/0x1f0 [rtw89_core]\n   rtw89_ops_hw_scan+0xae/0x120 [rtw89_core]\n   drv_hw_scan+0xbb/0x180 [mac80211]\n   __ieee80211_start_scan+0x2fc/0x750 [mac80211]\n   ieee80211_request_scan+0xe/0x20 [mac80211]\n   ieee80211_scan+0x123/0x190 [mac80211]\n   rdev_scan+0x40/0x110 [cfg80211]\n   cfg80211_scan_6ghz+0x5a1/0xa30 [cfg80211]\n\nBy objdump with source:\n\n\tfor (i = 0; i < req->n_6ghz_params; i++) {\n   5fbc0:\t83 c3 01             \tadd    $0x1,%ebx --> i++\n   5fbc3:\t0f b6 c3             \tmovzbl %bl,%eax  --> get counter\n   fbc6:\t41 3b 44 24 74       \tcmp    0x74(%r12),%eax\n\n   * RBX: 00000000137466a1 -> %bl = a1 -> EAX = 000000a1 (161)"}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/net/wireless/realtek/rtw89/fw.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"c6aa9a9c47252ac7b07ed6d10459027e2f2a2de0","lessThan":"966fbed4b4463fbcb49c5becf3f86eae776861bd","versionType":"git","status":"affected"},{"version":"c6aa9a9c47252ac7b07ed6d10459027e2f2a2de0","lessThan":"05d46e30303275f21f13c951166d39c85df976d4","versionType":"git","status":"affected"},{"version":"c6aa9a9c47252ac7b07ed6d10459027e2f2a2de0","lessThan":"7a1ab5fdcae896e20ca6d68fa0fbd2816cb7471f","versionType":"git","status":"affected"},{"version":"c6aa9a9c47252ac7b07ed6d10459027e2f2a2de0","lessThan":"140fa699cfd0e18ab2f1497acd951fb3548610f5","versionType":"git","status":"affected"},{"version":"c6aa9a9c47252ac7b07ed6d10459027e2f2a2de0","lessThan":"08fdcb529df6df3562dd2b0035f88dd5be8b3c68","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/net/wireless/realtek/rtw89/fw.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.4","status":"affected"},{"version":"0","lessThan":"6.4","versionType":"semver","status":"unaffected"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.97","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/05d46e30303275f21f13c951166d39c85df976d4","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/08fdcb529df6df3562dd2b0035f88dd5be8b3c68","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/140fa699cfd0e18ab2f1497acd951fb3548610f5","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/7a1ab5fdcae896e20ca6d68fa0fbd2816cb7471f","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/966fbed4b4463fbcb49c5becf3f86eae776861bd","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-74412","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:22:43.317","lastModified":"2026-08-15T06:22:43.317","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: rtw88: fix wrong pci_get_drvdata type in AER handlers\n\nrtw88 stores an ieee80211_hw pointer via pci_set_drvdata() at probe\ntime, but io_error_detected() and io_resume() retrieve it as a\nnet_device pointer.  This causes netif_device_detach/attach to\noperate on an ieee80211_hw struct, reading and writing at wrong\noffsets.\n\nUse ieee80211_stop_queues/wake_queues instead, consistent with\nevery other queue stop/start path in the driver."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/net/wireless/realtek/rtw88/pci.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"cdb82c80b9349ed1d9ce6b49856128e04f4effc9","lessThan":"1ef3d1338d94ec41f58fbfb6ba7742a27ea61d89","versionType":"git","status":"affected"},{"version":"cdb82c80b9349ed1d9ce6b49856128e04f4effc9","lessThan":"d7920797f721f944861f3c48ffb2b73f84b631fe","versionType":"git","status":"affected"},{"version":"cdb82c80b9349ed1d9ce6b49856128e04f4effc9","lessThan":"706183dbef4a79d120d4e928f693bea50df496f8","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/net/wireless/realtek/rtw88/pci.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.17","status":"affected"},{"version":"0","lessThan":"6.17","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/1ef3d1338d94ec41f58fbfb6ba7742a27ea61d89","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/706183dbef4a79d120d4e928f693bea50df496f8","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/d7920797f721f944861f3c48ffb2b73f84b631fe","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-74413","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:22:43.410","lastModified":"2026-08-15T06:22:43.410","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: rtw89: fix wrong pci_get_drvdata type in AER handlers\n\nrtw89 stores an ieee80211_hw pointer via pci_set_drvdata() at probe\ntime, but io_error_detected() and io_resume() retrieve it as a\nnet_device pointer.  This causes netif_device_detach/attach to\noperate on an ieee80211_hw struct, reading and writing at wrong\noffsets.  The adjacent io_slot_reset() already does it correctly.\n\nUse ieee80211_stop_queues/wake_queues instead, consistent with\nevery other queue stop/start path in the driver.\n\nTested on RTL8852CE by calling the handlers from a test module\nbefore and after the fix."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/net/wireless/realtek/rtw89/pci.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"16e3d93c6183649a3b210f82b83c1cb12aa5e8a3","lessThan":"aefc30e4a829c1683f6ae999df7f9310c27eae6c","versionType":"git","status":"affected"},{"version":"16e3d93c6183649a3b210f82b83c1cb12aa5e8a3","lessThan":"c1907b9a4fa9cb33d11a9af138374dd2e93f7a93","versionType":"git","status":"affected"},{"version":"16e3d93c6183649a3b210f82b83c1cb12aa5e8a3","lessThan":"7068c379cf9aa8afe4dce4d9d82390187aa9c4d0","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/net/wireless/realtek/rtw89/pci.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.17","status":"affected"},{"version":"0","lessThan":"6.17","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/7068c379cf9aa8afe4dce4d9d82390187aa9c4d0","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/aefc30e4a829c1683f6ae999df7f9310c27eae6c","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/c1907b9a4fa9cb33d11a9af138374dd2e93f7a93","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-74414","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:22:43.507","lastModified":"2026-08-15T06:22:43.507","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nhfsplus: Remove the duplicate attr inode dirty marking action\n\nSyzbot reported a null-ptr-deref in [1].\nIf the attributes file is not loaded during system mount, a trigger\noccurs [1] when setxattr is executed in userspace.\n\nRemove the first mark attr inode dirty operation.\n\n[1]\nKASAN: null-ptr-deref in range [0x0000000000000008-0x000000000000000f]\nCall Trace:\n hfsplus_setxattr+0x124/0x340 fs/hfsplus/xattr.c:555\n hfsplus_trusted_setxattr+0x40/0x60 fs/hfsplus/xattr_trusted.c:30\n __vfs_setxattr+0x43c/0x480 fs/xattr.c:218\n __vfs_setxattr_noperm+0x12d/0x660 fs/xattr.c:252\n vfs_setxattr+0x163/0x360 fs/xattr.c:339\n do_setxattr fs/xattr.c:654 [inline]"}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["fs/hfsplus/xattr.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"ee8422d00b7cfa028823ebf1f28bf9dea428cac3","lessThan":"b3c7ccb1a93cbb5a9a13196abf608ffa2516817e","versionType":"git","status":"affected"},{"version":"ee8422d00b7cfa028823ebf1f28bf9dea428cac3","lessThan":"7a41fd2b32e5908f19a68732008d581c167279dd","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["fs/hfsplus/xattr.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"7.1","status":"affected"},{"version":"0","lessThan":"7.1","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/7a41fd2b32e5908f19a68732008d581c167279dd","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/b3c7ccb1a93cbb5a9a13196abf608ffa2516817e","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-74415","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:22:43.600","lastModified":"2026-08-15T06:22:43.600","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nspi: atcspi200: fix use-after-free when driver unbind\n\nDMA resource is initialized after SPI controller registration. So\nwhen driver unbind, this can trigger a use-after-free when DMA is\ntorn down while the controller is still alive and triggers DMA transfers."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/spi/spi-atcspi200.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"34e3815ea4597131d4324a4aa243d2201e672005","lessThan":"af6a34c41683067a314d2b58b39edecb2e5e4ac6","versionType":"git","status":"affected"},{"version":"34e3815ea4597131d4324a4aa243d2201e672005","lessThan":"565bdf45125a05aa8f622f58f598283f46ba43f4","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/spi/spi-atcspi200.