Total CVEs

138,363

Critical Severity

3,557

High Severity

12,776

Last 7 Days

1,993
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 2,621 - 2,640 of 12,473 CVEs
CVE-2026-46102 HIGH - 7.5

In the Linux kernel, the following vulnerability has been resolved: net: strparser: fix skb_head leak in strp_abort_strp() When the stream parser is aborted, for example after a message assembly timeout, it can still hold a reference to a partially assembled message in strp->skb_head. That skb...

Vendor: Linux
Product: Linux
Published: May 27, 2026
Source: NVD
CVE-2026-46100 HIGH - 7.8

In the Linux kernel, the following vulnerability has been resolved: fs: afs: revert mmap_prepare() change Partially reverts commit 9d5403b1036c ("fs: convert most other generic_file_*mmap() users to .mmap_prepare()"). This is because the .mmap invocation establishes a refcount, but .mma...

Vendor: Linux
Product: Linux
Published: May 27, 2026
Source: NVD
CVE-2026-46099 HIGH - 8.1

In the Linux kernel, the following vulnerability has been resolved: net: ipv6: fix NOREF dst use in seg6 and rpl lwtunnels seg6_input_core() and rpl_input() call ip6_route_input() which sets a NOREF dst on the skb, then pass it to dst_cache_set_ip6() invoking dst_hold() unconditionally. On PREEMPT...

Vendor: Linux
Product: Linux
Published: May 27, 2026
Source: NVD
CVE-2026-46093 HIGH - 7.8

In the Linux kernel, the following vulnerability has been resolved: mm/vmalloc: take vmap_purge_lock in shrinker decay_va_pool_node() can be invoked concurrently from two paths: __purge_vmap_area_lazy() when pools are being purged, and the shrinker via vmap_node_shrink_scan(). However, decay_va_p...

Vendor: Linux
Product: Linux
Published: May 27, 2026
Source: NVD
CVE-2026-46090 HIGH - 7.8

In the Linux kernel, the following vulnerability has been resolved: ALSA: aloop: Fix peer runtime UAF during format-change stop loopback_check_format() may stop the capture side when playback starts with parameters that no longer match a running capture stream. Commit 826af7fa62e3 ("ALSA: alo...

Vendor: Linux
Product: Linux
Published: May 27, 2026
Source: NVD
CVE-2026-46085 HIGH - 7.5

In the Linux kernel, the following vulnerability has been resolved: rxrpc: Fix rxkad crypto unalignment handling Fix handling of a packet with a misaligned crypto length. Also handle non-ENOMEM errors from decryption by aborting. Further, remove the WARN_ON_ONCE() so that it can't be remote...

Vendor: Linux
Product: Linux
Published: May 27, 2026
Source: NVD
CVE-2026-46081 HIGH - 7.8

In the Linux kernel, the following vulnerability has been resolved: crypto: acomp - fix wrong pointer stored by acomp_save_req() acomp_save_req() stores &req->chain in req->base.data. When acomp_reqchain_done() is invoked on asynchronous completion, it receives &req->chain as the ...

Vendor: Linux
Product: Linux
Published: May 27, 2026
Source: NVD
CVE-2026-46078 HIGH - 7.1

In the Linux kernel, the following vulnerability has been resolved: erofs: fix the out-of-bounds nameoff handling for trailing dirents Currently we already have boundary-checks for nameoffs, but the trailing dirents are special since the namelens are calculated with strnlen() with unchecked nameof...

Vendor: Linux
Product: Linux
Published: May 27, 2026
Source: NVD
CVE-2026-46076 HIGH - 7.9

In the Linux kernel, the following vulnerability has been resolved: KVM: nSVM: Raise #UD if unhandled VMMCALL isn't intercepted by L1 Explicitly synthesize a #UD for VMMCALL if L2 is active, L1 does NOT want to intercept VMMCALL, nested_svm_l2_tlb_flush_enabled() is true, and the hypercall is...

Vendor: Linux
Product: Linux
Published: May 27, 2026
Source: NVD
CVE-2026-46070 HIGH - 7.1

In the Linux kernel, the following vulnerability has been resolved: md/raid5: validate payload size before accessing journal metadata r5c_recovery_analyze_meta_block() and r5l_recovery_verify_data_checksum_for_mb() iterate over payloads in a journal metadata block using on-disk payload size fields...

