87,929 indexed
CVECVE vulnerabilities
87,929 CVEs indexed — newest first. Filter by CVSS severity or CISA KEV listing; KEV-flagged entries surface a rose pill. Authored by Adam Lundqvist.
Showing 601–650 of 87,929 · page 13 of 1759
| ID | Title | Summary |
|---|---|---|
| CVE-2026-97944 | CVE-2026-97944 | In the Linux kernel, the following vulnerability has been resolved: x86/cfi: Fix FineIBT hash offset in cfi_get_func_hash() The switch of the FineIBT preambl… |
| CVE-2026-97943 | CVE-2026-97943 | In the Linux kernel, the following vulnerability has been resolved: x86/mm/pat: Acquire init_mm write lock on collapse to avoid UAF x86 implements page attri… |
| CVE-2026-97942 | CVE-2026-97942 | In the Linux kernel, the following vulnerability has been resolved: x86/alternatives: Exclude text poking against change_page_attr() From time to time, the f… |
| CVE-2026-97941 | CVE-2026-97941 CVSS 7.8 | In the Linux kernel, the following vulnerability has been resolved: mm/slab: take n->list_lock in __slab_try_return_freelist() to avoid race Commit ba7425312… |
| CVE-2026-97940 | CVE-2026-97940 CVSS 7.8 | In the Linux kernel, the following vulnerability has been resolved: ipv6: fix fib6 walker UAF on seq stop ipv6_route_iter_active() treats a walker in FWS_U a… |
| CVE-2026-9794 | CVE-2026-9794 CVSS 5.3redhat | A flaw was found in Keycloak. A remote, unauthenticated attacker can exploit this vulnerability by sending specially crafted SOAP requests to the SAML ECP (Sec… |
| CVE-2026-97939 | CVE-2026-97939 | In the Linux kernel, the following vulnerability has been resolved: ipmr: account multicast table and route memory A netadmin in a user+net namespace can cre… |
| CVE-2026-97938 | CVE-2026-97938 | In the Linux kernel, the following vulnerability has been resolved: reboot: fix cad_pid use-after-free race cad_pid is a single kernel-wide struct pid pointe… |
| CVE-2026-97937 | CVE-2026-97937 CVSS 7.8 | In the Linux kernel, the following vulnerability has been resolved: ftrace: fork: Initialize function graph state before copy_exec_state() dup_task_struct() … |
| CVE-2026-97936 | CVE-2026-97936 | In the Linux kernel, the following vulnerability has been resolved: tracing: Fix memory corruption from the histogram stacktrace modifier parse_field() sets … |
| CVE-2026-97935 | CVE-2026-97935 | In the Linux kernel, the following vulnerability has been resolved: tracing: Set the trace clock before registering the histogram trigger hist_register_trigg… |
| CVE-2026-97934 | CVE-2026-97934 | In the Linux kernel, the following vulnerability has been resolved: tracing: Fix memory corruption from a "STACKTRACE" histogram key "cpu", "CPU", "stacktrac… |
| CVE-2026-97933 | CVE-2026-97933 | In the Linux kernel, the following vulnerability has been resolved: tracing: Take trace_array reference when opening a tracer options file When a tracer opti… |
| CVE-2026-97932 | CVE-2026-97932 | In the Linux kernel, the following vulnerability has been resolved: tracing: Don't dereference trace_event_file in deferred trigger free The enable_event tri… |
| CVE-2026-97931 | CVE-2026-97931 CVSS 7.0 | In the Linux kernel, the following vulnerability has been resolved: ALSA: us122l: Prevent write upgrades for read mappings The hwdep mmap callback rejects re… |
| CVE-2026-97930 | CVE-2026-97930 | In the Linux kernel, the following vulnerability has been resolved: ALSA: usbusx2y: fix in04_last array size mismatch with in04_buf The in04_last array in st… |
| CVE-2026-9793 | CVE-2026-9793 CVSS 5.9redhat | A flaw was found in Keycloak. When a JSON Web Encryption (JWE) encrypted request object is submitted, Keycloak may incorrectly process unsigned claims if the d… |
| CVE-2026-97929 | CVE-2026-97929 | In the Linux kernel, the following vulnerability has been resolved: ALSA: usbusx2y: validate URB actual_length in interrupt callback i_usx2y_in04_int() proce… |
| CVE-2026-97928 | CVE-2026-97928 | In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu: skip the VMID 0 flush for VRAM Clear-on-release only runs on VRAM, which amdg… |
| CVE-2026-97927 | CVE-2026-97927 | In the Linux kernel, the following vulnerability has been resolved: ufs: create the root dentry after loading cylinder metadata ufs_fill_super() installed sb… |
| CVE-2026-97926 | CVE-2026-97926 CVSS 7.0 | In the Linux kernel, the following vulnerability has been resolved: ufs: validate cylinder group metadata before caching it ufs_read_cylinder() copies the cy… |
| CVE-2026-97925 | CVE-2026-97925 | In the Linux kernel, the following vulnerability has been resolved: tick/broadcast: Plug clockevents replacement race 朱恺乾 reported and decoded the following … |
| CVE-2026-97924 | CVE-2026-97924 | In the Linux kernel, the following vulnerability has been resolved: tracing/user_events: Don't destroy fields when event removal fails destroy_user_event() d… |
| CVE-2026-97923 | CVE-2026-97923 | In the Linux kernel, the following vulnerability has been resolved: tracing: Free histogram the var ref when its initialization fails create_var_ref() alloca… |