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"7.0","status":"affected"},{"version":"0","lessThan":"7.0","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/565bdf45125a05aa8f622f58f598283f46ba43f4","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/af6a34c41683067a314d2b58b39edecb2e5e4ac6","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-74416","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:22:43.690","lastModified":"2026-08-15T06:22:43.690","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/radeon: fix memory leak in radeon_ring_restore() on lock failure\n\nradeon_ring_restore() takes ownership of the data buffer allocated by\nradeon_ring_backup(). The caller (radeon_gpu_reset()) only frees it in\nthe non-restore branch; in the restore branch it relies on\nradeon_ring_restore() to free it.\n\nIf radeon_ring_lock() fails, the function returned early without calling\nkvfree(data), leaking the ring backup buffer on every GPU reset that\nfails at the lock stage. During repeated GPU resets this causes\ncumulative kernel memory exhaustion.\n\nFree data before returning the error."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/gpu/drm/radeon/radeon_ring.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"55d7c22192becd0ec827a6901899ff56fa985658","lessThan":"63912418f1fbb6456ea04bbcdf8f4d5090d23350","versionType":"git","status":"affected"},{"version":"55d7c22192becd0ec827a6901899ff56fa985658","lessThan":"919e3e398bf301c6418dffdcd5e5c4fd9be39cf7","versionType":"git","status":"affected"},{"version":"55d7c22192becd0ec827a6901899ff56fa985658","lessThan":"07c213f3499dd72e2922c1c73fe9ffea24874bef","versionType":"git","status":"affected"},{"version":"55d7c22192becd0ec827a6901899ff56fa985658","lessThan":"1c9ba32308c02c198c378fcdf06be9ffc3111147","versionType":"git","status":"affected"},{"version":"55d7c22192becd0ec827a6901899ff56fa985658","lessThan":"eecfb76129ebef7e3aa41e18a4668cd91dfc6267","versionType":"git","status":"affected"},{"version":"55d7c22192becd0ec827a6901899ff56fa985658","lessThan":"06dc892561f5a08b2493c34c8ec2cb94dea33159","versionType":"git","status":"affected"},{"version":"55d7c22192becd0ec827a6901899ff56fa985658","lessThan":"ccc42187fc2d0720947a63ce1b9e399d2c068ff4","versionType":"git","status":"affected"},{"version":"55d7c22192becd0ec827a6901899ff56fa985658","lessThan":"82f1d6042611d45b8b9de423bbcb4e0ced9ec62b","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/gpu/drm/radeon/radeon_ring.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"3.6","status":"affected"},{"version":"0","lessThan":"3.6","versionType":"semver","status":"unaffected"},{"version":"5.10.261","lessThanOrEqual":"5.10.*","versionType":"semver","status":"unaffected"},{"version":"5.15.212","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.178","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.97","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/06dc892561f5a08b2493c34c8ec2cb94dea33159","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/07c213f3499dd72e2922c1c73fe9ffea24874bef","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/1c9ba32308c02c198c378fcdf06be9ffc3111147","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/63912418f1fbb6456ea04bbcdf8f4d5090d23350","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/82f1d6042611d45b8b9de423bbcb4e0ced9ec62b","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/919e3e398bf301c6418dffdcd5e5c4fd9be39cf7","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/ccc42187fc2d0720947a63ce1b9e399d2c068ff4","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/eecfb76129ebef7e3aa41e18a4668cd91dfc6267","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-74417","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:22:43.807","lastModified":"2026-08-15T06:22:43.807","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/radeon: fix integer overflow in radeon_align_pitch()\n\nradeon_align_pitch() has the same kind of overflow issue as the old\namdgpu helper: both the alignment round-up add and the final\n'aligned * cpp' calculation can overflow signed int.\n\nIf that wraps, radeon_mode_dumb_create() can end up returning an\ninvalid pitch or creating a zero-sized dumb buffer.\n\nFix this by using check_add_overflow() for the alignment round-up and\ncheck_mul_overflow() for the final pitch calculation, returning 0 on\noverflow. Also reject zero pitch and size in\nradeon_mode_dumb_create().\n\nFound via AST-based call-graph analysis using sqry."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/gpu/drm/radeon/radeon_gem.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"ff72145badb834e8051719ea66e024784d000cb4","lessThan":"b7b44937c548c2c987fcdd129f8896741004bed6","versionType":"git","status":"affected"},{"version":"ff72145badb834e8051719ea66e024784d000cb4","lessThan":"415bb9893e249e46aa5159f7363a11512cf06fa9","versionType":"git","status":"affected"},{"version":"ff72145badb834e8051719ea66e024784d000cb4","lessThan":"d9dfa176899d488e48bb7342d2c43ddd36e66318","versionType":"git","status":"affected"},{"version":"ff72145badb834e8051719ea66e024784d000cb4","lessThan":"dfc7b5b5599472277e71e5bd2712740651c7c5be","versionType":"git","status":"affected"},{"version":"ff72145badb834e8051719ea66e024784d000cb4","lessThan":"ce3b24eb3ee8f82de851535f516bf21f83e82259","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/gpu/drm/radeon/radeon_gem.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"2.6.39","status":"affected"},{"version":"0","lessThan":"2.6.39","versionType":"semver","status":"unaffected"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.97","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/415bb9893e249e46aa5159f7363a11512cf06fa9","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/b7b44937c548c2c987fcdd129f8896741004bed6","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/ce3b24eb3ee8f82de851535f516bf21f83e82259","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/d9dfa176899d488e48bb7342d2c43ddd36e66318","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/dfc7b5b5599472277e71e5bd2712740651c7c5be","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-74418","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:22:43.907","lastModified":"2026-08-15T06:22:43.907","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\ndma-fence: Fix potential tracepoint null pointer dereferences\n\nTrace_dma_fence_signaled, trace_dma_fence_wait_end and\ntrace_dma_fence_destroy can all currently dereference a null fence->ops\npointer after it has been reset on fence signalling.\n\nLets use the safe string getters for most tracepoints to avoid this class\nof a problem, while for the signal tracepoint we move it to before ops are\ncleared to avoid losing the driver and timeline name information. Apart\nfrom moving it we also need to add a new tracepoint class to bypass the\nsafe name getters since the signaled bit is already set.\n\nFor dma_fence_init we also need to use the new tracepoint class since the\nrcu read lock is not held there, and we can do the same for the enable\nsignaling since there we are certain the fence cannot be signaled while\nwe are holding the lock and have even validated the fence->ops."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/dma-buf/dma-fence.c","include/trace/events/dma_fence.h"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"541c8f2468b933acc5d129e84bd264923675a66e","lessThan":"4e01fc9a5bc49b04fad403ffa71299b35e132ca8","versionType":"git","status":"affected"},{"version":"541c8f2468b933acc5d129e84bd264923675a66e","lessThan":"e94b9f01543cc6a83538c2c2cc645a424d3015ca","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/dma-buf/dma-fence.c","include/trace/events/dma_fence.h"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"7.1","status":"affected"},{"version":"0","lessThan":"7.1","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/4e01fc9a5bc49b04fad403ffa71299b35e132ca8","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/e94b9f01543cc6a83538c2c2cc645a424d3015ca","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-74419","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:22:43.997","lastModified":"2026-08-15T06:22:43.997","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\naccel/amdxdna: Adjust size for copy_to_user()\n\nThe amount of data returned to user space should be limited by the buffer\nsize provided by the application. If the buffer is smaller than the data\nsize, return only the portion that fits instead of failing."