Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
46228
Total
3680
Critical
13668
High
13614
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-72306 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: vduse: Fix race in vduse_dev_msg_sync and vduse_dev_read_iter There is one race case in vduse_dev_msg_sync and … | Aug 15, 2026 |
| CVE-2026-72305 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: VDUSE: avoid leaking information to userspace The bounceing is not necessarily page aligned, so current … | Aug 15, 2026 |
| CVE-2026-72304 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: ASoC: SOF: ipc4-control: Fix TOCTOU in sof_ipc4_bytes_put In sof_ipc4_bytes_put(), the copy size is derived from … | Aug 15, 2026 |
| CVE-2026-72303 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: ASoC: SOF: ipc4-control: Validate notification payload size Validate MODULE_NOTIFICATION payload length before reading bytes/channel data … | Aug 15, 2026 |
| CVE-2026-72302 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: ASoC: SOF: ipc3-control: Use overflow checks in control_update size calc In sof_ipc3_control_update(), the expected_size calculation … | Aug 15, 2026 |
| CVE-2026-72301 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: ASoC: SOF: ipc3-control: Fix TOCTOU in bytes_put and bytes_get In sof_ipc3_bytes_put(), the size used for … | Aug 15, 2026 |
| CVE-2026-72300 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: ASoC: SOF: topology: validate vendor array size before parsing sof_parse_token_sets() reads array->size while iterating over … | Aug 15, 2026 |
| CVE-2026-72299 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: tipc: restrict socket queue dumps in enqueue tracepoints tipc_sk_enqueue() runs with sk->sk_lock.slock held while the … | Aug 15, 2026 |
| CVE-2026-72298 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: net: qrtr: fix 32-bit integer overflow in qrtr_endpoint_post() qrtr_endpoint_post() validates an incoming packet with if … | Aug 15, 2026 |
| CVE-2026-72297 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: net: atm: reject out-of-range traffic classes in QoS validation Reject ATM traffic classes above ATM_ANYCLASS … | Aug 15, 2026 |
| CVE-2026-72296 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: net: ife: require ETH_HLEN to be pullable in ife_decode() ife decode may return after making … | Aug 15, 2026 |
| CVE-2026-72295 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: LoongArch: KVM: Validate irqchip index in irqfd routing Sashiko reported that the irqchip index is … | Aug 15, 2026 |
| CVE-2026-72294 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: LoongArch: KVM: Check irq validity in kvm_vcpu_ioctl_interrupt() Function kvm_vcpu_ioctl_interrupt() can be called from userspace, here … | Aug 15, 2026 |
| CVE-2026-72293 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: KVM: s390: vsie: Add missing radix_tree_preload() in _gaccess_shadow_fault() Add missing radix_tree_preload() in _gaccess_shadow_fault() to guarantee … | Aug 15, 2026 |
| CVE-2026-72292 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: KVM: s390: Initialize KVM_S390_GET_CMMA_BITS memory kvm_s390_get_cmma_bits() allocates its output buffer with vmalloc(), which does not … | Aug 15, 2026 |
| CVE-2026-72291 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: KVM: s390: Fix unlikely race in try_get_locked_pte() Fix an unlikely race in try_get_locked_pte(), which could … | Aug 15, 2026 |
| CVE-2026-72290 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: KVM: s390: pci: Fix GISC refcount leak on AIF enable failure kvm_s390_gisc_register() registers the guest … | Aug 15, 2026 |
| CVE-2026-72289 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: KVM: arm64: vgic: Check the interrupt is still ours before migrating it vgic_prune_ap_list() drops both … | Aug 15, 2026 |
| CVE-2026-72288 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: KVM: arm64: vgic: Handle race between interrupt affinity change and LPI disabling Hyunwoo Kim reports … | Aug 15, 2026 |
| CVE-2026-72287 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: KVM: nVMX: Move vTPR vs. TPR Threshold consistency check into "normal" checks Move the off-by-default … | Aug 15, 2026 |
| CVE-2026-72286 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: KVM: SEV: Do not allow intra-host migration/mirroring of SNP VMs The intra-host migration/mirroring feature is … | Aug 15, 2026 |
| CVE-2026-72285 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: KVM: TDX: Reject concurrent change to CPUID entry count Reject KVM_TDX_INIT_VM if userspace changes cpuid.nent … | Aug 15, 2026 |
| CVE-2026-72284 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: KVM: x86: Ignore pending PV EOI if the vCPU has since disabled PV EOIs Ignore … | Aug 15, 2026 |
| CVE-2026-72283 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: KVM: x86: Nullify irqfd->producer if updating IRTE for bypass fails Nullify irqfd->producer if updating the … | Aug 15, 2026 |
| CVE-2026-72282 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: KVM: Move kvm_io_bus_get_dev() locking responsibilities to callers kvm_io_bus_get_dev() returns a device that is only matched … | Aug 15, 2026 |