Database/Kernel, userspace & hypervisor
Linux kernel and hypervisor vulnerabilities for GPU hosts
Host kernel, userspace, virtualization, and CPU microcode flaws that break the line between tenant and host: KVM, Xen, QEMU, VMware, and the kernel every GPU node boots.
1,169 entries135 critical48 known exploitedFilter and search this layer
2026605
- Apache MINA SSHD: a server requiring two public keys accepts the same key twice, a partial auth bypassHighSep 30, 2026
- OpenSSL: SSL_set_SSL_CTX mid-handshake leaves a stale slot count, allowing heap OOB read/writeHighSep 29, 2026
- OpenSSL 4.0: use-after-free in the X.509 extension cache crashes multi-threaded TLS peersHighSep 29, 2026
- OpenSSL QUIC: unthrottled RETIRE_CONNECTION_ID backlog lets a peer force ~400MB of allocationHighSep 29, 2026
- OpenSSL QUIC: missing connection-level flow control lets a peer force ~100MB of heap per connectionMediumSep 29, 2026
- OpenSSL CMP client: NULL dereference when revoking a certificate by PKCS#10 CSRMediumSep 29, 2026
- OpenSSL: non-constant-time SM2 point multiplication on AArch64 and RISC-V leaks key bits via timing and cacheLowSep 29, 2026
- OpenSSL: certificate with many relative-name CRL distribution points inflates heap on TLS handshakeUnscoredSep 29, 2026
- OpenSSL QUIC server: per-packet credit accounting breaks the RFC 9000 3x amplification limitUnscoredSep 29, 2026
- OpenSSL QUIC: quadratic stream reassembly lets a peer burn CPU with in-window framesUnscoredSep 29, 2026
- OpenSSL QUIC: peer controls how long packet buffers stay pinned, inflating memory per streamUnscoredSep 29, 2026
Linux KVM x86/mmu: write tracking checked in one address space only, reaching a kernel BUGUnscoredSep 29, 2026- wolfSSL: trusted-peer matching ignores the public key, so a forged CA clone verifiesHighSep 27, 2026
- Linux cgroup: task iterator can resurrect a zero-refcount dying task, giving a use-after-freeUnscoredSep 26, 2026
- QEMU 9pfs: use-after-free race between Tlcreate and Twalk lets a guest escape the shared directory to host filesHighSep 25, 2026
- Linux kernel qla2xxx: unserialized NVMe-FC unsolicited-context list can be corrupted by concurrent add and deleteHighSep 25, 2026
- Linux kernel qla2xxx: NVMe-FC unsolicited context freed while still linked, leaving a freed node on the listHighSep 25, 2026
- Linux kernel x86/mm/pat: split page tables bypass kernel page table tracking, leaving stale IOTLB entries after freeHighSep 25, 2026
- Linux kernel net/rds: teardown samples RDS_IN_XMIT instead of owning it, racing the transmit path into freed ring stateHighSep 25, 2026
- Linux slab allocator: ABA race in the optimistic freelist return corrupts the partial listHighSep 25, 2026
- Linux AMD IOMMU: sign-discarding error check lets nested domains use an unallocated domain IDHighSep 25, 2026
- Linux qla2xxx: dying NPIV vport re-inserted into host_map during report ID acquisition, causing use-after-freeHighSep 25, 2026
- Linux qla2xxx: pending qpair work runs after response queue teardown, causing use-after-freeHighSep 25, 2026
- Linux nvme: sparse NSID gaps make namespace scan iterate billions of times, causing soft lockupHighSep 25, 2026
- Linux kernel BPF verifier: JMP32 comparisons against zero mispredicted, allowing unsafe pointer arithmeticHighSep 25, 2026
- Linux kernel BPF: per-CPU map updates accept invalid CPU IDs on sparse CPU masks, corrupting kernel memoryHighSep 25, 2026
- Linux kernel nvme-rdma: double cleanup and DMA unmap after request completion on the -EIO pathHighSep 25, 2026
- Linux kernel BPF: tp_btf program dereferencing SEND_SIG_NOINFO can panic the nodeMediumSep 25, 2026
- Linux kernel nvmet-rdma: queue and IB resources leak when the connect backlog is exceededMediumSep 25, 2026
- Linux kernel bpf: BPF_REFCOUNT field was not marked unique in the verifier's field checksUnscoredSep 25, 2026
- Linux kernel qla2xxx: unvalidated FC BSG request length causes out-of-bounds heap readsUnscoredSep 25, 2026
- Linux kernel qla2xxx: FC frame payload aliasing 0xDEADDEAD spins the interrupt handler into a CPU soft lockupUnscoredSep 25, 2026
- Linux qla2xxx: double free and NULL dma_pool use when adapter memory allocation fails at probeUnscoredSep 25, 2026
- Linux kernel qla2xxx: NPIV virtual-port index above 128 writes past the VP control IOCB bitmapUnscoredSep 25, 2026
- Linux qla2xxx: NULL dma_free and mismatched bitmap locking in multiqueue queue teardownUnscoredSep 25, 2026
- Linux kernel io_uring: MSG_TRUNC recv over-advances the provided buffer ringUnscoredSep 25, 2026
- Linux kernel io_uring: deferred write accounting deadlocks a task against filesystem freezeUnscoredSep 25, 2026
- Linux kernel x86/mm: pmd_modify() drops the dirty bit, losing written data on PMD-mapped THPUnscoredSep 25, 2026
- Linux kernel powerpc/eeh: recursive locking hangs the EEH handler during PCI error recoveryUnscoredSep 25, 2026
- Linux LIO iSCSI target: LUN_RESET on a WRITE_PENDING command deadlocks the target worker threadUnscoredSep 25, 2026
- Linux kernel vhost-vdpa: failed eventfd install leaves an ERR_PTR reachable by the config callbackUnscoredSep 25, 2026
- Linux kernel vhost-vdpa: queue size is not checked against the device maximum, giving an out-of-bounds descriptor readUnscoredSep 25, 2026
- Linux kernel BPF verifier (bpf_loop nr_loops argument type): bpf_loop() declared nr_loops as ARG_ANYTHING, so aUnscoredSep 25, 2026
- Linux kernel BPF: bpf_btf_find_by_name_kind() can sleep in softirq context and install an fd into the interrupted taskUnscoredSep 25, 2026
- Linux kernel BPF: bpf_snprintf_btf() on a BTF_KIND_VAR from base BTF NULL-derefs in btf_var_show()UnscoredSep 25, 2026
- Linux kernel BPF: rendering a "const void" BTF type through bpf_snprintf_btf() NULL-derefs a missing show opUnscoredSep 25, 2026
- Linux kernel BPF: a key-less BTF hash map can be created and reading it through bpffs NULL-derefsUnscoredSep 25, 2026
- Linux kernel net/rds: a shutdown consuming a racing drop leaves an accepted socket wedged and never torn downUnscoredSep 25, 2026
- Linux kernel net/rds: a blanket cp_flags store in the connection reset races atomic bitops and discards updatesUnscoredSep 25, 2026
- Linux kernel net/rds: a missing barrier in release_in_xmit() loses the wake-up and strands the RDS shutdown workerUnscoredSep 25, 2026
- Linux kernel BPF: a BPF_PSEUDO_FUNC load of the main program is never relocated, leaving a call to a bogus addressUnscoredSep 25, 2026
- Linux kernel mpt3sas: NUMA_NO_NODE from dev_to_node() causes an out-of-bounds node_to_cpumask_map readUnscoredSep 25, 2026
- Linux kernel mpi3mr: error path in mpi3mr_sas_port_add() leaks a target device referenceUnscoredSep 25, 2026
- Linux kernel mpi3mr: NULL dereference and sas_port leak when SAS port allocation failsUnscoredSep 25, 2026
- Linux kernel SUNRPC server GSS auth (svcauth_gss_decode_credbody): svcauth_gss_decode_credbody() fills the caller'sCriticalSep 24, 2026
- Linux kernel nvme-fc: error recovery iterates an uninitialized IO tagset when admin connect times outHighSep 24, 2026
- Linux kernel virtio-fs: double free of fs->vqs and fs->mq_map when queue setup fails during probeHighSep 24, 2026
- Linux kernel NVMe driver (FDP configurations log parsing): While walking the Flexible Data Placement configurationsHighSep 24, 2026
- Linux kernel nfsd: unserialized grace_ended flag lets two contexts double-free every client reclaim recordHighSep 24, 2026
- Linux vhost-scsi: stale response iovecs after a memory-table change write into unrelated memoryHighSep 24, 2026
- Linux kernel arm-smmu-v3: device teardown frees the IOPF queue before the IRQ handler that uses itUnscoredSep 24, 2026
- Linux kernel PCI/proc: config space read checked against the reader's credentials, not the opener'sUnscoredSep 24, 2026
- Linux kernel BPF: sysctl value replaced by a BPF program is not NUL-terminated, giving out-of-bounds readsUnscoredSep 24, 2026
- Linux kernel net/rds: unprivileged container reads every RDS socket and connection on the hostUnscoredSep 24, 2026
- Linux kernel net/rds: RDS-over-IB shutdown sleeps in a shared worker and hangs fabric teardownUnscoredSep 24, 2026
- Linux PCI sysfs: BAR resize via resourceN_resize had no CAP_SYS_ADMIN checkUnscoredSep 24, 2026
- virtio-win Viosock: integer overflow in the select IOCTL overflows a NonPagedPool array and escalates in the guestHighSep 18, 2026
- Linux kernel qla2xxx: double completion in async IOCB timeout frees a live stack frameCriticalSep 16, 2026
- Linux kernel qla2xxx: NVMe LS reject path advances the request ring without the qpair lockCriticalSep 16, 2026
- Linux kernel nvmet-tcp: over-long PDU writes past the 128-byte receive bufferCriticalSep 16, 2026
- Linux kernel nvmet-auth: use-after-free when auth timeout work races SQ teardownCriticalSep 16, 2026
- Linux kernel nvme: missing SRCU grace period on the namespace-allocation error pathCriticalSep 16, 2026
- Linux kernel CephFS client: use-after-free when an MDS session reopens during an access checkCriticalSep 16, 2026
- Linux kernel NFSD: client use-after-free when the laundromat reaps a blocked lockCriticalSep 16, 2026
- Linux kernel NFSD: client use-after-free when the laundromat reaps close_lru open ownersCriticalSep 16, 2026
- Linux kernel NFSD: client use-after-free when an export is removed during client expiryCriticalSep 16, 2026
- Linux kernel CephFS client: oops decrypting filenames from vmalloc() message buffersCriticalSep 16, 2026
KVM arm64: negative stage-1 walk level mis-sizes VNCR TLB invalidation to zeroCriticalSep 16, 2026
KVM arm64: missing VA sign extension in range-based TLB invalidation decodingCriticalSep 16, 2026
Linux kernel KVM/arm64: VM-wide VNCR mapping counter lets TLB invalidations be missed under nested virtCriticalSep 16, 2026
Linux kernel KVM/arm64: VNCR invalidation races nested page fault and installs a stale TLB entryCriticalSep 16, 2026
Linux kernel KVM/arm64: address rollover at the end of VA space makes TLB invalidation by VA silently failCriticalSep 16, 2026
Linux kernel KVM nVMX: queued TLB flushes skipped when a nested VM-Enter fails, leaving stale VPID mappingsCriticalSep 16, 2026- Linux kernel qla2xxx: unbounded rsp_info_len underflows sense length and leaks adjacent kernel memoryCriticalSep 16, 2026
- Linux kernel iSCSI target: login payload can fill the buffer with no NUL, so CHAP parsing reads past the slabCriticalSep 16, 2026
- Linux kernel vfio/pci: freed MSI permission table left in the device, giving use-after-free and double freeHighSep 16, 2026
- Linux kernel qla2xxx: host_map btree updated without vport_slock in the format-1 path, corrupting the mapHighSep 16, 2026
Linux kernel qla2xxx: unexpected status IOCB for a non-SCSI handle causes a wild pointer dereferenceHighSep 16, 2026- Linux kernel qla2xxx: re-initializing a queued work item on a repeated FC-NVMe abort corrupts the workqueue listHighSep 16, 2026
KVM arm64 vgic-v3: unreferenced LPI iteration lets a freed vgic_irq be dereferenced while saving pending tablesHighSep 16, 2026
KVM x86/mmu: lockless aging walk re-reads the rmap and can follow a pte_list_desc chain being freedHighSep 16, 2026
KVM nVMX: emulated INVVPID can run on the wrong physical CPU, leaving stale L2 TLB entriesHighSep 16, 2026
KVM nVMX: vpid02 is not flushed on first use after VMXOFF/VMXON, reusing another VM's TLB entriesHighSep 16, 2026- Linux kernel dma-direct: dma_direct_alloc_pages() treats a CPU address as a struct page pointerHighSep 16, 2026
- Linux kernel qla2xxx: MSI-X vector count truncates to zero and the driver dereferences ZERO_SIZE_PTRHighSep 16, 2026
- Linux kernel nvme-tcp: a controller can force a host WARN by answering a write with C2HDataHighSep 16, 2026
- Linux kernel qla2xxx: use-after-free when a late response interrupt reaches an already-freed request queueHighSep 16, 2026
- Linux kernel qla2xxx: virtual port used after vport_slock is dropped, allowing a use-after-freeHighSep 16, 2026
Linux kernel KVM/arm64: guest-controlled TLBI Range can overflow the hypervisor's range computationHighSep 16, 2026- Linux kernel perf: use-after-free when an mmap revival races the last munmap, giving local rootHighSep 16, 2026
- Linux kernel BPF: bpf_get_stackid runs get_perf_callchain preemptible, exposing its trace bufferHighSep 16, 2026
- Linux kernel qla2xxx: use-after-free reading 84xx_fw_version during Fibre Channel HBA teardownHighSep 16, 2026
- Linux kernel mm/migrate_device: compound folio at the end of a range writes past the PFN arrayHighSep 16, 2026
- Linux kernel mm/mempolicy: weighted-interleave bulk allocation sleeps in atomic contextHighSep 16, 2026
- Linux kernel megaraid_sas: NVMe PRP list overruns the chain frame and corrupts other in-flight commandsHighSep 16, 2026
- Linux kernel SCSI bsg: TOCTOU on the shared io_uring SQE overflows the SCSI command bufferHighSep 16, 2026
- Linux kernel bsg: sense data copy ignores max_response_len and overruns the user bufferHighSep 16, 2026
- Linux kernel page allocator: unsafe spin_trylock in NMI context on uniprocessor buildsHighSep 16, 2026
- Linux nvmet-tcp: unsolicited H2CData PDU double-completes a command and wedges the targetHighSep 16, 2026
- Linux NVMe host: a positive Identify status is ignored and a zoned queue is set up with zero zone sizeHighSep 16, 2026
- Linux nvme-fc: double free of fabrics options when nvme_add_ctrl() fails during connectHighSep 16, 2026
KVM arm64 vgic-its: guest MAPC with V=0 crashes the host when the VMM saves ITS tablesHighSep 16, 2026
KVM x86 Hyper-V stimer: overflowed deadline livelocks the vCPU thread and stalls RCU on the hostHighSep 16, 2026- Linux qla2xxx: D_Port diagnostics copies uninitialized kernel heap bytes to user spaceUnscoredSep 16, 2026
- PackageKit dnf5 backend: an unprivileged local user can uninstall packages under a simulate flagHighSep 14, 2026
- Linux kernel net/smc: unlocked bitfield sharing corrupts SMC connection state flagsCriticalSep 11, 2026
- Linux kernel SMC-R: use-after-free of the LLC queue entry when adding a second RDMA linkCriticalSep 11, 2026
- Linux NFSD: use-after-free in the inter-server copy mount expiry walkCriticalSep 11, 2026
- Linux NFSD: NFSv2 SETATTR reaches notify_change without a mount write referenceCriticalSep 11, 2026
- Linux NFSD: TOCTOU lets a SETATTR truncate an append-only fileCriticalSep 11, 2026
- Linux iommufd: use-after-free on a borrowed attach handle in the selftest IOPF pathHighSep 11, 2026
- Linux NFSD: NFSv2 SETATTR/CREATE useconds wrap to a bogus tv_nsec on 32-bit serversHighSep 11, 2026
- Linux NFSD: bogus WARN_ON_ONCE fires on NFS re-export lookupsHighSep 11, 2026
- Linux SUNRPC: unchecked percpu_counter_init leaves nfsd running on NULL per-cpu statsHighSep 11, 2026
- Linux NFSD: filecache shutdown race leaks nfsd_file objects and their stateHighSep 11, 2026
- Linux kernel nfsd: use-after-free on the per-net file cache disposal queue during namespace teardownHighSep 11, 2026
- Linux kernel SMC: use-after-free when a splice reader releases RMB pages during concurrent socket closeHighSep 11, 2026
- Linux kernel sunrpc: use-gss-proxy proc entry published before its mutex is initializedHighSep 11, 2026
- Linux kernel nfsd: use-after-free reading NFSv4 compound ops from the rpc_status netlink dumpHighSep 11, 2026
- Linux kernel mm/pagewalk: stale ACTION_AGAIN causes duplicate walk callbacks and an out-of-bounds write via mincore()HighSep 11, 2026
- Linux kernel mm/migrate_device: stale swapcache mapping after folio_free_swap() corrupts folio refcountsHighSep 11, 2026
- Linux kernel mm/mempolicy: device-private PMD from GPU THP migration decoded as a PFN, yielding a bogus folioHighSep 11, 2026
- Linux kernel mm/swap: hibernation slot freed while cached corrupts unrelated processes' memoryHighSep 11, 2026
Linux kernel trusted keys: use-after-free when the trusted-key TPM backend is torn downHighSep 11, 2026- Linux kernel ntb_transport: oversized transmit buffers leak skbs until the host runs out of memoryHighSep 11, 2026
- Linux kernel SUNRPC: gssx decode error paths NULL-deref and leak group_info on the NFS serverHighSep 11, 2026
- Linux kernel nfsd: transports routed to threadless service pools hang the connection indefinitelyHighSep 11, 2026
- Linux kernel nfsd: broken short-write detection writes the next segment at the wrong file offsetHighSep 11, 2026
- Linux kernel nfsd: NFSv4 SETATTR with the special ONE stateid NULL-derefs and oopses the serverHighSep 11, 2026
- Linux kernel nfsd: each failed inter-server COPY leaks an nfsd_file, pinning inode and mountHighSep 11, 2026
- Linux kernel nfsd: race between cpntf publish and OFFLOAD_CANCEL oopses on an uninitialised list headHighSep 11, 2026
- Linux kernel nfsd: clock-domain mismatch lets one client hold the server in grace indefinitelyHighSep 11, 2026
- Linux kernel nfsd: file returned by dentry_create() may not actually be open before useHighSep 11, 2026
