← All tracked CVEs
Updated 09:00
last 30 days
933 fixed within SLA
| CVE | Status | Severity | Summary | Release | Clock started | Deadline | Fixed | Time to fix |
|---|---|---|---|---|---|---|---|---|
| Fixed within SLA | Medium | PowerPC64: PMD migration/munmap race causes VM_BUG_ON in pmdp_huge_get_and_clear_full | secure-packages-26.05 | Jul 27, 2026 | Sep 10, 2026 | Aug 11, 2026 | 15 days | |
| Fixed within SLA | High | Use-after-free when filling offloaded BPF map/prog info due to netns teardown race | secure-packages-26.05 | Jul 27, 2026 | Aug 11, 2026 | Aug 11, 2026 | 15 days | |
| Fixed within SLA | Medium | Linux kernel ice driver TX timestamp ring cleanup race causes NULL dereference | secure-packages-26.05 | Jul 16, 2026 | Aug 30, 2026 | Aug 11, 2026 | 26 days | |
| Fixed within SLA | Medium | Potential NULL dereference in ice_set_ringparam error path due to uncleared ICE_TX_RING_FLAGS_TXTIME | secure-packages-26.05 | Jul 16, 2026 | Aug 30, 2026 | Aug 11, 2026 | 26 days | |
| Fixed within SLA | Critical | secure-packages-rolling | Aug 10, 2026 | Aug 17, 2026 | Aug 11, 2026 | 1 day | ||
| Fixed within SLA | High | GSO headers not in skb->head during qdisc init, risking tso_build_hdr memcpy misuse | secure-packages-25.11 | Jul 27, 2026 | Aug 11, 2026 | Aug 11, 2026 | 15 days | |
| Fixed within SLA | High | fbcon_do_set_font error rollback misses hi_font state restore, causing out-of-bounds font reads | secure-packages-25.11 | Aug 4, 2026 | Aug 19, 2026 | Aug 10, 2026 | 6 days | |
| Fixed within SLA | Critical | nfsd setlease failure frees layout stid without idr_remove, causing IDR dangling pointer dereference | secure-packages-25.11 | Aug 4, 2026 | Aug 11, 2026 | Aug 10, 2026 | 6 days | |
| Fixed within SLA | High | NFSv4 flexfiles ff_layout_alloc_lseg accepts zero fh_count, causing NULL pointer dereference | secure-packages-25.11 | Aug 4, 2026 | Aug 19, 2026 | Aug 10, 2026 | 6 days | |
| Fixed within SLA | Medium | vsock/virtio zerocopy multi-skb sends miss completion tracking, leaking pinned pages, no notification | secure-packages-25.11 | Jul 23, 2026 | Sep 6, 2026 | Aug 10, 2026 | 18 days | |
| Fixed within SLA | Medium | Phonet: pn_socket_autobind BUG_ON on EINVAL bind causes user-triggerable kernel panic | secure-packages-25.11 | Jul 9, 2026 | Aug 23, 2026 | Aug 10, 2026 | 32 days | |
| Fixed within SLA | Medium | Rockchip GPIO: generic IRQ chips leaked on remove, causing potential UAF and crashes | secure-packages-25.11 | Jul 6, 2026 | Aug 20, 2026 | Aug 10, 2026 | 35 days | |
| Fixed within SLA | Medium | NTFS3: Missing vcn0 run load causes SPARSE_LCN and WARN_ON in attr_data_get_block_locked | secure-packages-25.11 | Jul 17, 2026 | Aug 31, 2026 | Aug 10, 2026 | 24 days | |
| Fixed within SLA | Medium | drm/v3d infinite loop via empty multisync extension; userspace self-referential chain DoS | secure-packages-25.11 | Jul 9, 2026 | Aug 23, 2026 | Aug 10, 2026 | 32 days | |
| Fixed within SLA | Medium | ImageMagick <7.1.2-27 magick CLI memory leak on malformed options causes DoS | secure-packages-rolling | Aug 5, 2026 | Sep 19, 2026 | Aug 10, 2026 | 5 days | |
| Fixed within SLA | Medium | Crafted image triggers heap buffer over-read in ImageMagick BGR decoder pre-7.1.2-27 | secure-packages-rolling | Aug 4, 2026 | Sep 18, 2026 | Aug 10, 2026 | 6 days | |
