Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
29988
Total
2361
Critical
8982
High
9341
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-43448 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: nvme-pci: Fix race bug in nvme_poll_irqdisable() In the following scenario, pdev can be disabled between … | May 08, 2026 |
| CVE-2026-43447 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: iavf: fix PTP use-after-free during reset Commit 7c01dbfc8a1c5f ("iavf: periodically cache PHC time") introduced a … | May 08, 2026 |
| CVE-2026-43446 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: accel/amdxdna: Fix runtime suspend deadlock when there is pending job The runtime suspend callback drains … | May 08, 2026 |
| CVE-2026-43445 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: e1000/e1000e: Fix leak in DMA error cleanup If an error is encountered while mapping TX … | May 08, 2026 |
| CVE-2026-43444 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: drm/amdkfd: Unreserve bo if queue update failed Error handling path should unreserve bo then return … | May 08, 2026 |
| CVE-2026-43443 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: ASoC: amd: acp-mach-common: Add missing error check for clock acquisition The acp_card_rt5682_init() and acp_card_rt5682s_init() functions … | May 08, 2026 |
| CVE-2026-43442 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: io_uring: fix physical SQE bounds check for SQE_MIXED 128-byte ops When IORING_SETUP_SQE_MIXED is used without … | May 08, 2026 |
| CVE-2026-43441 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: net: bonding: Fix nd_tbl NULL dereference when IPv6 is disabled When booting with the 'ipv6.disable=1' … | May 08, 2026 |
| CVE-2026-43440 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: net/mana: Null service_wq on setup error to prevent double destroy In mana_gd_setup() error path, set … | May 08, 2026 |
| CVE-2026-43439 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: cgroup: fix race between task migration and iteration When a task is migrated out of … | May 08, 2026 |
| CVE-2026-43438 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: sched_ext: Remove redundant css_put() in scx_cgroup_init() The iterator css_for_each_descendant_pre() walks the cgroup hierarchy under cgroup_lock(). … | May 08, 2026 |
| CVE-2026-43437 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: ALSA: pcm: fix use-after-free on linked stream runtime in snd_pcm_drain() In the drain loop, the … | May 08, 2026 |
| CVE-2026-43436 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: ALSA: usb-audio: Check endpoint numbers at parsing Scarlett2 mixer interfaces The Scarlett2 mixer quirk in … | May 08, 2026 |
| CVE-2026-43435 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: rust_binder: fix oneway spam detection The spam detection logic in TreeRange was executed before the … | May 08, 2026 |
| CVE-2026-43434 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: rust_binder: check ownership before using vma When installing missing pages (or zapping them), Rust Binder … | May 08, 2026 |
| CVE-2026-43433 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: rust_binder: avoid reading the written value in offsets array When sending a transaction, its offsets … | May 08, 2026 |
| CVE-2026-43432 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: usb: xhci: Fix memory leak in xhci_disable_slot() xhci_alloc_command() allocates a command structure and, when the … | May 08, 2026 |
| CVE-2026-43431 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: xhci: Fix NULL pointer dereference when reading portli debugfs files Michal reported and debgged a … | May 08, 2026 |
| CVE-2026-43430 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: usb: yurex: fix race in probe The bbu member of the descriptor must be set … | May 08, 2026 |
| CVE-2026-43429 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: USB: usbtmc: Use usb_bulk_msg_killable() with user-specified timeouts The usbtmc driver accepts timeout values specified by … | May 08, 2026 |
| CVE-2026-43428 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: USB: core: Limit the length of unkillable synchronous timeouts The usb_control_msg(), usb_bulk_msg(), and usb_interrupt_msg() APIs … | May 08, 2026 |
| CVE-2026-43427 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: usb: class: cdc-wdm: fix reordering issue in read code path Quoting the bug report: Due … | May 08, 2026 |
| CVE-2026-43426 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: usb: renesas_usbhs: fix use-after-free in ISR during device removal In usbhs_remove(), the driver frees resources … | May 08, 2026 |
| CVE-2026-43425 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: usb: image: mdc800: kill download URB on timeout mdc800_device_read() submits download_urb and waits for completion. … | May 08, 2026 |
| CVE-2026-43424 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: usb: gadget: f_tcm: Fix NULL pointer dereferences in nexus handling The `tpg->tpg_nexus` pointer in the … | May 08, 2026 |