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/accel/amdxdna/aie2_error.c","drivers/accel/amdxdna/aie2_message.c","drivers/accel/amdxdna/aie2_pci.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"850d71f6bf4c2010efae845f9ff841cce902f22c","lessThan":"097e57195ef813735c8b714d6503bf3ad0742515","versionType":"git","status":"affected"},{"version":"850d71f6bf4c2010efae845f9ff841cce902f22c","lessThan":"6e87001fe19f251e2ae14373bc76554358a13df2","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/accel/amdxdna/aie2_error.c","drivers/accel/amdxdna/aie2_message.c","drivers/accel/amdxdna/aie2_pci.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.14","status":"affected"},{"version":"0","lessThan":"6.14","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/097e57195ef813735c8b714d6503bf3ad0742515","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/6e87001fe19f251e2ae14373bc76554358a13df2","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-74420","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:22:44.100","lastModified":"2026-08-15T06:22:44.100","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/gpusvm: Reject VMAs with VM_IO or VM_PFNMAP when creating SVM ranges\n\nVMAs marked with VM_IO or VM_PFNMAP are not backed by struct page\nobjects, which GPUSVM requires in order to operate correctly. In\nparticular, get_pages() relies on hmm_range_fault() to resolve struct\npages for the target range.\n\nAttempting to create an SVM range on such VMAs results in repeated\nget_pages() failures and can lead to an infinite loop inside a driver’s\npage‑fault handler. Prevent this by rejecting ranges on VM_IO or\nVM_PFNMAP VMAs and returning -EIO."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/gpu/drm/drm_gpusvm.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"99624bdff8670795b678eafa6509aaad3a5c0175","lessThan":"353f26c74660bcbd8d82cd76622748e14a5a5db3","versionType":"git","status":"affected"},{"version":"99624bdff8670795b678eafa6509aaad3a5c0175","lessThan":"63f443384979563f16f70420f4fa85bba31238ca","versionType":"git","status":"affected"},{"version":"99624bdff8670795b678eafa6509aaad3a5c0175","lessThan":"b82a225e57a334335a21462b75ee2223bc6efe6d","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/gpu/drm/drm_gpusvm.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.15","status":"affected"},{"version":"0","lessThan":"6.15","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/353f26c74660bcbd8d82cd76622748e14a5a5db3","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/63f443384979563f16f70420f4fa85bba31238ca","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/b82a225e57a334335a21462b75ee2223bc6efe6d","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-74421","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:22:44.197","lastModified":"2026-08-15T06:22:44.197","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/rockchip: dw_dp: Switch to drmm_kzalloc()\n\nDriver makes use of drmm_encoder_init() to initialize the encoder and\nautomatically handle the cleanup by registering drm_encoder_cleanup()\nwith drmm_add_action().\n\nHowever, the internal structure containing the encoder part gets\nallocated with devm_kzalloc(), which happens while component_bind_all()\nis being called from Rockchip DRM driver.  The component framework\nfurther ensures it is deallocated as part of releasing all the resources\nclaimed during bind, which is triggered from component_unbind_all().\n\nWhen the reference to the DRM device gets eventually dropped via\ndrm_dev_put() in rockchip_drm_unbind(), drmm_encoder_alloc_release()\nattempts to access the now released encoder structure, leading to\nuse-after-free.\n\nEnsure driver's internal structure is still reachable on encoder cleanup\nby switching from a device-managed allocation to a drm-managed one."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/gpu/drm/rockchip/dw_dp-rockchip.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"d68ba7bac9555d05e2f5b310c898b2a5c7eff174","lessThan":"0d60b835bca42f0f790689dd47819ed881a92ccc","versionType":"git","status":"affected"},{"version":"d68ba7bac9555d05e2f5b310c898b2a5c7eff174","lessThan":"6b0b92d1110eccccbd5ba2949bd2b9fb6ea5fc12","versionType":"git","status":"affected"},{"version":"d68ba7bac9555d05e2f5b310c898b2a5c7eff174","lessThan":"ed9da8d23020352ad24c528db09b5acdd78b81fd","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/gpu/drm/rockchip/dw_dp-rockchip.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.18","status":"affected"},{"version":"0","lessThan":"6.18","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/0d60b835bca42f0f790689dd47819ed881a92ccc","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/6b0b92d1110eccccbd5ba2949bd2b9fb6ea5fc12","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/ed9da8d23020352ad24c528db09b5acdd78b81fd","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-74422","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:22:44.293","lastModified":"2026-08-15T06:22:44.293","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/rockchip: inno-hdmi: Switch to drmm_kzalloc()\n\nDriver makes use of drmm_encoder_init() to initialize the encoder and\nautomatically handle the cleanup by registering drm_encoder_cleanup()\nwith drmm_add_action().\n\nHowever, the internal structure containing the encoder part gets\nallocated with devm_kzalloc(), which happens while component_bind_all()\nis being called from Rockchip DRM driver.  The component framework\nfurther ensures it is deallocated as part of releasing all the resources\nclaimed during bind, which is triggered from component_unbind_all().\n\nWhen the reference to the DRM device gets eventually dropped via\ndrm_dev_put() in rockchip_drm_unbind(), drmm_encoder_alloc_release()\nattempts to access the now released encoder structure, leading to\nuse-after-free.\n\nEnsure driver's internal structure is still reachable on encoder cleanup\nby switching from a device-managed allocation to a drm-managed one."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/gpu/drm/rockchip/inno_hdmi-rockchip.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"969325a2597ebc4cb001a92992f06f698ab2b467","lessThan":"195ab348af4b2bdf5988f9397059317bb68fd797","versionType":"git","status":"affected"},{"version":"969325a2597ebc4cb001a92992f06f698ab2b467","lessThan":"3cc50e7f73fcf79f28660b9d91566b13cb62e520","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/gpu/drm/rockchip/inno_hdmi-rockchip.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"7.0","status":"affected"},{"version":"0","lessThan":"7.0","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/195ab348af4b2bdf5988f9397059317bb68fd797","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/3cc50e7f73fcf79f28660b9d91566b13cb62e520","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-74423","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:22:44.387","lastModified":"2026-08-15T06:22:44.387","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\naccel/amdxdna: Fix leak when pinning ubuf pages\n\nWhen pin_user_pages_fast() returns fewer pages than requested, the pages\nthat were successfully pinned are not released, leading to a leak.\n\nFix this by unpinning any partially pinned pages before returning failure."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/accel/amdxdna/amdxdna_ubuf.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"bd72d4acda1069579b35123e3cc0b21ec1193a21","lessThan":"68dc52f308a17c3103a349f722dd5dea32c50a88","versionType":"git","status":"affected"},{"version":"bd72d4acda1069579b35123e3cc0b21ec1193a21","lessThan":"5b24e0903c58cdfd8ebfecb6ac5c5bacfd06e4e7","versionType":"git","status":"affected"},{"version":"bd72d4acda1069579b35123e3cc0b21ec1193a21","lessThan":"d946347edc4f0a7b846325323d77e936a4c90d0f","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/accel/amdxdna/amdxdna_ubuf.