| Fixed within SLA | High | KVM: Missing memslot bounds check causes OOB lpage_info access during hugepage recovery | secure-packages-rolling | Aug 4, 2026 | Aug 19, 2026 | Aug 10, 2026 | 6 days | |
| Fixed within SLA | High | Guest-triggered kernel BUG via unaligned ioeventfd datamatch on KVM page-split MMIO | secure-packages-rolling | Aug 4, 2026 | Aug 19, 2026 | Aug 10, 2026 | 6 days | |
| Fixed within SLA | High | Linux nx crypto: kernel oops from wrong ctx type passed to nx_crypto_ctx_exit | secure-packages-rolling | Aug 4, 2026 | Aug 19, 2026 | Aug 10, 2026 | 6 days | |
| Fixed within SLA | High | gfs2: use-after-free in gfs2_qd_dealloc when superblock freed before RCU callbacks finish | secure-packages-rolling | Aug 4, 2026 | Aug 19, 2026 | Aug 10, 2026 | 6 days | |
| Fixed within SLA | High | Use-after-free from PPP protocol timers when HDLC state is freed during detach | secure-packages-rolling | Aug 4, 2026 | Aug 19, 2026 | Aug 10, 2026 | 6 days | |
| Fixed within SLA | High | Use-after-free in blk-cgroup __blkcg_rstat_flush via llist_del_all during concurrent blkg releases | secure-packages-rolling | Aug 4, 2026 | Aug 19, 2026 | Aug 10, 2026 | 6 days | |
| Fixed within SLA | High | TIPC decrypt async completion UAF from missing netns ref when crypto_aead_decrypt offloaded | secure-packages-rolling | Aug 4, 2026 | Aug 19, 2026 | Aug 10, 2026 | 6 days | |
| Fixed within SLA | Critical | Use-after-free in pNFS pnfs_update_layout() tracepoint after freeing lo with pnfs_put_layout_hdr | secure-packages-rolling | Aug 4, 2026 | Aug 11, 2026 | Aug 10, 2026 | 6 days | |
| Fixed within SLA | High | sched/mmcid: OOB clear_bit from MM_CID_UNSET during per-CPU CID fixup | secure-packages-rolling | Aug 4, 2026 | Aug 19, 2026 | Aug 10, 2026 | 6 days | |
| Fixed within SLA | Medium | imgpdc irqchip resource leak and dangling chained handlers cause use-after-free, kernel crashes | secure-packages-rolling | Aug 4, 2026 | Sep 18, 2026 | Aug 10, 2026 | 6 days | |
| Fixed within SLA | High | rpmsg char: callbacks use freed eptdev after probe failure due to stale priv | secure-packages-rolling | Aug 4, 2026 | Aug 19, 2026 | Aug 10, 2026 | 6 days | |
| Fixed within SLA | High | OCFS2 accepts oversized group bitmap descriptors causing OOB bitmap access and use-after-free | secure-packages-rolling | Aug 4, 2026 | Aug 19, 2026 | Aug 10, 2026 | 6 days | |
| Fixed within SLA | Critical | 9p p9_client_walk error drops oldfid reference when clone=false, causing UAF/refcount underflow | secure-packages-rolling | Aug 4, 2026 | Aug 11, 2026 | Aug 10, 2026 | 6 days | |
| Fixed within SLA | High | KVM SVM unbounded destination offset causes page overflow and memcpy overrun in sev_dbg_crypt ENCRYPT | secure-packages-rolling | Aug 4, 2026 | Aug 19, 2026 | Aug 10, 2026 | 6 days | |
| Fixed within SLA | Medium | ImageMagick JNX parsing integer overflow on 32-bit platforms causes heap buffer overwrite | secure-packages-rolling | Aug 4, 2026 | Sep 18, 2026 | Aug 10, 2026 | 6 days | |
| Fixed within SLA | Medium | Heap buffer overwrite in ImageMagick fx operation via crafted argument before 7.1.2-27 | secure-packages-rolling | Aug 4, 2026 | Sep 18, 2026 | Aug 10, 2026 | 6 days | |
| Fixed within SLA | Medium | fbdev: fb_videomode_to_var NULL deref when new modelist omits current mode | secure-packages-rolling | Aug 4, 2026 | Sep 18, 2026 | Aug 10, 2026 | 6 days | |
