Total CVEs

138,940

Critical Severity

3,615

High Severity

12,982

Last 7 Days

1,046
Quick preset (or use dates below)
Clear Filters
Showing 2,841 - 2,860 of 12,982 CVEs
CVE-2026-46055 HIGH - 7.1

In the Linux kernel, the following vulnerability has been resolved: apparmor: Fix string overrun due to missing termination When booting Ubuntu 26.04 with Linux 7.0-rc4 on an ARM64 Qualcomm Snapdragon X1 we see a string buffer overrun: BUG: KASAN: slab-out-of-bounds in aa_dfa_match (security/appa...

Vendor: Linux
Product: Linux
Published: May 27, 2026
Source: NVD
CVE-2026-46054 HIGH - 7.1

In the Linux kernel, the following vulnerability has been resolved: selinux: fix overlayfs mmap() and mprotect() access checks The existing SELinux security model for overlayfs is to allow access if the current task is able to access the top level file (the "user" file) and the mounter&#...

Vendor: Linux
Product: Linux
Published: May 27, 2026
Source: NVD
CVE-2026-46053 HIGH - 7.8

In the Linux kernel, the following vulnerability has been resolved: net: rds: fix MR cleanup on copy error __rds_rdma_map() hands sg/pages ownership to the transport after get_mr() succeeds. If copying the generated cookie back to user space fails after that point, the error path must not free tho...

Vendor: Linux
Product: Linux
Published: May 27, 2026
Source: NVD
CVE-2026-46052 HIGH - 7.5

In the Linux kernel, the following vulnerability has been resolved: ceph: only d_add() negative dentries when they are unhashed Ceph can call d_add(dentry, NULL) on a negative dentry that is already present in the primary dcache hash. In the current VFS that is not safe. d_add() goes through __d...

Vendor: Linux
Product: Linux
Published: May 27, 2026
Source: NVD
CVE-2026-46037 HIGH - 8.2

In the Linux kernel, the following vulnerability has been resolved: ipv4: icmp: validate reply type before using icmp_pointers Extended echo replies use ICMP_EXT_ECHOREPLY as the outbound reply type. That value is outside the range covered by icmp_pointers[], which only describes the traditional I...

Vendor: Linux
Product: Linux
Published: May 27, 2026
Source: NVD
CVE-2026-46036 HIGH - 7.8

In the Linux kernel, the following vulnerability has been resolved: vfio/cdx: Serialize VFIO_DEVICE_SET_IRQS with a per-device mutex vfio_cdx_set_msi_trigger() reads vdev->config_msi and operates on the vdev->cdx_irqs array based on its value, but provides no serialization against concurrent...

Vendor: Linux
Product: Linux
Published: May 27, 2026
Source: NVD
CVE-2026-46031 HIGH - 7.5

In the Linux kernel, the following vulnerability has been resolved: net: ks8851: Reinstate disabling of BHs around IRQ handler If the driver executes ks8851_irq() AND a TX packet has been sent, then the driver enables TX queue via netif_wake_queue() which schedules TX softirq to queue packets for ...

Vendor: Linux
Product: Linux
Published: May 27, 2026
Source: NVD
CVE-2026-46029 HIGH - 7.0

In the Linux kernel, the following vulnerability has been resolved: mm/slab: return NULL early from kmalloc_nolock() in NMI on UP On UP kernels (!CONFIG_SMP), spin_trylock() is a no-op that unconditionally succeeds even when the lock is already held. As a result, kmalloc_nolock() called from NMI c...

Vendor: Linux
Product: Linux
Published: May 27, 2026
Source: NVD
CVE-2026-46027 HIGH - 7.5

In the Linux kernel, the following vulnerability has been resolved: net/smc: avoid early lgr access in smc_clc_wait_msg A CLC decline can be received while the handshake is still in an early stage, before the connection has been associated with a link group. The decline handling in smc_clc_wait_m...

Vendor: Linux
Product: Linux
Published: May 27, 2026
Source: NVD
CVE-2026-46024 HIGH - 7.5

In the Linux kernel, the following vulnerability has been resolved: libceph: Prevent potential null-ptr-deref in ceph_handle_auth_reply() If a message of type CEPH_MSG_AUTH_REPLY contains a zero value for both protocol and result, this is currently not treated as an error. In case of ac->negoti...