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.18","status":"affected"},{"version":"0","lessThan":"6.18","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/5b24e0903c58cdfd8ebfecb6ac5c5bacfd06e4e7","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/68dc52f308a17c3103a349f722dd5dea32c50a88","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/d946347edc4f0a7b846325323d77e936a4c90d0f","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-74424","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:22:44.480","lastModified":"2026-08-15T06:22:44.480","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nfbcon: fix NULL pointer dereference for a console without vc_data\n\nfbcon_new_modelist() runs when a framebuffer's modelist changes. For each\nconsole mapped to it with fb_display[i].mode set, it reads vc_cons[i].d and\npasses the vc_num to fbcon_set_disp(). This assumes a console with a mode\nset has a vc_data, but it can be NULL. fbcon_set_disp() sets\nfb_display[i].mode before it checks vc_data, and fbcon_deinit() leaves the\nmode set after the vc_data is freed. fbcon_new_modelist() then dereferences\nthe NULL vc_data.\n\nKeep fb_display[i].mode set only while the console has a vc_data. Check\nvc_data before setting the mode in fbcon_set_disp(), and clear the mode in\nfbcon_deinit(). The existing mode check in fbcon_new_modelist() then skips\nsuch consoles."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/video/fbdev/core/fbcon.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"8e9b8b008f4036df0318870c5d754134ff1b94cc","versionType":"git","status":"affected"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"cc4382dc5134826a3936a6b08de17f7dc7abe232","versionType":"git","status":"affected"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"9b783b7e03dc78ec102edf618259a2b55911fc6a","versionType":"git","status":"affected"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"ac970358c5ca0775841bd2a56ce15dc464b99003","versionType":"git","status":"affected"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"6617df8c246311c82cebf061a4cee55b9df60922","versionType":"git","status":"affected"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"b134ad2f7c06b3c1098dcc95008e2045ff4b49b2","versionType":"git","status":"affected"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"5fae9a928482d4845bca169a3a098789203a1ca4","versionType":"git","status":"affected"},{"version":"0","lessThan":"5.15.212","versionType":"semver","status":"affected"},{"version":"0","lessThan":"6.1.178","versionType":"semver","status":"affected"},{"version":"0","lessThan":"6.6.145","versionType":"semver","status":"affected"},{"version":"0","lessThan":"6.12.97","versionType":"semver","status":"affected"},{"version":"0","lessThan":"6.18.40","versionType":"semver","status":"affected"},{"version":"0","lessThan":"7.1.5","versionType":"semver","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/video/fbdev/core/fbcon.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"5.15.212","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.178","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.97","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/5fae9a928482d4845bca169a3a098789203a1ca4","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/6617df8c246311c82cebf061a4cee55b9df60922","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/8e9b8b008f4036df0318870c5d754134ff1b94cc","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/9b783b7e03dc78ec102edf618259a2b55911fc6a","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/ac970358c5ca0775841bd2a56ce15dc464b99003","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/b134ad2f7c06b3c1098dcc95008e2045ff4b49b2","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/cc4382dc5134826a3936a6b08de17f7dc7abe232","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-74425","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:22:44.590","lastModified":"2026-08-15T06:22:44.590","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nafs: handle CB.InitCallBackState3 requests without a server record\n\nThe cache manager callback path now attaches the server record to an\nincoming call through the rxrpc peer's app data.  That association is\nnot guaranteed to exist for every callback request, and most callback\nhandlers already tolerate that case.\n\nMake CB.InitCallBackState3 follow the same pattern by checking whether a\nserver record was attached before using it.  If the peer is not mapped\nto a server record, trace the request and ignore it, matching the\nexisting behaviour for other unmatched callback requests.\n\nThis keeps the callback handler consistent with the rest of the cache\nmanager service and avoids depending on peer state that may not be\navailable for a given request."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["fs/afs/cmservice.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"39ba6af83a7f9dee3e6a7916f41a48bcbda54eba","lessThan":"42e3917cdbdc3d35e191c525687a6d5427f237fd","versionType":"git","status":"affected"},{"version":"40e8b52fe8c8ab6920ea5f59c5469b6918cce624","lessThan":"cc848a080f7a6848dfeef441722419fdcbfe9b8d","versionType":"git","status":"affected"},{"version":"40e8b52fe8c8ab6920ea5f59c5469b6918cce624","lessThan":"0bd5f2786a878148190b4c7c259d01313d5f2357","versionType":"git","status":"affected"},{"version":"40e8b52fe8c8ab6920ea5f59c5469b6918cce624","lessThan":"f3cf725cd284b7912d5522babb44721bf38c8887","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["fs/afs/cmservice.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.15","status":"affected"},{"version":"0","lessThan":"6.15","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc2","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/0bd5f2786a878148190b4c7c259d01313d5f2357","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/42e3917cdbdc3d35e191c525687a6d5427f237fd","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/cc848a080f7a6848dfeef441722419fdcbfe9b8d","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/f3cf725cd284b7912d5522babb44721bf38c8887","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-74426","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:22:44.690","lastModified":"2026-08-15T06:22:44.690","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nafs: fix NULL pointer dereference in afs_get_tree()\n\nafs_alloc_sbi() uses kzalloc for memory allocation. And, if\nctx->dyn_root is not null, as->cell and as->volume are null.\nIn trace_afs_get_tree() they are dereferenced.\n\nKASAN error message:\n\nKASAN: null-ptr-deref in range [0x0000000000000000-0x0000000000000007]\nCPU: 2 PID: 18478 Comm: syz-executor.7 Not tainted 5.10.246-syzkaller #0\nHardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS 1.12.0-1\n04/01/2014\nRIP: 0010:perf_trace_afs_get_tree+0x1d9/0x550\ninclude/trace/events/afs.h:1365\n\nCall Trace:\ntrace_afs_get_tree include/trace/events/afs.h:1365 [inline]\nafs_get_tree+0x922/0x1350 fs/afs/super.c:599\nvfs_get_tree+0x8e/0x300 fs/super.c:1572\ndo_new_mount fs/namespace.c:3011 [inline]\npath_mount+0x14a5/0x2220 fs/namespace.c:3341\ndo_mount fs/namespace.c:3354 [inline]\n__do_sys_mount fs/namespace.c:3562 [inline]\n__se_sys_mount fs/namespace.c:3539 [inline]\n__x64_sys_mount+0x283/0x300 fs/namespace.c:3539\n do_syscall_64+0x33/0x50 arch/x86/entry/common.c:46\nentry_SYSCALL_64_after_hwframe+0x67/0xd1\n\nFound by Linux Verification Center (linuxtesting.org) with Syzkaller."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["fs/afs/super.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"80548b03991f58758a336424a90bf9f988e3b077","lessThan":"67fb48c4a0874953212321cd5d57fdb4900dbc31","versionType":"git","status":"affected"},{"version":"80548b03991f58758a336424a90bf9f988e3b077","lessThan":"d648cc2069eb081707c061849046d909f57c78b1","versionType":"git","status":"affected"},{"version":"80548b03991f58758a336424a90bf9f988e3b077","lessThan":"d5b17474feed3c30991f07affa2473adbad95055","versionType":"git","status":"affected"},{"version":"80548b03991f58758a336424a90bf9f988e3b077","lessThan":"867b3ea146a041023bfcd258e6db516b1bb28f19","versionType":"git","status":"affected"},{"version":"80548b03991f58758a336424a90bf9f988e3b077","lessThan":"ea19edf71721cd42f923e3c70f4ff995b422fe3b","versionType":"git","status":"affected"},{"version":"80548b03991f58758a336424a90bf9f988e3b077","lessThan":"23b3d457d8387bcb2a61063a9e520063ada9335f","versionType":"git","status":"affected"},{"version":"80548b03991f58758a336424a90bf9f988e3b077","lessThan":"70b2842734d831c908474779bb8a76daf55f782c","versionType":"git","status":"affected"},{"version":"80548b03991f58758a336424a90bf9f988e3b077","lessThan":"0b70716081c6462be9b2928ad736d0d527b09678","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["fs/afs/super.