| Fixed within SLA | High | fbcon_do_set_font err_out misses hi_font rollback, enabling OOB read/memory leak | secure-packages-rolling | Aug 4, 2026 | Aug 19, 2026 | Aug 10, 2026 | 6 days | |
| Fixed within SLA | High | i2c core adapter registration race causes i2c_get_adapter to access uninitialized device, NULL/UAF | secure-packages-rolling | Aug 4, 2026 | Aug 19, 2026 | Aug 10, 2026 | 6 days | |
| Fixed within SLA | Critical | Use-after-free via IDR leak and uninitialized delayed_work on nfsd layout setlease failure | secure-packages-rolling | Aug 4, 2026 | Aug 11, 2026 | Aug 10, 2026 | 6 days | |
| Fixed within SLA | Critical | NFSD: SECINFO_NO_NAME decode leaves stale sin_exp; exp_put called after truncated XDR | secure-packages-rolling | Aug 4, 2026 | Aug 11, 2026 | Aug 10, 2026 | 6 days | |
| Fixed within SLA | High | nfsd: posix_acl memory leak when SETACL decode fails; pc_release didn't free ACLs | secure-packages-rolling | Aug 4, 2026 | Aug 19, 2026 | Aug 10, 2026 | 6 days | |
| Fixed within SLA | High | Linux nfsd4_create_file ignores ACL conversion errors; leaks posix_acl allocations | secure-packages-rolling | Aug 4, 2026 | Aug 19, 2026 | Aug 10, 2026 | 6 days | |
| Fixed within SLA | High | Dead ACL conflict guard in nfsd4_create leaks posix_acls, causing unbounded slab exhaustion | secure-packages-rolling | Aug 4, 2026 | Aug 19, 2026 | Aug 10, 2026 | 6 days | |
| Fixed within SLA | High | nfsd memory leak: pre-allocated openowner overwritten during unconfirmed owner retry race | secure-packages-rolling | Aug 4, 2026 | Aug 19, 2026 | Aug 10, 2026 | 6 days | |
| Fixed within SLA | Medium | nfsd fails to reset write verifier on deferred writeback errors, causing COMMIT data loss | secure-packages-rolling | Aug 4, 2026 | Sep 18, 2026 | Aug 10, 2026 | 6 days | |
| Fixed within SLA | High | NFSv4/flexfiles accepts zero fh_count, causing ZERO_SIZE_PTR and KASAN null dereference | secure-packages-rolling | Aug 4, 2026 | Aug 19, 2026 | Aug 10, 2026 | 6 days | |
| Fixed within SLA | High | NFSv4/pNFS: zero-length r_addr triggers NULL pointer dereference in nfs4_decode_mp_ds_addr | secure-packages-rolling | Aug 4, 2026 | Aug 19, 2026 | Aug 10, 2026 | 6 days | |
| Fixed within SLA | High | ksmbd: OOB read in smb_check_perm_dacl due to ACE/SID length mismatch | secure-packages-rolling | Aug 4, 2026 | Aug 19, 2026 | Aug 10, 2026 | 6 days | |
| Fixed within SLA | High | Use-after-free in TCP-AO del_async due to dangling current_key/rnext_key on LISTEN sockets | secure-packages-rolling | Aug 4, 2026 | Aug 19, 2026 | Aug 10, 2026 | 6 days | |
| Fixed within SLA | High | Linux kernel IPv4 __ip_append_data paged allocation miscalculates fraggap, causing undersized linear area, overstated pagedlen | secure-packages-rolling | Jul 23, 2026 | Aug 7, 2026 | Aug 7, 2026 | 15 days | |
| Fixed within SLA | High | Unprivileged IPv6 UDP fraggap misaccounting overflows skb in paged allocation using MSG_SPLICE_PAGES | secure-packages-rolling | Jul 23, 2026 | Aug 7, 2026 | Aug 7, 2026 | 15 days | |
| Fixed within SLA | High | af_unix race: unix_gc may run with gc_in_progress false, breaking MSG_PEEK safety | secure-packages-rolling | Jul 23, 2026 | Aug 7, 2026 | Aug 7, 2026 | 15 days | |
| Fixed within SLA | High | KVM x86 shadow paging UAF due to child page role mismatch after PDE change | secure-packages-rolling | Jul 23, 2026 | Aug 7, 2026 | Aug 7, 2026 | 15 days |