- Linux kernel nfsd: failed delegation-recall queue latches a flag and permanently blocks the recallHighSep 11, 2026
- Linux kernel cxl/ras: RCH AER capability copy reads past the mapped register blockHighSep 11, 2026
- strongSwan: expired pointer dereference in PKCS#7 parsing crashes the IKE daemonMediumSep 11, 2026
libvirt: symlink-following chown on the swtpm logfile hands arbitrary file ownership to the swtpm userMediumSep 11, 2026- strongSwan: PKCS#7 certificate enumeration in the openssl plugin leaks memoryLowSep 11, 2026
- Linux crypto iaa: DMA buffer not unmapped before software fallback corrupts decompressed dataUnscoredSep 11, 2026
- Linux fuse io-uring: request headers copied from a non-whitelisted slab object panics hardened usercopyUnscoredSep 11, 2026
- Linux net/smc: connection freed before tasklet drain leaves a use-after-free on the SMC-D receive pathUnscoredSep 11, 2026
- Linux kernel net/smc: oversized SMC-Rv2 LLC messages let a peer delete or install RDMA rkeysUnscoredSep 11, 2026
- Linux kernel net/smc: out-of-bounds read parsing the v2 extension on every SMC-Rv2 link additionUnscoredSep 11, 2026
- Linux kernel io_uring/query: unclamped user size lets a local task request ~4 GiB of clear_user zeroingUnscoredSep 11, 2026
- Linux kernel io_uring/waitid: canceled task work runs __do_wait() in the wrong task contextUnscoredSep 11, 2026
- Linux kernel Intel Speed Select: unvalidated ioctl indices reach MMIO offsets and NULL instancesUnscoredSep 11, 2026
- Linux kernel iommufd: current IOAS rwsem and reference leaked when the unwind path misses itUnscoredSep 11, 2026
- Linux kernel iommufd: reference leak on unmap when an internal access is skippedUnscoredSep 11, 2026
- Linux kernel VT-d: ACS not requested under tboot, leaving peer-to-peer DMA isolation offUnscoredSep 11, 2026
- Linux kernel Tegra241 CMDQV: oversized guest vSID truncates and aliases the wrong Stream IDUnscoredSep 11, 2026
- Linux kernel iommu/sva: racing bind can return an SVA handle with a NULL dev pointerUnscoredSep 11, 2026
- Linux kernel iommu/amd: every handled PPR fault leaks a PCI device referenceUnscoredSep 11, 2026
- Linux kernel RDMA/uverbs: legacy write() bundle has no ioctl method element, causing a NULL dereferenceUnscoredSep 11, 2026
- Linux kernel RDMA/uverbs: REG_MR ioctl passes NULL udata, crashing mthca, irdma and siwUnscoredSep 11, 2026
- Linux kernel fnic: sleeping allocation under an IRQ-safe spinlock during FCoE VLAN discoveryUnscoredSep 11, 2026
- Linux kernel SCSI core: uninitialized kernel heap bytes are DMA'd out as DMA pad on unaligned transfersUnscoredSep 11, 2026
- Linux kernel sched_ext: BUG_ON panic when a DSQ is destroyed before a deferred re-enqueue runsUnscoredSep 11, 2026
- Linux kernel sched_ext: core-scheduling pick state corrupted when dispatch drops the rq lockUnscoredSep 11, 2026
- Linux kernel sched_ext: deadlock and NULL deref when dispatch kfuncs assume the local rqUnscoredSep 11, 2026
- Linux kernel sched/core: core-scheduling selection corrupted by lock-dropping picks and concurrent flipsUnscoredSep 11, 2026
- Linux kernel SUNRPC: use-after-free of the lower transport when a TLS handshake cancel races completionUnscoredSep 11, 2026
- Linux kernel SUNRPC: short Kerberos MIC tokens read past a slab allocation on the RPC client and serverUnscoredSep 11, 2026
- Linux kernel SUNRPC: oversized krb5 wrap-token ec field leaves the receive xdr_buf in an inconsistent stateUnscoredSep 11, 2026
- Linux kernel SUNRPC: integer overflow in krb5p reply length check lets a hostile NFS server drive OOB readsUnscoredSep 11, 2026
- Linux kernel SUNRPC: short krb5 wrap tokens cause OOB reads, a divide-by-zero and a huge memmoveUnscoredSep 11, 2026
- Linux kernel SUNRPC: stale pipefs_sb pointer leaves dentries referencing a freed rpc_clntUnscoredSep 11, 2026
- Linux kernel SUNRPC: nfsd request buffers freed before the RCU grace period, causing a use-after-freeUnscoredSep 11, 2026
- Linux kernel NFS: backchannel request racing callback shutdown leaks transport refs or queues onto a freed svc_servUnscoredSep 11, 2026
- Linux kernel SUNRPC: use-after-free when a network namespace tears down an RPC cacheUnscoredSep 11, 2026
- Linux kernel nfsd: undersized Kerberos token reaches the krb5 unwrap core and divides by zeroUnscoredSep 11, 2026
- Linux kernel SUNRPC: xdr_buf_trim underflows buf->len, handing XDR decoders a near-UINT_MAX boundUnscoredSep 11, 2026
- Linux kernel CXL: MCE notifier outlives its memory device, giving NULL deref and use-after-freeUnscoredSep 11, 2026
- Linux kernel CXL fwctl: unchecked op_size reads past the input buffer and into the device mailboxUnscoredSep 11, 2026
- Linux kernel BPF: preemptible bpf_get_stack reuses a per-CPU callchain buffer and writes out of boundsUnscoredSep 11, 2026
- Linux kernel BPF x86 JIT: per-CPU address lands in the wrong register, clobbering RAX or the frame pointerUnscoredSep 11, 2026
- Linux kernel GHES: CXL CPER work locks taken without IRQ protection can deadlock a CPUUnscoredSep 11, 2026
- Linux kernel hugetlb: reservation counter underflow when a parent unmaps a shared huge page firstUnscoredSep 11, 2026
- Linux kernel efivarfs: unprivileged statfs() floods the UEFI QueryVariableInfo runtime serviceUnscoredSep 11, 2026
- Linux CephFS client: unchecked dentry name length overflows a NAME_MAX buffer in the NFS re-export pathUnscoredSep 11, 2026
- Linux CephFS client: out-of-range MDS rank in mdsmap export_targets writes past a stack bitmapUnscoredSep 11, 2026
- Linux CephFS client: use-after-free on an MDS session freed while check_new_map drops mdsc->mutexUnscoredSep 11, 2026
- Linux CephFS client: use-after-free when a cap-flush entry is freed by a fast FLUSH_ACK mid-iterationUnscoredSep 11, 2026
- Linux libceph: malformed CRUSH map aliases bucket workspaces and overflows the permutation bufferUnscoredSep 11, 2026
- Linux libceph: malformed OSD sparse-read reply advances the message cursor past the request buffer and panicsUnscoredSep 11, 2026
- Linux kernel nfsd: dentry reference leak on every crafted NFSv3 filehandle against a V4ROOT exportUnscoredSep 11, 2026
- Linux nfsd: ACL translation errors in NFSv4 CREATE are discarded and the file is created without the requested ACLUnscoredSep 11, 2026
- Linux nfsd: any authenticated NFSv4.2 client can cancel and free another client's copy-notify stateidUnscoredSep 11, 2026
- Linux nfsd: unprivileged netlink dump leaks 8 bytes of rq_flags and truncates IPv6 client addressesUnscoredSep 11, 2026
- Linux nfsd: NFSD_A_SOCK_ADDR has no minimum length, giving a 12-byte out-of-bounds read in listener_setUnscoredSep 11, 2026
- Linux nfsd: TIME_DELEG decode paths accept out-of-range nseconds and propagate a malformed timespec to diskUnscoredSep 11, 2026
- Linux NFS client: every failed NFSv4 mount leaks 4 KiB of unreclaimable slabUnscoredSep 11, 2026
- Linux NFS localio: reference leak on nfs_uuid_add_file failure pins an nfsd_file and blocks netns teardownUnscoredSep 11, 2026
KVM arm64 vGICv2: guest write of an out-of-range GICV_DIR INTID triggers a host WARN and panics panic_on_warn hostsUnscoredSep 11, 2026- Linux x86/tdx: off-by-one GENMASK makes the port I/O value mask one bit too wide in a TDX guestUnscoredSep 11, 2026
- Linux memcg: concurrent memory.max writers reclaim toward a stale target and can loop indefinitelyUnscoredSep 11, 2026
- Linux mm/vmscan: direct reclaim never reports an RCU-tasks quiescent state, stalling rcu_tasks under memory pressureUnscoredSep 11, 2026
- Linux kernel mm/migrate: long page-migration batches stall Tasks-RCU grace periods on KVM hostsUnscoredSep 11, 2026
Linux kernel KVM s390 vsie: stale crypto bits let a nested guest reach a revoked crypto deviceHighSep 9, 2026- Linux kernel crypto/krb5: derived Kerberos keys left in freed slab memoryHighSep 9, 2026
- Linux kernel io_uring: eventfd signaled inline from a waitqueue wakeup handler can feed back into epollUnscoredSep 9, 2026
Windows Update Stack: link following lets a local user escalate to SYSTEMHighSep 8, 2026
Windows ALPC: heap overflow gives a local user privilege escalation to SYSTEMHighSep 8, 2026
Windows Server Services for NFS: use-after-free in the ONCRPC XDR driver gives local code executionHighSep 8, 2026
Xen: x86 PV guest keeps a stale TLB entry to a freed page and can write it after scrubbingMediumSep 8, 2026
Xen: guest with a passthrough PCI device exposing an IO port BAR can trigger a hypervisor BUG()UnscoredSep 8, 2026- libcurl: pooled TLS connection outlives its easy handle and reuses a freed OpenSSL library contextUnscoredSep 6, 2026
libtpms: malformed TPM state blob drives an out-of-bounds heap read and kills the VM's vTPMMediumSep 4, 2026- Linux nvmet-tcp: remote initiator can trip a kernel WARN via an oversized SGL, killing panic-on-warn hostsUnscoredSep 4, 2026
- Linux kernel nvmet-tcp: unbounded kernel allocation from an unauthenticated NVMe/TCP peerUnscoredSep 4, 2026
- Linux kernel nvmet-auth: uninitialized slab sent to a remote initiator during NVMe-oF authenticationUnscoredSep 4, 2026
- Linux kernel io_uring: folio shift overflow writes past the bvec array on 16G-hugepage kernelsUnscoredSep 4, 2026
- Linux kernel io_uring uring_cmd: iovec leak under NVMe passthrough once the alloc cache fillsUnscoredSep 4, 2026
- Linux kernel nvmet: NULL dereference when a host issues Identify CNS 07h against an NVMe-oF targetUnscoredSep 4, 2026
- Linux kernel iommufd: NULL dereference racing IOAS change_process against a file-backed mappingUnscoredSep 4, 2026
- Linux kernel tegra241-cmdqv: use-after-free issuing CMD_SYNC on a freed command queue at teardownUnscoredSep 4, 2026
- Linux kernel virtio-crypto: unbounded device-reported result length over-reads guest kernel heapUnscoredSep 4, 2026
Linux KVM SEV: sub-page command buffer on SNP hosts triggers RMP faults and host panicUnscoredSep 4, 2026- Linux kernel FUSE: interrupted DAX truncate on O_TRUNC open leaks the invalidate lock, wedging the fileUnscoredSep 4, 2026
- Linux kernel FUSE: setattr writeback failure leaks the invalidate lock on a DAX truncateUnscoredSep 4, 2026
- Linux kernel FUSE: abort_on_kill returns without waiting for FR_FINISHED, freeing an in-flight requestUnscoredSep 4, 2026
- Linux kernel FUSE: io_uring queues published without release ordering can be read half-initializedUnscoredSep 4, 2026
- Linux kernel FUSE: missing read barrier in the io-uring readiness check can reintroduce a lock-order deadlockUnscoredSep 4, 2026
- Linux kernel FUSE: race between request interrupt and resend leaves a request queued on the interrupt listUnscoredSep 4, 2026
- Linux kernel nvme-tcp: unserialized page_frag_cache corrupts page refcounts and panics the hostUnscoredSep 4, 2026
- Linux kernel bpf: copy_user_syms calls __get_user on a userspace pointer array with no access_ok checkUnscoredSep 4, 2026
Linux kernel KVM/arm64 nested virt: injected SError leaves ESR_EL2 stale for the guest hypervisorUnscoredSep 4, 2026- Linux kernel vmwgfx: integer overflow in the shader offset bound check lets an unbounded offset reach host SVGA commandsUnscoredSep 4, 2026
- Linux kernel vmwgfx: dma_buf reference leaked on foreign prime import pins the exporter's memory indefinitelyUnscoredSep 4, 2026
- Linux kernel hugetlb: fork() corrupts migration and hwpoison swap entries by clearing uffd-wp at the wrong bitUnscoredSep 4, 2026
- Linux kernel iommufd: hwpt replace responds to faults on the wrong domain, stranding faults on the old hwptUnscoredSep 4, 2026
- Linux kernel eBPF: syncookie helpers read sk_protocol on mini-sockets without a fullsock checkHighSep 3, 2026
Linux kernel KVM x86 MMU: invalid parent role propagates to child shadow pages, use-after-freeUnscoredSep 3, 2026- Linux kernel x86/mce: CMCI discovery kicks the MCE polling timer before it is initializedUnscoredSep 3, 2026
- Linux kernel mm: folio split leaves memcg-charged page-cache xa_nodes off the shadow_nodes list_lruUnscoredSep 3, 2026
- PREVAIL eBPF verifier: stale offset tracking lets out-of-bounds BPF programs pass verificationCriticalSep 2, 2026
- PREVAIL: writes through a context pointer are modelled as a no-op, so unsafe eBPF programs verify as safeCriticalSep 2, 2026
- PREVAIL: ALU32 arithmetic on pointers passes verification but truncates the pointer at runtimeHighSep 2, 2026
- util-linux nsenter: --join-cgroup leaks a root-opened cgroup.procs fd into the target containerHighSep 2, 2026
- zbus_polkit: caller-supplied UID is silently discarded, leaving polkit authorization open to a PID-reuse raceHighAug 31, 2026
sudo: intercept policy checks skipped for execveat, letting allowed users run denied commandsHighAug 29, 2026- perf sched: integer overflow and strcpy overflow parsing untrusted perf.dataCriticalAug 28, 2026
- perf tools: out-of-bounds heap read parsing a crafted perf.data CPU indexCriticalAug 28, 2026
- Linux kernel io_uring: per-task restrictions are freed across exec, so post-exec rings are unrestrictedHighAug 28, 2026
- Linux kernel ltc4282 hwmon driver: out-of-bounds read reading the VGPIO minimum alarm voltageHighAug 28, 2026
- Linux kernel LIO iblock: missing PR handler checks let PERSISTENT RESERVE OUT NULL-deref the kernelHighAug 28, 2026
- Linux kernel iomap: ioend splitting draws from its own exhausted bio_set and deadlocks writebackHighAug 28, 2026
- Linux kernel CXL: oversized header-log size overruns the RAS iomap and leaks kernel stack via tracefsHighAug 28, 2026
Linux kernel KVM arm64 NV: unresolvable VNCR translation crashes the host instead of injecting an abortHighAug 28, 2026- Linux kernel mm: snapshot_page() reads a non-existent tail page for order-1 folios and oopses the hostHighAug 28, 2026
- Linux kernel AMD LBR: user-only branch sampling leaks kernel addresses to unprivileged usersUnscoredAug 28, 2026
- Linux kernel iommufd: dma_buf_unpin() without dma_resv lock warns on every DMABUF IOAS teardownUnscoredAug 28, 2026
- Linux kernel CXL fwctl: supported-features query trips a fortify panic and takes the host downUnscoredAug 28, 2026
- Linux ccp/SEV: zero-length cert chain in PDH export hits a BUG_ON on CONFIG_DEBUG_VIRTUAL kernelsUnscoredAug 28, 2026
- Linux BPF LSM: attaching to xfrm_decode_session turns packet classification into a kernel panicUnscoredAug 28, 2026
- Linux kernel migrate_device: pte_pfn/pte_dirty called on non-present PTEs during device migrationUnscoredAug 28, 2026
- Linux iommufd: vDEVICE alloc error path leaks the igroup mutex and deadlocks later vDEVICE operationsUnscoredAug 28, 2026
- Linux kernel idxd: double free of wq, engine and group structs on setup error and cleanup pathsUnscoredAug 28, 2026
Linux kernel KVM arm64 vGIC: double-deactivate of nested IRQs trips an AmpereOne erratumUnscoredAug 28, 2026- Linux kernel MGLRU: stale batch updates after memcg reparenting cause premature OOM killsUnscoredAug 28, 2026
- OpenZFS: ioctl checks accept unprivileged user-namespace capabilities, granting local pool adminHighAug 26, 2026
- Linux kernel perf/core: exited event accepted as group leader leaves a sibling pointing at freed memoryUnscoredAug 26, 2026
- Linux kernel CephFS client: readers hang indefinitely after cap revocation leaves stale mds_wantedUnscoredAug 26, 2026
- Linux kernel CephFS client: reclaim during MDS reply handling crashes the kernel via ext4 journal_infoUnscoredAug 26, 2026
- Linux kernel libceph: out-of-bounds read in decode_watchers() from a zero-length struct_lenUnscoredAug 26, 2026
- Linux kernel libceph: unvalidated primary_temp OSD index causes out-of-bounds array readsUnscoredAug 26, 2026
- Linux kernel libceph: unchecked decodes in decode_locker() let a malicious OSD read out of boundsUnscoredAug 26, 2026
- OpenSSL: raw-public-key endpoints with no certificate abort on a peer-sent signature_algorithms_cert extensionHighAug 25, 2026
- OpenSSL QUIC: malformed INITIAL packet double-frees the record-layer object and kills the server processHighAug 25, 2026
- OpenSSL DTLS: buffering future-epoch records retains a full 16 KB read buffer each, ~1200x memory amplificationHighAug 25, 2026
- OpenSSL: crafted CMS message causes an 8-byte out-of-bounds heap write during CMS_decrypt()HighAug 25, 2026
- OpenSSL QUIC: a peer withholding acknowledgements makes ACK-only metadata accumulate for the connection's lifeHighAug 25, 2026
- OpenSSL CMP: unchecked protectionAlg parameter type is dereferenced as a PBMParameter and crashes the processHighAug 25, 2026
- OpenSSL: CMP servers cache rejected extraCerts forever, letting a client drive the process to OOMMediumAug 25, 2026
- OpenSSL: attacker-controlled CMP sender DN reaches ERR_raise_data() as a format string, crashing the clientUnscoredAug 25, 2026
- Linux kernel BPF sockmap: use-after-free on the cached redirect socket in the send verdict pathUnscoredAug 22, 2026