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"5.2","status":"affected"},{"version":"0","lessThan":"5.2","versionType":"semver","status":"unaffected"},{"version":"5.10.261","lessThanOrEqual":"5.10.*","versionType":"semver","status":"unaffected"},{"version":"5.15.212","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.178","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.97","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc2","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/0b70716081c6462be9b2928ad736d0d527b09678","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/23b3d457d8387bcb2a61063a9e520063ada9335f","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/67fb48c4a0874953212321cd5d57fdb4900dbc31","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/70b2842734d831c908474779bb8a76daf55f782c","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/867b3ea146a041023bfcd258e6db516b1bb28f19","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/d5b17474feed3c30991f07affa2473adbad95055","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/d648cc2069eb081707c061849046d909f57c78b1","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/ea19edf71721cd42f923e3c70f4ff995b422fe3b","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-74427","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:22:44.810","lastModified":"2026-08-15T06:22:44.810","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nafs: Fix netns teardown to cancel the preallocation charger\n\nFix the teardown of an afs network namespace to make sure it cancels the\nwork item that keeps the preallocated rxrpc call/conn/peer queue charged\nbefore incoming calls are disabled (i.e. listen 0).\n\nAlso, if net->live is false because the afs netns is being deleted, make\nafs_charge_preallocation() skip charging and make afs_rx_new_call() avoid\nrequeuing the charger.\n\n(This was found by AI review)."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["fs/afs/rxrpc.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"00e907127e6f86d0f9b122d9b4347a8aa09a8b61","lessThan":"63ccaf1bdf8be2330f47f9b5b233dd3fd04acbd9","versionType":"git","status":"affected"},{"version":"00e907127e6f86d0f9b122d9b4347a8aa09a8b61","lessThan":"f5096e18b6b7fbd1c2a1942e275a51bcfdfb2ad1","versionType":"git","status":"affected"},{"version":"00e907127e6f86d0f9b122d9b4347a8aa09a8b61","lessThan":"59e8b7652f6cbfb62d377ead0ad553c1b4e39a7a","versionType":"git","status":"affected"},{"version":"00e907127e6f86d0f9b122d9b4347a8aa09a8b61","lessThan":"85d5fb80fe4f0cc836b6df83f26de204fe102ff7","versionType":"git","status":"affected"},{"version":"00e907127e6f86d0f9b122d9b4347a8aa09a8b61","lessThan":"a33975ff2b6ea47b8f29956403374b1cdd057539","versionType":"git","status":"affected"},{"version":"00e907127e6f86d0f9b122d9b4347a8aa09a8b61","lessThan":"b83ecf80e28afb7b6595ba79932e77ca68a5a83d","versionType":"git","status":"affected"},{"version":"00e907127e6f86d0f9b122d9b4347a8aa09a8b61","lessThan":"eec89c5f8e1adc1de4824042ef75f62aed804153","versionType":"git","status":"affected"},{"version":"00e907127e6f86d0f9b122d9b4347a8aa09a8b61","lessThan":"47694fbc9d24ab6bf210f91e8efe06a10a478064","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["fs/afs/rxrpc.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"4.9","status":"affected"},{"version":"0","lessThan":"4.9","versionType":"semver","status":"unaffected"},{"version":"5.10.261","lessThanOrEqual":"5.10.*","versionType":"semver","status":"unaffected"},{"version":"5.15.212","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.178","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.97","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/47694fbc9d24ab6bf210f91e8efe06a10a478064","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/59e8b7652f6cbfb62d377ead0ad553c1b4e39a7a","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/63ccaf1bdf8be2330f47f9b5b233dd3fd04acbd9","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/85d5fb80fe4f0cc836b6df83f26de204fe102ff7","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/a33975ff2b6ea47b8f29956403374b1cdd057539","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/b83ecf80e28afb7b6595ba79932e77ca68a5a83d","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/eec89c5f8e1adc1de4824042ef75f62aed804153","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/f5096e18b6b7fbd1c2a1942e275a51bcfdfb2ad1","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-74428","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:22:44.923","lastModified":"2026-08-15T06:22:44.923","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nrxrpc: Fix double unlock in rxrpc_recvmsg()\n\nFix a double unlock in rxrpc_recvmsg() when dealing with OOB messages."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["net/rxrpc/recvmsg.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"5800b1cf3fd8ccab752a101865be1e76dac33142","lessThan":"8cd8cf3052fff9a4b86b25734f610e4af03786d3","versionType":"git","status":"affected"},{"version":"5800b1cf3fd8ccab752a101865be1e76dac33142","lessThan":"1297ae6aeebc3863cb437e42a1bc4cd6173e43d9","versionType":"git","status":"affected"},{"version":"5800b1cf3fd8ccab752a101865be1e76dac33142","lessThan":"a2f299b4d5510147fa8629a6aba2869bbcc88aea","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["net/rxrpc/recvmsg.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.16","status":"affected"},{"version":"0","lessThan":"6.16","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/1297ae6aeebc3863cb437e42a1bc4cd6173e43d9","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/8cd8cf3052fff9a4b86b25734f610e4af03786d3","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/a2f299b4d5510147fa8629a6aba2869bbcc88aea","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-74429","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:22:45.027","lastModified":"2026-08-15T06:22:45.027","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nrxrpc: Fix the reception of a reply packet before data transmission\n\nFix rxrpc_receiving_reply() to handle the reception of an apparent reply\nDATA packet before rxrpc has had a chance to send any request DATA packets\non a client call by checking to see if the call has been exposed yet by\nsending the first packet.\n\nWithout this, rxrpc_rotate_tx_window() might oops.\n\nAlso fix rxrpc_rotate_tx_window() to handle the Tx queue being empty by\nchanging the do...while loop into a while loop, just in case a call is\nabnormally terminated by an early reply before the last request packet is\ntransmitted."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["net/rxrpc/input.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"b341a0263b1b804d329f864c2dc24815364510ec","lessThan":"f9be514984471ff0003738b2e1efed12bc3433ff","versionType":"git","status":"affected"},{"version":"b341a0263b1b804d329f864c2dc24815364510ec","lessThan":"e220ae559e5a0fc33e41ec6a348ea50387cb8b0f","versionType":"git","status":"affected"},{"version":"b341a0263b1b804d329f864c2dc24815364510ec","lessThan":"a58e33405acd2584e730c1da72635f822ada6b49","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["net/rxrpc/input.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.14","status":"affected"},{"version":"0","lessThan":"6.14","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/a58e33405acd2584e730c1da72635f822ada6b49","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/e220ae559e5a0fc33e41ec6a348ea50387cb8b0f","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/f9be514984471ff0003738b2e1efed12bc3433ff","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-74430","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:22:45.120","lastModified":"2026-08-15T06:22:45.120","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nrxrpc: Fix ACKALL packet handling\n\nrxrpc_input_ackall() accepts ACKALL packets without checking whether the\ncall is in a state that can legitimately have outstanding transmit buffers.\nA forged ACKALL can therefore reach a new service call in\nRXRPC_CALL_SERVER_RECV_REQUEST before any reply packets have been queued.\n\nIn that state call->tx_top is zero and call->tx_queue is NULL, so\nrxrpc_rotate_tx_window() dereferences a NULL txqueue and triggers a\nnull-pointer dereference.