<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
<channel>
  <title>CVE Daily – Linux Kernel (High+Critical)</title>
  <link>https://cvedaily.com/pages/tags/linux.html</link>
  <atom:link href="https://cvedaily.com/feed-tags/linux-severe.xml" rel="self" type="application/rss+xml"/>
  <description>CVE Daily – Linux Kernel (High+Critical)</description>
  <language>en</language>
  <lastBuildDate>Wed, 03 Jun 2026 21:26:28 +0000</lastBuildDate>
  <item>
    <title>[High] CVE-2026-40290 – OP-TEE is a Trusted Execution Environment (TEE) designed as companion to a non-s...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-40290</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-40290</guid>
    <pubDate>Wed, 03 Jun 2026 18:16:23 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-40290</strong></p>
  <p>OP-TEE is a Trusted Execution Environment (TEE) designed as companion to a non-secure Linux kernel running on Arm; Cortex-A cores using the TrustZone technology. Starting in version 3.16.0 and prior to 4.11.0, a user-after-free (UAF) race condition exists in the shared memory teardown logic of FF-A  within OP-TEE SPMC/SP flows. This only applies when OP-TEE is configured as an SPMC for S-EL0 SPs,…</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-416</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-40290">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-8036 – Improper input validation in NI-PAL may allow a local authenticated user to acce...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-8036</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-8036</guid>
    <pubDate>Tue, 02 Jun 2026 20:16:41 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-8036</strong></p>
  <p>Improper input validation in NI-PAL may allow a local authenticated user to access arbitrary system memory, potentially leading to privilege escalation. This vulnerability affects NI-PAL 26.3.0 and prior versions on Windows and Linux.</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> CWE-1285</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-8036">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-8035 – Improper input validation in the NI-PAL kernel driver may allow a local authenti...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-8035</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-8035</guid>
    <pubDate>Tue, 02 Jun 2026 20:16:41 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-8035</strong></p>
  <p>Improper input validation in the NI-PAL kernel driver may allow a local authenticated user to cause a denial of service by triggering a crash due to a NULL pointer dereference. This vulnerability affects NI-PAL 26.3.0 and prior versions on Windows and Linux.</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> CWE-476</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-8035">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-46243 – In the Linux kernel, the following vulnerability has been resolved:

smb: client...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-46243</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-46243</guid>
    <pubDate>Mon, 01 Jun 2026 17:17:34 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-46243</strong></p>
  <p>In the Linux kernel, the following vulnerability has been resolved:  smb: client: reject userspace cifs.spnego descriptions  cifs.spnego key descriptions contain authority-bearing fields such as pid, uid, creduid, and upcall_target that cifs.upcall treats as kernel-originating inputs. However, userspace can also create keys of this type through request_key(2) or add_key(2), allowing those fields…</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-46243">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-0826 – In certain scenarios when the admin has enabled Interactive Connectivity Establi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-0826</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-0826</guid>
    <pubDate>Mon, 01 Jun 2026 15:16:29 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-0826</strong></p>
  <p>In certain scenarios when the admin has enabled Interactive Connectivity Establishment (ICE), a buffer overflow could enable                remote code execution on Poly Voice products on the Linux platform.</p>
  <p><strong>CVSS:</strong> 9.2 · <strong>CWE:</strong> CWE-121</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-0826">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-10056 – CORS misconfiguration in the REST API of Network Optix Nx Witness VMS before ver...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-10056</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-10056</guid>
    <pubDate>Fri, 29 May 2026 09:16:17 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-10056</strong></p>
  <p>CORS misconfiguration in the REST API of Network Optix Nx Witness VMS before version 6.1.2, when running in the default Standard security mode, on Linux and Windows allows an unauthenticated remote attacker to steal the session token of an authenticated user and perform Administrator Account Takeover via a malicious cross-origin web page visited by the victim. The High security mode is not affect…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-942</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-10056">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-9988 – Use after free in WebRTC in Google Chrome on Linux prior to 148.0.7778.216 allow...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-9988</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-9988</guid>
    <pubDate>Thu, 28 May 2026 23:16:57 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-9988</strong></p>
  <p>Use after free in WebRTC in Google Chrome on Linux prior to 148.0.7778.216 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)</p>
  <p><strong>CVSS:</strong> 8.3 · <strong>CWE:</strong> CWE-416</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-9988">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-47333 – Ubuntu Linux 6.8, 6.17 and 7.0 contain AppArmor SAUCE patches which can potentia...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-47333</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-47333</guid>
    <pubDate>Thu, 28 May 2026 19:16:42 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-47333</strong></p>
  <p>Ubuntu Linux 6.8, 6.17 and 7.0 contain AppArmor SAUCE patches which can potentially incorrectly compute the size of an internal buffer, leading to a heap memory out-of-bounds read in notification handling code. The bug can be triggered by an unprivileged local user and can result in invalid data being processed by the AppArmor DFA policy engine.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-125</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-47333">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-47331 – Ubuntu Linux 6.8 contains AppArmor SAUCE patches which fail to acquire a lock wh...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-47331</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-47331</guid>
    <pubDate>Thu, 28 May 2026 19:16:41 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-47331</strong></p>
  <p>Ubuntu Linux 6.8 contains AppArmor SAUCE patches which fail to acquire a lock when modifying a linked list. An unprivileged local user could trigger the race condition that can lead to a use-after-free (UAF) and, theoretically, arbitrary code execution.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-416</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-47331">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-44543 – Local Path Provisioner provides a way for the Kubernetes users to utilize the lo...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-44543</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-44543</guid>
    <pubDate>Thu, 28 May 2026 17:16:30 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-44543</strong></p>
  <p>Local Path Provisioner provides a way for the Kubernetes users to utilize the local storage in each node. Prior to 0.0.36, a malicious user with permission to edit the local-path-config ConfigMap in the local-path-storage namespace can manipulate the helperPod.yaml template used by rancher/local-path-provisioner. The helperPod.yaml template is loaded by the provisioner and used to create HelperPo…</p>
  <p><strong>CVSS:</strong> 8.7 · <strong>CWE:</strong> CWE-269</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-44543">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-46240 – In the Linux kernel, the following vulnerability has been resolved:

media: iris...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-46240</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-46240</guid>
    <pubDate>Thu, 28 May 2026 10:16:39 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-46240</strong></p>
  <p>In the Linux kernel, the following vulnerability has been resolved:  media: iris: Fix use-after-free in iris_release_internal_buffers()  The recent change in commit 1dabf00ee206 ("media: iris: gen1: Destroy internal buffers after FW releases") introduced a regression where session_release_buf() may free the buffer. The caller, iris_release_internal_buffers(), continued to access `buffer` after th…</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-46240">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-46238 – In the Linux kernel, the following vulnerability has been resolved:

batman-adv:...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-46238</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-46238</guid>
    <pubDate>Thu, 28 May 2026 10:16:39 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-46238</strong></p>
  <p>In the Linux kernel, the following vulnerability has been resolved:  batman-adv: stop caching unowned originator pointers in BAT IV  BAT IV keeps the last-hop neighbor address in each neigh_node, but some paths also cache an originator pointer derived from a temporary lookup. That pointer is not owned by the neigh_node and may no longer refer to a live originator entry after purge handling runs.…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-46238">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-46237 – In the Linux kernel, the following vulnerability has been resolved:

drm/amdgpu/...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-46237</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-46237</guid>
    <pubDate>Thu, 28 May 2026 10:16:39 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-46237</strong></p>
  <p>In the Linux kernel, the following vulnerability has been resolved:  drm/amdgpu/vcn3: Avoid overflow on msg bound check  As pointed out by SDL, the previous condition may be vulnerable to overflow.  (cherry picked from commit db00257ac9e4a51eb2515aaea161a019f7125e10)</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-46237">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-46232 – In the Linux kernel, the following vulnerability has been resolved:

