Linux kernel CVEs

Three-year CVE watchlist for Linux kernel vulnerabilities relevant to virtualized, dedicated and colocated server environments.

Dedicated CVE watchlist

Linux kernel CVEs

Three-year CVE watchlist for Linux kernel vulnerabilities relevant to virtualized, dedicated and colocated server environments.

Server administration
CategorySwitch between product-focused CVE watchlists.
Showsorted by operational relevance for DataHouse infrastructure
CVE-2024-1086CVSS 7.8CISA KEVLinux

CVE-2024-1086: Linux Kernel Use-After-Free Vulnerability

A use-after-free vulnerability in the Linux kernel's netfilter: nf_tables component can be exploited to achieve local privilege escalation. The nft_verdict_init() function allows positive values as drop error within the hook verdict, and hence the nf_hook_...

Updated: 2026-06-17
CVE-2024-53197CVSS 7.8CISA KEVLinux

CVE-2024-53197: Linux Kernel Out-of-Bounds Access Vulnerability

In the Linux kernel, the following vulnerability has been resolved: ALSA: usb-audio: Fix potential out-of-bound accesses for Extigy and Mbox devices A bogus device can provide a bNumConfigurations value that exceeds the initial value used in usb_get_confi...

Updated: 2026-06-17
CVE-2024-53104CVSS 7.8CISA KEVLinux

CVE-2024-53104: Linux Kernel Out-of-Bounds Write Vulnerability

In the Linux kernel, the following vulnerability has been resolved: media: uvcvideo: Skip parsing frames of type UVC_VS_UNDEFINED in uvc_parse_format This can lead to out of bounds writes since frames of this type were not taken into account when calculat...

Updated: 2026-06-17
CVE-2024-36971CVSS 7.8CISA KEVLinux

CVE-2024-36971: Android Kernel Remote Code Execution Vulnerability

In the Linux kernel, the following vulnerability has been resolved: net: fix __dst_negative_advice() race __dst_negative_advice() does not enforce proper RCU rules when sk->dst_cache must be cleared, leading to possible UAF. RCU rules are that we must fi...

Updated: 2026-06-17
CVE-2024-53150CVSS 7.1CISA KEVLinux

CVE-2024-53150: Linux Kernel Out-of-Bounds Read Vulnerability

In the Linux kernel, the following vulnerability has been resolved: ALSA: usb-audio: Fix out of bounds reads when finding clock sources The current USB-audio driver code doesn't check bLength of each descriptor at traversing for clock descriptors. That i...

Updated: 2026-06-17
CVE-2024-50302CVSS 5.5CISA KEVLinux

CVE-2024-50302: Linux Kernel Use of Uninitialized Resource Vulnerability

In the Linux kernel, the following vulnerability has been resolved: HID: core: zero-initialize the report buffer Since the report buffer is used by all kinds of drivers in various ways, let's zero-initialize it during allocation to make sure that it can't...

Updated: 2026-06-17
CVE-2026-43500CVSS 7.8Linux

CVE-2026-43500: linux kernel vulnerability

In the Linux kernel, the following vulnerability has been resolved: rxrpc: Also unshare DATA/RESPONSE packets when paged frags are present The DATA-packet handler in rxrpc_input_call_event() and the RESPONSE handler in rxrpc_verify_response() copy the skb...

Updated: 2026-07-15
CVE-2025-37924CVSS 9.8Linux

CVE-2025-37924: linux kernel vulnerability

In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix use-after-free in kerberos authentication Setting sess->user = NULL was introduced to fix the dangling pointer created by ksmbd_free_user. However, it is possible another threa...

Updated: 2026-06-17
CVE-2026-43284CVSS 8.8Linux

CVE-2026-43284: linux kernel vulnerability

In the Linux kernel, the following vulnerability has been resolved: xfrm: esp: avoid in-place decrypt on shared skb frags MSG_SPLICE_PAGES can attach pages from a pipe directly to an skb. TCP marks such skbs with SKBFL_SHARED_FRAG after skb_splice_from_it...

Updated: 2026-07-15
CVE-2023-52440CVSS 7.8Mail

CVE-2023-52440: linux kernel vulnerability

In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix slub overflow in ksmbd_decode_ntlmssp_auth_blob() If authblob->SessionKey.Length is bigger than session key size(CIFS_KEY_SIZE), slub overflow can happen in key exchange codes....