| CVE-2026-97922 | CVE-2026-97922 | In the Linux kernel, the following vulnerability has been resolved: tracing: Free histogram var refs regardless of how often they are referenced Using the sa… |
| CVE-2026-97921 | CVE-2026-97921 | In the Linux kernel, the following vulnerability has been resolved: tracing: Free histogram the field rejected for a bad modifier Writing a hist trigger whos… |
| CVE-2026-97920 | CVE-2026-97920 | In the Linux kernel, the following vulnerability has been resolved: tracing: Keep the entry count when the histogram stats allocation fails print_entries() u… |
| CVE-2026-9792 | CVE-2026-9792 CVSS 6.5redhat | A flaw was found in Keycloak's Client Policies, specifically within the `org.keycloak.protocol.oidc` component. When certain condition providers (client-type, … |
| CVE-2026-97919 | CVE-2026-97919 | In the Linux kernel, the following vulnerability has been resolved: tracing: Take the reference before publishing the named histogram trigger event_hist_trig… |
| CVE-2026-97918 | CVE-2026-97918 | In the Linux kernel, the following vulnerability has been resolved: tracing: Undo the registration when enabling the histogram trigger fails Commit 6f86bdeab… |
| CVE-2026-97917 | CVE-2026-97917 | In the Linux kernel, the following vulnerability has been resolved: accel/ivpu: Validate full buffer range in ivpu_to_cpu_addr Add a size parameter to ivpu_t… |
| CVE-2026-97916 | CVE-2026-97916 | In the Linux kernel, the following vulnerability has been resolved: accel/ivpu: Validate firmware log buffer metadata The tracing log headers parsed by fw_lo… |
| CVE-2026-97915 | CVE-2026-97915 | In the Linux kernel, the following vulnerability has been resolved: accel/ivpu: Limit firmware log name prints to field size The name in struct vpu_tracing_b… |
| CVE-2026-97914 | CVE-2026-97914 | In the Linux kernel, the following vulnerability has been resolved: accel: ethosu: Fix ethosu_job_open() return value A WARN_ON() returns a 0 or 1, not the o… |
| CVE-2026-97913 | CVE-2026-97913 | In the Linux kernel, the following vulnerability has been resolved: accel: ethosu: Ensure cmd stream ends with a stop op While the QSIZE register setting sho… |
| CVE-2026-97912 | CVE-2026-97912 | In the Linux kernel, the following vulnerability has been resolved: accel: ethosu: Ensure SRAM size is 0 on mapping failure On a mapping failure of the SRAM,… |
| CVE-2026-97911 | CVE-2026-97911 CVSS 7.8 | In the Linux kernel, the following vulnerability has been resolved: accel: ethosu: Ensure SRAM region size matches job It is possible for userspace to set th… |
| CVE-2026-97910 | CVE-2026-97910 CVSS 7.8 | In the Linux kernel, the following vulnerability has been resolved: ASoC: sprd: validate compress buffer sizes against fixed allocations sprd_platform_compr_… |
| CVE-2026-9791 | CVE-2026-9791 CVSS 4.3redhat | A flaw was found in Keycloak. An authenticated user with existing organization membership can exploit this flaw by accessing user-facing APIs, such as the acco… |
| CVE-2026-97909 | CVE-2026-97909 | In the Linux kernel, the following vulnerability has been resolved: ASoC: sti: initialize IRQ lock before requesting IRQ uni_reader_init() registers the shar… |
| CVE-2026-97908 | CVE-2026-97908 | In the Linux kernel, the following vulnerability has been resolved: Bluetooth: btqcomsmd: destroy RPMsg endpoints before freeing hci_dev The command and ACL … |
| CVE-2026-97907 | CVE-2026-97907 | In the Linux kernel, the following vulnerability has been resolved: Bluetooth: btrtl: Don't leak return code when parsing firmware format v2 When key_id from… |
| CVE-2026-97906 | CVE-2026-97906 | In the Linux kernel, the following vulnerability has been resolved: bootconfig: Fix integer overflow in initrd size check Sashiko reported that in get_boot_c… |
| CVE-2026-97905 | CVE-2026-97905 | In the Linux kernel, the following vulnerability has been resolved: cpufreq: zero-initialize policy cpumask before sysfs publication cpufreq_policy_alloc() a… |
| CVE-2026-97904 | CVE-2026-97904 | In the Linux kernel, the following vulnerability has been resolved: cpufreq: initialize policy rwsem before sysfs publication cpufreq_policy_alloc() initiali… |
| CVE-2026-97903 | CVE-2026-97903 CVSS 7.8 | In the Linux kernel, the following vulnerability has been resolved: exit: hold a reference to thread_pid across proc_flush_pid Commit 0a36bad01731 ("release_… |
| CVE-2026-97902 | CVE-2026-97902 | In the Linux kernel, the following vulnerability has been resolved: fs: don't return -EINVAL for successful nested thaw Commit 7366f8b6fc6a ("fs: handle free… |
| CVE-2026-97901 | CVE-2026-97901 | In the Linux kernel, the following vulnerability has been resolved: genetlink: pin family module during policy dump The generic netlink controller's policy d… |
| CVE-2026-97900 | CVE-2026-97900 | In the Linux kernel, the following vulnerability has been resolved: drm/drm_exec: fix up contended obj when num_objects is 0 drm_exec_prepare_array() silentl… |
| CVE-2026-97899 | CVE-2026-97899 | In the Linux kernel, the following vulnerability has been resolved: drm/i915: Fix memory leak in query_perf_config_list() When krealloc() fails, free the ori… |