- Linux kernel mm/filemap: page cache folio can be stored at the wrong index after an allocation retryUnscoredAug 22, 2026
- Linux kernel IMA: truncation does not invalidate cached measurements, leaving stale appraisal stateUnscoredAug 22, 2026
- Linux kernel sched_ext: lock inversion between scx_cgroup_lock and cgroup_mutex deadlocks the nodeUnscoredAug 22, 2026
- Linux kernel PSI: rtpoll timer can outlive its cgroup and fire on freed memoryUnscoredAug 22, 2026
- Linux kernel page_table_check: unprivileged zero mappings overflow the file map counter and panic the hostUnscoredAug 22, 2026
KVM SVM SEV: races between encryption-context move and copy corrupt the mirror list and misdirect a VM referenceUnscoredAug 22, 2026- Linux kernel mm: huge-zero-folio shrinker races a page fault and misidentifies the huge zero pageUnscoredAug 22, 2026
- Linux kernel perf/core: use-after-free on a freed group leader after a sibling is detached during CPU hotplugUnscoredAug 22, 2026
- Linux kernel IMA: integer underflow in xattr_verify() causes out-of-bounds read on truncated security.imaUnscoredAug 22, 2026
- Linux kernel mm/vmalloc: use-after-free when vmap huge-page promotion frees a page table under a concurrent ptdump walkUnscoredAug 22, 2026
- Linux kernel mm: page-table reclaim flushes the wrong address, allowing reuse of a still-cached page tableUnscoredAug 22, 2026
- Linux kernel net/smc: listener close race leaks child sockets, letting a remote peer exhaust kernel memoryUnscoredAug 22, 2026
- Linux kernel vhost-scsi (VHOST_SET_FEATURES after endpoint setup): vhost_scsi_setup_vq_cmds() sizes each command'sUnscoredAug 22, 2026
- Linux kernel vhost-scsi: malformed guest request with T10 protection bytes panics the hostUnscoredAug 22, 2026
- Linux kernel mlx5 vDPA: memory-region key creation reads past the firmware command bufferUnscoredAug 22, 2026
- Linux kernel BPF TCP iterator: stolen reference on a half-published request socket ends in use-after-freeUnscoredAug 22, 2026
- Linux kernel BPF conntrack kfuncs: racing opts update unbalances the netns reference countUnscoredAug 22, 2026
- Linux kernel SMC-R: duplicate LLC link messages from a peer leak one kmalloc-96 object eachUnscoredAug 22, 2026
- Linux kernel BPF verifier: commuted pointer arithmetic loses pointer provenance stateUnscoredAug 22, 2026
- Linux kernel sched_ext: a failed sub-scheduler enable races root disable into a use-after-freeUnscoredAug 22, 2026
- Incus: instance snapshots bypass restricted.containers.lowlevel, giving command execution on the hostCriticalAug 21, 2026
- Linux kernel vhost: stale vring metadata cache lets a reconfigured vring access memory outside its IOTLB mappingUnscoredAug 21, 2026
libvirt: integer overflow in NodeGetFreePages gives a local user heap corruption in the root daemonHighAug 20, 2026- FreeBSD ZFS: size truncation in ZFS_IOC_USERSPACE_MANY gives a local user a kernel heap overflowHighAug 19, 2026
- FreeBSD ZFS: 64-to-32-bit size truncation in the heal receive path corrupts kernel memoryUnscoredAug 19, 2026
- FreeBSD ZFS: unprivileged local user can set the internal $hasrecvd metadata flag on a datasetUnscoredAug 19, 2026
- Linux kernel LIO target: unbounded iSCSI TransportID parse in PR OUT reads past the parameter bufferCriticalAug 15, 2026
- Linux kernel - NVMe-oF target DH-HMAC-CHAP authentication, drivers/nvme/target/fabrics-cmd-auth.c: The sibling of theCriticalAug 15, 2026
- Linux kernel - iSCSI TCP initiator, drivers/scsi/libiscsi_tcp.c: The iSCSI initiator receives PDU data segments into aCriticalAug 15, 2026
- Linux kernel mlx5_core MACsec offload: Deleting an offloaded MACsec RX secure channel frees the per-SC metadata_dstHighAug 15, 2026
- Linux kernel bpf: fork bailout frees an uninitialized task->bpf_storage, causing UAF or hangHighAug 15, 2026
- Linux kernel mm: DAX hotplug into an early section leaves ZONE_DEVICE tail struct pages uninitializedHighAug 15, 2026
- Linux kernel amdkfd (KFD compute driver, /dev/kfd) (drm/amdkfd): A use-after-free in the amdkfd (KFD compute driverHighAug 15, 2026
- Linux kernel BPF uprobe_multi: unchecked __get_user on user-supplied data allows local memory disclosure or corruptionHighAug 15, 2026
- Linux kernel mlx5_ib (queue pair sizing): set_rq_size() computes the receive-queue work-entry size as 1 << rq_wqe_shiftHighAug 15, 2026
- Linux kernel BPF: BPF_PROG_QUERY writes the revision field past a short bpf_attr from userspaceHighAug 15, 2026
- Linux kernel amdkfd (KFD compute driver, /dev/kfd) (drm/amdkfd): A race condition or locking defect in the amdkfd (KFDHighAug 15, 2026
- Linux kernel amdkfd (KFD compute driver, /dev/kfd) (drm/amdkfd): An out-of-bounds access in the amdkfd (KFD computeHighAug 15, 2026
- Linux kernel THP split: use-after-free on the inode when memory-failure splits a shmem huge pageHighAug 15, 2026
- Linux kernel hugetlbfs: list corruption in reservation top-up can link a kernel-stack address into MM stateHighAug 15, 2026
- Linux kernel libiscsi: out-of-bounds read leaks stale connection data into the SCSI sense bufferHighAug 15, 2026
- Linux kernel keyrings: out-of-bounds read in keyring_get_key_chunk() from unprivileged add_key(2)HighAug 15, 2026
- Linux perf/x86/amd/brs - kernel address leakage through Branch Sampling: A user-only branch stack collected via AMDUnscoredAug 15, 2026
- Linux BPF verifier: kernel pointers leak through verifier logs for three pseudo ldimm64 sourcesUnscoredAug 15, 2026
- Linux kernel amdkfd (KFD compute driver, /dev/kfd) (drm/amdkfd): A correctness defect in the amdkfd (KFD computeUnscoredAug 15, 2026
- Linux kernel amdkfd (KFD compute driver, /dev/kfd) (drm/amdkfd): Memory is handed to a consumer without beingUnscoredAug 15, 2026
- OpenSSL: QUIC listener queues unlimited pending connections, exhausting server memoryHighAug 13, 2026
- Linux kernel libceph: truncated monitor reply decodes stale bytes from the reused bufferHighAug 12, 2026
- Linux kernel amdkfd (KFD compute driver, /dev/kfd) (drm/amdkfd): A memory or reference-count leak in the amdkfd (KFDHighAug 12, 2026
OpenSSH: use-after-free in the ssh client when remote-forwarding operations run concurrentlyMediumAug 11, 2026
OpenSSH ssh-agent: locking bypass lets a forwarded remote session add tokens and use keysLowAug 11, 2026
OpenSSH sshd: restrict keyword in authorized_keys did not cover tunnel forwardingLowAug 11, 2026- Linux libceph: CRUSH map with a zero bucket type makes the mapper index the OSD weight array negativelyCriticalAug 10, 2026
- Linux libceph: stale authorizer buffer pointer after ticket refresh causes a use-after-free on msgr1 reconnectCriticalAug 10, 2026
- Linux libceph: integer overflow in osdmap decoding defeats the bounds check and reads out of boundsCriticalAug 10, 2026
- Linux kernel libceph: unbounded pg_temp length lets a malicious monitor cause a stack out-of-bounds writeCriticalAug 10, 2026
libvirt swtpm state handling: symlink following lets the swtpm user take ownership of arbitrary filesHighAug 10, 2026- Linux kernel iomap: zero-length write range underflows into an out-of-bounds bitmap_set()HighAug 10, 2026
- Linux kernel libceph: use-after-free reading the monmap debugfs file during client teardownHighAug 10, 2026
- Linux kernel amdkfd (KFD compute driver, /dev/kfd) (drm/amdkfd): An out-of-bounds access in the amdkfd (KFD computeHighAug 10, 2026
- Linux kernel sockmap: cork use-after-free when two threads send on the same socketHighAug 10, 2026
- Linux kernel virtio-gpu: unvalidated EDID block offset lets a malicious backend read past a kernel bufferHighAug 10, 2026
- Linux kernel libceph: a monmap advertising zero monitors hits a BUG_ON and takes down the client nodeHighAug 10, 2026
- Linux kernel libceph: NULL dereference in CRUSH locality lookup when a parent bucket's type name is missingHighAug 10, 2026
- Linux kernel amdkfd (KFD compute driver, /dev/kfd) (drm/amdkfd): A correctness defect in the amdkfd (KFD computeHighAug 10, 2026
- Linux kernel mlx5_core port / transceiver module EEPROM (MCIA register): The MCIA register can return 32 dwordsHighAug 10, 2026
- systemd-homed: local homed-managed user can gain membership in arbitrary system groupsMediumAug 10, 2026
- systemd-oomd: unprivileged local users can kill arbitrary processes via unvalidated IPC pathMediumAug 10, 2026
- QEMU: signed/unsigned mismatch in vhost inflight migration state overruns the mmap-backed regionMediumAug 10, 2026
- Linux i915 GPU kernel driver (context SSEU parameter): NULL dereference reachable by setting a context engine slotUnscoredAug 10, 2026
- Linux kernel amdkfd (KFD compute driver, /dev/kfd) (drm/amdkfd): A correctness defect in the amdkfd (KFD computeUnscoredAug 10, 2026
- Linux kernel Intel IOMMU: out-of-bounds memset in dmar_latency_disable() corrupts adjacent memoryUnscoredAug 10, 2026
- Linux kernel BPF sockmap: unhashed UDP sockets leak socket refcounts, exhausting host memoryUnscoredAug 10, 2026
Linux kernel KVM x86 MMU: use-after-free when a vendor module is reloaded after a failed initUnscoredAug 10, 2026- Linux kernel libceph: malicious OSD triggers out-of-bounds reads in RBD lock-info decodeCriticalAug 8, 2026
- Linux kernel BPF TCP iterator: double socket release on batch realloc failure panics the nodeHighAug 5, 2026
- OpenSSL: memory leak per handshake when a server staples an OCSP response with no entriesHighAug 5, 2026
Xen (vRTC): Out-of-bounds read in vRTC emulation - hypervisor memory disclosure to a guestHighJul 28, 2026
Xen (grant tables): Type confusion in grant-copy - guest corrupts hypervisor stateUnscoredJul 28, 2026
Xen (grant tables): Grant-table version change racing with other operationsUnscoredJul 28, 2026- Linux kernel virtio-net: loose length check in receive_big() lets a malicious backend write past the frag arrayHighJul 27, 2026
- Linux kernel BPF devmap: cloning fragmented XDP frames for broadcast redirect reads out of boundsCriticalJul 25, 2026
- Linux kernel krb5 crypto: use-after-free when an async AEAD backend is bound to the enctypeCriticalJul 25, 2026
- Linux kernel - NVMe-oF target DH-HMAC-CHAP authentication, drivers/nvme/target/fabrics-cmd-auth.c: Nvmet_auth_reply()CriticalJul 25, 2026
- Linux kernel - NVMe-oF target discovery controller, drivers/nvme/target/discovery.c: The discovery controller validatedCriticalJul 25, 2026
- Linux kernel crypto/ecc: missing carry in 128-bit accumulation corrupts ECC arithmetic at a boundaryHighJul 25, 2026
- Linux kernel QAT: use-after-free tearing down SR-IOV while VF2PF response work is in flightHighJul 25, 2026
- Linux SLUB: krealloc __GFP_ZERO guarantee broken when red zoning is enabled without user trackingHighJul 25, 2026
- Linux kernel perf AUX buffer: missing aux_mutex in map_range lets a local user map a freed pageHighJul 25, 2026
- Linux kernel QAT crypto driver: oversized RSA CRT components overflow half-size DMA buffersHighJul 25, 2026
- Linux kernel Intel QAT: unlocked service_table walks can corrupt the list or use freed entriesHighJul 25, 2026
- Linux kernel BPF: LPM trie RCU annotations reject sleepable programs and spam lockdep warningsHighJul 25, 2026
- Linux BPF: BTF repeated-field count overflow allows an out-of-bounds write on BPF_BTF_LOADHighJul 25, 2026
- Linux mm: shrinker_info teardown races with expansion, giving a double free of memcg shrinker mapsHighJul 25, 2026
- Linux kernel pcrypt: padata fallback leaves the parallel completion callback on the child requestHighJul 25, 2026
- Linux kernel RT scheduler: RT_PUSH_IPI can livelock a busy many-core node under softirq loadHighJul 25, 2026
- Linux kernel mm: mincore/MADV_PAGEOUT ownership checks use the wrong idmap on idmapped mountsMediumJul 25, 2026
- Linux kernel x86/mm: vmemmap pages freed as page tables leak memory on memory hot-removeMediumJul 25, 2026
- Linux kernel CTR_DRBG: generate can report success while leaving the output buffer uninitializedMediumJul 25, 2026
- Linux kernel ccp: /dev/sev ioctls re-run SEV platform init and can crash a host running VMsMediumJul 25, 2026
- Linux kernel chacha20poly1305 template: missing argument check dereferences an error pointerMediumJul 25, 2026
- Linux nvmet-rdma: device reference leaks whenever a queue connect is rejected as busyMediumJul 25, 2026
- Linux kernel BPF verifier: map-in-map lookup nullness elided using the wrong max_entriesMediumJul 25, 2026
- Linux mm/swap: full-cluster reclaim runs without rescheduling and softlocks large-core-count hostsMediumJul 25, 2026
- Linux mm: NULL dereference in lookup_swap_cgroup_id panics swapless hosts at process exitMediumJul 25, 2026
- Linux kernel io_uring: linked work items keep running after ring exit starts, stalling teardownMediumJul 25, 2026
- Linux io_uring: NOP with IOSQE_FIXED_FILE leaks a struct file reference on every submissionMediumJul 25, 2026
- Linux kernel x86: no IBPB flush on BPF JIT memory reuse while Spectre-v2 mitigations are in useUnscoredJul 25, 2026
- Linux kernel BPF JIT: reused JIT memory can inherit branch predictions from the program that freed itUnscoredJul 25, 2026
- libssh: incorrect AES-GCM finalization removes integrity protection on SSH sessionsHighJul 21, 2026
QEMU Guest Agent: symlink and TOCTOU flaws in SSH key injection give root inside the guestHighJul 20, 2026- Linux kernel BPF inode storage: map creation without BPF LSM initialized panics the host on RCU callbackMediumJul 20, 2026
- Linux kernel - LIO iSCSI target CHAP authentication, drivers/target/iscsi/iscsi_target_auth.cCriticalJul 19, 2026
- Linux kernel mlx5_core TX timeout devlink health reporter: The TX timeout recovery handler accesses the netdev pointerCriticalJul 19, 2026
- Linux kernel arm_ffa: use-after-free racing a notifier unregister against notification deliveryCriticalJul 19, 2026
- Linux kernel arm_ffa: unvalidated notification layout drives out-of-bounds read of the shared RX bufferHighJul 19, 2026
- Linux kernel amdkfd (KFD compute driver, /dev/kfd) (drm/amdkfd): An out-of-bounds access in the amdkfd (KFD computeHighJul 19, 2026
- Linux i915 GPU kernel driver: A use-after-free in the i915 GPU kernel driver. The general shape is that a GPU object isHighJul 19, 2026
- Linux kernel nvme-pci: use-after-free when Host Memory Buffer setup fails during device probeHighJul 19, 2026
- Linux kernel adm1266 hwmon: PDIO scan bound confused with PMBus command code, out-of-bounds read and writeHighJul 19, 2026
- Linux kernel adm1266 hwmon: device-supplied block length overflows the blackbox NVMEM buffer by 191 bytesHighJul 19, 2026
- Linux kernel adm1266 hwmon: PMBus block read buffer one byte short, i2c write and PEC compare overrunHighJul 19, 2026
- Linux kernel IOMMU core: unbalanced unmap accounting on the map error path with iommu_debug onHighJul 19, 2026
Linux KVM/SVM - AVIC IPI virtualization on Hygon Family 18h: AVIC inter-processor-interrupt virtualization is unsafe onHighJul 19, 2026- Linux kernel amdkfd (KFD compute driver, /dev/kfd) (drm/amdkfd): Missing or insufficient validation of user-suppliedMediumJul 19, 2026
- Linux kernel NVMe: bio leaked when integrity mapping fails on a user-mapped requestMediumJul 19, 2026
- Linux kernel amdkfd (KFD compute driver, /dev/kfd) (drm/amdkfd): A NULL pointer dereference in the amdkfd (KFD computeUnscoredJul 19, 2026
- QEMU: guest-triggered out-of-bounds write when a physical memory map returns shortHighJul 16, 2026
SSSD LDAP sudo provider: unscoped sudoRole search lets any LDAP writer grant themselves root fleet-wideHighJul 7, 2026
Linux KVM - GHCB v2+ scratch area location enforcement: KVM did not require the GHCB software scratch area to liveHighJul 4, 2026- Linux kernel IPv6: heap overwrite into skb_shared_info via UDPv6 MSG_MORE with MSG_SPLICE_PAGESHighJul 4, 2026
Linux KVM - dirty-page tracking without a vCPU on a dying VM: KVM warned (and on panic_on_warn hosts, panicked)MediumJul 1, 2026
Linux KVM arm64: page-table walks without kvm->srcu can race memslot changesHighJun 25, 2026- Linux kernel amdkfd (KFD compute driver, /dev/kfd) (drm/amdkfd): An out-of-bounds access in the amdkfd (KFD computeHighJun 25, 2026
- Linux kernel list_lru: cgroup teardown race lets two CPUs unlink the same list item under different locksHighJun 25, 2026
- Linux drm/xe GPU kernel driver (suspend/shutdown without display): The xe driver oopses on suspend or shutdownMediumJun 25, 2026
- Linux kernel amdkfd (KFD compute driver, /dev/kfd) (drm/amdkfd): Missing or insufficient validation of user-suppliedMediumJun 25, 2026
- Linux kernel io_uring poll: cancel flag makes the ownership slowpath unreachableHighJun 24, 2026
- Linux kernel PSI: use-after-free racing a cgroup pressure write against cgroup removalHighJun 24, 2026
- Linux kernel ice driver: double free of transmit skb on the TSO/checksum error pathHighJun 24, 2026
- Linux kernel ccp driver: IV restore overruns the 8-byte RFC3686 IV bufferHighJun 24, 2026
- Linux kernel BPF: sock_ops same-register context access leaks a kernel pointer and reads out of boundsHighJun 24, 2026