Updated: 2026-06-17
CVE-2023-2163CVSS 10.0Linux

CVE-2023-2163: linux kernel vulnerability

Incorrect verifier pruning in BPF in Linux Kernel >=5.4 leads to unsafe code paths being incorrectly marked as safe, resulting in arbitrary read/write in kernel memory, lateral privilege escalation, and container escape.

Updated: 2026-06-17
CVE-2026-64459CVSS 9.8Linux

CVE-2026-64459

In the Linux kernel, the following vulnerability has been resolved: tcp: restore RCU grace period in tcp_ao_destroy_sock Commit 51e547e8c89c ("tcp: Free TCP-AO/TCP-MD5 info/keys without RCU") removed the call_rcu() callback from tcp_ao_destroy_sock(), arg...

Updated: 2026-07-27
CVE-2024-26594CVSS 7.1Linux

CVE-2024-26594: linux kernel vulnerability

In the Linux kernel, the following vulnerability has been resolved: ksmbd: validate mech token in session setup If client send invalid mech token in session setup request, ksmbd validate and make the error if it is invalid.

Updated: 2026-06-17
CVE-2023-44466CVSS 8.8Linux

CVE-2023-44466: linux kernel vulnerability

An issue was discovered in net/ceph/messenger_v2.c in the Linux kernel before 6.4.5. There is an integer signedness error, leading to a buffer overflow and remote code execution via HELLO or one of the AUTH frames. This occurs because of an untrusted length...

Updated: 2026-06-17
CVE-2023-52755CVSS 8.4Linux

CVE-2023-52755: linux kernel vulnerability

In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix slab out of bounds write in smb_inherit_dacl() slab out-of-bounds write is caused by that offsets is bigger than pntsd allocation size. This patch add the check to validate 3 o...

Updated: 2026-06-17
CVE-2024-0582CVSS 7.8Linux

CVE-2024-0582: linux kernel vulnerability

A memory leak flaw was found in the Linux kernel’s io_uring functionality in how a user registers a buffer ring with IORING_REGISTER_PBUF_RING, mmap() it, and then frees it. This flaw allows a local user to crash or potentially escalate their privileges on ...

Updated: 2026-06-17
CVE-2025-39946CVSS 9.8Linux

CVE-2025-39946: linux kernel vulnerability

In the Linux kernel, the following vulnerability has been resolved: tls: make sure to abort the stream if headers are bogus Normally we wait for the socket to buffer up the whole record before we service it. If the socket has a tiny buffer, however, we re...

Updated: 2026-06-17
CVE-2023-38428CVSS 9.1Linux

CVE-2023-38428: linux kernel vulnerability

An issue was discovered in the Linux kernel before 6.3.4. fs/ksmbd/smb2pdu.c in ksmbd does not properly check the UserName value because it does not consider the address of security buffer, leading to an out-of-bounds read.

Updated: 2026-06-17
CVE-2023-32254CVSS 9.8Linux

CVE-2023-32254: linux kernel vulnerability

A flaw was found in the Linux kernel's ksmbd, a high-performance in-kernel SMB server. The specific flaw exists within the processing of SMB2_TREE_DISCONNECT commands. The issue results from the lack of proper locking when performing operations on an object...

Updated: 2026-06-17
CVE-2023-32250CVSS 9.0Linux

CVE-2023-32250: linux kernel vulnerability

A flaw was found in the Linux kernel's ksmbd, a high-performance in-kernel SMB server. The specific flaw exists within the processing of SMB2_SESSION_SETUP commands. The issue results from the lack of proper locking when performing operations on an object. ...

Updated: 2026-06-17
CVE-2023-38426CVSS 9.1Linux

CVE-2023-38426: linux kernel vulnerability

An issue was discovered in the Linux kernel before 6.3.4. ksmbd has an out-of-bounds read in smb2_find_context_vals when create_context's name_len is larger than the tag length.

Updated: 2026-06-17
CVE-2023-38432CVSS 9.1Linux

CVE-2023-38432: linux kernel vulnerability

An issue was discovered in the Linux kernel before 6.3.10. fs/smb/server/smb2misc.c in ksmbd does not validate the relationship between the command payload size and the RFC1002 length specification, leading to an out-of-bounds read.

Updated: 2026-06-17
CVE-2026-43407CVSS 9.1Linux

CVE-2026-43407: linux kernel vulnerability

In the Linux kernel, the following vulnerability has been resolved: libceph: Fix potential out-of-bounds access in ceph_handle_auth_reply() This patch fixes an out-of-bounds access in ceph_handle_auth_reply() that can be triggered by a message of type CEP...

