Vulnerabilities
Summary — last 7 days
New vulnerabilities2,737▼ 486 vs. last week
Critical / high1,302▼ 188 vs. last week
New active exploitation (KEV)3▼ 5 vs. last week
Unscored (no CVSS)227▼ 275 vs. last week
402,856 results, sorted by published date (most recent first)
| CVE | Status | Severity | EPSS | Active exploitation | Affected technologies | Published ▼ | Modified | Description |
|---|---|---|---|---|---|---|---|---|
| Received | Unscored | 0.18% | — | Linux KernelAI | 10/6/2026 | 10/6/2026 | In the Linux kernel, the following vulnerability has been resolved: net/sched: act_api: release tail references on DELACTION failure A batched RTM_DELACTION request takes a temporary reference on each action before attempting any deletion. tcf_action_delete() clears each processed slot and drops its temporary… | |
| Received | Unscored | 0.18% | — | Linux KernelAI | 10/6/2026 | 10/6/2026 | In the Linux kernel, the following vulnerability has been resolved: net/sched: hhf: cap hh_flows_limit at change time hhf_change() stores TCA_HHF_HH_FLOWS_LIMIT with no upper bound. A huge hh_flows_limit lets each new heavy-hitter flow pass the hh_flows_current_cnt check in alloc_new_hh() and forces a fixed-size… | |
| Received | Unscored | 0.18% | — | Linux KernelAI | 10/6/2026 | 10/6/2026 | In the Linux kernel, the following vulnerability has been resolved: net/packet: clear RX owner on VNET header error Commit 61fad6816fc1 ("net/packet: tpacket_rcv: avoid a producer race condition") added rx_owner_map and made tpacket_rcv() claim a V1 or V2 ring slot before converting the virtio-net header. If the… | |
| Received | Unscored | 0.18% | — | Linux KernelAI | 10/6/2026 | 10/6/2026 | In the Linux kernel, the following vulnerability has been resolved: scsi: core: Validate MODE SENSE lengths in scsi_cdl_enable() scsi_cdl_enable() uses length fields returned by MODE SENSE to locate the ATA feature mode page in a 64-byte stack buffer. A target can report a total length shorter than its mode header and… | |
| Received | Unscored | 0.20% | — | Linux KernelAI | 10/6/2026 | 10/6/2026 | In the Linux kernel, the following vulnerability has been resolved: xfrm: serialize state GC with device state flush The deferred-device pass in xfrm_dev_state_flush() finds states under xfrm_state_dev_gc_lock, but drops the lock before calling xfrm_dev_state_free() because the driver callback may sleep. The device GC… | |
| Received | High (7) | 0.12% | — | Linux KernelAI | 10/6/2026 | 10/7/2026 | In the Linux kernel, the following vulnerability has been resolved: xfrm: use hlist_del_init_rcu for state_cache and state_cache_input Commit 14acf9652e56 ("xfrm: defensively unhash xfrm_state lists in __xfrm_state_delete") converted bydst/bysrc/byseq/byspi from hlist_del_rcu() to hlist_del_init_rcu() so that a second… | |
| Received | High (7.8) | 0.16% | — | Linux KernelAI | 10/6/2026 | 10/7/2026 | In the Linux kernel, the following vulnerability has been resolved: xfrm: save input state data before secpath resets xfrm_input() stores the current xfrm_state in the skb secpath while it continues receive-side processing. Some input paths can reset that secpath before xfrm_input() has finished dereferencing the… | |
| Received | High (7.8) | 0.12% | — | Linux KernelAI | 10/6/2026 | 10/7/2026 | In the Linux kernel, the following vulnerability has been resolved: mips: select CONFIG_WEAK_REORDERING_BEYOND_LLSC from CONFIG_EYEQ On I6500 CPU cores, lld and scd give no ordering guarantees (same as all other instructions). To respect the assumption that arch_cmpxchg() is fully ordered, we must inject sync… | |
| Received | Unscored | 0.18% | — | Linux KernelAI | 10/6/2026 | 10/6/2026 | In the Linux kernel, the following vulnerability has been resolved: memstick: ms_block: destroy io_queue workqueue on removal msb_init_disk() creates the per-card ordered workqueue msb->io_queue with alloc_ordered_workqueue(). It is torn down with destroy_workqueue() only on the init error path; msb_remove() never… | |
| Received | Unscored | 0.17% | — | Linux KernelAI | 10/6/2026 | 10/6/2026 | In the Linux kernel, the following vulnerability has been resolved: mm, swap: fix SWAP_USAGE_OFFLIST_BIT collision with real usage count SWAP_USAGE_OFFLIST_BIT is embedded in the si->inuse_pages usage counter, and is meant to sit above any value that counter can reach. However, it is defined from… | |
| Received | Unscored | 0.16% | — | Linux KernelAI | 10/6/2026 | 10/6/2026 | In the Linux kernel, the following vulnerability has been resolved: mm/shrinker: fix bogus set_shrinker_bit() with cgroup.memory=nokmem With cgroup.memory=nokmem, shrinker_memcg_alloc() bails out early and never allocates an id, so shrinker->id keeps the 0 it got from the kzalloc() in shrinker_alloc().… | |
| Received | Unscored | 0.17% | — | Linux KernelAI | 10/6/2026 | 10/6/2026 | In the Linux kernel, the following vulnerability has been resolved: mm/vma: correctly unaccount on mmap_prepare() failure __mmap_setup() accounts memory for relevant mappings via: If __mmap_setup() fails, this indicates that this accounting did not take place, and thus it's appropriate for __mmap_region() to jump to… | |