- Linux BPF offload: refcount increment on a dying netns causes use-after-free during info queryHighJun 24, 2026
- Linux kernel BPF verifier: ld_abs/ld_ind failure path left unverified inside subprogramsHighJun 24, 2026
- Linux kernel BPF verifier: mis-tracked rX += rX delta lets a program diverge from its verified boundsHighJun 24, 2026
OpenSSH client: double free on attacker-controlled DH-GEX parameters crashes the client in FIPS modeMediumJun 23, 2026
OpenSSH client X11 forwarding: a local user can pre-bind the X socket and hijack a forwarded sessionMediumJun 23, 2026
OpenSSH: heap out-of-bounds read during GSSAPI indicator cleanup crashes the authentication pathLowJun 23, 2026- Linux kernel SO_REUSEPORT: cBPF program freed without an RCU grace period, use-after-free in UDP receiveHighJun 19, 2026
- QEMU: missing iov bounds check in the virtio-snd input callback gives a guest a heap out-of-bounds writeHighJun 19, 2026
Xen (x86 HVM): x86 HVM I/O port list traversal flawUnscoredJun 18, 2026- Netty: client TLS silently skips hostname verification when a plain X509TrustManager is suppliedHighJun 12, 2026
- QEMU virtio-blk: malformed guest SCSI request causes host-heap out-of-bounds writeMediumJun 12, 2026
KVM arm64 vgic-its: double reference drop on the ITS translation cache frees an in-use interruptCriticalJun 9, 2026- OpenSSL: use-after-free in PKCS7_verify when a signed message carries an empty digestAlgorithms setHighJun 9, 2026
- Linux kernel nvmet-tcp - ICReq/teardown race and data-digest error paths: Three lifecycle bugs an initiator can driveCriticalMay 28, 2026
- Linux kernel vmw_pvrdma: double free on ucontext allocation error pathHighMay 28, 2026
- Linux kernel amdkfd (KFD compute driver, /dev/kfd) (drm/amdkfd): An out-of-bounds access in the amdkfd (KFD computeHighMay 28, 2026
- Linux kernel amdkfd (KFD compute driver, /dev/kfd) (drm/amdkfd): Memory is handed to a consumer without beingMediumMay 28, 2026
- Linux kernel BPF: negative CO-RE accessor index causes an out-of-bounds read and deterministic kernel crashHighMay 27, 2026
- Linux kernel amdkfd (KFD compute driver, /dev/kfd) (drm/amdkfd): An out-of-bounds access in the amdkfd (KFD computeHighMay 27, 2026
- Linux kernel crypto authencesn: out-of-bounds access with a 1-3 byte ahash digest via AF_ALGHighMay 27, 2026
Go x/crypto ssh/agent: destination restrictions silently dropped when adding keys to a remote agentCriticalMay 22, 2026- Linux kernel mlx5_core RX datapath (striding RQ, page_pool): A regression introduced by the fix for CVE-2025-40350CriticalMay 8, 2026
- Linux kernel mm: stale page->private survives page free and causes a use-after-free in the swap subsystemHighMay 8, 2026
- Linux kernel Intel uncore PMU: die ID lookup bugs trip a warning and skip PMON unitsMediumMay 8, 2026
- Linux kernel amdkfd (KFD compute driver, /dev/kfd) (drm/amdkfd): A correctness defect in the amdkfd (KFD computeMediumMay 8, 2026
- Linux kernel amdkfd (KFD compute driver, /dev/kfd) (drm/amdkfd): An out-of-bounds access in the amdkfd (KFD computeHighMay 6, 2026
- Linux kernel BPF verifier: atomic-fetch precision gap lets equivalent-looking states be prunedHighMay 1, 2026
- Linux i915 GPU kernel driver: A use-after-free in the i915 GPU kernel driver. The general shape is that a GPU object isHighApr 24, 2026
- Linux i915 GPU kernel driver (submission backend setup): i915 dereferences the submission backend before checkingMediumApr 24, 2026
- Linux kernel (crypto algif_aead): Incorrect resource transfer between spheres in algif_aead (reverted to out-of-placeHighApr 22, 2026
sudo: failed setuid/setgid/setgroups before running the mailer is non-fatal, allowing privilege escalationHighApr 3, 2026- Linux kernel mlx5_core IPsec full offload (ESN handling): The extended-sequence-number wrap event can be processedHighApr 3, 2026
OpenSSH scp: file fetched as root with -O and without -p can land setuid or setgidHighApr 2, 2026- libssh SCP client: malicious server can write files outside the client's working directoryMediumMar 26, 2026
- polkit: unbounded stdin read in polkit-agent-helper-1 lets a local user exhaust system memoryMediumMar 26, 2026
Xen (EPT): Use-after-free of EPT paging structures - HVM guest to host compromiseUnscoredMar 23, 2026- systemd-machined: unvalidated RegisterMachine class lets a local user reach root command executionMediumMar 13, 2026
- QEMU VMDK driver: a crafted image causes an out-of-bounds read leaking 12 bytes or crashing the processMediumFeb 19, 2026
- OpenStack Nova: crafted QCOW header on a Flat-backend disk lets a tenant destroy host data on resizeHighFeb 18, 2026
Linux KVM - irqfd routing type clobbered on deassign: Deassigning a KVM_IRQFD clobbers the irqfd's copy of theHighFeb 14, 2026- Linux kernel (net/tls): Closing a kTLS socket cancelled the transmit work item, but the write-space callback couldCritical2026
- Linux kernel (net/smc): An inbound SYN handled in softirq reads the smc_sock out of the listening TCP socket'sCritical2026
- Linux kernel (net/tls): When the crypto engine backlogs a kTLS encrypt request, both the async completion callback andCritical2026
- Linux kernel (net/ipv4): A child socket created from an inbound handshake is inserted into the TCP hash table beforeCritical2026
- Linux kernel (net/rds): If RDS/IB queue-pair setup fails after the send ring is allocated but before the receive ringCritical2026
- Linux kernel (net/xfrm): IPTFS fragment consumption loses the shared-page marker, so ESP concludes the payload pagesCritical2026
- Linux kernel (net/tls): A particular kTLS ring state builds a scatterlist whose chain link points directly at anotherCritical2026
- Linux kernel (net/tls): When the kTLS transmit scatterlist ring wraps, the chain link that stitches the tail back toCritical2026
- Linux kernel (drivers/nvme/target): A client connected to your NVMe-oF TCP target can drive a reference-count underflowCritical2026
- Linux kernel NVMe-oF TCP target (nvmet-tcp, data-digest mismatch handling): With data digests enabled, a digestCritical2026
- Linux kernel SMC-R connection data control (smc_cdc_rx_handler socket lifetime): The CDC receive handler looks theCritical2026
- Linux kernel (net/xfrm): The same ownership-marker bug as CVE-2026-53363, in the other IPTFS frag-transfer helper.Critical2026
- CephFS kernel client (ceph.ko, ceph_handle_caps): The kernel trusts snap_trace_len straight off the wire, so aCritical2026
- Linux kernel (net/xfrm): When IPsec crypto offload takes a GSO segment asynchronously, the segment is unlinked from theCritical2026
- Linux kernel (net/xfrm): The ESP-in-TCP send path mis-tracked scatter-gather message offsets and socket memory chargesCritical2026
- Linux kernel (net/xfrm): NAT-keepalive frees the keepalive skb whenever the IPv4/IPv6 send helper returns an errorCritical2026
- Linux kernel (net/xfrm): The IPsec input path validates a security association before taking the state lock, so a stateCritical2026
- Linux kernel (net/xfrm): Async ESP resumption holds a reference on the original skbCritical2026
- Linux kernel SoftiWARP connection manager (siw_cm, endpoint/socket disassociation): A malformed MPA request duringCritical2026
- Linux kernel (drivers/nvme/host): An off-by-one in the Flexible Data Placement index check accepts a placement indexCritical2026
- Linux kernel (drivers/nvme/host): The multipath current-path array is sized by the count of possible NUMA nodes butCritical2026
- Linux kernel (net/smc): Link-group termination drops conns_lock after finding a connection but before taking a socketCritical2026
- Linux kernel (net/core, net/tls): The bitmap that marks sk_msg scatterlist entries as externally owned was not carriedCritical2026
- Intel Data Center GPU driver for VMware ESXi (buffer overflow): A buffer overflow in the Intel datacenter graphicsCritical2026
Linux kernel (arch/x86/kvm/svm): Page State Change requests from a confidential guest were validated against theCritical2026
Linux kernel (arch/x86/kvm/svm): KVM computed the usable size of the guest-provided GHCB scratch area wrongly, so aCritical2026
Linux kernel (arch/x86/kvm/svm): A confidential guest can hand KVM a port-I/O request with length or count zeroCritical2026- Linux kernel (drivers/iommu/intel): The VT-d scalable-mode context entry is zeroed while its Present bit is still setCritical2026
Linux kernel (arch/x86/kvm): The I/O APIC's delayed EOI work was cancelled only after vCPUs were freed, so the workCritical2026- Linux kernel (drivers/iommu/arm/arm-smmu-v3): On Arm hosts a virtual device is mapped to only the first of its StreamCritical2026
KubeVirt virt-handler (symlink following in migration proxy): During live migration virt-handler dials Unix socketsHigh2026
Linux kernel (arch/x86/kvm): An emulated MMIO write that straddles a page boundary onto a second MMIO page is splitHigh2026- Linux kernel (drivers/iommu/generic_pt): When an unmap lands in the middle of a large or contiguous page-table entryHigh2026
- Linux kernel (drivers/iommu/intel): A live 512-bit VT-d PASID entry is replaced with a single structure copy, so theHigh2026
Linux kernel (arch/x86/kvm/mmu): The shadow MMU derives GFNs for direct shadow pages arithmetically, which breaks ifHigh2026- Linux kernel (drivers/iommu): The IOMMU group's domain pointer is left stale when a device reset races a detach, andHigh2026
- Linux kernel (drivers/iommu/amd): On AMD hosts the Device Table Entry copied to a DMA-alias device is looked up usingHigh2026
- Linux kernel (drivers/iommu/riscv): The RISC-V IOMMU driver updated device-directory and process-directory entriesHigh2026
- Linux kernel (net/xfrm): An unlocked read of the IPTFS reassembly state lets two CPUs disagree about who owns a socketHigh2026
- Linux kernel (drivers/iommu/intel): When the PASID is not found on the device list, VT-d runs the teardown anyway andHigh2026
- Linux kernel (drivers/vfio/pci): When a tenant closes its passed-through PCI device, vfio disables the function beforeHigh2026
Linux kernel (arch/x86/kvm/mmu): Shadow-page lookup reuses a page without comparing its role, so a direct (2MB) shadowHigh2026
Linux kernel (arch/x86/kvm/mmu): A guest that creates a hugepage mapping extending below the bounds of a memslot makesHigh2026- Linux kernel (net/xfrm): Transport-mode reinjection stashes a network-namespace pointer in the socket buffer's controlHigh2026
Linux kernel (arch/x86/kvm/svm): KVM read Page State Change entries and indices out of a guest-writable buffer moreHigh2026- Linux kernel (drivers/vfio/pci): Vfio-pci exports a dma-buf over BAR memory without confirming those BAR resources wereHigh2026
- Linux kernel (drivers/vfio/pci): If vfio-pci device registration fails after the device joined the VGA arbiter, theHigh2026
Linux kernel (arch/x86/kvm/mmu): If reclaiming shadow pages invalidates the root a fault is being serviced against, KVMHigh2026
Linux kernel (arch/x86/kvm/vmx): Nested teardown freed the shadow VMCS page while vmcs01 still referenced it, andHigh2026- Linux kernel (drivers/iommu/amd): Iommu_completion_wait() returned without waiting whenever another CPU had alreadyHigh2026
- Linux kernel (net/xfrm): The rtnetlink changelink path for xfrm interfaces checked CAP_NET_ADMIN only against theHigh2026
Linux kernel (arch/x86/kvm): When KVM failed to program the interrupt remapping table for irq bypass, it left aHigh2026- Linux kernel (drivers/iommu): Every peer-to-peer segment in a scatter-gather list inherits the length of the firstHigh2026
- Linux kernel (drivers/iommu/iommufd): Iommufd tears down the page-tracking state behind a dma-buf backed IOAS mappingHigh2026
- Linux kernel (drivers/iommu): An I/O page-fault group is handed to userspace through iommufd while still sitting on theHigh2026
Linux kernel (arch/x86/kvm): A nested guest can put an out-of-range virtual-processor ID into an enlightened VMCS andHigh2026- Intel Data Center GPU driver for VMware ESXi (out-of-bounds read): Out-of-bounds read in the ESXi GPU driver exposingHigh2026
- Intel Data Center GPU driver for VMware ESXi (out-of-bounds write): Out-of-bounds write in the ESXi GPU driver causingHigh2026
- Linux kernel (drivers/iommu/intel): A device that does not support ATS never gets inserted into the VT-d deviceHigh2026
Linux kernel (arch/x86/kvm/svm): If AVIC is inhibited while a nested guest is running, KVM leaves the x2APIC MSRsHigh2026
Linux kernel (virt/kvm): The dirty-ring reset path bounds-checks an offset with unchecked 64-bit arithmetic, so aHigh2026
Linux kernel (arch/x86/kvm/svm): VMLOAD/VMSAVE executed by an L2 guest and not intercepted by L1 were emulated againstHigh2026- Linux kernel (net/xfrm): Closing an ESP-in-TCP socket cancels its transmit work item, but the write-space callback canHigh2026
- Linux kernel (drivers/iommu): Unbinding shared virtual addressing touches the mm's IOMMU state after the domain-freeHigh2026
- Linux kernel (net/xfrm): Flushing xfrm states during namespace cleanup re-arms the NAT-keepalive delayed work after itHigh2026
- Linux kernel (drivers/vfio/pci): The error path of the vfio-pci dma-buf export falls through the whole unwind chainHigh2026
- Linux kernel (net/smc): Tee(2) duplicates an SMC splice pipe buffer without duplicating the private state hanging offHigh2026
- Linux kernel (net/xfrm): An XFRM_MSG_NEWSPDINFO request queues a per-namespace work item on the global systemHigh2026
- Linux kernel (drivers/pci): The PCI slot-lock failure path releases a lock the caller never took, which at best warnsHigh2026
- Linux kernel (net/rds): When pinning user pages for a zerocopy RDS send fails, the pages are released but theHigh2026
- Linux kernel (net/rds): A zerocopy RDS send that fails after pinning user pages but before the message reaches theHigh2026
- Linux kernel (drivers/iommu/intel): VT-d publishes the address of a freshly allocated PASID table into the PASIDHigh2026
- Linux kernel (drivers/iommu/intel): The 512-bit VT-d PASID entry is zeroed all at once while still marked present, andHigh2026
- Linux kernel (drivers/vfio/cdx): VFIO_DEVICE_SET_IRQS was not serialized, so two concurrent interrupt-configurationHigh2026
- Linux kernel (net/xfrm): SA deletion decided whether to unhash from the by-SPI and by-sequence chains using fieldHigh2026
- Linux kernel (drivers/net/ethernet/mellanox/mlx4): Shared receive queue objects are looked up from an asynchronousHigh2026
- Linux kernel (net/xfrm): ESP-in-TCP keeps a single in-flight transmit. For a blocking caller the flush of that stateHigh2026
- Linux kernel (net/xfrm): Policy deletion dropped the policy lock before pruning the inexact-policy bin, and aHigh2026
Linux kernel (arch/x86/kvm/svm): The SEV debug-encrypt path bounds each iteration by the source page offset but not theHigh2026- Linux kernel (net/xfrm): Cloning an IPTFS security association kmemdups the mode data, so the clone shares the originalHigh2026
- Linux kernel (net/smc): The SMC socket hashtables are re-initialised at the end of module init, after the protocol andHigh2026
- Linux kernel (net/xfrm): An unprivileged user who can create IPsec SAs turns one outbound datagram into a multi-exabyteHigh2026
- Linux kernel (net/xfrm): Setting a per-socket IPsec policy reset the socket's destination cache non-atomically whileHigh2026
- Linux kernel (net/rds): Network-namespace teardown frees the per-netns RDS/TCP listen socket before unregistering theHigh2026
- Linux kernel RDS (rds_find_bound socket lookup ignores network namespace): This is a literal cross-tenant delivery bug.High2026
Linux kernel (arch/x86/kvm/vmx): The nested vTPR versus TPR-threshold consistency check ran only after KVM had alreadyHigh2026- Linux kernel (net/xfrm): Xfrm_selector_match() compared selectors without checking that the selector family matches theHigh2026
- Linux kernel (drivers/vfio/pci/qat): Two concurrent writes to the QAT VF migration-resume file both pass the boundsHigh2026
- Linux kernel (net/rds): Bind() on an RDS socket with a scoped IPv6 address looks up the interface under RCU, drops theHigh2026
- Linux kernel (drivers/pci): The option-ROM parser trusts the header and data-structure offsets it reads out of theHigh2026
- Linux kernel (drivers/nvme/target): Ordinary client I/O to an nvmet block-device namespace can hit a completion raceHigh2026
- Linux kernel (net/tls): The queue that pins encrypted input buffers while the AEAD engine still references them wasHigh2026
- Linux kernel (net/xfrm): One crafted inner IPv4 header (tot_len = 0) inside an IPTFS payload puts the receive path intoHigh2026
- Linux kernel (net/xfrm): A peer that mixes zero-copy-eligible and copy-path IPTFS fragments in one datagram makesHigh2026
- Linux kernel (drivers/iommu/amd): The AMD IOMMU busy-waits for command completion while holding its spinlock withHigh2026