HID: playst...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-46232</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-46232</guid>
    <pubDate>Thu, 28 May 2026 10:16:38 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-46232</strong></p>
  <p>In the Linux kernel, the following vulnerability has been resolved:  HID: playstation: Clamp num_touch_reports  A device would never lie about the number of touch reports would it?  If it does the loop in dualshock4_parse_report will read off the end of the touch_reports array, up to about 2 KiB for the maximum number of 256 loop iteraions. The data that is read is emitted via evdev if the DS4_TO…</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-46232">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-46230 – In the Linux kernel, the following vulnerability has been resolved:

drm/amdgpu/...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-46230</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-46230</guid>
    <pubDate>Thu, 28 May 2026 10:16:38 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-46230</strong></p>
  <p>In the Linux kernel, the following vulnerability has been resolved:  drm/amdgpu/vcn3: Prevent OOB reads when parsing dec msg  Check bounds against the end of the BO whenever we access the msg.</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-46230">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-46227 – In the Linux kernel, the following vulnerability has been resolved:

sctp: reval...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-46227</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-46227</guid>
    <pubDate>Thu, 28 May 2026 10:16:38 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-46227</strong></p>
  <p>In the Linux kernel, the following vulnerability has been resolved:  sctp: revalidate list cursor after sctp_sendmsg_to_asoc() in SCTP_SENDALL  The SCTP_SENDALL path in sctp_sendmsg() iterates ep->asocs with list_for_each_entry_safe(), which caches the next entry in @tmp before the loop body runs.  The body calls sctp_sendmsg_to_asoc(), which may drop the socket lock inside sctp_wait_for_sndbuf()…</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-46227">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-46218 – In the Linux kernel, the following vulnerability has been resolved:

drm/amdgpu:...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-46218</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-46218</guid>
    <pubDate>Thu, 28 May 2026 10:16:37 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-46218</strong></p>
  <p>In the Linux kernel, the following vulnerability has been resolved:  drm/amdgpu: Add bounds checking to ib_{get,set}_value  The uvd/vce/vcn code accesses the IB at predefined offsets without checking that the IB is large enough. Check the bounds here. The caller is responsible for making sure it can handle arbitrary return values.  Also make the idx a uint32_t to prevent overflows causing the con…</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-46218">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-46215 – In the Linux kernel, the following vulnerability has been resolved:

drm: Set ol...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-46215</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-46215</guid>
    <pubDate>Thu, 28 May 2026 10:16:37 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-46215</strong></p>
  <p>In the Linux kernel, the following vulnerability has been resolved:  drm: Set old handle to NULL before prime swap in change_handle  There was a potential race condition in change_handle. The ioctl briefly had a single object with two idr entries; a concurrent gem_close could delete the object and remove one of the handles while leaving the other one dangling, which could subsequently be derefere…</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-46215">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-46212 – In the Linux kernel, the following vulnerability has been resolved:

batman-adv:...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-46212</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-46212</guid>
    <pubDate>Thu, 28 May 2026 10:16:36 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-46212</strong></p>
  <p>In the Linux kernel, the following vulnerability has been resolved:  batman-adv: bla: prevent use-after-free when deleting claims  When batadv_bla_del_backbone_claims() removes all claims for a backbone, it does this by dropping the link entry in the hash list. This list entry itself was one of the references which need to be dropped at the same time via batadv_claim_put().  But the batadv_claim_…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-46212">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-46210 – In the Linux kernel, the following vulnerability has been resolved:

media: iris...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-46210</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-46210</guid>
    <pubDate>Thu, 28 May 2026 10:16:36 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-46210</strong></p>
  <p>In the Linux kernel, the following vulnerability has been resolved:  media: iris: fix use-after-free of fmt_src during MBPF check  During concurrency testing, multiple instances can run in parallel, and each instance uses its own inst->lock while the core->lock protects the list of active instances. The race happens because these locks cover different scopes, inst->lock protects only the internal…</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-46210">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-46209 – In the Linux kernel, the following vulnerability has been resolved:

drm/gem: Fi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-46209</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-46209</guid>
    <pubDate>Thu, 28 May 2026 10:16:36 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-46209</strong></p>
  <p>In the Linux kernel, the following vulnerability has been resolved:  drm/gem: Fix inconsistent plane dimension calculation in drm_gem_fb_init_with_funcs()  drm_gem_fb_init_with_funcs() computes sub-sampled plane dimensions using plain integer division:    unsigned int width  = mode_cmd->width  / (i ? info->hsub : 1);   unsigned int height = mode_cmd->height / (i ? info->vsub : 1);  However, the i…</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-46209">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-46208 – In the Linux kernel, the following vulnerability has been resolved:

batman-adv:...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-46208</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-46208</guid>
    <pubDate>Thu, 28 May 2026 10:16:36 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-46208</strong></p>
  <p>In the Linux kernel, the following vulnerability has been resolved:  batman-adv: stop tp_meter sessions during mesh teardown  TP meter sessions remain linked on bat_priv->tp_list after the netlink request has already finished. When the mesh interface is removed, batadv_mesh_free() currently tears down the mesh without first draining these sessions.  A running sender thread or a late incoming tp_m…</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-46208">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-46206 – In the Linux kernel, the following vulnerability has been resolved:

batman-adv:...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-46206</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-46206</guid>
    <pubDate>Thu, 28 May 2026 10:16:36 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-46206</strong></p>
  <p>In the Linux kernel, the following vulnerability has been resolved:  batman-adv: reject new tp_meter sessions during teardown  Prevent tp_meter from starting new sender or receiver sessions after mesh_state has left BATADV_MESH_ACTIVE.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-46206">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-46205 – In the Linux kernel, the following vulnerability has been resolved:

staging: me...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-46205</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-46205</guid>
    <pubDate>Thu, 28 May 2026 10:16:36 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-46205</strong></p>
  <p>In the Linux kernel, the following vulnerability has been resolved:  staging: media: atomisp: Disallow all private IOCTLs  Disallow all private IOCTLs. These aren't quite as safe as one could assume of IOCTL handlers; disable them for now. Instead of removing the code, return in the beginning of the function if cmd is non-zero in order to keep static checkers happy.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-46205">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-46204 – In the Linux kernel, the following vulnerability has been resolved:

drm/amdgpu/...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-46204</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-46204</guid>
    <pubDate>Thu, 28 May 2026 10:16:36 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-46204</strong></p>
  <p>In the Linux kernel, the following vulnerability has been resolved:  drm/amdgpu/vcn4: Prevent OOB reads when parsing IB  Rewrite the IB parsing to use amdgpu_ib_get_value() which handles the bounds checks.</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-46204">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-46201 – In the Linux kernel, the following vulnerability has been resolved:

drm/xe: Fix...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-46201</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-46201</guid>
    <pubDate>Thu, 28 May 2026 10:16:35 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-46201</strong></p>
  <p>In the Linux kernel, the following vulnerability has been resolved:  drm/xe: Fix dma-buf attachment leak in xe_gem_prime_import()  When xe_dma_buf_init_obj() fails, the attachment from dma_buf_dynamic_attach() is not detached. Add dma_buf_detach() before returning the error. Note: we cannot use goto out_err here because xe_dma_buf_init_obj() already frees bo on failure, and out_err would double-f…</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-46201">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-46199 – In the Linux kernel, the following vulnerability has been resolved:

drm/amdgpu/...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-46199</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-46199</guid>
    <pubDate>Thu, 28 May 2026 10:16:35 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-46199</strong></p>
  <p>In the Linux kernel, the following vulnerability has been resolved:  drm/amdgpu/vcn4: Prevent OOB reads when parsing dec msg  Check bounds against the end of the BO whenever we access the msg.</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-46199">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-46198 – In the Linux kernel, the following vulnerability has been resolved:

batman-adv:...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-46198</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-46198</guid>
    <pubDate>Thu, 28 May 2026 10:16:35 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-46198</strong></p>
  <p>In the Linux kernel, the following vulnerability has been resolved:  batman-adv: fix integer overflow on buff_pos  Fixing an integer overflow present in batadv_iv_ogm_send_to_if. The size check is done using the int type in batadv_iv_ogm_aggr_packet whereas the buff_pos variable uses the s16 type. This could lead to an out-of-bound read.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-46198">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-46197 – In the Linux kernel, the following vulnerability has been resolved:

drm/amdkfd:...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-46197</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-46197</guid>
    <pubDate>Thu, 28 May 2026 10:16:35 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-46197</strong></p>
  <p>In the Linux kernel, the following vulnerability has been resolved:  drm/amdkfd: validate SVM ioctl nattr against buffer size  Validate nattr field against the buffer size, preventing out-of-bounds buffer access via user-controlled attribute count.  (cherry picked from commit 5eca8bfdfa456c3304ca77523718fe24254c172f)</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-46197">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-46195 – In the Linux kernel, the following vulnerability has been resolved:

smb: client...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-46195</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-46195</guid>
    <pubDate>Thu, 28 May 2026 10:16:35 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-46195</strong></p>
  <p>In the Linux kernel, the following vulnerability has been resolved:  smb: client: validate dacloffset before building DACL pointers  parse_sec_desc(), build_sec_desc(), and the chown path in id_mode_to_cifs_acl() all add the server-supplied dacloffset to pntsd before proving a DACL header fits inside the returned security descriptor.  On 32-bit builds a malicious server can return dacloffset near…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-46195">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-46190 – In the Linux kernel, the following vulnerability has been resolved:

mtd: spi-no...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-46190</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-46190</guid>
    <pubDate>Thu, 28 May 2026 10:16:34 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-46190</strong></p>
  <p>In the Linux kernel, the following vulnerability has been resolved:  mtd: spi-nor: debugfs: fix out-of-bounds read in spi_nor_params_show()  Sashiko noticed an out-of-bounds read [1].  In spi_nor_params_show(), the snor_f_names array is passed to spi_nor_print_flags() using sizeof(snor_f_names).  Since snor_f_names is an array of pointers, sizeof() returns the total number of bytes occupied by th…</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-46190">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-46185 – In the Linux kernel, the following vulnerability has been resolved:

smb/client:...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-46185</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-46185</guid>
    <pubDate>Thu, 28 May 2026 10:16:34 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-46185</strong></p>
  <p>In the Linux kernel, the following vulnerability has been resolved:  smb/client: fix out-of-bounds read in symlink_data()  Since smb2_check_message() returns success without length validation for the symlink error response, in symlink_data() it is possible for iov->iov_len to be smaller than sizeof(struct smb2_err_rsp). If the buffer only contains the base SMB2 header (64 bytes), accessing err->E…</p>
  <p><strong>CVSS:</strong> 9.1 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-46185">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-46181 – In the Linux kernel, the following vulnerability has been resolved:

RDMA/mlx4: ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-46181</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-46181</guid>
    <pubDate>Thu, 28 May 2026 10:16:33 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-46181</strong></p>
  <p>In the Linux kernel, the following vulnerability has been resolved:  RDMA/mlx4: Fix mis-use of RCU in mlx4_srq_event()  Sashiko points out the radix_tree itself is RCU safe, but nothing ever frees the mlx4_srq struct with RCU, and it isn't even accessed within the RCU critical section. It also will crash if an event is delivered before the srq object is finished initializing.  Use the spinlock si…</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-46181">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-46178 – In the Linux kernel, the following vulnerability has been resolved:

RDMA/mlx4: ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-46178</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-46178</guid>
    <pubDate>Thu, 28 May 2026 10:16:33 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-46178</strong></p>
  <p>In the Linux kernel, the following vulnerability has been resolved:  RDMA/mlx4: Fix resource leak on error in mlx4_ib_create_srq()  Sashiko points out that mlx4_srq_alloc() was not undone during error unwind, add the missing call to mlx4_srq_free().</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-46178">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-46177 – In the Linux kernel, the following vulnerability has been resolved:

ipmi: Add l...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-46177</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-46177</guid>
    <pubDate>Thu, 28 May 2026 10:16:33 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-46177</strong></p>
  <p>In the Linux kernel, the following vulnerability has been resolved:  ipmi: Add limits to event and receive message requests  The driver would just fetch events and receive messages until the BMC said it was done.  To avoid issues with BMCs that never say they are done, add a limit of 10 fetches at a time.  In addition, an si interface has an attn state it can return from the hardware which is sup…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-46177">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-46176 – In the Linux kernel, the following vulnerability has been resolved:

RDMA/mlx5: ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-46176</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-46176</guid>
    <pubDate>Thu, 28 May 2026 10:16:33 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-46176</strong></p>
  <p>In the Linux kernel, the following vulnerability has been resolved:  RDMA/mlx5: Fix error path fall-through in mlx5_ib_dev_res_srq_init()  mlx5_ib_dev_res_srq_init() allocates two SRQs, s0 and s1. When ib_create_srq() fails for s1, the error branch destroys s0 but falls through and unconditionally assigns the freed s0 and the ERR_PTR s1 to devr->s0 and devr->s1.  This leads to several problems: t…</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-46176">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-46175 – In the Linux kernel, the following vulnerability has been resolved:

f2fs: fix f...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-46175</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-46175</guid>
    <pubDate>Thu, 28 May 2026 10:16:33 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-46175</strong></p>
  <p>In the Linux kernel, the following vulnerability has been resolved:  f2fs: fix fsck inconsistency caused by FGGC of node block  During FGGC node block migration, fsck may incorrectly treat the migrated node block as fsync-written data.  The reproduction scenario: root@vm:/mnt/f2fs# seq 1 2048 | xargs -n 1 ./test_sync // write inline inode and sync root@vm:/mnt/f2fs# rm -f 1 root@vm:/mnt/f2fs# syn…</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-46175">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-46174 – In the Linux kernel, the following vulnerability has been resolved:

x86/CPU/AMD...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-46174</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-46174</guid>
    <pubDate>Thu, 28 May 2026 10:16:33 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-46174</strong></p>
  <p>In the Linux kernel, the following vulnerability has been resolved:  x86/CPU/AMD: Prevent improper isolation of shared resources in Zen2's op cache  Make sure resources are not improperly shared in the op cache and cause instruction corruption this way.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-46174">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-46173 – In the Linux kernel, the following vulnerability has been resolved:

exit: preve...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-46173</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-46173</guid>
    <pubDate>Thu, 28 May 2026 10:16:32 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-46173</strong></p>
  <p>In the Linux kernel, the following vulnerability has been resolved:  exit: prevent preemption of oopsing TASK_DEAD task  When an already-exiting task oopses, make_task_dead() currently calls do_task_dead() with preemption enabled.  That is forbidden: do_task_dead() calls __schedule(), which has a comment saying "WARNING: must be called with preemption disabled!".  If an oopsing task is preempted…</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-46173">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-46166 – In the Linux kernel, the following vulnerability has been resolved:

wifi: mac80...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-46166</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-46166</guid>
    <pubDate>Thu, 28 May 2026 10:16:32 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-46166</strong></p>
  <p>In the Linux kernel, the following vulnerability has been resolved:  wifi: mac80211: use safe list iteration in radar detect work  The call to ieee80211_dfs_cac_cancel can cause the iterated chanctx to be freed and removed from the list. Guard against this to avoid a slab-use-after-free error.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-46166">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-46164 – In the Linux kernel, the following vulnerability has been resolved:

btrfs: fix ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-46164</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-46164</guid>
    <pubDate>Thu, 28 May 2026 10:16:32 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-46164</strong></p>
  <p>In the Linux kernel, the following vulnerability has been resolved:  btrfs: fix double free in create_space_info_sub_group() error path  When kobject_init_and_add() fails, the call chain is:  create_space_info_sub_group() -> btrfs_sysfs_add_space_info_type() -> kobject_init_and_add() -> failure -> kobject_put(&sub_group->kobj) -> space_info_release() -> kfree(sub_group)  Then control returns to c…</p>
  <p><strong>CVSS:</strong> 7.0 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-46164">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-46157 – In the Linux kernel, the following vulnerability has been resolved:

ALSA: pcm: ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-46157</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-46157</guid>
    <pubDate>Thu, 28 May 2026 10:16:31 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-46157</strong></p>
  <p>In the Linux kernel, the following vulnerability has been resolved:  ALSA: pcm: oss: Fix data race at accessing runtime.oss.trigger  Currently the runtime.oss.trigger field may be accessed concurrently without protection, which may lead to the data race.  And, in this case, it may lead to more severe problem because it's a bit field; as writing the data, it may overwrite other bit fields as well,…</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-46157">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-46155 – In the Linux kernel, the following vulnerability has been resolved:

smb/client:...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-46155</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-46155</guid>
    <pubDate>Thu, 28 May 2026 10:16:31 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-46155</strong></p>
  <p>In the Linux kernel, the following vulnerability has been resolved:  smb/client: fix out-of-bounds read in smb2_compound_op()  If a server sends a truncated response but a large OutputBufferLength, and terminates the EA list early, check_wsl_eas() returns success without validating that the entire OutputBufferLength fits within iov_len.  Then smb2_compound_op() does:     memcpy(idata->wsl.eas, da…</p>
  <p><strong>CVSS:</strong> 9.1 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-46155">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-46154 – In the Linux kernel, the following vulnerability has been resolved:

sched_ext: ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-46154</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-46154</guid>
    <pubDate>Thu, 28 May 2026 10:16:31 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-46154</strong></p>
  <p>In the Linux kernel, the following vulnerability has been resolved:  sched_ext: Read scx_root under scx_cgroup_ops_rwsem in cgroup setters  scx_group_set_{weight,idle,bandwidth}() cache scx_root before acquiring scx_cgroup_ops_rwsem, so the pointer can be stale by the time the op runs. If the loaded scheduler is disabled and freed (via RCU work) and another is enabled between the naked load and t…</p>
  <p><strong>CVSS:</strong> 7.0 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-46154">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-46152 – In the Linux kernel, the following vulnerability has been resolved:

wifi: mac80...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-46152</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-46152</guid>
    <pubDate>Thu, 28 May 2026 10:16:30 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-46152</strong></p>
  <p>In the Linux kernel, the following vulnerability has been resolved:  wifi: mac80211: drop stray 'static' from fast-RX rx_result  ieee80211_invoke_fast_rx() is documented as safe for parallel RX, but its per-invocation rx_result is declared static. Concurrent callers then share one instance and can overwrite each other's result between ieee80211_rx_mesh_data() and the switch on res.  That can make…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-46152">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-46150 – In the Linux kernel, the following vulnerability has been resolved:

fanotify: f...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-46150</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-46150</guid>
    <pubDate>Thu, 28 May 2026 10:16:30 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-46150</strong></p>
  <p>In the Linux kernel, the following vulnerability has been resolved:  fanotify: fix false positive on permission events  fsnotify_get_mark_safe() may return false for a mark on an unrelated group, which results in bypassing the permission check.  Fix by skipping over detached marks that are not in the current group.</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-46150">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-46149 – In the Linux kernel, the following vulnerability has been resolved:

scsi: targe...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-46149</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-46149</guid>
    <pubDate>Thu, 28 May 2026 10:16:30 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-46149</strong></p>
  <p>In the Linux kernel, the following vulnerability has been resolved:  scsi: target: configfs: Bound snprintf() return in tg_pt_gp_members_show()  target_tg_pt_gp_members_show() formats LUN paths with snprintf() into a 256-byte stack buffer, then will memcpy() cur_len bytes from that buffer.  snprintf() returns the length the output would have had, which can exceed the buffer size when the fabric W…</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-46149">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-46145 – In the Linux kernel, the following vulnerability has been resolved:

RDMA/mana: ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-46145</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-46145</guid>
    <pubDate>Thu, 28 May 2026 10:16:30 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-46145</strong></p>
  <p>In the Linux kernel, the following vulnerability has been resolved:  RDMA/mana: Validate rx_hash_key_len  Sashiko points out that rx_hash_key_len comes from a uAPI structure and is blindly passed to memcpy, allowing the userspace to trash kernel memory. Bounds check it so the memcpy cannot overflow.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-46145">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-46138 – In the Linux kernel, the following vulnerability has been resolved:

Bluetooth: ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-46138</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-46138</guid>
    <pubDate>Thu, 28 May 2026 10:16:29 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-46138</strong></p>
  <p>In the Linux kernel, the following vulnerability has been resolved:  Bluetooth: hci_event: Fix OOB read and infinite loop in hci_le_create_big_complete_evt  hci_le_create_big_complete_evt() iterates over BT_BOUND connections for a BIG handle using a while loop, accessing ev->bis_handle[i++] on each iteration.  However, there is no check that i stays within ev->num_bis before the array access.  Wh…</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-46138">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-46137 – In the Linux kernel, the following vulnerability has been resolved:

mptcp: pm: ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-46137</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-46137</guid>
    <pubDate>Thu, 28 May 2026 10:16:29 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-46137</strong></p>
  <p>In the Linux kernel, the following vulnerability has been resolved:  mptcp: pm: ADD_ADDR rtx: fix potential data-race  This mptcp_pm_add_timer() helper is executed as a timer callback in softirq context. To avoid any data races, the socket lock needs to be held with bh_lock_sock().  If the socket is in use, retry again soon after, similar to what is done with the keepalive timer.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-46137">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-46135 – In the Linux kernel, the following vulnerability has been resolved:

nvmet-tcp: ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-46135</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-46135</guid>
    <pubDate>Thu, 28 May 2026 10:16:29 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-46135</strong></p>
  <p>In the Linux kernel, the following vulnerability has been resolved:  nvmet-tcp: fix race between ICReq handling and queue teardown  nvmet_tcp_handle_icreq() updates queue->state after sending an Initialization Connection Response (ICResp), but it does so without serializing against target-side queue teardown.  If an NVMe/TCP host sends an Initialization Connection Request (ICReq) and immediately…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-46135">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-46133 – In the Linux kernel, the following vulnerability has been resolved:

RDMA/rxe: R...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-46133</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-46133</guid>
    <pubDate>Thu, 28 May 2026 10:16:28 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-46133</strong></p>
  <p>In the Linux kernel, the following vulnerability has been resolved:  RDMA/rxe: Reject unknown opcodes before ICRC processing  Even after applying commit 7244491dab34 ("RDMA/rxe: Validate pad and ICRC before payload_size() in rxe_rcv"), a single unauthenticated UDP packet can still trigger panic.  That patch handled payload_size() underflow only for valid opcodes with short packets, not for packet…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-46133">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-46129 – In the Linux kernel, the following vulnerability has been resolved:

btrfs: fix ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-46129</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-46129</guid>
    <pubDate>Thu, 28 May 2026 10:16:28 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-46129</strong></p>
  <p>In the Linux kernel, the following vulnerability has been resolved:  btrfs: fix double free in create_space_info() error path  When kobject_init_and_add() fails, the call chain is:  create_space_info() -> btrfs_sysfs_add_space_info_type() -> kobject_init_and_add() -> failure -> kobject_put(&space_info->kobj) -> space_info_release() -> kfree(space_info)  Then control returns to create_space_info()…</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-46129">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-46125 – In the Linux kernel, the following vulnerability has been resolved:

wifi: mac80...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-46125</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-46125</guid>
    <pubDate>Thu, 28 May 2026 10:16:28 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-46125</strong></p>
  <p>In the Linux kernel, the following vulnerability has been resolved:  wifi: mac80211: remove station if connection prep fails  If connection preparation fails for MLO connections, then the interface is completely reset to non-MLD. In this case, we must not keep the station since it's related to the link of the vif being removed. Delete an existing station. Any "new_sta" is already being removed, s…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-46125">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-46124 – In the Linux kernel, the following vulnerability has been resolved:

isofs: vali...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-46124</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-46124</guid>
    <pubDate>Thu, 28 May 2026 10:16:27 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-46124</strong></p>
  <p>In the Linux kernel, the following vulnerability has been resolved:  isofs: validate block number from NFS file handle in isofs_export_iget  isofs_fh_to_dentry() and isofs_fh_to_parent() pass an attacker- controlled block number (ifid->block or ifid->parent_block) from the NFS file handle to isofs_export_iget(), which only rejects block == 0 before calling isofs_iget() and ultimately sb_bread().…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-46124">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-46123 – In the Linux kernel, the following vulnerability has been resolved:

Bluetooth: ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-46123</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-46123</guid>
    <pubDate>Thu, 28 May 2026 10:16:27 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-46123</strong></p>
  <p>In the Linux kernel, the following vulnerability has been resolved:  Bluetooth: virtio_bt: clamp rx length before skb_put  virtbt_rx_work() calls skb_put(skb, len) where len comes directly from virtqueue_get_buf() with no validation against the buffer we posted to the device. The RX skb is allocated in virtbt_add_inbuf() and exposed to virtio as exactly 1000 bytes via sg_init_one().  Checking len…</p>
  <p><strong>CVSS:</strong> 7.7 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-46123">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-46120 – In the Linux kernel, the following vulnerability has been resolved:

ip6_gre: Us...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-46120</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-46120</guid>
    <pubDate>Thu, 28 May 2026 10:16:27 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-46120</strong></p>
  <p>In the Linux kernel, the following vulnerability has been resolved:  ip6_gre: Use cached t->net in ip6erspan_changelink().  After commit 5e72ce3e3980 ("net: ipv6: Use link netns in newlink() of rtnl_link_ops"), ip6erspan_newlink() correctly resolves the per-netns ip6gre hash via link_net. ip6erspan_changelink() was not converted in that series and still uses dev_net(dev), which diverges from the…</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-46120">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-46119 – In the Linux kernel, the following vulnerability has been resolved:

libceph: Fi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-46119</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-46119</guid>
    <pubDate>Thu, 28 May 2026 10:16:27 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-46119</strong></p>
  <p>In the Linux kernel, the following vulnerability has been resolved:  libceph: Fix slab-out-of-bounds access in auth message processing  If a (potentially corrupted) message of type CEPH_MSG_AUTH_REPLY contains a positive value in its result field, it is treated as an error code by ceph_handle_auth_reply() and returned to handle_auth_reply(). Thereafter, an attempt is made to send the preallocated…</p>
  <p><strong>CVSS:</strong> 9.1 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-46119">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-46117 – In the Linux kernel, the following vulnerability has been resolved:

RDMA/mana: ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-46117</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-46117</guid>
    <pubDate>Thu, 28 May 2026 10:16:27 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-46117</strong></p>
  <p>In the Linux kernel, the following vulnerability has been resolved:  RDMA/mana: Remove user triggerable WARN_ON() in mana_ib_create_qp_rss()  Sashiko points out that the user can specify WQs sharing the same CQ as a part of the uAPI and this will trigger the WARN_ON() then go on to corrupt the kernel.  Just reject it outright and fail the QP creation.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-46117">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-46116 – In the Linux kernel, the following vulnerability has been resolved:

xfrm: defen...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-46116</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-46116</guid>
    <pubDate>Thu, 28 May 2026 10:16:27 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-46116</strong></p>
  <p>In the Linux kernel, the following vulnerability has been resolved:  xfrm: defensively unhash xfrm_state lists in __xfrm_state_delete  KASAN reproduces a slab-use-after-free in __xfrm_state_delete()'s hlist_del_rcu calls under syzkaller load on linux-6.12.y stable (reproduced on 6.12.47, also reachable via the same code path on torvalds/master and on the ipsec tree). Nine unique signatures cluste…</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-46116">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-46115 – In the Linux kernel, the following vulnerability has been resolved:

block: add ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-46115</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-46115</guid>
    <pubDate>Thu, 28 May 2026 10:16:26 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-46115</strong></p>
  <p>In the Linux kernel, the following vulnerability has been resolved:  block: add pgmap check to biovec_phys_mergeable  biovec_phys_mergeable() is used by the request merge, DMA mapping, and integrity merge paths to decide if two physically contiguous bvec segments can be coalesced into one. It currently has no check for whether the segments belong to different dev_pagemaps.  When zone device memor…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-46115">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-46114 – In the Linux kernel, the following vulnerability has been resolved:

RDMA/rxe: R...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-46114</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-46114</guid>
    <pubDate>Thu, 28 May 2026 10:16:26 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-46114</strong></p>
  <p>In the Linux kernel, the following vulnerability has been resolved:  RDMA/rxe: Reject non-8-byte ATOMIC_WRITE payloads  atomic_write_reply() at drivers/infiniband/sw/rxe/rxe_resp.c unconditionally dereferences 8 bytes at payload_addr(pkt):      value = *(u64 *)payload_addr(pkt);  check_rkey() previously accepted an ATOMIC_WRITE request with pktlen == resid == 0 because the length validation only…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-46114">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-46113 – In the Linux kernel, the following vulnerability has been resolved:

KVM: x86: F...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-46113</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-46113</guid>
    <pubDate>Thu, 28 May 2026 10:16:26 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-46113</strong></p>
  <p>In the Linux kernel, the following vulnerability has been resolved:  KVM: x86: Fix shadow paging use-after-free due to unexpected GFN  The shadow MMU computes GFNs for direct shadow pages using sp->gfn plus the SPTE index. This assumption breaks for shadow paging if the guest page tables are modified between VM entries (similar to commit aad885e77496, "KVM: x86/mmu: Drop/zap existing present SPTE…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-46113">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-46112 – In the Linux kernel, the following vulnerability has been resolved:

