CVE-2026-90427
- EPSS 0.12%
- Veröffentlicht 17.09.2026 16:09:49
- Zuletzt bearbeitet 18.09.2026 18:17:58
In the Linux kernel, the following vulnerability has been resolved: iommu/tegra241-cmdqv: Don't fall back to a freed smmu after devm_krealloc() __tegra241_cmdqv_probe() uses devm_krealloc() to grow @smmu into the larger tegra241_cmdqv, which frees ...
- EPSS 0.17%
- Veröffentlicht 17.09.2026 16:09:49
- Zuletzt bearbeitet 17.09.2026 17:17:47
In the Linux kernel, the following vulnerability has been resolved: iommu/tegra241-cmdqv: Don't run the error ISR before probe sets up vintfs __tegra241_cmdqv_probe() requests the error IRQ before it has allocated the cmdqv->vintfs array and set cm...
- EPSS 0.2%
- Veröffentlicht 17.09.2026 16:09:48
- Zuletzt bearbeitet 17.09.2026 17:17:47
In the Linux kernel, the following vulnerability has been resolved: iommu/tegra241-cmdqv: Free the error IRQ before tearing down VINTFs tegra241_cmdqv_remove() tears each VINTF down first, then calls free_irq(). Tearing a VINTF down frees vintf0 an...
- EPSS 0.17%
- Veröffentlicht 17.09.2026 16:09:47
- Zuletzt bearbeitet 17.09.2026 17:17:47
In the Linux kernel, the following vulnerability has been resolved: iommu/tegra241-cmdqv: Fix VINTF0 leak on the init-failure path tegra241_cmdqv_init_structures() allocates VINTF0 with kzalloc_obj(), inits it, and preallocates its logical VCMDQs. ...
CVE-2026-90425
- EPSS 0.13%
- Veröffentlicht 17.09.2026 16:09:47
- Zuletzt bearbeitet 18.09.2026 18:17:58
In the Linux kernel, the following vulnerability has been resolved: iommu/tegra241-cmdqv: Require exactly one Stream ID for a vSID tegra241_vintf_init_vsid() maps a guest vSID to a single physical Stream ID taken from master->streams[0], and only w...
CVE-2026-90423
- EPSS 0.13%
- Veröffentlicht 17.09.2026 16:09:46
- Zuletzt bearbeitet 18.09.2026 18:17:58
In the Linux kernel, the following vulnerability has been resolved: RDMA/rxe: Fix UAF in ODP init error-handling path rxe_odp_mr_init_user() stores &umem_odp->umem in mr->umem before calling rxe_odp_init_pages(). If rxe_odp_init_pages() fails, rxe_...
- EPSS 0.19%
- Veröffentlicht 17.09.2026 16:09:45
- Zuletzt bearbeitet 17.09.2026 17:17:46
In the Linux kernel, the following vulnerability has been resolved: PCI: Fix UAF when probe runs concurrent to dyn ID removal Dynamic IDs are only guaranteed to be valid when dynids.lock is held, as remove_id_store() can free the node. Thus, make a...
- EPSS 0.2%
- Veröffentlicht 17.09.2026 16:09:45
- Zuletzt bearbeitet 17.09.2026 17:17:46
In the Linux kernel, the following vulnerability has been resolved: clk: mediatek: pllfh: Fix IO remapping leak in register_pllfhs error path When mtk_clk_register_pllfhs function fails to register a PLL, it unregisters all PLLs and cleans up itsel...
- EPSS 0.21%
- Veröffentlicht 17.09.2026 16:09:44
- Zuletzt bearbeitet 17.09.2026 17:17:46
In the Linux kernel, the following vulnerability has been resolved: nilfs2: fix infinite loop in nilfs_clean_segments() syzbot reported a hung task in nilfs_transaction_begin(). This occurs because the cleaner ioctl falls into an infinite loop if n...
- EPSS 0.17%
- Veröffentlicht 17.09.2026 16:09:43
- Zuletzt bearbeitet 17.09.2026 17:17:46
In the Linux kernel, the following vulnerability has been resolved: nilfs2: fix BUG in nilfs_copy_dirty_pages() on dirty state mismatch Syzbot reported a kernel BUG triggered within nilfs_copy_dirty_pages(), which copies dirty DAT file folios/pages...