- Linux kernel (drivers/iommu/intel): The 128-bit VT-d context entry is zeroed with multiple writes while its Present bitHigh2026
- Linux kernel SMC (early link-group access on CLC decline in smc_clc_wait_msg): A peer can send a CLC decline before theHigh2026
- Linux kernel (net/tls): When kTLS RX offload fails at tls_dev_add, the rollback frees the software context but neverHigh2026
- Linux kernel SMC-D client (CHID matching against unpopulated ism_dev slot): Slot 0 of the client's ISM device array isHigh2026
- Linux kernel (net/tls): A remote peer sends a zero-length TLS 1.3 application_data record - which the RFC explicitlyHigh2026
- Linux kernel (drivers/nvme/target): A client that completes the TLS handshake against the NVMe-oF TCP target and thenHigh2026
- Linux kernel (drivers/nvme/target): Every connection that dies partway through queue allocation on the NVMe-oF TCPHigh2026
Linux kernel (arch/x86/kvm/svm): After a CPU offline/online cycle, KVM's ASID generation counter is reset in a way thatHigh2026- Linux kernel (net/xfrm, net/key): No memory corruption here, but a clean namespace boundary break. SA migrationHigh2026
- Linux kernel (drivers/pci/controller/dwc): Raising an MSI-X interrupt is a posted PCI write, and the endpoint driverHigh2026
- Linux kernel (drivers/iommu/intel): Killing a VM that has a device attached through the VT-d nested/PASID path makesHigh2026
Linux kernel (virt/kvm): A guest store that splits a page and lands on a datamatch-enabled ioeventfd reaches a BUG_ONHigh2026- Linux kernel (net/xfrm): Outbound policies rejected optional tunnel and BEET templates but never got the same check forHigh2026
Linux kernel (arch/x86/kvm): A guest that disables paravirtual EOI while KVM still has a pending PV-EOI request, andHigh2026- Linux kernel (arch/x86/kernel/fpu): A guest that disables an XSAVE feature through XFD while the saved XSTATE_BV stillHigh2026
- Linux kernel (net/rds): RDS always programs the masked variants of the RDMA atomic opcodes, but the send-completionHigh2026
- Linux kernel (drivers/pci): An SR-IOV device that stops answering config reads makes the VF Resizable BAR restore pathHigh2026
- Linux kernel (drivers/bus/fsl-mc): The fsl-mc bus read its driver_override string without holding the device lock, soMedium2026
- Linux kernel (drivers/pci): The PCI bus match callback read driver_override without the device lock, so the overrideMedium2026
- Linux kernel (drivers/vfio/pci/xe): Resetting a passed-through Intel GPU virtual function that does not supportMedium2026
- Linux kernel (net/xfrm): The async-event reply buffer was sized without accounting for the interface-ID attribute, soMedium2026
- Linux kernel (drivers/iommu/amd): AMD-Vi hands out the completion-wait sequence number outside the IOMMU lock, soMedium2026
- Linux kernel (net/xfrm): Tearing down an IPTFS security association cancels its hrtimers while holding the very locksMedium2026
- Linux kernel (net/smc): Setsockopt() on an SMC socket copies the option value from user memory while holding the socketMedium2026
- Linux kernel (drivers/iommu/iommufd): A tenant using nested translation can ask iommufd to process a cache-invalidationMedium2026
- Linux kernel (drivers/iommu/iommufd): Iommufd accepted any non-zero virtual event queue depth up to U32_MAX, so aMedium2026
- Linux kernel (net/xfrm): The policy-hash rebuild preallocates for exactly the wrong half of the policy set - the guardMedium2026
- Linux kernel (drivers/nvme/target): A client that asks the target to create a submission queue with an invalid queue IDMedium2026
- Linux kernel (drivers/iommu): The ARM long-descriptor unmap path returns a negative errno through an unsigned size_tMedium2026
- Linux kernel (drivers/pci): Tearing down a PF that still has SR-IOV VFs takes pci_rescan_remove_lock recursively andMedium2026
- Linux kernel (drivers/iommu/iommufd): A failed copy_to_user while draining the iommufd fault queue restarts the sameMedium2026
- Linux kernel (drivers/vfio): A blocked migration-state transition makes the vfio state machine spin forever whileMedium2026
- Linux kernel (drivers/vfio/cdx): A tenant can call the interrupt-configuration ioctl with the trigger flags before MSIMedium2026
- Linux kernel (drivers/iommu): An unaligned DMA mapping with no aligned middle section calls into the mapper with lengthMedium2026
- Linux kernel (drivers/pci): A failed mmap of peer-to-peer DMA memory leaks the pgmap reference it took, and the leak isMedium2026
- Linux kernel RDS connection info (uninitialised per-item buffer copied to userspace): The connection-info walkers handMedium2026
- Linux kernel (drivers/iommu): The reset-completion path re-attaches an IOMMU group's domain without checking that theMedium2026
- Linux kernel (drivers/iommu/intel): VT-d accepted a PASID attachment to a nested domain whose parent has dirty trackingMedium2026
- Linux kernel (drivers/vfio/pci): The disable_idle_d3 power-management flag was a module-wide global that could changeMedium2026
- Linux kernel (drivers/iommu/intel): SVA bind and unbind are asymmetric on VT-d hardware without PCI/PRI - bind skipsMedium2026
Linux kernel (arch/x86/kvm/vmx): When a nested VM-Enter fails on invalid guest state, KVM took an open-coded exit pathMedium2026- Linux kernel (drivers/vfio): Vfio deleted the device before removing its debugfs tree, so debugfs files stay visibleMedium2026
- Linux kernel (drivers/pci/controller): The Hyper-V PCI front-end frees its PCI domain number twice on a probe failureMedium2026
202397
- Proxmox VE: unauthenticated API login bypass via arbitrary tfa-challenge yields root@pamCriticalSep 1, 2026
- Linux i915 GPU kernel driver: A use-after-free in the i915 GPU kernel driver. The general shape is that a GPU object isHighDec 30, 2025
- Linux kernel amdkfd (KFD compute driver, /dev/kfd) (drm/amdkfd): A NULL pointer dereference in the amdkfd (KFD computeUnscoredDec 30, 2025
- Linux kernel amdkfd (KFD compute driver, /dev/kfd) (drm/amdkfd): A race condition or locking defect in the amdkfd (KFDUnscoredDec 24, 2025
- Linux kernel amdkfd (KFD compute driver, /dev/kfd) (drm/amdkfd): A use-after-free in the amdkfd (KFD compute driverHighDec 9, 2025
- Linux i915 GPU kernel driver: A use-after-free in the i915 GPU kernel driver. The general shape is that a GPU object isHighOct 4, 2025
- Linux cpufreq/amd-pstate-ut - kernel panic when loading the unit-test driver: Loading the amd-pstate unit-test moduleMediumOct 4, 2025
- Linux i915 GPU kernel driver (display page table objects): The buffer object backing a display page tableHighSep 18, 2025
- Linux i915 GPU kernel driver (active barrier tracking): Non-idle barriers were misused as fence trackers, corruptingHighMay 2, 2025
- Linux kernel amdkfd (KFD compute driver, /dev/kfd) (drm/amdkfd): Missing or insufficient validation of user-suppliedHighMay 2, 2025
- Linux i915 GPU kernel driver (GEM tiling): A double-free reachable by racing I915_GEM_SET_TILING from multiple threads.HighMar 27, 2025
- Linux kernel amdkfd (KFD compute driver, /dev/kfd) (drm/amdkfd): A correctness defect in the amdkfd (KFD computeHighMar 27, 2025
- Linux i915 GPU kernel driver: A use-after-free in the i915 GPU kernel driver. The general shape is that a GPU object isHighAug 21, 2024
- AMD CPU (Sinkclose): Sinkclose: SMM lock bypassHighAug 12, 2024
- Linux kernel amdkfd (KFD compute driver, /dev/kfd) (drm/amdkfd): An out-of-bounds access in the amdkfd (KFD computeHighMay 21, 2024
- Linux kernel amdkfd (KFD compute driver, /dev/kfd) (drm/amdkfd): A use-after-free in the amdkfd (KFD compute driverHighMay 21, 2024
- Linux kernel amdkfd (KFD compute driver, /dev/kfd) (drm/amdkfd): Missing or insufficient validation of user-suppliedHighMay 17, 2024
- Linux kernel BPF verifier: stack bound arithmetic done in 32 bits could overflowMediumMay 17, 2024
- Linux kernel amdkfd (KFD compute driver, /dev/kfd) (drm/amdkfd): A race condition or locking defect in the amdkfd (KFDMediumApr 2, 2024
- Linux kernel - NVMe-oF TCP target, drivers/nvme/target/tcp.c: A host sending an H2CData command with a DATALHighFeb 23, 2024
- GPU local/shared memory not cleared between kernels (AMD, Apple, Qualcomm, Imagination): A GPU kernel reads whateverMediumJan 16, 2024
Xen (64-bit PV): Top-level shadow reference dropped too early for 64-bit PV guests - privilege escalation to hostHighJan 5, 2024
Xen (libfsimage/pygrub): Multiple vulnerabilities in libfsimage disk handlingHighJan 5, 2024
Xen on AMD - debug extensions (DBEXT) exposure to guests: AMD CPUs since roughly 2014 carry extensions to x86 debuggingMediumJan 5, 2024
Xen on AMD - debug extensions (DBEXT) exposure to guests: Companion to the other XSA-444 debug-extension issue on AMD.MediumJan 5, 2024- shadow-utils: Possible password leak during passwd(1) change (uninitialised memory)MediumDec 27, 2023
- Linux kernel (perf): Out-of-bounds write in perf_read_group() via read_size overflow - local rootHighDec 19, 2023
- Linux kernel (IGMP): Use-after-free in IPv4 IGMP - local privilege escalationHighDec 19, 2023
- Linux kernel (netfilter pipapo): Inactive elements mishandled in nft_pipapo_walk - use-after-free, local rootHighDec 18, 2023
OpenSSH (transport): Terrapin: prefix-truncation attack on the SSH Binary Packet ProtocolMediumDec 18, 2023- Intel CPU (Reptar): Redundant REX-prefix MOVSB causes unpredictable behaviourHighNov 14, 2023
- AMD SEV-ES (CacheWarp): CacheWarp: INVD lets a malicious hypervisor revert SEV-ES guest memory writes, breaking guestMediumNov 14, 2023
- QEMU (IDE/ATAPI): Improper IDE controller reset lets a guest overwrite the host MBR of an attached deviceMediumNov 3, 2023
- VMware vCenter: Out-of-bounds write in the DCERPC implementation - unauthenticated remote code executionCriticalOct 25, 2023
- glibc (ld.so): Looney Tunables: buffer overflow in the ld.so GLIBC_TUNABLES parser - local root on default installsHighOct 3, 2023
- Arm Mali GPU kernel driver: Use-after-free via improper GPU memory processingMediumOct 1, 2023
Linux (Xen netback): Buffer overrun in netback due to an unusual packet - guest attacks dom0HighSep 22, 2023- Linux kernel (eBPF verifier): Incorrect verifier pruning marks unsafe paths as safeHighSep 20, 2023
- QEMU (net): Triggerable assertion via a race on NIC hot-unplug - guest can abort the host QEMU processMediumSep 13, 2023
- Linux kernel (net/sched hfsc): Use-after-free in sch_hfsc qdisc - local rootHighSep 6, 2023
- Linux kernel (AF_UNIX): Use-after-free in unix_stream_sendpage - local privilege escalation, no capabilities neededMediumSep 6, 2023
- AMD CPU (DIV0): Division-by-zero leaves stale quotient data readable across contexts - confidentiality loss on Zen 1MediumAug 8, 2023
- AMD CPU (Inception / SRSO): Inception: Speculative Return Stack OverflowMediumAug 8, 2023
- Linux kernel (nf_tables): UAF adding a rule with NFTA_RULE_CHAIN_ID - local rootHighAug 7, 2023
- Linux kernel (netfilter pipapo): UAF from improper element removal in nft_pipapo_remove() - local rootHighJul 31, 2023
- AMD CPU (Zenbleed): Zenbleed: cross-process/cross-VM register-file data leak on Zen 2 at ~30 kB/s per core, no specialMediumJul 24, 2023
OpenSSH (ssh-agent): Remote code execution in ssh-agent PKCS#11 support when agent forwarding reaches a hostile hostCriticalJul 20, 2023- Linux kernel (mm VMA): StackRot: privilege escalation via non-RCU-protected VMA traversalHighJul 11, 2023
- Linux kernel (nf_tables): Use-after-free in nft_chain_lookup_byid() - local root (Pwn2Own Vancouver chain)HighJul 5, 2023
- Linux kernel (nf_tables): Stack out-of-bounds read/write in nft_byteorder_eval() - local root (Pwn2Own)HighJul 5, 2023
- Linux kernel (nf_tables): UAF in nft_set_lookup_global after mixed named/anonymous set batches - local rootHighJun 28, 2023
- VMware Tools: A fully compromised ESXi host can force VMware Tools to skip host-to-guest authenticationLowJun 13, 2023
- Linux kernel (io_uring): io_uring fixed-buffer registration gives out-of-bounds access to physical memoryHighJun 1, 2023
- Intel i915 graphics driver for Linux (kernel < 6.2.10): A memory-buffer bounds failure in the i915 kernel driver thatHighMay 10, 2023
- Linux kernel (nf_tables): Use-after-free in nf_tables anonymous-set batch processingHighMay 8, 2023
- Oracle VirtualBox: Core component flaw allowing a low-privileged guest user to take over the host VirtualBoxHighApr 18, 2023
- Linux kernel (net/sched tcindex): Use-after-free in the tcindex traffic-control filter - local rootHighApr 12, 2023
KVM (nested VMX): Missing CR0/CR4 consistency checks in nVMX - L2 guest can break nested-virt assumptions / crash hostMediumApr 10, 2023- Linux kernel (netfilter): Integer overflow in nft_payload_copy_vlan - stack leak plus local privilege escalationHighMar 27, 2023
- Linux kernel (OverlayFS/FUSE): OverlayFS copies setuid files from a nosuid FUSE mountHighMar 22, 2023
- systemd: Privilege escalation via the systemctl `less` pager when sudo-granted systemctl is availableMediumMar 3, 2023
- OpenSSL: X.400 address type confusion in X.509 GeneralNameHighFeb 8, 2023
- Linux kernel (ALSA): Use-after-free in snd_ctl_elem_read - local privilege escalationHighJan 30, 2023
- Linux kernel NVMe target core (nvmet_req_complete submission-queue dereference): Nvmet_req_complete() dereferenced reqCritical2023
- Linux kernel (net/smc): When an incoming connection tries SMC-Rv2 and device setup fails, the listener does not resetCritical2023
- Linux kernel (net/smc): On the server side of the SMC-R LLC handshake, adding a second link to a link group runsCritical2023
- CephFS/RBD kernel client (libceph messenger v2): A signedness bug in net/ceph/messenger_v2.c turns an attacker-chosenHigh2023
- Linux kernel (drivers/iommu/iommufd): Splitting a mapping area - which is what a partial unmap does - leaves theHigh2023
- Linux kernel (drivers/iommu): The IOVA allocator's retry path overflows, so the lower-bound check is made against zeroHigh2023
- Linux kernel (drivers/iommu/iommufd): An unmap runs off the end of the pinned page list and drops pin counts on pagesHigh2023
- Linux kernel (drivers/iommu/iommufd): The same hardware page table gets linked into an address space's page-table listHigh2023
- Linux kernel (drivers/iommu/iommufd): The pfn batch end index is left at zero after a carry, so the unpin path walks anHigh2023
- Linux kernel (net/smc): The IB port-up handler walks the global link-group list without holding its lock, so a fabricHigh2023
- Linux kernel SMC-R (fallback path, DECLINE message leaking into the application stream): Silent data corruption, whichHigh2023
- Linux kernel (drivers/iommu/iommufd): The pfn batch carries the wrong page-frame number forward when a mapping spans aHigh2023
- Linux kernel (net/smc): Closing an SMC socket can leave the internal TCP kernel socket with its timers still armed andHigh2023
- Linux kernel (drivers/iommu/iommufd): The destroy ioctl takes a temporary reference on an iommufd object without theHigh2023
- Linux kernel (net/tls): A receiver that holds its TCP window at zero keeps the kTLS sender blocked inside tx_lockHigh2023
- Linux kernel (net/xfrm): A qdisc that reuses skbHigh2023
- Linux kernel (drivers/vfio/pci/hisilicon): The VFIO migration save and resume paths do not advance the data pointer byHigh2023
- Linux kernel (arch/s390/pci): When an SR-IOV VF is hot-unplugged its MMIO resources are freed, but the parent bus keepsHigh2023
- Linux kernel (drivers/pci/pcie): The ASPM link state keeps a raw pointer to function 0 of a multi-function device.Medium2023
- Linux kernel (net/xfrm): XFRM_MSG_NEWAE lets a caller update replay-window state on a state that never had replay_esnMedium2023
- Linux kernel (drivers/vfio): Pinned-memory accounting for a VFIO container is lost across exec(), then underflows to aMedium2023
- Linux kernel (drivers/iommu/iommufd): Iommufd accepts a user address plus length that wraps past zero, then asks the mmMedium2023
- Linux kernel (drivers/iommu/arm/arm-smmu-v3): A process using SVA that unmaps memory drives a flood of SMMU rangeMedium2023
- Linux kernel (drivers/pci): The DOE state machine signals the caller's completion before destroying the work_structMedium2023
- Linux kernel (net/tls): Sendfile() on a kTLS socket whose plaintext and ciphertext buffers are both empty drives theMedium2023
- Linux kernel (net/xfrm): Structure padding in the xfrm algorithm and encapsulation templates was copied to userspaceMedium2023
- Linux kernel (drivers/iommu/amd): The AMD-Vi interrupt thread dereferences a NULL domain while reporting an IOMMU pageMedium2023
- Linux kernel (drivers/vfio): An uninitialized pointer in the VFIO group structure is dereferenced from a group ioctlMedium2023
- Linux kernel (drivers/pci): When the kernel coalesces two adjacent host-bridge apertures it invalidates the absorbedMedium2023
- Linux kernel (drivers/iommu/amd): Unbinding a PASID races the I/O page-fault (PPR) notifications still in flightMedium2023