RDMA/hns: F...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-46112</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-46112</guid>
    <pubDate>Thu, 28 May 2026 10:16:26 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-46112</strong></p>
  <p>In the Linux kernel, the following vulnerability has been resolved:  RDMA/hns: Fix unlocked call to hns_roce_qp_remove()  Sashiko points out that hns_roce_qp_remove() requires the caller to hold locks.  The error flow in hns_roce_create_qp_common() doesn't hold those locks for the error unwind so it risks corrupting memory.  Grab the same locks the other two callers use.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-46112">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-46111 – In the Linux kernel, the following vulnerability has been resolved:

Bluetooth: ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-46111</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-46111</guid>
    <pubDate>Thu, 28 May 2026 10:16:26 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-46111</strong></p>
  <p>In the Linux kernel, the following vulnerability has been resolved:  Bluetooth: hci_conn: fix potential UAF in create_big_sync  Add hci_conn_valid() check in create_big_sync() to detect stale connections before proceeding with BIG creation. Handle the resulting -ECANCELED in create_big_complete() and re-validate the connection under hci_dev_lock() before dereferencing, matching the pattern used b…</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-46111">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-46110 – In the Linux kernel, the following vulnerability has been resolved:

net: stmmac...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-46110</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-46110</guid>
    <pubDate>Thu, 28 May 2026 10:16:26 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-46110</strong></p>
  <p>In the Linux kernel, the following vulnerability has been resolved:  net: stmmac: Prevent NULL deref when RX memory exhausted  The CPU receives frames from the MAC through conventional DMA: the CPU allocates buffers for the MAC, then the MAC fills them and returns ownership to the CPU. For each hardware RX queue, the CPU and MAC coordinate through a shared ring array of DMA descriptors: one descr…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-46110">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-46107 – In the Linux kernel, the following vulnerability has been resolved:

dm-thin: fi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-46107</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-46107</guid>
    <pubDate>Thu, 28 May 2026 10:16:26 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-46107</strong></p>
  <p>In the Linux kernel, the following vulnerability has been resolved:  dm-thin: fix metadata refcount underflow  There's a bug in dm-thin in the function rebalance_children. If the internal btree node has one entry, the code tries to copy all btree entries from the node's child to the node itself and then decrement the child's reference count.  If the child node is shared (it has reference count >…</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-46107">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-46105 – In the Linux kernel, the following vulnerability has been resolved:

scsi: mpt3s...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-46105</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-46105</guid>
    <pubDate>Thu, 28 May 2026 10:16:25 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-46105</strong></p>
  <p>In the Linux kernel, the following vulnerability has been resolved:  scsi: mpt3sas: Limit NVMe request size to 2 MiB  The HBA firmware reports NVMe MDTS values based on the underlying drive capability. However, because the driver allocates a fixed 4K buffer for the PRP list, accommodating at most 512 entries, the driver supports a maximum I/O transfer size of 2 MiB.  Limit max_hw_sectors to the s…</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-46105">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-32997 – A vulnerability allowing an authenticated user with the Backup Administrator rol...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-32997</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-32997</guid>
    <pubDate>Thu, 28 May 2026 05:16:35 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-32997</strong></p>
  <p>A vulnerability allowing an authenticated user with the Backup Administrator role to write arbitrary files on Linux-based Veeam Backup & Replication server.</p>
  <p><strong>CVSS:</strong> 8.6 · <strong>CWE:</strong> CWE-36</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-32997">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-47269 – pam_usb provides hardware authentication for Linux using ordinary removable medi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-47269</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-47269</guid>
    <pubDate>Wed, 27 May 2026 21:16:18 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-47269</strong></p>
  <p>pam_usb provides hardware authentication for Linux using ordinary removable media. Prior to 0.9.0,  pam_usb's deny_remote feature checks utmpx ut_addr_v6 to detect whether an authentication request originates from a remote session. The outer guard was if (utent->ut_addr_v6[0] != 0), which only tests the first 32-bit word of the 128-bit address field. IPv4-mapped IPv6 addresses (::ffff:x.x.x.x) st…</p>
  <p><strong>CVSS:</strong> 7.4 · <strong>CWE:</strong> CWE-284</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-47269">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-44713 – pam_usb provides hardware authentication for Linux using ordinary removable medi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-44713</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-44713</guid>
    <pubDate>Wed, 27 May 2026 21:16:18 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-44713</strong></p>
  <p>pam_usb provides hardware authentication for Linux using ordinary removable media. Prior to 0.8.7, src/tmux.c reads the user's $TMUX environment variable, splits it on commas, and interpolates the socket-path component directly into a shell command passed to popen(). Because the value is placed inside double-quotes without sanitisation, any value containing " terminates the quoted string and inje…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-78</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-44713">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-44712 – pam_usb provides hardware authentication for Linux using ordinary removable medi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-44712</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-44712</guid>
    <pubDate>Wed, 27 May 2026 21:16:18 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-44712</strong></p>
  <p>pam_usb provides hardware authentication for Linux using ordinary removable media. Prior to 0.8.7, a crafted UUID such as $(id>/tmp/rce) in the config causes root RCE when pamusb-conf --reset-pads is run. A USB device with a crafted filesystem UUID (some controllers allow this) can inject the payload at --add-device time. Also, userName from the XML config is passed to os.system() in pamusb-agent…</p>
  <p><strong>CVSS:</strong> 8.2 · <strong>CWE:</strong> CWE-78</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-44712">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-44711 – pam_usb provides hardware authentication for Linux using ordinary removable medi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-44711</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-44711</guid>
    <pubDate>Wed, 27 May 2026 21:16:18 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-44711</strong></p>
  <p>pam_usb provides hardware authentication for Linux using ordinary removable media. Prior to 0.8.7, symlink attacks on pad directory and pad files enable authentication bypass and root file corruption. This vulnerability is fixed in 0.8.7.</p>
  <p><strong>CVSS:</strong> 7.9 · <strong>CWE:</strong> CWE-59</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-44711">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-44709 – pam_usb provides hardware authentication for Linux using ordinary removable medi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-44709</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-44709</guid>
    <pubDate>Wed, 27 May 2026 21:16:17 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-44709</strong></p>
  <p>pam_usb provides hardware authentication for Linux using ordinary removable media. Prior to 0.8.7, pamusb-pinentry reads the PINENTRY_FALLBACK_APP environment variable and executes it directly without any validation. Any process that can set environment variables before pamusb-pinentry is invoked can point PINENTRY_FALLBACK_APP at an arbitrary binary or script and have it executed with the privil…</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-78</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-44709">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-48064 – pam_usb provides hardware authentication for Linux using ordinary removable medi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-48064</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-48064</guid>
    <pubDate>Wed, 27 May 2026 20:16:40 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-48064</strong></p>
  <p>pam_usb provides hardware authentication for Linux using ordinary removable media. Prior to 0.9.1, when a PAM service is configured with deny_remote=false in pam_usb (commonly done for display managers such as gdm-password or lightdm to bypass process/TTY heuristics for local sessions), the PAM_RHOST check in pusb_do_auth() is also skipped. PAM_RHOST is set by remote daemons (sshd, XDMCP servers)…</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-863</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-48064">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-47272 – pam_usb provides hardware authentication for Linux using ordinary removable medi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-47272</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-47272</guid>
    <pubDate>Wed, 27 May 2026 20:16:39 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-47272</strong></p>
  <p>pam_usb provides hardware authentication for Linux using ordinary removable media. Prior to 0.9.0, the pusb_pad_compare() function in src/pad.c only verified that the user-side pad (~/.pamusb/device.pad) could be read, but did not enforce that the system-side pad (the pad file on the USB device) was also present and readable. If the user-side pad was deleted or unreadable, the function returned a…</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> CWE-287</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-47272">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-44724 – systeminformation is a System and OS information library for node.js. From 4.17...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-44724</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-44724</guid>
    <pubDate>Wed, 27 May 2026 20:16:37 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-44724</strong></p>
  <p>systeminformation is a System and OS information library for node.js. From 4.17.0 to 5.31.5, on Linux, systeminformation is vulnerable to command injection in networkInterfaces() when an active NetworkManager connection profile name contains shell metacharacters. The vulnerable value is obtained internally from real nmcli device status output. The library sanitizes the network interface name befo…</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-78</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-44724">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-46102 – In the Linux kernel, the following vulnerability has been resolved:

net: strpar...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-46102</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-46102</guid>
    <pubDate>Wed, 27 May 2026 14:17:32 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-46102</strong></p>
  <p>In the Linux kernel, the following vulnerability has been resolved:  net: strparser: fix skb_head leak in strp_abort_strp()  When the stream parser is aborted, for example after a message assembly timeout, it can still hold a reference to a partially assembled message in strp->skb_head.  That skb is not released in strp_abort_strp(), which leaks the partially assembled message and can be triggere…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-46102">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-46100 – In the Linux kernel, the following vulnerability has been resolved:

fs: afs: re...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-46100</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-46100</guid>
    <pubDate>Wed, 27 May 2026 14:17:31 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-46100</strong></p>
  <p>In the Linux kernel, the following vulnerability has been resolved:  fs: afs: revert mmap_prepare() change  Partially reverts commit 9d5403b1036c ("fs: convert most other generic_file_*mmap() users to .mmap_prepare()").  This is because the .mmap invocation establishes a refcount, but .mmap_prepare is called at a point where a merge or an allocation failure might happen after the call, which woul…</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-46100">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-46099 – In the Linux kernel, the following vulnerability has been resolved:

net: ipv6: ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-46099</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-46099</guid>
    <pubDate>Wed, 27 May 2026 14:17:31 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-46099</strong></p>
  <p>In the Linux kernel, the following vulnerability has been resolved:  net: ipv6: fix NOREF dst use in seg6 and rpl lwtunnels  seg6_input_core() and rpl_input() call ip6_route_input() which sets a NOREF dst on the skb, then pass it to dst_cache_set_ip6() invoking dst_hold() unconditionally. On PREEMPT_RT, ksoftirqd is preemptible and a higher-priority task can release the underlying pcpu_rt between…</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-46099">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-46093 – In the Linux kernel, the following vulnerability has been resolved:

mm/vmalloc:...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-46093</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-46093</guid>
    <pubDate>Wed, 27 May 2026 14:17:30 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-46093</strong></p>
  <p>In the Linux kernel, the following vulnerability has been resolved:  mm/vmalloc: take vmap_purge_lock in shrinker  decay_va_pool_node() can be invoked concurrently from two paths: __purge_vmap_area_lazy() when pools are being purged, and the shrinker via vmap_node_shrink_scan().  However, decay_va_pool_node() is not safe to run concurrently, and the shrinker path currently lacks serialization, le…</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-46093">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-46090 – In the Linux kernel, the following vulnerability has been resolved:

ALSA: aloop...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-46090</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-46090</guid>
    <pubDate>Wed, 27 May 2026 14:17:30 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-46090</strong></p>
  <p>In the Linux kernel, the following vulnerability has been resolved:  ALSA: aloop: Fix peer runtime UAF during format-change stop  loopback_check_format() may stop the capture side when playback starts with parameters that no longer match a running capture stream. Commit 826af7fa62e3 ("ALSA: aloop: Fix racy access at PCM trigger") moved the peer lookup under cable->lock, but the actual snd_pcm_sto…</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-46090">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-46085 – In the Linux kernel, the following vulnerability has been resolved:

rxrpc: Fix ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-46085</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-46085</guid>
    <pubDate>Wed, 27 May 2026 14:17:29 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-46085</strong></p>
  <p>In the Linux kernel, the following vulnerability has been resolved:  rxrpc: Fix rxkad crypto unalignment handling  Fix handling of a packet with a misaligned crypto length.  Also handle non-ENOMEM errors from decryption by aborting.  Further, remove the WARN_ON_ONCE() so that it can't be remotely triggered (a trace line can still be emitted).</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-46085">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-46081 – In the Linux kernel, the following vulnerability has been resolved:

crypto: aco...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-46081</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-46081</guid>
    <pubDate>Wed, 27 May 2026 14:17:29 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-46081</strong></p>
  <p>In the Linux kernel, the following vulnerability has been resolved:  crypto: acomp - fix wrong pointer stored by acomp_save_req()  acomp_save_req() stores &req->chain in req->base.data. When acomp_reqchain_done() is invoked on asynchronous completion, it receives &req->chain as the data argument but casts it directly to struct acomp_req. Since data points to the chain member, all subsequent field…</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-46081">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-46078 – In the Linux kernel, the following vulnerability has been resolved:

erofs: fix ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-46078</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-46078</guid>
    <pubDate>Wed, 27 May 2026 14:17:29 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-46078</strong></p>
  <p>In the Linux kernel, the following vulnerability has been resolved:  erofs: fix the out-of-bounds nameoff handling for trailing dirents  Currently we already have boundary-checks for nameoffs, but the trailing dirents are special since the namelens are calculated with strnlen() with unchecked nameoffs.  If a crafted EROFS has a trailing dirent with nameoff >= maxsize, maxsize - nameoff can underf…</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-46078">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-46076 – In the Linux kernel, the following vulnerability has been resolved:

KVM: nSVM: ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-46076</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-46076</guid>
    <pubDate>Wed, 27 May 2026 14:17:28 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-46076</strong></p>
  <p>In the Linux kernel, the following vulnerability has been resolved:  KVM: nSVM: Raise #UD if unhandled VMMCALL isn't intercepted by L1  Explicitly synthesize a #UD for VMMCALL if L2 is active, L1 does NOT want to intercept VMMCALL, nested_svm_l2_tlb_flush_enabled() is true, and the hypercall is something other than one of the supported Hyper-V hypercalls. When all of the above conditions are met,…</p>
  <p><strong>CVSS:</strong> 7.9 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-46076">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-46070 – In the Linux kernel, the following vulnerability has been resolved:

md/raid5: v...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-46070</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-46070</guid>
    <pubDate>Wed, 27 May 2026 14:17:28 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-46070</strong></p>
  <p>In the Linux kernel, the following vulnerability has been resolved:  md/raid5: validate payload size before accessing journal metadata  r5c_recovery_analyze_meta_block() and r5l_recovery_verify_data_checksum_for_mb() iterate over payloads in a journal metadata block using on-disk payload size fields without validating them against the remaining space in the metadata block.  A corrupted journal co…</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-46070">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-46065 – In the Linux kernel, the following vulnerability has been resolved:

fbdev: defi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-46065</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-46065</guid>
    <pubDate>Wed, 27 May 2026 14:17:27 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-46065</strong></p>
  <p>In the Linux kernel, the following vulnerability has been resolved:  fbdev: defio: Disconnect deferred I/O from the lifetime of struct fb_info  Hold state of deferred I/O in struct fb_deferred_io_state. Allocate an instance as part of initializing deferred I/O and remove it only after the final mapping has been closed. If the fb_info and the contained deferred I/O meanwhile goes away, clear struc…</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-46065">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-46062 – In the Linux kernel, the following vulnerability has been resolved:

ntfs3: fix ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-46062</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-46062</guid>
    <pubDate>Wed, 27 May 2026 14:17:26 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-46062</strong></p>
  <p>In the Linux kernel, the following vulnerability has been resolved:  ntfs3: fix integer overflow in run_unpack() volume boundary check  The volume boundary check `lcn + len > sbi->used.bitmap.nbits` uses raw addition which can wrap around for large lcn and len values, bypassing the validation.  Use check_add_overflow() as is already done for the adjacent prev_lcn + dlcn and vcn64 + len checks add…</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-46062">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-46058 – In the Linux kernel, the following vulnerability has been resolved:

media: amph...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-46058</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-46058</guid>
    <pubDate>Wed, 27 May 2026 14:17:25 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-46058</strong></p>
  <p>In the Linux kernel, the following vulnerability has been resolved:  media: amphion: Fix race between m2m job_abort and device_run  Fix kernel panic caused by race condition where v4l2_m2m_ctx_release() frees m2m_ctx while v4l2_m2m_try_run() is about to call device_run with the same context.  Race sequence:   v4l2_m2m_try_run():           v4l2_m2m_ctx_release():     lock/unlock…</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-46058">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-46056 – In the Linux kernel, the following vulnerability has been resolved:

Bluetooth: ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-46056</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-46056</guid>
    <pubDate>Wed, 27 May 2026 14:17:25 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-46056</strong></p>
  <p>In the Linux kernel, the following vulnerability has been resolved:  Bluetooth: hci_event: fix potential UAF in SSP passkey handlers  hci_conn lookup and field access must be covered by hdev lock in hci_user_passkey_notify_evt() and hci_keypress_notify_evt(), otherwise the connection can be freed concurrently.  Extend the hci_dev_lock critical section to cover all conn usage in both handlers.  Ke…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-46056">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-46055 – In the Linux kernel, the following vulnerability has been resolved:

apparmor: F...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-46055</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-46055</guid>
    <pubDate>Wed, 27 May 2026 14:17:25 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-46055</strong></p>
  <p>In the Linux kernel, the following vulnerability has been resolved:  apparmor: Fix string overrun due to missing termination  When booting Ubuntu 26.04 with Linux 7.0-rc4 on an ARM64 Qualcomm Snapdragon X1 we see a string buffer overrun:  BUG: KASAN: slab-out-of-bounds in aa_dfa_match (security/apparmor/match.c:535) Read of size 1 at addr ffff0008901cc000 by task snap-update-ns/2120  CPU: 5 UID:…</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-46055">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-46054 – In the Linux kernel, the following vulnerability has been resolved:

selinux: fi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-46054</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-46054</guid>
    <pubDate>Wed, 27 May 2026 14:17:25 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-46054</strong></p>
  <p>In the Linux kernel, the following vulnerability has been resolved:  selinux: fix overlayfs mmap() and mprotect() access checks  The existing SELinux security model for overlayfs is to allow access if the current task is able to access the top level file (the "user" file) and the mounter's credentials are sufficient to access the lower level file (the "backing" file).  Unfortunately, the current…</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-46054">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-46053 – In the Linux kernel, the following vulnerability has been resolved:

net: rds: f...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-46053</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-46053</guid>
    <pubDate>Wed, 27 May 2026 14:17:24 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-46053</strong></p>
  <p>In the Linux kernel, the following vulnerability has been resolved:  net: rds: fix MR cleanup on copy error  __rds_rdma_map() hands sg/pages ownership to the transport after get_mr() succeeds. If copying the generated cookie back to user space fails after that point, the error path must not free those resources again before dropping the MR reference.  Remove the duplicate unpin/free from the put_…</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-46053">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-46052 – In the Linux kernel, the following vulnerability has been resolved:

ceph: only ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-46052</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-46052</guid>
    <pubDate>Wed, 27 May 2026 14:17:24 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-46052</strong></p>
  <p>In the Linux kernel, the following vulnerability has been resolved:  ceph: only d_add() negative dentries when they are unhashed  Ceph can call d_add(dentry, NULL) on a negative dentry that is already present in the primary dcache hash.  In the current VFS that is not safe.  d_add() goes through __d_add() to __d_rehash(), which unconditionally reinserts dentry->d_hash into the hlist_bl bucket.  I…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-46052">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-46043 – In the Linux kernel, the following vulnerability has been resolved:

RDMA/rxe: V...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-46043</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-46043</guid>
    <pubDate>Wed, 27 May 2026 14:17:23 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-46043</strong></p>
  <p>In the Linux kernel, the following vulnerability has been resolved:  RDMA/rxe: Validate pad and ICRC before payload_size() in rxe_rcv  rxe_rcv() currently checks only that the incoming packet is at least header_size(pkt) bytes long before payload_size() is used.  However, payload_size() subtracts both the attacker-controlled BTH pad field and RXE_ICRC_SIZE from pkt->paylen:    payload_size = pkt-…</p>
  <p><strong>CVSS:</strong> 9.1 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-46043">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-46039 – In the Linux kernel, the following vulnerability has been resolved:

rxgk: Fix p...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-46039</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-46039</guid>
    <pubDate>Wed, 27 May 2026 14:17:23 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-46039</strong></p>
  <p>In the Linux kernel, the following vulnerability has been resolved:  rxgk: Fix potential integer overflow in length check  Fix potential integer overflow in rxgk_extract_token() when checking the length of the ticket.  Rather than rounding up the value to be tested (which might overflow), round down the size of the available data.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-46039">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-46037 – In the Linux kernel, the following vulnerability has been resolved:

ipv4: icmp:...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-46037</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-46037</guid>
    <pubDate>Wed, 27 May 2026 14:17:23 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-46037</strong></p>
  <p>In the Linux kernel, the following vulnerability has been resolved:  ipv4: icmp: validate reply type before using icmp_pointers  Extended echo replies use ICMP_EXT_ECHOREPLY as the outbound reply type. That value is outside the range covered by icmp_pointers[], which only describes the traditional ICMP types up to NR_ICMP_TYPES.  Avoid consulting icmp_pointers[] for reply types outside that range…</p>
  <p><strong>CVSS:</strong> 8.2 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-46037">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-46036 – In the Linux kernel, the following vulnerability has been resolved:

vfio/cdx: S...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-46036</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-46036</guid>
    <pubDate>Wed, 27 May 2026 14:17:22 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-46036</strong></p>
  <p>In the Linux kernel, the following vulnerability has been resolved:  vfio/cdx: Serialize VFIO_DEVICE_SET_IRQS with a per-device mutex  vfio_cdx_set_msi_trigger() reads vdev->config_msi and operates on the vdev->cdx_irqs array based on its value, but provides no serialization against concurrent VFIO_DEVICE_SET_IRQS ioctls.  Two callers can race such that one observes config_msi as set while anothe…</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-46036">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-46031 – In the Linux kernel, the following vulnerability has been resolved:

net: ks8851...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-46031</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-46031</guid>
    <pubDate>Wed, 27 May 2026 14:17:22 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-46031</strong></p>
  <p>In the Linux kernel, the following vulnerability has been resolved:  net: ks8851: Reinstate disabling of BHs around IRQ handler  If the driver executes ks8851_irq() AND a TX packet has been sent, then the driver enables TX queue via netif_wake_queue() which schedules TX softirq to queue packets for this device.  If CONFIG_PREEMPT_RT=y is set AND a packet has also been received by the MAC, then ks…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-46031">View on NVD</a></p>
]]>
    </description>
  </item>
</channel>
</rss>