\n\nFix the handling of ACKALL packets by the following means:\n\n (1) Add two new call states: RXRPC_CALL_CLIENT_PRE_SEND which indicates\n     that the client call is connected, but nothing has been transmitted as\n     yet; and RXRPC_CALL_CLIENT_AWAIT_ACK, which indicates that everything\n     has been transmitted at least once, but we're now waiting for the\n     stuff remaining in the Tx buffer to be ACK'd (retransmissions may\n     still happen).\n\n     The RXRPC_CALL_CLIENT_PRE_SEND state is set when the call is assigned\n     a channel and transitions to RXRPC_CALL_CLIENT_SEND_REQUEST when the\n     first packet is transmitted.\n\n     RXRPC_CALL_CLIENT_AWAIT_REPLY is then narrowed in scope to indicate\n     that all Tx packets have been ACK'd and we're now waiting for the\n     reply to be received.\n\n (2) As per Wyatt Feng's original patch[1], the ACKALL handler then checks\n     that the call state is one in which there might be stuff in the Tx\n     buffer to ACK, but now this includes AWAIT_ACK rather than\n     AWAIT_REPLY.  ACKALL packets are ignored if received in the wrong\n     state.\n\n     Note that unlike Wyatt Feng's patch, it's no longer necessary to check\n     to see if the Tx buffer exists as this the state set now covers this.\n\n (3) Make the ACKALL handler use call->tx_transmitted rather than\n     call->tx_top as the former is explicitly the highest packet seq number\n     transmitted, whereas the latter has a looser definition.\n\nThanks to Jeffrey Altman for a description of the history of the ACKALL\npacket[1]."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["net/rxrpc/ar-internal.h","net/rxrpc/call_event.c","net/rxrpc/call_object.c","net/rxrpc/conn_client.c","net/rxrpc/input.c","net/rxrpc/sendmsg.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"b341a0263b1b804d329f864c2dc24815364510ec","lessThan":"8db6a2c95e36938076b37466ce36774526a5c8c3","versionType":"git","status":"affected"},{"version":"b341a0263b1b804d329f864c2dc24815364510ec","lessThan":"523cb585672ae681b2d3b0d620aec5313774e2e2","versionType":"git","status":"affected"},{"version":"b341a0263b1b804d329f864c2dc24815364510ec","lessThan":"9b6ce594808580b2a19e6e1aa459ef56c0153ac1","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["net/rxrpc/ar-internal.h","net/rxrpc/call_event.c","net/rxrpc/call_object.c","net/rxrpc/conn_client.c","net/rxrpc/input.c","net/rxrpc/sendmsg.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.14","status":"affected"},{"version":"0","lessThan":"6.14","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/523cb585672ae681b2d3b0d620aec5313774e2e2","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/8db6a2c95e36938076b37466ce36774526a5c8c3","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/9b6ce594808580b2a19e6e1aa459ef56c0153ac1","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-74431","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:22:45.227","lastModified":"2026-08-15T06:22:45.227","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nrxrpc: Fix potential infinite loop in rxrpc_recvmsg()\n\nFix the wait in rxrpc_recvmsg() also take check the oob queue."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["net/rxrpc/recvmsg.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"5800b1cf3fd8ccab752a101865be1e76dac33142","lessThan":"0fc5b37faec26241d3cbee732e29ac35ad3184f8","versionType":"git","status":"affected"},{"version":"5800b1cf3fd8ccab752a101865be1e76dac33142","lessThan":"da371b003a4a44f44741275d5e8dc74181cbb017","versionType":"git","status":"affected"},{"version":"5800b1cf3fd8ccab752a101865be1e76dac33142","lessThan":"67a0332f442ef07713cd2d9c13d59db0f1c23648","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["net/rxrpc/recvmsg.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.16","status":"affected"},{"version":"0","lessThan":"6.16","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/0fc5b37faec26241d3cbee732e29ac35ad3184f8","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/67a0332f442ef07713cd2d9c13d59db0f1c23648","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/da371b003a4a44f44741275d5e8dc74181cbb017","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-74432","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:22:45.317","lastModified":"2026-08-15T06:22:45.317","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nrxrpc: Fix leak of released call in recvmsg(MSG_PEEK)\n\nFix rxrpc_recvmsg() to also drop the ref it holds on an already-released\ncall if MSG_PEEK is in force (the function holds a ref on the call\nirrespective of whether MSG_PEEK is specified or not)."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["net/rxrpc/recvmsg.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"7692bde890061797f3dece0148d7859e85c55778","lessThan":"86eff3140c9d4b52bba13d1cba266da933403e51","versionType":"git","status":"affected"},{"version":"839fe96c15209dc2255c064bb44b636efe04f032","lessThan":"e473cd3046a1aaec1e39af5df2042ce7c04d5e74","versionType":"git","status":"affected"},{"version":"962fb1f651c2cf2083e0c3ef53ba69e3b96d3fbc","lessThan":"2b69b61057eb0b3db9ad754ef0f1436b7af3a9f5","versionType":"git","status":"affected"},{"version":"962fb1f651c2cf2083e0c3ef53ba69e3b96d3fbc","lessThan":"04c7103dc0923cc6ac95b97aa66bab70da7ace84","versionType":"git","status":"affected"},{"version":"962fb1f651c2cf2083e0c3ef53ba69e3b96d3fbc","lessThan":"4bdb9e471f5b1ac9cbe4add5de7ff085a0ec303c","versionType":"git","status":"affected"},{"version":"6c75a97a32a5fa2060c3dd30207e63b6914b606d","versionType":"git","status":"affected"},{"version":"6.6.100","lessThan":"6.6.145","versionType":"semver","status":"affected"},{"version":"6.12.40","lessThan":"6.12.97","versionType":"semver","status":"affected"},{"version":"6.15.8","lessThan":"6.16","versionType":"semver","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["net/rxrpc/recvmsg.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.16","status":"affected"},{"version":"0","lessThan":"6.16","versionType":"semver","status":"unaffected"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.97","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/04c7103dc0923cc6ac95b97aa66bab70da7ace84","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/2b69b61057eb0b3db9ad754ef0f1436b7af3a9f5","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/4bdb9e471f5b1ac9cbe4add5de7ff085a0ec303c","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/86eff3140c9d4b52bba13d1cba266da933403e51","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/e473cd3046a1aaec1e39af5df2042ce7c04d5e74","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-74433","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:22:45.417","lastModified":"2026-08-15T06:22:45.417","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nrxrpc: Fix UAF in rxgk_issue_challenge()\n\nFix rxgk_issue_challenge() to free the page containing the challenge\ncontent after invoking the tracepoint as the whdr passed to the tracepoint\npoints into the page just freed."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["net/rxrpc/rxgk.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"9d1d2b59341f58126a69b51f9f5f8ccb9f12e54a","lessThan":"844b8525ce503405c462ad67f750bec648720397","versionType":"git","status":"affected"},{"version":"9d1d2b59341f58126a69b51f9f5f8ccb9f12e54a","lessThan":"83bb0ed050e2ad9453d8ef50e4d6e624eac6eed8","versionType":"git","status":"affected"},{"version":"9d1d2b59341f58126a69b51f9f5f8ccb9f12e54a","lessThan":"107a4cb0d47e735830f852d83970d5c81f8e1e08","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["net/rxrpc/rxgk.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.16","status":"affected"},{"version":"0","lessThan":"6.16","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/107a4cb0d47e735830f852d83970d5c81f8e1e08","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/83bb0ed050e2ad9453d8ef50e4d6e624eac6eed8","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/844b8525ce503405c462ad67f750bec648720397","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-74434","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:22:45.510","lastModified":"2026-08-15T06:22:45.510","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nrxrpc: Don't move a peeked OOB message onto the pending queue\n\nrxrpc_recvmsg_oob() takes a received oob message off recvmsg_oobq and,\nif a response is needed, moves it onto the pending_oobq tree. However,\nonly the unlink from recvmsg_oobq is guarded by MSG_PEEK; the move onto\npending_oobq always runs.