| Received | Unscored | 0.17% | — | Linux KernelAI | 10/6/2026 | 10/6/2026 | In the Linux kernel, the following vulnerability has been resolved: mm: filemap: retain mapped dropbehind folios Fault-around can map ready dropbehind folios without going through the normal page-cache lookup that clears dropbehind. A mapping represents a competing cached user, so retain the folio instead of forcibly… | |
| Received | Unscored | 0.17% | — | Linux KernelAI | 10/6/2026 | 10/6/2026 | In the Linux kernel, the following vulnerability has been resolved: KEYS: encrypted: fix integer overflow of datablob_len encrypted_key_alloc() stores datablob_len in a u16. It is computed from multiple string and payload lengths. If the result exceeds U16_MAX, the assignment truncates the allocation size. KASAN… | |
| Received | Unscored | 0.17% | — | Linux KernelAI | 10/6/2026 | 10/6/2026 | In the Linux kernel, the following vulnerability has been resolved: KEYS: trusted: Fix tpm2_load_cmd() boundary check tpm2_load_cmd() does boundary checks against the ASN.1 size i.e., payload->blob_len. Address this by passing the decoded blob size to tpm2_load_cmd(), and use it for the boundary checks. | |
| Received | Unscored | 0.20% | — | Linux KernelAI | 10/6/2026 | 10/6/2026 | In the Linux kernel, the following vulnerability has been resolved: sched_ext: Fix NULL sched deref in kfunc sub-sched error paths When the root scheduler has sub-scheds attached, the COMPAT kfunc wrappers scx_bpf_select_cpu_and() and scx_bpf_dsq_insert_vtime() refuse the call and report to @p's scheduler: The… | |
| Received | Unscored | 0.16% | — | Linux KernelAI | 10/6/2026 | 10/6/2026 | In the Linux kernel, the following vulnerability has been resolved: sched_ext: Close the pre-enable ops error claim window scx_alloc_and_add_sched() publishes ops->priv before scx_root_enable_workfn() switches the state to SCX_ENABLING. An error claimed via scx_bpf_error_bstr() from an associated BPF program in that… | |
| Received | Unscored | 0.18% | — | Linux KernelAI | 10/6/2026 | 10/6/2026 | In the Linux kernel, the following vulnerability has been resolved: i2c: atr: fix dangling adapter pointer on add failure i2c_atr_add_adapter() stores atr->adapter[chan_id] before i2c_add_adapter() so that the I2C bus notifier can match child clients during registration. On failure the channel is freed but the slot… | |
| Received | Unscored | 0.18% | — | Linux KernelAI | 10/6/2026 | 10/6/2026 | In the Linux kernel, the following vulnerability has been resolved: IB/mlx4: Fix use-after-free on pkey sysfs registration failure register_pkey_tree() ignores errors from register_one_pkey_tree() and continues registering the remaining slaves. The per-slave error path has already released the pkey parent kobjects,… | |
| Received | High (7.1) | 0.13% | — | Linux KernelAI | 10/6/2026 | 10/7/2026 | In the Linux kernel, the following vulnerability has been resolved: IB/hfi1: Fix the PIO_CRED credit-return mmap hfi1_file_mmap()'s PIO_CRED case must hand user space the single credit-return page that holds this context's entry. That page is the second or third page of the per-node credit-return allocation once the… | |
| Received | Unscored | 0.21% | — | Linux KernelAI | 10/6/2026 | 10/6/2026 | In the Linux kernel, the following vulnerability has been resolved: selinux: preserve user SID across nested backing files SELinux saves the user file SID in a backing-file security blob so it remains available after mmap() replaces vma->vm_file with a backing file. For nested backing files (overlayfs over overlayfs,… | |
| Received | Unscored | 0.22% | — | Linux KernelAI | 10/6/2026 | 10/6/2026 | In the Linux kernel, the following vulnerability has been resolved: selinux: recheck intermediate backing files on mprotect() mprotect() can be used to bypass the SELinux checks that mmap() performs against the intermediate layers of a stacked filesystem. mmap() checks every backing layer as the request descends… | |
| Received | Unscored | 0.21% | — | Linux KernelAI | 10/6/2026 | 10/6/2026 | In the Linux kernel, the following vulnerability has been resolved: mmc: core: Cancel SDIO IRQ work before freeing host A host controller that uses sdio_signal_irq() schedules host->sdio_irq_work from its interrupt handler. That work is only cancelled on the suspend path (mmc_sdio_suspend()), not on the remove/free… | |
| Received | Unscored | 0.21% | — | Linux KernelAI | 10/6/2026 | 10/6/2026 | In the Linux kernel, the following vulnerability has been resolved: mmc: hsq: Fix use-after-free in retry work mmc_hsq_pump_requests() queues retry_work when request_atomic() returns -EBUSY; today sdhci-sprd is the only consumer that implements request_atomic(). The work is embedded in a devm-allocated mmc_hsq, but is… | |
| Received | Unscored | 0.21% | — | Linux KernelAI | 10/6/2026 | 10/6/2026 | In the Linux kernel, the following vulnerability has been resolved: mmc: mmci: Fix use-after-free in busy-timeout work ux500_busy_complete() can queue ux500_busy_timeout_work for an R1b command, but mmci_remove() never cancels it. The work can subsequently dereference the devm-allocated mmci_host after it has been… |