Vendor: Linux
Product: Linux
Published: May 27, 2026
Source: NVD
CVE-2026-46065 HIGH - 7.8

In the Linux kernel, the following vulnerability has been resolved: fbdev: defio: Disconnect deferred I/O from the lifetime of struct fb_info Hold state of deferred I/O in struct fb_deferred_io_state. Allocate an instance as part of initializing deferred I/O and remove it only after the final mapp...

Vendor: Linux
Product: Linux
Published: May 27, 2026
Source: NVD
CVE-2026-46062 HIGH - 7.8

In the Linux kernel, the following vulnerability has been resolved: ntfs3: fix integer overflow in run_unpack() volume boundary check The volume boundary check `lcn + len > sbi->used.bitmap.nbits` uses raw addition which can wrap around for large lcn and len values, bypassing the validation....

Vendor: Linux
Product: Linux
Published: May 27, 2026
Source: NVD
CVE-2026-46058 HIGH - 7.8

In the Linux kernel, the following vulnerability has been resolved: media: amphion: Fix race between m2m job_abort and device_run Fix kernel panic caused by race condition where v4l2_m2m_ctx_release() frees m2m_ctx while v4l2_m2m_try_run() is about to call device_run with the same context. Race s...

Vendor: Linux
Product: Linux
Published: May 27, 2026
Source: NVD
CVE-2026-46056 HIGH - 8.8

In the Linux kernel, the following vulnerability has been resolved: Bluetooth: hci_event: fix potential UAF in SSP passkey handlers hci_conn lookup and field access must be covered by hdev lock in hci_user_passkey_notify_evt() and hci_keypress_notify_evt(), otherwise the connection can be freed co...

Vendor: Linux
Product: Linux
Published: May 27, 2026
Source: NVD
CVE-2026-46055 HIGH - 7.1

In the Linux kernel, the following vulnerability has been resolved: apparmor: Fix string overrun due to missing termination When booting Ubuntu 26.04 with Linux 7.0-rc4 on an ARM64 Qualcomm Snapdragon X1 we see a string buffer overrun: BUG: KASAN: slab-out-of-bounds in aa_dfa_match (security/appa...

Vendor: Linux
Product: Linux
Published: May 27, 2026
Source: NVD
CVE-2026-46054 HIGH - 7.1

In the Linux kernel, the following vulnerability has been resolved: selinux: fix overlayfs mmap() and mprotect() access checks The existing SELinux security model for overlayfs is to allow access if the current task is able to access the top level file (the "user" file) and the mounter&#...

Vendor: Linux
Product: Linux
Published: May 27, 2026
Source: NVD
CVE-2026-46053 HIGH - 7.8

In the Linux kernel, the following vulnerability has been resolved: net: rds: fix MR cleanup on copy error __rds_rdma_map() hands sg/pages ownership to the transport after get_mr() succeeds. If copying the generated cookie back to user space fails after that point, the error path must not free tho...

Vendor: Linux
Product: Linux
Published: May 27, 2026
Source: NVD
CVE-2026-46052 HIGH - 7.5

In the Linux kernel, the following vulnerability has been resolved: ceph: only d_add() negative dentries when they are unhashed Ceph can call d_add(dentry, NULL) on a negative dentry that is already present in the primary dcache hash. In the current VFS that is not safe. d_add() goes through __d...

Vendor: Linux
Product: Linux
Published: May 27, 2026
Source: NVD
CVE-2026-46037 HIGH - 8.2

In the Linux kernel, the following vulnerability has been resolved: ipv4: icmp: validate reply type before using icmp_pointers Extended echo replies use ICMP_EXT_ECHOREPLY as the outbound reply type. That value is outside the range covered by icmp_pointers[], which only describes the traditional I...

Vendor: Linux
Product: Linux
Published: May 27, 2026
Source: NVD
CVE-2026-46036 HIGH - 7.8

In the Linux kernel, the following vulnerability has been resolved: vfio/cdx: Serialize VFIO_DEVICE_SET_IRQS with a per-device mutex vfio_cdx_set_msi_trigger() reads vdev->config_msi and operates on the vdev->cdx_irqs array based on its value, but provides no serialization against concurrent...

Vendor: Linux
Product: Linux
Published: May 27, 2026
Source: NVD