Updated: 2026-06-17
CVE-2026-53224CVSS 9.1Linux

CVE-2026-53224: linux kernel vulnerability

In the Linux kernel, the following vulnerability has been resolved: sctp: validate embedded INIT chunk and address list lengths in cookie sctp_unpack_cookie() only checked that the embedded INIT chunk length did not exceed the remaining cookie payload, bu...

Updated: 2026-07-02
CVE-2026-64113CVSS 9.8Linux

CVE-2026-64113

In the Linux kernel, the following vulnerability has been resolved: ixgbevf: fix use-after-free in VEPA multicast source pruning ixgbevf_clean_rx_irq() prunes frames whose source MAC matches the VF's own address (VEPA multicast workaround) by freeing the ...

Updated: 2026-07-20
CVE-2026-63808CVSS 9.8Linux

CVE-2026-63808

In the Linux kernel, the following vulnerability has been resolved: exfat: fix potential use-after-free in exfat_find_dir_entry() In exfat_find_dir_entry(), the buffer_head obtained from exfat_get_dentry() is released with brelse(bh) before the fall-throu...

Updated: 2026-07-27
CVE-2026-53384CVSS 9.8Linux

CVE-2026-53384

In the Linux kernel, the following vulnerability has been resolved: serial: 8250_dw: unregister 8250 port if clk_notifier_register() fails dw8250_probe() registers the 8250 port via serial8250_register_8250_port() and then, if the device has a clock, regi...

Updated: 2026-07-28
CVE-2026-45898CVSS 9.8Linux

CVE-2026-45898: linux kernel vulnerability

In the Linux kernel, the following vulnerability has been resolved: RDMA/iwcm: Fix workqueue list corruption by removing work_list The commit e1168f0 ("RDMA/iwcm: Simplify cm_event_handler()") changed the work submission logic to unconditionally call queu...

Updated: 2026-07-15
CVE-2026-46316CVSS 9.3Linux

CVE-2026-46316: linux kernel vulnerability

In the Linux kernel, the following vulnerability has been resolved: KVM: arm64: vgic-its: Drop the translation cache reference only for the erased entry vgic_its_invalidate_cache() walks the per-ITS translation cache with xa_for_each() and drops the cache...

Updated: 2026-07-23
CVE-2026-43465CVSS 9.8Linux

CVE-2026-43465: linux kernel vulnerability

In the Linux kernel, the following vulnerability has been resolved: net/mlx5e: RX, Fix XDP multi-buf frag counting for striding RQ XDP multi-buf programs can modify the layout of the XDP buffer when the program calls bpf_xdp_pull_data() or bpf_xdp_adjust_...

Updated: 2026-06-17
CVE-2026-31705CVSS 9.8Linux

CVE-2026-31705: linux kernel vulnerability

In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix out-of-bounds write in smb2_get_ea() EA alignment smb2_get_ea() applies 4-byte alignment padding via memset() after writing each EA entry. The bounds check on buf_free_len is p...

Updated: 2026-06-17
CVE-2026-23428CVSS 9.8Linux

CVE-2026-23428: linux kernel vulnerability

In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix use-after-free of share_conf in compound request smb2_get_ksmbd_tcon() reuses work->tcon in compound requests without validating tcon->t_state. ksmbd_tree_conn_lookup() checks ...

Updated: 2026-06-17
CVE-2026-46244CVSS 9.1Linux

CVE-2026-46244: linux kernel vulnerability

In the Linux kernel, the following vulnerability has been resolved: netfilter: nft_inner: Fix IPv6 inner_thoff desync In nft_inner_parse_l2l3(), when processing inner IPv6 packets, ipv6_find_hdr() correctly computes the transport header offset traversing ...

Updated: 2026-07-22
CVE-2026-23427CVSS 9.8Linux

CVE-2026-23427: linux kernel vulnerability

In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix use-after-free in durable v2 replay of active file handles parse_durable_handle_context() unconditionally assigns dh_info->fp->conn to the current connection when handling a DU...

Updated: 2026-06-17
CVE-2026-63939CVSS 9.3Linux

CVE-2026-63939

In the Linux kernel, the following vulnerability has been resolved: KVM: SEV: Compute the correct max length of the in-GHCB scratch area When setting the length of the GHCB scratch area, and the area is in the GHCB shared buffer, set the effective length ...