\n\nAs a result, reading a challenge with MSG_PEEK leaves the skb on\nrecvmsg_oobq while also adding it to pending_oobq. Since struct\nsk_buff's rbnode shares storage with its next and prev pointers,\nrb_insert_color() overwrites the list linkage, and the skb, which holds\na single reference, becomes reachable from both queues at once.\n\nWhen the socket is closed both queues are drained in turn. While\ndraining recvmsg_oobq, __skb_unlink() follows the next and prev\npointers that rbnode has overwritten and writes to a bad address. Also,\nas the skb holds a single reference but is freed from each queue, both\nthe skb and the connection reference it holds are released twice. This\nleads to memory corruption and to a use-after-free caused by the\nconnection refcount underflow.\n\nMSG_PEEK does not consume the message from the queue, so only unlink it\nfrom recvmsg_oobq and then move it onto pending_oobq or free it when\nthe message is actually consumed."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["net/rxrpc/recvmsg.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"5800b1cf3fd8ccab752a101865be1e76dac33142","lessThan":"9ada3931beb37068fcb725b34b0398457009f343","versionType":"git","status":"affected"},{"version":"5800b1cf3fd8ccab752a101865be1e76dac33142","lessThan":"5f470cc883416fea6d3bce18ef96bf91dd49ffc3","versionType":"git","status":"affected"},{"version":"5800b1cf3fd8ccab752a101865be1e76dac33142","lessThan":"5801cff7d5d7b4e9d877dfb627b23eb63167f02c","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["net/rxrpc/recvmsg.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.16","status":"affected"},{"version":"0","lessThan":"6.16","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/5801cff7d5d7b4e9d877dfb627b23eb63167f02c","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/5f470cc883416fea6d3bce18ef96bf91dd49ffc3","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/9ada3931beb37068fcb725b34b0398457009f343","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-74435","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:22:45.607","lastModified":"2026-08-15T06:22:45.607","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nrxrpc: rxrpc_verify_data ensure rx_dec_buffer alloc\n\nrxrpc_recvmsg_data() calls rxrpc_verify_data() whenever the\nrxrpc_call.rx_dec_buffer is unallocated and assumes that upon\nsuccessful return that rx_dec_buffer must be allocated.\nHowever, rxrpc_verify_data() does not request an allocation if\nthe rxrpc_skb_priv.len is zero.\n\nIn addition, failure to allocate rx_dec_buffer will result in a\ncall to skb_copy_bits() with a NULL destination which can\ntrigger a NULL pointer dereference.\n\nTo prevent these issues rxrpc_verify_data() is modified to\nalways attempt to allocate the rxrpc_call.rx_dec_buffer if it\nis NULL.\n\nThis issue was identified with assistance of a private\nsashiko instance."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["net/rxrpc/recvmsg.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"a05bf6d9e621fa71e89ccebe3047ba45218d7b38","lessThan":"8bbede0afced346b24e4fbde0c68cf12980ba948","versionType":"git","status":"affected"},{"version":"b94a6ccbaf1104dd980150a65fdeb2f69d17d2f5","lessThan":"6563b4eb38c35d75892445bcf8aacdc29914821c","versionType":"git","status":"affected"},{"version":"46cb765e2e5ad52303ea157e10d370bb6b7acbbf","lessThan":"d3b642cf95d48234590cc91450d8705a9bf6b540","versionType":"git","status":"affected"},{"version":"d2bc90cf6c75cb96d2ce549be6c35efa3099d25b","lessThan":"a962bc8508592c4d51092edac68579bd8b18fe44","versionType":"git","status":"affected"},{"version":"d2bc90cf6c75cb96d2ce549be6c35efa3099d25b","lessThan":"16c8ae9735c5bd7e54dd7478d6348e0fc860842d","versionType":"git","status":"affected"},{"version":"c580087743712112778a06d65a4074053072d7bf","versionType":"git","status":"affected"},{"version":"6.6.143","lessThan":"6.6.145","versionType":"semver","status":"affected"},{"version":"6.12.93","lessThan":"6.12.97","versionType":"semver","status":"affected"},{"version":"6.18.35","lessThan":"6.18.40","versionType":"semver","status":"affected"},{"version":"7.0.11","lessThan":"7.1","versionType":"semver","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["net/rxrpc/recvmsg.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"7.1","status":"affected"},{"version":"0","lessThan":"7.1","versionType":"semver","status":"unaffected"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.97","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/16c8ae9735c5bd7e54dd7478d6348e0fc860842d","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/6563b4eb38c35d75892445bcf8aacdc29914821c","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/8bbede0afced346b24e4fbde0c68cf12980ba948","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/a962bc8508592c4d51092edac68579bd8b18fe44","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/d3b642cf95d48234590cc91450d8705a9bf6b540","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-74436","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:22:45.710","lastModified":"2026-08-15T06:22:45.710","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nrxrpc: serialize kernel accept preallocation with socket teardown\n\nrxrpc_kernel_charge_accept() reads rx->backlog without any\nsocket/backlog synchronization and passes that raw pointer into\nrxrpc_service_prealloc_one(). A concurrent rxrpc_discard_prealloc()\nsets rx->backlog = NULL and frees the backlog rings, so a kernel\npreallocation worker can keep using a freed struct rxrpc_backlog\nwhile updating *_backlog_head/tail and array slots.\n\nSerialize the state check and backlog lookup with the socket lock,\nand reject kernel preallocation once teardown has disabled\nlistening or discarded the service backlog."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["net/rxrpc/call_accept.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"00e907127e6f86d0f9b122d9b4347a8aa09a8b61","lessThan":"0337cdba0c477f176c0459bed012109453184573","versionType":"git","status":"affected"},{"version":"00e907127e6f86d0f9b122d9b4347a8aa09a8b61","lessThan":"dfa0b2bbc5e50119f89c6b5407faa5ed86dfa7c5","versionType":"git","status":"affected"},{"version":"00e907127e6f86d0f9b122d9b4347a8aa09a8b61","lessThan":"35a967ff8b24db09ee429c39c5b5e6571639997d","versionType":"git","status":"affected"},{"version":"00e907127e6f86d0f9b122d9b4347a8aa09a8b61","lessThan":"1741378a7a83dfd8e53a9196730df709b903cd33","versionType":"git","status":"affected"},{"version":"00e907127e6f86d0f9b122d9b4347a8aa09a8b61","lessThan":"dc175389b18c29a5303ee83169ec653adfae3e17","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["net/rxrpc/call_accept.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"4.9","status":"affected"},{"version":"0","lessThan":"4.9","versionType":"semver","status":"unaffected"},{"version":"6.6.148","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.101","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/0337cdba0c477f176c0459bed012109453184573","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/1741378a7a83dfd8e53a9196730df709b903cd33","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/35a967ff8b24db09ee429c39c5b5e6571639997d","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/dc175389b18c29a5303ee83169ec653adfae3e17","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/dfa0b2bbc5e50119f89c6b5407faa5ed86dfa7c5","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-74437","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:22:45.810","lastModified":"2026-08-15T06:22:45.810","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nmedia: uvcvideo: Fix deadlock if uvc_status_stop is called from async_ctrl.work\n\nIf a UVC camera has an asynchronous control, uvc_status_stop may be\ncalled from async_ctrl.work:\n\nuvc_ctrl_status_event_work()\n    uvc_ctrl_status_event()\n        uvc_ctrl_clear_handle()\n\t    uvc_pm_put()\n\t        uvc_status_put()\n\t\t    uvc_status_stop()\n\t\t        cancel_work_sync()\n\nThis will cause a deadlock, since cancel_work_sync will wait for\nuvc_ctrl_status_event_work to complete before returning.