- Linux kernel (drivers/iommu/iommufd): The vfio type1 info structure is not zeroed before being filled and copied outMedium2023
- Linux kernel (drivers/vfio): Uninitialized kernel stack bytes sitting in a structure hole are copied out to userspaceMedium2023
- Linux kernel (net/xfrm): The 32-bit compat translation of xfrm netlink attributes uses the attacker-supplied attributeMedium2023
- Linux kernel (drivers/vfio/mdev): If creating an mdev type's sysfs entries partially fails, the parent still registersMedium2023
2025153
Xen varstored (Xapi UEFI variable service, OVMF shared buffer): varstored runs in the host's control domain andCriticalJul 9, 2026
Xen (x86): CPU opcode cache corruption - host instability triggerable from a guestHighMay 15, 2026
Xen / x86 CPU: Floating Point Divider State Sampling - transient-execution leak of FP divider state across domainsUnscoredApr 27, 2026- OpenSSL: oversized AEAD IV in a CMS EnvelopedData message overflows a stack buffer before authenticationHighJan 27, 2026
- Linux kernel iomap: length underflow on non-block-aligned reads returns a position past the folioCriticalJan 13, 2026
- Linux kernel mlx5_core RX datapath (striding RQ + XDP multi-buffer): The mlx5 driver assumed an XDP program couldCriticalDec 16, 2025
- Linux kernel amdkfd (KFD compute driver, /dev/kfd) (amd/amdkfd): A division by zero in the amdkfd (KFD compute driverHighDec 16, 2025
- Linux kernel amdkfd (KFD compute driver, /dev/kfd) (drm/amdkfd): A race condition or locking defect in the amdkfd (KFDUnscoredDec 9, 2025
- Linux kernel amdkfd (KFD compute driver, /dev/kfd) (amd/amdkfd): A NULL pointer dereference in the amdkfd (KFD computeUnscoredDec 8, 2025
- Linux kernel BPF: tailcalls ignore expected_attach_type, yielding NULL deref and bypassed context checksHighNov 12, 2025
- Linux kernel SMC: dst entry can be freed under smc_clc_prfx_set during connect(), a local UAFHighNov 12, 2025
- Linux kernel amdkfd (KFD compute driver, /dev/kfd) (drm/amdkfd): A NULL pointer dereference in the amdkfd (KFD computeUnscoredNov 12, 2025
- QEMU e1000: guest-triggered stack overflow in the loopback receive path crashes the host QEMU processMediumOct 31, 2025
Xen (Viridian): Incorrect input sanitisation in Viridian (Hyper-V enlightenment) hypercallsUnscoredOct 31, 2025
Linux kernel KVM arm64: vCPU event ioctls before init hit a BUG() and take down the hostUnscoredOct 30, 2025- Linux kernel mlx5_core flow steering / flow counters (hardware steering): Use-after-free releasingHighOct 15, 2025
- QEMU: use-after-free in the VNC WebSocket handshake crashes the VM process before client authenticationHighOct 3, 2025
- Linux kernel i40e: out-of-bounds read through the netdev_ops debugfs fileHighOct 1, 2025
- VMware Aria Operations / VMware Tools: Local privilege escalation to root inside a managed VM via SDMP service discoveryHighSep 29, 2025
- AMD Zen 1-Zen 5 - branch predictor isolation between guest and userspace hypervisor (AMD-SB-7046): InsufficientUnscoredSep 11, 2025
- Linux kernel amdkfd (KFD compute driver, /dev/kfd) (drm/amdkfd): A NULL pointer dereference in the amdkfd (KFD computeMediumSep 5, 2025
- Linux kernel mlx5_core IPsec RX offload: When hardware reports an xfrm state ID for a decrypted packet whose stateHighAug 19, 2025
- Linux kernel BPF verifier: narrow read of a pointer context field triggers a verifier bug warningMediumAug 19, 2025
Linux KVM - CPU soft lockup setting per-page memory attributes on large SNP guests: Running an SEV-SNP guestMediumAug 16, 2025- Linux kernel amdkfd (KFD compute driver, /dev/kfd) (drm/amdkfd): Missing or insufficient validation of user-suppliedMediumAug 16, 2025
- Intel ice driver (Ethernet 800 Series, Linux kernel mode): Improper input validation in the 800-series Linux kernelHighAug 12, 2025
- Intel ice driver (Ethernet 800 Series, Linux kernel mode): A missing check for an exceptional condition in theHighAug 12, 2025
- Intel ice driver (Ethernet 800 Series, Linux kernel mode): Kernel-mode flaw in the 800-series Ethernet Linux driver (anHighAug 12, 2025
- Intel ice driver (Ethernet 800 Series, Linux kernel mode): Kernel-mode flaw in the 800-series Ethernet Linux driverHighAug 12, 2025
- Intel ice driver (Ethernet 800 Series, Linux kernel mode): Kernel-mode flaw in the 800-series Ethernet Linux driver (aHighAug 12, 2025
- Intel ice driver (Ethernet 800 Series, Linux kernel mode): Kernel-mode flaw in the 800-series Ethernet Linux driverHighAug 12, 2025
- Intel ice driver (Ethernet 800 Series, Linux kernel mode): Kernel-mode flaw in the 800-series Ethernet Linux driver (anHighAug 12, 2025
- Linux i915 GPU kernel driver (GT timeline / VMA allocation): A timeline is left held when VMA allocation fails, soHighJul 25, 2025
- PAM (pam-config): Local user is treated as `allow_active` in PAMHighJul 23, 2025
- Linux kernel (posix-cpu-timers): TOCTOU race between handle_posix_cpu_timers() and posix_cpu_timer_del()HighJul 22, 2025
Xen (VT-d passthrough): Deadlock potential with VT-d and legacy PCI device pass-through - host hangUnscoredJul 17, 2025- VMware ESXi / Workstation / Fusion: Integer overflow in the VMXNET3 virtual NICCriticalJul 15, 2025
- VMware ESXi / Workstation / Fusion: Integer underflow in VMCI leading to an out-of-bounds writeCriticalJul 15, 2025
- VMware ESXi / Workstation / Fusion: Heap overflow in the PVSCSI controllerCriticalJul 15, 2025
- VMware ESXi / Workstation / Tools: Uninitialised memory in vSockets discloses host memory to the guestHighJul 15, 2025
- polkit: out-of-bounds write parsing deeply nested XML policy filesMediumJul 14, 2025
- libssh: unchecked OpenSSL error can leave a partially initialized ChaCha20 context in useHighJul 7, 2025
- libssh: failed key derivation returns success, leaving SSH sessions keyed with uninitialized memoryHighJul 4, 2025
sudo: Local privilege escalation via the `--chroot` optionHighJun 30, 2025
sudo: Local privilege escalation via the `--host` option against host-specific sudoers rulesHighJun 30, 2025- libblockdev / udisks: allow_active to root via libblockdev through udisksHighJun 19, 2025
- Linux kernel (ksmbd): Use-after-free in ksmbd session logoff (found by an LLM-assisted audit)MediumMay 20, 2025
- glibc: Static setuid binaries incorrectly search LD_LIBRARY_PATH during dlopen - local privilege escalationHighMay 16, 2025
- Linux kernel amdkfd (KFD compute driver, /dev/kfd) (drm/amdkfd): A use-after-free in the amdkfd (KFD compute driverHighMay 9, 2025
- Linux kernel amdkfd (KFD compute driver, /dev/kfd) (drm/amdkfd): A NULL pointer dereference in the amdkfd (KFD computeMediumMay 9, 2025
- Linux kernel (net/sched SFQ): Missing limit validation in sch_sfq - out-of-bounds writeMediumMay 1, 2025
- Linux kernel - NVMe/TCP host (initiator), drivers/nvme/host/tcp.c: Nvme_tcp_recv_pdu() did not validate the PDU headerCriticalApr 1, 2025
- Linux kernel amdkfd (KFD compute driver, /dev/kfd) (drm/amdkfd): A NULL pointer dereference in the amdkfd (KFD computeMediumApr 1, 2025
- Linux kernel io_uring: sqe->opcode used unsanitized for table lookups under speculative executionHighMar 12, 2025
- Linux kernel amdkfd (KFD compute driver, /dev/kfd) (amdkfd): A correctness defect in the amdkfd (KFD compute driverHighMar 7, 2025
- VMware ESXi / Workstation: TOCTOU race leading to an out-of-bounds write in VMX - full VM escape to host code executionCriticalMar 4, 2025
- VMware ESXi: Arbitrary kernel write from the VMX process - sandbox escape completing the zero-day chainHighMar 4, 2025
- VMware ESXi / Workstation / Fusion: Out-of-bounds read in HGFS leaks vmx process memory to the guestHighMar 4, 2025
OpenSSH (sshd): Pre-auth memory/CPU amplification - denial of service against sshdMediumFeb 28, 2025- Linux kernel mlx5_ib on-demand paging (ODP): Implicit on-demand-paging memory region destroy work can be queued twiceHighFeb 27, 2025
- Linux kernel (vsock): vsock binding not kept until socket destruction - use-after-free, local root with a public exploitHighFeb 27, 2025
OpenSSH (client): Machine-in-the-middle against the client when VerifyHostKeyDNS is enabledMediumFeb 18, 2025- Linux kernel (net/sched ETS): Out-of-bounds indexing in the ETS qdisc - memory corruption from CAP_NET_ADMINMediumFeb 10, 2025
Microsoft Hyper-V: Heap-based buffer overflow in the NT Kernel Integration VSPHighJan 14, 2025
Microsoft Hyper-V: Use-after-free in the NT Kernel Integration VSP - elevation of privilege, exploited in the wildHighJan 14, 2025
Microsoft Hyper-V: Use-after-free in the NT Kernel Integration VSP - elevation of privilege, exploited in the wildHighJan 14, 2025- Linux kernel (drivers/nvme/target): The target disables a namespace without waiting for in-flight I/O to drain, so aCritical2025
- Linux kernel (net/tls): The strparser kept a stale reference to an skb that TCP had already coalesced away, and theCritical2025
- Linux kernel (net/smc): The SMC listen worker keeps touching the SMC socket after smc_listen_out() has handed it offCritical2025
- Linux kernel (net/tls): A zero-length record already sitting on the rx_list breaks the invariant that zero-copy decryptCritical2025
- Linux kernel SoftiWARP transmit path (siw_qp_tx, siw_tcp_sendpages byte accounting): After do_tcp_sendpages() wasCritical2025
- Linux kernel (net/tls): When the socket buffer is too small to hold a whole record, kTLS parses early and re-parses asCritical2025
- Linux kernel (net/tls): If the skb clone that pins the input buffer for an async decrypt cannot be allocated, kTLSCritical2025
Linux kernel (arch/x86/kvm/svm): When a GSI route changed to something that cannot be posted, KVM only fixed up theHigh2025
Linux kernel (arch/x86/kvm): A guest that is in SMM and then triple-faults makes SVM take the SHUTDOWN intercept andHigh2025- Linux kernel (drivers/iommu/intel): VT-d switched from set-and-check to clear-and-reset when programming device-tableHigh2025
- Linux kernel (drivers/vfio/pci/hisilicon): The guest decides whether the host's VFIO migration code has a valid queueHigh2025
- Linux kernel (drivers/gpu/drm/xe): On SR-IOV-partitioned Intel GPUs, the local-memory translation tables handed to a VFHigh2025
- Linux kernel (drivers/iommu/iommufd): The IOVA allocator's alignment arithmetic wraps near ULONG_MAX and yields aHigh2025
- Linux kernel (drivers/iommu/intel): VT-d advertised IOMMU dirty-page tracking on units whose page walk is not coherentHigh2025
- Linux kernel (drivers/gpu/drm): The shared GPU SVM layer mis-computes the mapping order when an HMM range onlyHigh2025
- CephFS kernel client (ceph.ko, MDS auth caps): In a multi-FS Ceph cluster the kernel client applies an MDS auth capHigh2025
- AMD Pensando ionic cloud driver for VMware ESXi (heap overflow): Second heap overflow in the ionic ESXi driverHigh2025
- AMD Pensando ionic cloud driver for VMware ESXi (heap overflow): Heap-based buffer overflow in the ionic SmartNICHigh2025
- Linux kernel (drivers/iommu): This is the substantive fix for stale IOMMU translations of the kernel address spaceHigh2025
- Linux kernel (net/tls): When a BPF socket policy shrinks the plaintext after the ciphertext length was computed, kTLSHigh2025
- Linux kernel (net/smc): The CLC prefix-match check on the listen path dereferences the destination cache entry'sHigh2025
- Linux kernel (drivers/vfio/platform): Vfio-platform never bounds-checked the count and offset a caller passes toHigh2025
- Linux kernel (drivers/gpu/drm/xe): Xe built its scatter-gather table from HMM page pointers without holding theHigh2025
- Linux kernel (net/tls): KTLS never supported disconnect, but nothing stopped it. A connect(AF_UNSPEC) on a TLS socketHigh2025
- Linux kernel (drivers/gpu/drm/xe): A GPU TLB invalidation for a very large address range computes its length with aHigh2025
- Linux kernel (drivers/gpu/drm/nouveau): A buffer object imported over PRIME leaves a dangling pointer behind, and theHigh2025
- Linux kernel (drivers/gpu/drm/xe): The error path of the Xe VRAM clear helper waits on a fence pointer that is onlyHigh2025
- Linux kernel (drivers/iommu): With iommufd, a tenant can change a passthrough device's IOMMU domain while MSIHigh2025
- Linux kernel (net/tls): A BPF verdict that grows the scatterlist (bpf_msg_push_data) combined with a cork_bytes settingHigh2025
- Linux kernel SMC (struct smc_sock type confusion with inet_sock): Struct smc_sock does not embed struct inet_sock asHigh2025
- Linux kernel (net/xfrm): The guard that forbids changing a collect_md xfrm interface never fired, so a changelink putsHigh2025
- Linux kernel (drivers/iommu/intel): VT-d tore the device off the I/O page-fault queue before the hardware had stoppedHigh2025
- Linux kernel (net/tls): KTLS assumes it owns the TCP receive queue. When another reader drains bytes first, the oldHigh2025
- Linux kernel (net/xfrm): If the task is preempted onto another CPU during SA lookup, a hit in the per-CPU state cacheHigh2025
- Linux kernel (drivers/gpu/drm/xe): Xe frees data that its exported dma-fences still point at - notably the timelineHigh2025
- Linux kernel (drivers/gpu/drm/xe): A tenant that submits a deliberately malformed array bind to the Xe VM_BIND ioctlHigh2025
- Linux kernel (drivers/gpu/drm/xe): On the migration error path the previous fence is released before the code waits onHigh2025
- Linux kernel (net/xfrm): SPI 0 means 'no SPI assigned', but the duplicate-SPI rework started creating states with SPI 0High2025
- Linux kernel (drivers/iommu/iommufd): Aborting an iommufd object allocation freed the object immediately while theHigh2025
- Linux kernel (net/smc): SMC-D loopback registers DMBs (the direct memory buffers a peer reads and writes) out ofHigh2025
- Linux kernel (net/smc): Connect() on an SMC socket takes the destination device pointer out of the dst cache without aHigh2025
- Linux kernel (drivers/gpu/drm/scheduler): When adding reservation-object dependencies to a job, the helper alreadyHigh2025
- Linux kernel (drivers/gpu/drm/vmwgfx): A guest process can get a node left in the vmwgfx validation hash table afterHigh2025
- Linux kernel (net/tls): The kTLS device-offload setup resolved the socket's netdevice outside RCU, so the net_device itHigh2025
Linux kernel (virt/kvm): Unbinding a memslot from a guest_memfd was skipped once the file was already dying, so if theHigh2025- Linux kernel (drivers/gpu/drm/vmwgfx): The vmwgfx command-buffer parser trusted a size field taken straight from theHigh2025
Linux kernel (virt/kvm): KVM blocked turning KVM_MEM_GUEST_MEMFD on for an existing memslot but not turning it off, andHigh2025- Linux kernel (drivers/iommu): In an SVA context the IOMMU walks and caches the CPU's page tables, and on x86 everyHigh2025
- Linux kernel (drivers/gpu/drm/xe): The observation-config ioctl dereferences the config object after releasing the lockHigh2025
- Linux kernel (net/tls): If a page allocation fails while the TLS strparser is copying a partial record, the receiveHigh2025
- Linux kernel (drivers/nvme/target): A connecting client that abandons the TCP connection at the right moment duringHigh2025
- Linux kernel (net/xfrm): Several error paths in the ESP-in-TCP receive code return without freeing the skb, soHigh2025
- Linux kernel (drivers/nvme/target): Every command a client sends to the target carrying metadata (protectionHigh2025
- Linux kernel (net/xfrm): Xfrm_alloc_spi could hand out an SPI that is already in use by another inbound SA, because theHigh2025
- Linux kernel (net/smc): On hosts using soft-RoCE, the IB device has no DMA device, and the SMC buffer-mapping pathHigh2025
Linux kernel (arch/x86/kvm/svm): On AMD hosts that cannot report the next RIP, KVM's WRMSR/HLT/INVD fastpath has toHigh2025- Linux kernel (drivers/gpu/drm/radeon): The radeon video-encode command-stream parser used an uninitialised stack valueMedium2025
- Linux kernel (drivers/gpu/drm/xe): The Xe userptr path takes folio locks while holding the MMU notifier lock, whichMedium2025
Linux kernel (arch/x86/kvm): A guest using its APIC timer in periodic mode can leave KVM programming an already-expiredMedium2025- Linux kernel (drivers/pci/hotplug): Powering off a physical function that still has child virtual functions drops theMedium2025
- Linux kernel (drivers/pci/endpoint): The endpoint function core calls list_del() on a structure that is a list HEADMedium2025
- Linux kernel (drivers/gpu/drm/scheduler): When one tenant's scheduler entity is killed, its scheduled fences are notMedium2025
- Linux kernel (drivers/gpu/drm/xe): A batched array of VM_BIND operations could evict other buffer objects belonging toMedium2025
- Linux kernel (drivers/gpu/drm/scheduler): Tearing down a GPU scheduler entity takes locks from a fence-signallingMedium2025
- Linux kernel (drivers/pci/endpoint/functions): When BAR allocation fails, the endpoint test function frees the backingMedium2025