Updated: 2026-07-27
CVE-2026-63940CVSS 9.3Linux

CVE-2026-63940

In the Linux kernel, the following vulnerability has been resolved: KVM: SEV: Ignore Port I/O requests of length '0' Explicitly ignore Port I/O requests of length '0' (or count '0'), so that setting up the software scratch area (and other code) doesn't ha...

Updated: 2026-07-27
CVE-2026-63938CVSS 9.3Linux

CVE-2026-63938

In the Linux kernel, the following vulnerability has been resolved: KVM: SEV: Check PSC request indices against the actual size of the buffer When processing Page State Change (PSC) requests, validate the PSC buffer against the effective size of the scrat...

Updated: 2026-07-27
CVE-2026-64106CVSS 9.0Linux

CVE-2026-64106

In the Linux kernel, the following vulnerability has been resolved: KVM: arm64: vgic-its: Reject restored DTE with out-of-range num_eventid_bits Userspace can restore an ITS Device Table Entry whose Size field encodes more EventID bits than the virtual IT...

Updated: 2026-07-20
CVE-2026-64247CVSS 8.4Linux

CVE-2026-64247

In the Linux kernel, the following vulnerability has been resolved: KVM: x86: hyper-v: Bound the bank index when querying sparse banks When checking if a VP ID is included in a sparse bank set, explicitly check that the ID can actually be contained in a s...

Updated: 2026-07-27
CVE-2026-46242CVSS 7.8Linux

CVE-2026-46242: linux kernel vulnerability

In the Linux kernel, the following vulnerability has been resolved: eventpoll: fix ep_remove struct eventpoll / struct file UAF ep_remove() (via ep_remove_file()) cleared file->f_ep under file->f_lock but then kept using @file inside the critical section ...

Updated: 2026-07-24
CVE-2026-46300CVSS 7.8Linux

CVE-2026-46300: linux kernel vulnerability

In the Linux kernel, the following vulnerability has been resolved: net: skbuff: preserve shared-frag marker during coalescing skb_try_coalesce() can attach paged frags from @from to @to. If @from has SKBFL_SHARED_FRAG set, the resulting @to skb can cont...

Updated: 2026-07-23
CVE-2026-23455CVSS 9.1Linux

CVE-2026-23455: linux kernel vulnerability

In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_conntrack_h323: check for zero length in DecodeQ931() In DecodeQ931(), the UserUserIE code path reads a 16-bit length from the packet, then decrements it by 1 to skip the pr...

Updated: 2026-07-24
CVE-2021-47274CVSS 9.8Linux

CVE-2021-47274: linux kernel vulnerability

In the Linux kernel, the following vulnerability has been resolved: tracing: Correct the length check which causes memory corruption We've suffered from severe kernel crashes due to memory corruption on our production environment, like, Call Trace: [1640...

Updated: 2026-06-17
CVE-2024-36031CVSS 9.8Linux

CVE-2024-36031: linux kernel vulnerability

In the Linux kernel, the following vulnerability has been resolved: keys: Fix overwrite of key expiration on instantiation The expiry time of a key is unconditionally overwritten during instantiation, defaulting to turn it permanent. This causes a problem...

Updated: 2026-06-17
CVE-2026-63888CVSS 9.8Linux

CVE-2026-63888

In the Linux kernel, the following vulnerability has been resolved: scsi: target: iscsi: Fix CRC overread and double-free in iscsit_handle_text_cmd() Two latent bugs in the Text-phase handler, both present since the original LIO integration in commit e483...

Updated: 2026-07-27
CVE-2026-63887CVSS 9.8Linux

CVE-2026-63887

In the Linux kernel, the following vulnerability has been resolved: scsi: target: iscsi: Bound iscsi_encode_text_output() appends to rsp_buf iscsi_encode_text_output() concatenates "key=value\0" records into login->rsp_buf, an 8192-byte kzalloc(MAX_KEY_VA...

Updated: 2026-07-27
CVE-2026-53176CVSS 9.8Linux

CVE-2026-53176: linux kernel vulnerability

In the Linux kernel, the following vulnerability has been resolved: IB/isert: Reject login PDUs shorter than ISER_HEADERS_LEN In drivers/infiniband/ulp/isert/ib_isert.c, isert_login_recv_done() computes the login request payload length as wc->byte_len min...