\n\nFix this by returning early from uvc_status_stop if we are currently in\nthe work function. flush_status now remains false until uvc_status_start\nis called again, ensuring that uvc_ctrl_status_event_work won't resubmit\nthe URB."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/media/usb/uvc/uvc_status.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"a32d9c41bdb86e09ce731aa5fd3add89ac2103a5","lessThan":"3659deaf7bf690510899a73906b772740d94342c","versionType":"git","status":"affected"},{"version":"a32d9c41bdb86e09ce731aa5fd3add89ac2103a5","lessThan":"7f6c5fe1633272c926361b73d83dfc6ae01b1504","versionType":"git","status":"affected"},{"version":"a32d9c41bdb86e09ce731aa5fd3add89ac2103a5","lessThan":"6d27f92c54ce28cfbd2a8a479a96d6f4a781b7d2","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/media/usb/uvc/uvc_status.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.16","status":"affected"},{"version":"0","lessThan":"6.16","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/3659deaf7bf690510899a73906b772740d94342c","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/6d27f92c54ce28cfbd2a8a479a96d6f4a781b7d2","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/7f6c5fe1633272c926361b73d83dfc6ae01b1504","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-74438","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:22:45.903","lastModified":"2026-08-15T06:22:45.903","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\ncrypto: sun4i-ss - Remove insecure and unused rng_alg\n\nRemove sun4i_ss_rng, as it is insecure and unused:\n\n- It has multiple vulnerabilities.  sun4i_ss_prng_seed() is missing\n  locking and has a buffer overflow.  sun4i_ss_prng_generate() fails to\n  fill the entire buffer with cryptographic random bytes, because it\n  rounds the destination length down and also doesn't actually wait for\n  the hardware to be ready before pulling bytes from it.\n\n- No user of this code is known.  It's usable only theoretically via the\n  \"rng\" algorithm type of AF_ALG.  But userspace actually just uses the\n  actual Linux RNG (/dev/random etc) instead.  And rng_algs don't\n  contribute entropy to the actual Linux RNG either.  (This may have\n  been confused with hwrng, which does contribute entropy.)\n\nThe sun4i_ss_prng_seed() buffer overflow was reported by Tianchu Chen\nand discovered by Atuin - Automated Vulnerability Discovery Engine\n\nThere's no point in fixing all these vulnerabilities individually when\nthis is unused code, so let's just remove it."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["arch/arm/configs/sunxi_defconfig","drivers/crypto/allwinner/Kconfig","drivers/crypto/allwinner/sun4i-ss/Makefile","drivers/crypto/allwinner/sun4i-ss/sun4i-ss-core.c","drivers/crypto/allwinner/sun4i-ss/sun4i-ss-prng.c","drivers/crypto/allwinner/sun4i-ss/sun4i-ss.h"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"b8ae5c7387ad075ee61e8c8774ce2bca46bc9236","lessThan":"2eafecaba1b46bb9774eaf3556619fd5b6a17c1c","versionType":"git","status":"affected"},{"version":"b8ae5c7387ad075ee61e8c8774ce2bca46bc9236","lessThan":"ee2458f8188732aa53a5d42f56e87bfad288b44e","versionType":"git","status":"affected"},{"version":"b8ae5c7387ad075ee61e8c8774ce2bca46bc9236","lessThan":"306ded31bfa00a69d25823a60d7c797170bfb4f8","versionType":"git","status":"affected"},{"version":"b8ae5c7387ad075ee61e8c8774ce2bca46bc9236","lessThan":"e4b7b9819811c4c51064c3d3d3c02f0be7491707","versionType":"git","status":"affected"},{"version":"b8ae5c7387ad075ee61e8c8774ce2bca46bc9236","lessThan":"c401492e01c7bfd38cf14c94d85c7efafe7d1a25","versionType":"git","status":"affected"},{"version":"b8ae5c7387ad075ee61e8c8774ce2bca46bc9236","lessThan":"9c8086d9511189c34dfa3f9e3a03f2bee12f56a5","versionType":"git","status":"affected"},{"version":"b8ae5c7387ad075ee61e8c8774ce2bca46bc9236","lessThan":"b2c41fa9dd8fc740c489e060b199165771f268d1","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["arch/arm/configs/sunxi_defconfig","drivers/crypto/allwinner/Kconfig","drivers/crypto/allwinner/sun4i-ss/Makefile","drivers/crypto/allwinner/sun4i-ss/sun4i-ss-core.c","drivers/crypto/allwinner/sun4i-ss/sun4i-ss-prng.c","drivers/crypto/allwinner/sun4i-ss/sun4i-ss.h"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"4.14","status":"affected"},{"version":"0","lessThan":"4.14","versionType":"semver","status":"unaffected"},{"version":"5.15.212","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.178","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.97","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/2eafecaba1b46bb9774eaf3556619fd5b6a17c1c","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/306ded31bfa00a69d25823a60d7c797170bfb4f8","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/9c8086d9511189c34dfa3f9e3a03f2bee12f56a5","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/b2c41fa9dd8fc740c489e060b199165771f268d1","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/c401492e01c7bfd38cf14c94d85c7efafe7d1a25","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/e4b7b9819811c4c51064c3d3d3c02f0be7491707","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/ee2458f8188732aa53a5d42f56e87bfad288b44e","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-74439","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-15T06:22:46.023","lastModified":"2026-08-15T06:22:46.023","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\niommu/vt-d: Clear Present bit before tearing down scalable-mode context entry\n\ndevice_pasid_table_teardown() zeroes the 128-bit scalable-mode context\nentry with context_clear_entry() while the Present bit is still set. This\ncreates a window where the hardware can fetch a torn entry, with some\nfields already zeroed while Present is still set, leading to unpredictable\nbehavior or spurious faults. The context-cache invalidation is issued only\nafter the entry has been zeroed, and intel_pasid_free_table() then frees\nthe PASID directory pages, so the IOMMU can keep walking a stale Present=1\nentry that points at freed memory.\n\nWhile x86 provides strong write ordering, the compiler may reorder the two\n64-bit writes to the entry, and the hardware fetch is not guaranteed to be\natomic with respect to multiple CPU writes.\n\nCommit c1e4f1dccbe9d (\"iommu/vt-d: Clear Present bit before tearing down\ncontext entry\") fixed this exact pattern in domain_context_clear_one() and\nthe copied-context path, but device_pasid_table_teardown() was not\nconverted.\n\nAlign it with the \"Guidance to Software for Invalidations\" in the VT-d\nspec, Section 6.5.3.3, using the same ownership handshake as the sibling\nfix: clear only the Present bit, flush it to the IOMMU, perform the\ncontext-cache invalidation, and only then zero the rest of the entry."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/iommu/intel/pasid.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"81e921fd321614c2ad8ac333b041aae1da7a1c6d","lessThan":"e9e83bcfe37dc719182500dd823c03ab57d934f0","versionType":"git","status":"affected"},{"version":"81e921fd321614c2ad8ac333b041aae1da7a1c6d","lessThan":"588718101e8449605f1c7e858fecb7cfa701cdab","versionType":"git","status":"affected"},{"version":"81e921fd321614c2ad8ac333b041aae1da7a1c6d","lessThan":"7fd4077dc92b91b1b844333c0a06bb9e286db10a","versionType":"git","status":"affected"},{"version":"81e921fd321614c2ad8ac333b041aae1da7a1c6d","lessThan":"f46452c3df7a8d8a5addc0926e76ef19ea7da0a0","versionType":"git","status":"affected"},{"version":"333fe86968482ca701c609af590003bcea450e8f","versionType":"git","status":"affected"},{"version":"6.8.2","lessThan":"6.9","versionType":"semver","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/iommu/intel/pasid.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.9","status":"affected"},{"version":"0","lessThan":"6.9","versionType":"semver","status":"unaffected"},{"version":"6.12.97","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/588718101e8449605f1c7e858fecb7cfa701cdab","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/7fd4077dc92b91b1b844333c0a06bb9e286db10a","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/e9e83bcfe37dc719182500dd823c03ab57d934f0","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/f46452c3df7a8d8a5addc0926e76ef19ea7da0a0","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}}]}