- Linux kernel (drivers/pci): Enabling or disabling SR-IOV virtual functions was not serialised against PCI hotplug, soMedium2025
Linux kernel (arch/x86/kvm): Guest-supplied array indices in the host's local-APIC emulation (an IPI destination id andMedium2025- Linux kernel (drivers/iommu/intel): On the VT-d PASID detach path, if the PASID being removed is not found the codeMedium2025
- Linux kernel (drivers/pci): When setting up an SR-IOV virtual function fails partway through, the half-initialised VFMedium2025
- Linux kernel (drivers/pci/hotplug): Removing nested PCIe hotplug ports can deadlock - a parent hotplug port holds theMedium2025
- Linux kernel (drivers/iommu): When IOMMU registration fails, the core tore down groups and default domains but leftMedium2025
- Linux kernel (drivers/vfio/pci/hisilicon): The VFIO migration driver reassembled the device's event-queue DMA addressesMedium2025
- Linux kernel (drivers/pci/hotplug): A surprise device removal freezes the PCI host bridge's partitionable endpoint andMedium2025
- Linux kernel (drivers/pci/hotplug): Unplugging the root of a nested PCIe bridge hierarchy leaks the IRQ resources theMedium2025
- Linux kernel (drivers/gpu/drm): The dma_buf pointer cached on a GEM object goes stale the moment userspace drops theMedium2025
- Linux kernel (drivers/gpu/drm/xe): The migration copy path falls back to a stack bounce buffer when the tenant's bufferMedium2025
- Linux kernel (drivers/pci/endpoint/functions): The endpoint test function releases DMA channels it may never haveMedium2025
- Linux kernel (drivers/pci/pcie): AER's rate limiter dereferences per-device error state without checking it exists.Medium2025
- Linux kernel (drivers/iommu/iommufd): A user-supplied page shift of 63 overflows the divisor in the iommufdMedium2025
- Linux kernel (drivers/pci/pcie): The AER subsystem allocates its per-device error-tracking structure without checkingMedium2025
- Linux kernel (drivers/pci/endpoint): Endpoint function sub-groups were created asynchronously by a delayed work itemMedium2025
- Linux kernel (drivers/iommu/iommufd): The iommufd dirty-tracking bitmap computed an index by shifting a 32-bit constantMedium2025
- Linux kernel (drivers/iommu): Removing a device from the per-IOMMU page-fault queue responds to outstanding faults butMedium2025
- Linux kernel (drivers/pci/controller): The Intel VMD driver guarded config-space access with a lock type that becomes aMedium2025
- Linux kernel (drivers/pci/pcie): PCIe bandwidth control dereferences a bridge's subordinate bus pointer withoutMedium2025
- Linux kernel (drivers/pci/endpoint/functions): The NTB endpoint function drivers never checked whether their workqueueMedium2025
- Linux kernel (drivers/vfio/pci/pds): The pds VFIO variant driver shipped without a detach_ioas operation, so it had noMedium2025
2024152
- AMD SEV-SNP (BadRAM): BadRAM: improper validation of DIMM SPD metadata lets an attacker with physical access or ring0MediumJun 10, 2026
- AMD CPU (TSA-L1): Transient Scheduler Attack - store-to-load forwarding leak across contexts on Zen 3/4MediumJul 8, 2025
- AMD CPU (TSA-SQ): Transient Scheduler Attack via the store queue - cross-context information leakMediumJul 8, 2025
- AMD CPU (EntrySign): Improper signature verification in the AMD CPU microcode patch loaderHighJun 27, 2025
Xen / Intel CPU (ITS): Indirect Target Selection - speculative execution leak across privilege domains on Intel partsMediumMay 13, 2025- Linux kernel - NVMe-oF target configfs, drivers/nvme/target/configfs.c: Nvmet_root_discovery_nqn_store() treated theMediumJan 15, 2025
- Linux kernel amdkfd (KFD compute driver, /dev/kfd) (drm/amdkfd): A race condition or locking defect in the amdkfd (KFDMediumJan 15, 2025
Linux KVM x86 - hypercall completion for protected guests: KVM used the wrong helper to decide whether a hypercallMediumJan 11, 2025- Linux kernel amdkfd (KFD compute driver, /dev/kfd) (drm/amdkfd): An out-of-bounds access in the amdkfd (KFD computeHighDec 28, 2024
- Linux kernel mlx5_ib (pkey change notifier): A race between InfiniBand device deregistration and the pkey-change workHighDec 27, 2024
- Linux kernel (ALSA usb-audio): Out-of-bounds access for Extigy/Mbox devicesMediumDec 27, 2024
- Linux kernel amdkfd (KFD compute driver, /dev/kfd) (drm/amdkfd): A correctness defect in the amdkfd (KFD computeMediumDec 27, 2024
- Linux kernel (ALSA usb-audio): Out-of-bounds read finding clock sourcesHighDec 24, 2024
Xen (x86 speculation): Xen hypercall page unsafe against speculative attacks - guest leaks hypervisor memoryUnscoredDec 24, 2024- Intel CPU (Native BHI): Native Branch History Injection - unprivileged user leaks kernel memory despite eIBRSMediumDec 19, 2024
- Linux kernel mlx5_core kTLS TX offload: The kTLS TX path mixes get_page() and page_ref_inc() when acquiring referencesCriticalDec 4, 2024
- Linux kernel (uvcvideo): Out-of-bounds write parsing UVC_VS_UNDEFINED frames - exploited in the wildHighDec 2, 2024
- Linux kernel (HID): Uninitialised HID report buffer leaks kernel memoryMediumNov 19, 2024
- Linux kernel (vsock/virtio): Dangling pointer in vskMediumNov 19, 2024
- Linux kernel amdkfd (KFD compute driver, /dev/kfd) (drm/amdkfd): A use-after-free in the amdkfd (KFD compute driverHighOct 21, 2024
- Linux kernel BPF verifier: sign-extended packet-pointer loads produce an invalid skb->data addressMediumOct 21, 2024
- Linux kernel x86/mm: identity maps built from 1 GB pages cover unrequested reserved memoryMediumOct 21, 2024
- Go FIPS OpenSSL: FIPS-mode zeroed buffers can force HMAC false matches and all-zero derived keysMediumOct 1, 2024
- Linux kernel amdkfd (KFD compute driver, /dev/kfd) (drm/amdkfd): Missing or insufficient validation of user-suppliedHighSep 27, 2024
- Linux kernel mlx5_core RX datapath (SHAMPO / HW-GRO): A remote sender can make the mlx5 receive path release a SHAMPOCriticalSep 18, 2024
- VMware vCenter: Heap overflow in DCERPC - unauthenticated remote code execution on vCenterCriticalSep 17, 2024
- VMware vCenter: Privilege escalation to root on vCenter via a crafted network packetHighSep 17, 2024
- Linux kernel mlx5_core TX timeout devlink health reporter: The TX timeout recovery path runs without the state lock, soHighSep 11, 2024
- Linux kernel mlx5_core RX datapath (SHAMPO): SHAMPO can deliver completion entries with zero consumed stridesCriticalSep 4, 2024
- Linux drm/xe GPU kernel driver (display opregion): A resource leak in the xe driver's display opregion handlingMediumSep 4, 2024
- Linux kernel mlx5_core TC connection tracking offload: Updating a connection-tracking entry allocates a replacementCriticalAug 21, 2024
- Intel ice driver (Ethernet 800 Series, Linux kernel mode): Improper initialisation in the Linux kernel-mode driver forHighAug 14, 2024
- Intel ice driver (Ethernet 800 Series, Linux kernel mode): Kernel-mode driver flaw in the Intel 800-series EthernetHighAug 14, 2024
- Intel ice driver (Ethernet 800 Series, Linux kernel mode): Kernel-mode driver flaw in the Intel 800-series EthernetHighAug 14, 2024
- Intel ice driver (Ethernet 800 Series, Linux kernel mode): Kernel-mode driver flaw in the Intel 800-series EthernetHighAug 14, 2024
- Intel ice driver (Ethernet 800 Series, Linux kernel mode): Kernel-mode driver flaw in the Intel 800-series EthernetHighAug 14, 2024
- Intel oneAPI Math Kernel Library (oneMKL): An uncontrolled library search path: the component loads a shared libraryMediumAug 14, 2024
- Intel ice driver (Ethernet 800 Series, Linux kernel mode): A protection-mechanism failure in the E810 Linux kernelMediumAug 14, 2024
- QEMU (NBD server): Improper synchronisation during socket closure - DoS of the QEMU NBD serverHighAug 5, 2024
- Linux kernel BPF: use-after-free freeing map elements that hold BPF timersHighJul 29, 2024
- Linux i915 GPU kernel driver: A use-after-free in the i915 GPU kernel driver. The general shape is that a GPU object isHighJul 29, 2024
- Linux kernel nvme-fabrics: admin tag exhaustion during reconnect can hang the host indefinitelyMediumJul 29, 2024
- Linux kernel amdkfd (KFD compute driver, /dev/kfd) (drm/amdkfd): A correctness defect in the amdkfd (KFD computeHighJul 18, 2024
- Linux kernel mlx5_ib (shared receive queue): The max_sge attribute for a shared receive queue is taken from the userHighJul 12, 2024
Microsoft Hyper-V: Hyper-V elevation of privilege, exploited in the wildHighJul 9, 2024- OpenSSH (sshd, RHEL9): Signal-handling race in the privsep child - possible RCE, RHEL 9 specificHighJul 8, 2024
- QEMU (qemu-img): `qemu-img info` on an untrusted qcow2 image reaches arbitrary host file read/writeHighJul 2, 2024
OpenSSH (sshd): regreSSHion: signal-handler race in sshd giving unauthenticated remote root on glibc LinuxHighJul 1, 2024- VMware ESXi: AD-integrated ESXi grants full host admin to any member of a re-created "ESX Admins" groupMediumJun 25, 2024
- VMware vCenter: Heap overflow in the DCERPC implementation - unauthenticated remote code execution on vCenterCriticalJun 18, 2024
- Linux kernel (net routing): Use-after-free in network route management (__dst_negative_advice) - actively exploitedHighJun 10, 2024
- Arm Mali GPU kernel driver: Use-after-free in the Bifrost/Valhall GPU kernel driverHighJun 7, 2024
- Linux kernel amdkfd (KFD compute driver, /dev/kfd) (drm/amdkfd): Missing or insufficient validation of user-suppliedMediumMay 30, 2024
Xen (x86 speculation): Incorrect logic for BTC/SRSO mitigationsHighMay 16, 2024- Intel DSA/IAA (idxd): Hardware erratum: direct access to Intel DSA/IAA accelerators by an untrusted application allowsMediumMay 16, 2024
- Linux i915 GPU kernel driver: A use-after-free in the i915 GPU kernel driver. The general shape is that a GPU object isHighMay 1, 2024
- Linux kernel amdkfd (KFD compute driver, /dev/kfd) (drm/amdkfd): A memory or reference-count leak in the amdkfd (KFDMediumMay 1, 2024
- glibc (iconv): Out-of-bounds write in the ISO-2022-CN-EXT iconv converter - turns PHP/app file-read bugs into RCEHighApr 17, 2024
- Oracle VirtualBox: Easily exploitable Core flaw allowing unauthorised access to VirtualBox-accessible dataMediumApr 16, 2024
- Linux kernel amdkfd (KFD compute driver, /dev/kfd) (amdkfd): An out-of-bounds access in the amdkfd (KFD compute driverMediumApr 13, 2024
- QEMU (virtio): DMA reentrancy leads to double free across virtio devices - guest-to-host code execution in QEMUHighApr 9, 2024
- Linux kernel (netfilter): nft_chain_filter NETDEV_UNREGISTER mishandling for inet/ingress basechains - UAFMediumApr 4, 2024
- util-linux (wall): WallEscape: escape-sequence injection via wall(1)MediumMar 27, 2024
libvirt: Off-by-one in udevListInterfacesByStatus() - libvirtd crash / info leakMediumMar 11, 2024- VMware ESXi / Workstation / Fusion: Use-after-free in the XHCI USB controllerCriticalMar 5, 2024
- VMware ESXi / Workstation / Fusion: Use-after-free in the UHCI USB controllerCriticalMar 5, 2024
- Linux kernel (ksmbd): Use-after-free in ksmbd_tcp_new_connection() - in-kernel SMB serverHighFeb 22, 2024
- Linux kernel (nf_tables): Use-after-free in nft_verdict_init() - double-free to local rootHighJan 31, 2024
- Linux kernel (kTLS): splice() into a kTLS socket overwrites read-only kernel pages - local privilege escalationHighJan 17, 2024
- Linux kernel (io_uring): Page use-after-free via io_uring buffer-ring mmap - unprivileged local user to rootHighJan 16, 2024
- Linux kernel (net/tls): The async decrypt completion released pages that the decrypt path never took a reference on, soCritical2024
- Linux kernel (net/tls): The thread in recvmsg/sendmsg can exit as soon as the async crypto callback signals completionCritical2024
- Linux kernel (net/tls): When the crypto queue is full the AEAD call returns -EBUSY instead of -EINPROGRESS and theCritical2024
- Linux kernel (net/tls): The async crypto callback signalled completion before scheduling the transmit work, so theCritical2024
- Linux kernel (net/tls): When a decrypt goes to the crypto backlog and a sibling decrypt fails, the error path releasesCritical2024
- Linux kernel (drivers/nvme/host): A discard (TRIM) request that is retried and fails again before a fresh payload isCritical2024
- Linux kernel SMC-R/SMC-D (CLC proposal parsing, smcd_v2_ext_offset): The SMC server trusted an offset field takenCritical2024
- Linux kernel RTRS client (rtrs-clt init_conns connection-id bound): When connection setup fails partway through, theCritical2024
- Linux kernel SMC-R/SMC-D (CLC proposal parsing, v2_ext_offset / eid_cnt / ism_gid_cnt): The same unvalidated-offsetCritical2024
- Linux kernel (net/smc): The server-side listen worker frees a connection outside the socket lock, so smc_conn_free()Critical2024
- Linux kernel (net/smc): A link-down work item can be queued before the link group is freed but run after, so the workerCritical2024
- Linux kernel (net/tls): The synchronous decrypt path shared refcounting and completion state with the async path, so aCritical2024
- Linux kernel (drivers/pci/controller/dwc): A PCIe BAR window can end up larger than the memory actually backing it, soCritical2024
- Linux kernel SMC-R/SMC-D (CLC proposal parsing, iparea_offset / ipv6_prefixes_cnt): Third instance of the same class inCritical2024
- Linux kernel (drivers/iommu/intel): The VT-d I/O page-fault reporting path looks up the faulting device with noHigh2024
- Linux kernel (drivers/iommu): A dropped return statement made the IOMMU fault handler process a partial PRIHigh2024
Linux kernel (arch/x86/kvm/vmx): KVM's guest/host-mode Intel PT virtualization was broken end to end and theHigh2024- Linux kernel (drivers/iommu/intel): Use-after-free of VT-d cache-tag objects. Device-TLB cache tags outlive the IOMMUHigh2024
Linux kernel (arch/x86/kvm/svm): Hardware ignores the low five bits of CR3 when loading PDPTEs, but KVM's nested SVMHigh2024- Linux kernel (net/tls): A non-DATA record already copied out of the pending list could be merged with a second recordHigh2024
- VMware ESXi / Workstation / Fusion (storage controller out-of-bounds read/write): A malicious actor inside a VMHigh2024
- Linux kernel (net/xfrm): The error path of xfrm_input leaves the secpath entry pointing at poisoned memory, and theHigh2024
- Linux kernel NVMe target authentication (nvmet-auth DH group setup): CtrlHigh2024
- Linux kernel (drivers/iommu/iommufd): On a partially-failed access attach, iommufd overwrites the xarray id that tracksHigh2024
- Linux kernel (drivers/vfio/pci): A tenant races a DisINTx write to emulated config space against a SET_IRQS ioctl, soHigh2024
- Linux kernel (drivers/vfio/pci): A tenant holding a passthrough PCI device can make the kernel signal an interruptHigh2024
- Linux kernel (drivers/gpu/drm): The shared VRAM buddy allocator reports success for a ranged allocation it neverHigh2024
- Linux kernel (drivers/gpu/drm/nouveau/nvkm/core): Nouveau's per-client object tree had no locking at all, so concurrentHigh2024
- Linux kernel (drivers/gpu/drm/nouveau): Nouveau's VM_BIND remap path miscalculates the address and range of the unmapHigh2024
- Linux kernel (drivers/gpu/drm): DRM core stores a pointer to the caller's struct pid before taking a reference on itHigh2024
- Linux kernel (drivers/pci/msi): When MSI vector allocation for a PCI device fails, the core MSI code keeps using aHigh2024
- Linux kernel (drivers/gpu/drm/xe): The Xe VRAM manager computed a buffer object's minimum page size by shifting aHigh2024
- Linux kernel (drivers/gpu/drm/i915/gem): The size of a partial GEM mapping is computed without accounting for theHigh2024
- Linux kernel (drivers/gpu/drm/xe): Freeing a scheduler job dereferences the VM it belongs to, but the final exec-queueHigh2024
- Linux kernel (drivers/gpu/drm/xe): The preempt-fence lock lives inside the exec queue, but the queue reference isHigh2024
- Linux kernel (drivers/pci): Pci_bus_lock() locked every device on the bus except the bridge itself, so a secondary busHigh2024
- Linux kernel (drivers/gpu/drm/xe): The per-client memory accounting walks buffer-object state (TTM resource, tt pages)High2024
- Linux kernel (drivers/gpu/drm/xe): The GPU VM is published into the id table before the create ioctl finishes with itHigh2024
- Linux kernel (drivers/gpu/drm/xe): The observation/OA path reuses one batch buffer and appends a batch-end command onHigh2024
- Linux kernel (drivers/iommu/intel): VT-d walked the PCI DMA-alias list for devices that are not PCI at all whileHigh2024
- Linux kernel (drivers/gpu/drm/xe): Xe freed a job from inside timeout-detection-and-recovery while the submissionHigh2024
- Linux kernel (drivers/vfio/pci): Out-of-bounds read past the ecap_perms table when a tenant touches emulated PCIeHigh2024
- Linux kernel (drivers/gpu/drm/xe): A tenant that suspends an exec queue and then closes it while the GuCHigh2024