Updated: 2026-07-15
CVE-2026-64320CVSS 9.1Linux

CVE-2026-64320

In the Linux kernel, the following vulnerability has been resolved: nvmet: fix pre-auth out-of-bounds heap read in Discovery Get Log Page nvmet_execute_disc_get_log_page() validates only the dword alignment of the host-supplied Log Page Offset (lpo). The...

Updated: 2026-07-27
CVE-2026-63912CVSS 9.8Linux

CVE-2026-63912

In the Linux kernel, the following vulnerability has been resolved: xfrm: esp: restore combined single-frag length gate The ESP out-of-place fast path appends the trailer in esp_output_head() before esp_output_tail() allocates the destination page frag. T...

Updated: 2026-07-27
CVE-2026-64268CVSS 9.8Linux

CVE-2026-64268

In the Linux kernel, the following vulnerability has been resolved: RDMA/siw: bound Read Response placement to the RREAD length In drivers/infiniband/sw/siw/siw_qp_rx.c, siw_proc_rresp() places each inbound Read Response DDP segment at sge->laddr + wqe->p...

Updated: 2026-07-27
CVE-2026-63924CVSS 9.8Linux

CVE-2026-63924

In the Linux kernel, the following vulnerability has been resolved: ipv6: exthdrs: refresh nh pointer after ipv6_hop_jumbo() ipv6_hop_jumbo() calls pskb_trim_rcsum(), which can change skb pointers. Let's recompute nh pointer to make sure any change won't ...

Updated: 2026-07-27
CVE-2026-63922CVSS 9.8Linux

CVE-2026-63922

In the Linux kernel, the following vulnerability has been resolved: ipv6: exthdrs: refresh nh after handling HAO option ip6_parse_tlv() caches skb_network_header(skb) in nh while walking IPv6 TLVs. ipv6_dest_hao() may call pskb_expand_head() for a cloned...

Updated: 2026-07-28
CVE-2026-64269CVSS 9.1Linux

CVE-2026-64269

In the Linux kernel, the following vulnerability has been resolved: RDMA/rtrs-srv: Bound RDMA-Write length to chunk size in rdma_write_sg When the server answers an RTRS READ, rdma_write_sg() builds the source scatter/gather entry for the IB_WR_RDMA_WRITE...

Updated: 2026-07-27
CVE-2026-64303CVSS 9.8Linux

CVE-2026-64303

In the Linux kernel, the following vulnerability has been resolved: spi: fsl-lpspi: terminate the RX channel on TX prepare failure path When dmaengine_prep_slave_sg() fails for the TX channel, the error path terminates the TX DMA channel but leaves the RX...

Updated: 2026-07-27
CVE-2026-46195CVSS 9.8Linux

CVE-2026-46195: linux kernel vulnerability

In the Linux kernel, the following vulnerability has been resolved: smb: client: validate dacloffset before building DACL pointers parse_sec_desc(), build_sec_desc(), and the chown path in id_mode_to_cifs_acl() all add the server-supplied dacloffset to pn...

Updated: 2026-07-15
CVE-2026-64257CVSS 9.1Linux

CVE-2026-64257

In the Linux kernel, the following vulnerability has been resolved: smb: client: reject overlapping data areas in SMB2 responses Commit 53b7c271f06b ("smb: client: restrict implied bcc[0] exemption to responses without data area") restricted the implied b...

Updated: 2026-07-27
CVE-2026-63886CVSS 9.8Linux

CVE-2026-63886

In the Linux kernel, the following vulnerability has been resolved: scsi: target: iscsi: Validate CHAP_R length before base64 decode chap_server_compute_hash() allocates client_digest as kzalloc(chap->digest_size) and then, for BASE64-encoded responses, p...

Updated: 2026-07-27
CVE-2026-43186CVSS 9.8Linux

CVE-2026-43186: linux kernel vulnerability

In the Linux kernel, the following vulnerability has been resolved: ipv6: ioam: fix heap buffer overflow in __ioam6_fill_trace_data() On the receive path, __ioam6_fill_trace_data() uses trace->nodelen to decide how much data to write for each node. It tru...

Updated: 2026-06-17

Security newsletter

Get new CVE alerts before they become an incident

We send selected infrastructure threats in English, with practical notes for DataHouse environments.

  • DataHouse: server administration and secure cloud
  • Hostilla.pl: hosting and mail services
  • SecDNS.pl: free DNS security layer