Vendor: Linux
Product: Linux
Published: May 27, 2026
Source: NVD
CVE-2026-46015 HIGH - 7.8

In the Linux kernel, the following vulnerability has been resolved: tcp: call sk_data_ready() after listener migration When inet_csk_listen_stop() migrates an established child socket from a closing listener to another socket in the same SO_REUSEPORT group, the target listener gets a new accept-qu...

Vendor: Linux
Product: Linux
Published: May 27, 2026
Source: NVD
CVE-2026-46011 HIGH - 7.8

In the Linux kernel, the following vulnerability has been resolved: media: mtk-jpeg: fix use-after-free in release path due to uncancelled work The mtk_jpeg_release() function frees the context structure (ctx) without first cancelling any pending or running work in ctx->jpeg_work. This creates ...

Vendor: Linux
Product: Linux
Published: May 27, 2026
Source: NVD
CVE-2026-46010 HIGH - 8.1

In the Linux kernel, the following vulnerability has been resolved: rxrpc: Fix error handling in rxgk_extract_token() Fix a missing bit of error handling in rxgk_extract_token(): in the event that rxgk_decrypt_skb() returns -ENOMEM, it should just return that rather than continuing on (for anythin...

Vendor: Linux
Product: Linux
Published: May 27, 2026
Source: NVD
CVE-2026-46006 HIGH - 7.8

In the Linux kernel, the following vulnerability has been resolved: drm/nouveau: fix u32 overflow in pushbuf reloc bounds check nouveau_gem_pushbuf_reloc_apply() validates each relocation with if (r->reloc_bo_offset + 4 > nvbo->bo.base.size) but reloc_bo_offset is __u32 (uapi/drm/no...

Vendor: Linux
Product: Linux
Published: May 27, 2026
Source: NVD
CVE-2026-45999 HIGH - 7.1

In the Linux kernel, the following vulnerability has been resolved: erofs: fix unsigned underflow in z_erofs_lz4_handle_overlap() Some crafted images can have illegal (!partial_decoding && m_llen < m_plen) extents, and the LZ4 inplace decompression path can be wrongly hit, but it cannot...

Vendor: Linux
Product: Linux
Published: May 27, 2026
Source: NVD
CVE-2026-45991 HIGH - 7.8

In the Linux kernel, the following vulnerability has been resolved: udf: fix partition descriptor append bookkeeping Mounting a crafted UDF image with repeated partition descriptors can trigger a heap out-of-bounds write in part_descs_loc[]. handle_partition_descriptor() deduplicates entries by p...

Vendor: Linux
Product: Linux
Published: May 27, 2026
Source: NVD
CVE-2026-45984 HIGH - 7.8

In the Linux kernel, the following vulnerability has been resolved: gfs2: Fix use-after-free in iomap inline data write path The inline data buffer head (dibh) is being released prematurely in gfs2_iomap_begin() via release_metapath() while iomap->inline_data still points to dibh->b_data. Th...

Vendor: Linux
Product: Linux
Published: May 27, 2026
Source: NVD
CVE-2026-45980 HIGH - 7.8

In the Linux kernel, the following vulnerability has been resolved: accel/amdxdna: Stop job scheduling across aie2_release_resource() Running jobs on a hardware context while it is in the process of releasing resources can lead to use-after-free and crashes. Fix this by stopping job scheduling be...

Vendor: Linux
Product: Linux
Published: May 27, 2026
Source: NVD
CVE-2026-45970 HIGH - 7.8

In the Linux kernel, the following vulnerability has been resolved: bonding: alb: fix UAF in rlb_arp_recv during bond up/down The ALB RX path may access rx_hashtbl concurrently with bond teardown. During rapid bond up/down cycles, rlb_deinitialize() frees rx_hashtbl while RX handlers are still run...

Vendor: Linux
Product: Linux
Published: May 27, 2026
Source: NVD
CVE-2026-45959 HIGH - 7.8

In the Linux kernel, the following vulnerability has been resolved: crypto: ccp - Fix a crash due to incorrect cleanup usage of kfree Annotating a local pointer variable, which will be assigned with the kmalloc-family functions, with the `__cleanup(kfree)` attribute will make the address of the lo...

Vendor: Linux
Product: Linux
Published: May 27, 2026
Source: NVD