- Linux kernel (drivers/iommu/iommufd): An error path releases the iommufd fault object and the iommufd context twiceHigh2024
- Linux kernel (net/xfrm): SA lookup can observe the new hash mask before the new bucket array is published, so itHigh2024
- Linux kernel NVMe target core (controller teardown racing queue-pair establishment): An initiator that disconnectsHigh2024
- Linux kernel NVMe-oF TCP target (nvmet-tcp queue command allocation failure): When command allocation for a new queueHigh2024
- Linux kernel SMC (CLC message drain loop, unchecked sock_recvmsg return): The length field in the CLC header isHigh2024
Linux kernel (arch/x86/kvm/vmx): With adaptive PEBS exposed, KVM never guaranteed that LBR MSRs held guest valuesHigh2024- Linux kernel (drivers/gpu/drm/nouveau): When the device-to-host copy behind a page fault silently fails, the faultHigh2024
- Linux kernel (drivers/gpu/drm/vmwgfx): A tenant that asks for a fence event on its DRM fd and then reads the fd backHigh2024
- Linux kernel (drivers/iommu/iommufd): A tenant supplies an IOVA and user pointer whose alignment math overflows, soHigh2024
- Linux kernel (drivers/pci): A Downstream Port Containment event and a device removal happening at the same time leaveMedium2024
- Linux kernel (drivers/pci): A pci_slot holds an uncounted pointer to the pci_bus below it, and on hot removal the busMedium2024
- Linux kernel SMC-D diagnostics (smc_diag, rmb_desc access during connection dump): Dumping SMC-D connections whileMedium2024
- Linux kernel (drivers/iommu/intel): The whole node hangs. VT-d keeps re-issuing an ATS device-TLB invalidation to aMedium2024
- Linux kernel (drivers/iommu/iommufd): The cache-invalidation ioctl calls a driver operation that may not exist, jumpingMedium2024
- Linux kernel (net/xfrm): An SA created with an AF_UNSPEC selector escaped prefix-length validation, and the kernel thenMedium2024
- Linux kernel (drivers/iommu/intel): Attaching a nested parent domain skips allocating the invalidation batch structureMedium2024
- Linux kernel (drivers/pci/pcie): The ASPM link state of a PCIe switch is freed as soon as ANY function on the upstreamMedium2024
- Linux kernel (drivers/pci): Pm_runtime_get_sync() does not wait for an already-running .runtime_idle() callback, so aMedium2024
- Linux kernel (drivers/vfio/platform): A tenant holding a vfio-platform device can loopback-trigger an interrupt beforeMedium2024
- Linux kernel (drivers/vfio/fsl-mc): The eventfd trigger for a vfio-fsl-mc interrupt starts out NULL and becomes NULLMedium2024
- Linux kernel (drivers/pci/endpoint): Pci_epc_destroy() releases the PCI domain ID using a device object it has alreadyMedium2024
- Linux kernel (drivers/iommu/intel): On device release VT-d could dereference a NULL domain and, separately, leave theMedium2024
- Linux kernel (drivers/gpu/drm/nouveau/nvkm/subdev/instmem): Concurrent GPU work races the instance-memory pointerMedium2024
- Linux kernel (drivers/vfio/pci): For passthrough devices whose INTx has to be masked at the irqchip, the IRQ is enabledMedium2024
- Linux kernel (drivers/gpu/drm/nouveau): Calling the legacy pushbuf submission ioctl on a client that has VM_BINDMedium2024
- Linux kernel (net/tls): Splice with MSG_SPLICE_PAGES and MSG_MORE could push more pages into the plaintext scatterlistMedium2024
- Linux kernel (net/tls): Tls_init published the new sk_prot before the TLS context was fully initialized, so aMedium2024
- Linux kernel (drivers/gpu/drm/xe): A tenant's jobs can occupy the same copy engines the driver needs to service GPUMedium2024
- Linux kernel (drivers/gpu/drm): Three lines of userspace - mmap a GEM object with PROT_WRITE and MAP_PRIVATE, thenMedium2024
- Linux kernel (drivers/vfio/pci): An uninitialized stack variable is used as the device count when a tenant asks vfioMedium2024
- Linux kernel (drivers/pci/hotplug): The hotplug driver disables MSI/MSI-X during slot unregistration after the MSI dataMedium2024
- Linux kernel (drivers/gpu/drm/xe): Same per-client accounting path, different failure - if the fdinfo read drops theMedium2024
- Linux kernel (drivers/gpu/drm/xe): User VM_BIND work is scheduled onto engines that can themselves take page faultsMedium2024
- Linux kernel (net/xfrm): Dumping SAs over xfrm netlink copies algorithm structures that were never fully initializedMedium2024
- Linux kernel (drivers/gpu/drm/xe): Passing a sync object that fails fence lookup makes the exec ioctl return toMedium2024
- Linux kernel (drivers/gpu/drm/xe): Every exec ioctl that bails on an input-validation error leaves an exec-queueMedium2024
- Linux kernel (drivers/vfio/pci): A failed interrupt-context allocation while enabling INTx leaks the IRQ name string.Medium2024
- Linux kernel (net/tls): Tls_sw_recvmsg takes a psock reference before acquiring the reader lock and returns withoutMedium2024
- Linux kernel (drivers/pci): Every write to a device's reset_method sysfs attribute that contains no space leaks theMedium2024
202286
- Linux kernel - NVMe-oF TCP target, drivers/nvme/target/tcp.c: The NVMe/TCP target used the host-supplied Transfer TagCriticalDec 24, 2025
- Linux kernel amdkfd (KFD compute driver, /dev/kfd) (drm/amdkfd): A memory or reference-count leak in the amdkfd (KFDUnscoredDec 8, 2025
- Linux kernel amdkfd (KFD compute driver, /dev/kfd) (drm/amdkfd): A memory or reference-count leak in the amdkfd (KFDHighOct 7, 2025
- Linux kernel iomap: memory corruption when recording I/O errors during writebackHighSep 18, 2025
- Linux kernel amdkfd (KFD compute driver, /dev/kfd) (drm/amdkfd): A NULL pointer dereference in the amdkfd (KFD computeHighSep 17, 2025
- Linux kernel amdkfd (KFD compute driver, /dev/kfd) (drm/amdkfd): A double free in the amdkfd (KFD compute driverHighSep 15, 2025
- Linux kernel amdkfd (KFD compute driver, /dev/kfd) (drm/amdkfd): A NULL pointer dereference in the amdkfd (KFD computeMediumMay 1, 2025
- Linux kernel amdkfd (KFD compute driver, /dev/kfd) (drm/amdkfd): A NULL pointer dereference in the amdkfd (KFD computeMediumFeb 26, 2025
- Linux kernel amdkfd (KFD compute driver, /dev/kfd) (drm/amdkfd): A race condition or locking defect in the amdkfd (KFDMediumFeb 26, 2025
- Linux kernel mlx5_core software steering (fs_dr): Adding a flow rule with 32 destinations overflows an undersizedHighAug 22, 2024
- Linux kernel drivers/vdpa/mlx5 (mlx5 vDPA net device): A guest with an assigned mlx5 vDPA net device sends anHighJul 16, 2024
- Linux kernel SUNRPC: sysfs read of an RPC transport can oops when the socket is torn down concurrentlyMediumJul 16, 2024
- Linux i915 GPU kernel driver: A use-after-free in the i915 GPU kernel driver. The general shape is that a GPU object isHighApr 28, 2024
- Linux kernel (net/sched cls_route): Use-after-free in the cls_route filterHighJan 8, 2024
- Linux kernel (io_uring): Use-after-free between io_uring and the unix GC - local rootHighJan 8, 2024
- Linux kernel (nf_tables): Cross-table use-after-free in nf_tables leading to local privilege escalationMediumJan 8, 2024
- Intel CPU (Downfall / GDS): Downfall: Gather Data Sampling leaks AVX gather-instruction data across SMT siblingsMediumAug 11, 2023
Xen on AMD Family 17h / Hygon Family 18h - guest SSBD selection: Setting Speculative Store Bypass Disable on AMD FamilyLowMay 17, 2023
Xen (shadow paging): x86 shadow paging arbitrary pointer dereference - host crash or worseUnscoredApr 25, 2023
Xen (shadow paging): x86 shadow plus log-dirty mode use-after-free - guest to hostHighMar 21, 2023- Linux i915 GPU kernel driver (TLB invalidation): An incorrect TLB flush in i915 leaves the GPU able to reach memory itHighJan 27, 2023
- Linux kernel (KASLR): EntryBleed: prefetch side channel defeats KASLR even with KPTIMediumJan 11, 2023
- VMware ESXi / Workstation / Fusion: Heap out-of-bounds write in the USB 2.0 EHCI controllerHighDec 14, 2022
Xen (xenstored): Guest can crash xenstored, taking down control-plane services for all guests on the hostHighNov 1, 2022- OpenSSL 3.0: X.509 email-address punycode buffer overflow (4-byte stack overflow)HighNov 1, 2022
- OpenSSL 3.0: X.509 email-address variable-length buffer overflow (DoS)HighNov 1, 2022
Xen (x86): Unintended memory sharing between guests - cross-tenant data exposureHighNov 1, 2022- Linux kernel (mm anon_vma): Use-after-free from leaf anon_vma double reuse - memory corruption / privesc primitiveMediumOct 9, 2022
KVM: NULL pointer dereference in kvm_irq_delivery_to_apic_fast() - guest crashes the hostMediumAug 31, 2022- Intel CPU (AEPIC Leak): Stale data read from the legacy xAPIC MMIO page - leaks SGX enclave and cross-domain dataMediumAug 18, 2022
- Linux kernel io_uring: missing work_flags identity types cause bad refcounts and a double freeHighJul 22, 2022
- AMD CPU (Branch Type Confusion): Non-Retbleed branch type confusion - speculative cross-domain leakMediumJul 14, 2022
- AMD CPU (Retbleed): Retbleed: arbitrary speculative code execution via return instructionsMediumJul 12, 2022
- Intel CPU (Retbleed): Retbleed on Intel - speculative execution of return instructions leaks across privilege boundariesMediumJul 12, 2022
- Linux kernel (nf_tables): Heap overflow in nft_set_elem_init() - local root, weaponised inside containersHighJul 4, 2022
- Intel CPU (MMIO Stale Data / SBDR): Incomplete cleanup of multi-core shared buffers - stale data read across domainsMediumJun 15, 2022
Xen (x86 PV): Insufficient care with non-coherent mappings - PV guest to host compromiseMediumJun 9, 2022
Xen (x86 PV): Race condition in typeref acquisition - PV guest escalates to host privilegeMediumJun 9, 2022- Linux kernel (netfilter): Use-after-free write in the netfilter subsystem - privilege escalation to rootHighJun 2, 2022
Xen on AMD-Vi - unity map handling on device reassignment: AMD-Vi unity mappings are not correctly torn down orHighApr 5, 2022
Xen on AMD-Vi - unity map handling: Second XSA-400 AMD-Vi unity-map issue. Stale or incorrect IOMMU mappings acrossHighApr 5, 2022
Xen on AMD-Vi - unity map handling: Third XSA-400 AMD-Vi issue. Same class - IOMMU mappings that outlive theirHighApr 5, 2022
Xen on AMD-Vi - unity map handling: Fourth XSA-400 AMD-Vi issue. Patch the set togetherHighApr 5, 2022- Linux i915 GPU kernel driver (GTT TLB handling): Stale GPU TLB entries let the GPU keep reading physical pages afterHighMar 25, 2022
- Linux kernel: out-of-bounds write in watch_queue filters lets a local user gain rootHighMar 25, 2022
- Linux kernel (IPsec ESP): Buffer overflow in the IPsec ESP transformation code - local rootHighMar 23, 2022
- QEMU (virtio-net): Map leaking on error during receive - guest-triggered host memory exhaustion / DoSHighMar 16, 2022
- Linux kernel (pipe): Dirty Pipe: uninitialised pipe_buffer flags allow overwriting read-only files, inclHighMar 10, 2022
- Linux kernel (cgroups v1): cgroups v1 release_agent lets a container with CAP_SYS_ADMIN (or an unconfined userns) runHighMar 3, 2022
- util-linux (chfn/chsh): Partial disclosure of arbitrary files via libreadline in setuid chfn/chshMediumFeb 21, 2022
- Linux kernel (fs_context): Heap overflow in legacy filesystem parameter handlingHighFeb 11, 2022
- Linux kernel (eBPF verifier): kernel/bpf/verifier.c mishandles pointer types - unprivileged BPF to local rootMediumJan 14, 2022
- Linux kernel (net/smc): When an SMC-R link is torn down, the kernel moves the QP to Error state and then destroys theCritical2022
- Linux kernel NVMe-oF TCP host (nvme-tcp, digest error handling in io_work): The initiator kept reading from the socketCritical2022
- Linux kernel NVMe target core (nvmet, request completion during IO connect): KASAN-confirmed use-after-free reachedCritical2022
- Linux kernel (drivers/nvme/host): On the NVMe/RDMA initiator, an async-event command can be submitted against an adminCritical2022
- Linux kernel (drivers/nvme/host): Same race as the RDMA variant but on NVMe/TCP, which is the far more common fabric inCritical2022
- Linux kernel (drivers/nvme/host): The multipath sibling list is walked without SRCU protection during path revalidationCritical2022
- Linux kernel (net/tls): KTLS allocates a 12-byte IV buffer for AES-128-CCM but the decrypt path copies 16 bytes out ofCritical2022
- Linux kernel (net/smc): An unprivileged tenant that opens an AF_SMC socket, registers it with epoll, and lets theHigh2022
- Linux kernel (drivers/gpu/drm/vmwgfx): When the copy of the fence reply back to userspace fails, the driver installs aHigh2022
- Linux kernel (drivers/gpu/drm/vmwgfx): User-resource lookup during command submission used a broken RCU fast path, soHigh2022
- Linux kernel (drivers/gpu/drm/virtio): GEM handle values are guessable, and the driver dereferences the buffer objectHigh2022
- Linux kernel (drivers/gpu/drm): The shared shmem GEM mmap helper dropped a reference it never owned, so the bufferHigh2022
- Linux kernel (drivers/gpu/drm/i915/gem): The access handler for a memory-mapped GEM object never bounds-checks theHigh2022
- Linux kernel (drivers/iommu/arm/arm-smmu-v3): The SMMUv3 SVA path released the pinned ASID without holding a referenceHigh2022
Linux kernel (arch/x86/kvm/mmu): When guest memory is backed by a VM_PFNMAP mapping, KVM derived the target page frameHigh2022- Linux kernel (drivers/gpu/drm/i915/gt): The GPU migration copy path used plain ints for sizes that a tenant controlsHigh2022
- Linux kernel (drivers/gpu/drm/vmwgfx): The dimensions of a DMA surface-copy box submitted in the command stream wereHigh2022
- Linux kernel (drivers/gpu/drm/nouveau): Importing a dma-buf whose backing buffer object fails to initialize leaves theHigh2022
- Linux kernel (drivers/nvme/host): The PRP list mempool is sized in the wrong units, so a large I/O that needs two PRPHigh2022
Linux kernel (arch/x86/kvm): A guest that is not advertised long mode makes the host's SMM emulator walk 16High2022- Linux kernel (net/tls): A BPF sockmap psock could be attached to a socket that already had the kTLS ULP installed. TheMedium2022
Linux kernel (arch/x86/kvm/vmx): The return stack buffer was not refilled on VM exit when the host used IBRS/eIBRS asMedium2022- Linux kernel (drivers/pci): Pci_dev_lock() and the sysfs SR-IOV path took the device lock and the config-space accessMedium2022
- Linux kernel (drivers/vfio/pci): Whoever holds the VFIO device fd for a passed-through PCI function can make the hostMedium2022
Linux kernel (arch/x86/kvm/vmx): Between the point where KVM loads the guest's SPEC_CTRL value and the actual VM entryMedium2022- Linux kernel (drivers/gpu/drm/scheduler): When a process is killed with GPU work still queued, the scheduler entityMedium2022
- Linux kernel (net/xfrm): Transmitting a packet carrying a metadata dst (no dstMedium2022
- Linux kernel (drivers/gpu/drm/i915/gt): Compression (CCS) metadata attached to local memory was not cleared when theMedium2022
- Linux kernel (drivers/vfio): VFIO core advertised migration ioctls for devices whose driver never actually initialisedMedium2022
- Linux kernel (net/xfrm): Transport-mode IPsec packets were reinjected in the same execution context instead of beingMedium2022
- Linux kernel (drivers/iommu/amd): AMD-Vi updated the domain's I/O page-table mode before running the code that freesMedium2022
- Linux kernel (drivers/pci): Pci_device_is_present() read the Vendor/Device ID directly, which always reads as all-onesMedium2022
- Linux kernel (drivers/iommu/intel): On VT-d scalable mode with VMD enabled, RID2PASID setup fails for devices behindMedium2022
- Linux kernel (drivers/iommu/amd): The AMD-Vi PPR (peripheral page request) notifier looked up the faulting PCI deviceMedium2022
202138
- Linux kernel amdkfd (KFD compute driver, /dev/kfd) (drm/amdkfd): An out-of-bounds access in the amdkfd (KFD computeHighOct 1, 2025
- Linux kernel amdkfd (KFD compute driver, /dev/kfd) (drm/amd/amdkfd): A correctness defect in the amdkfd (KFD computeHighMay 24, 2024
Linux KVM x86 - stack out-of-bounds in ioapic_write_indirect(): A guest write to the virtual IOAPIC causes a stackHighMay 21, 2024- Linux kernel amdkfd (KFD compute driver, /dev/kfd) (drm/amdkfd): A race condition or locking defect in the amdkfd (KFDMediumMay 21, 2024
- Linux kernel amdkfd (KFD compute driver, /dev/kfd) (drm/amdkfd): A memory or reference-count leak in the amdkfd (KFDMediumMay 21, 2024
Linux KVM/SVM - missing sev_decommission in sev_receive_start: KVM failed to DECOMMISSION the current SEV contextMediumMay 21, 2024- Linux kernel mlx5_core kTLS RX offload: TLS RX resync list corruption: entries are moved by the resync handlerCriticalApr 10, 2024
- Linux kernel mlx5_core representor TC path + net/sched tc extension: The TC_SKB_EXT skb extension is not zeroedHighMar 25, 2024
- Linux kernel (eBPF): eBPF improper input validation leading to local privilege escalationHighAug 24, 2022
- QEMU (virtio-net): Heap use-after-free in virtio_net_receive_rcu - guest-to-host code execution in the QEMU processHighMar 23, 2022
KVM (AMD SEV-ES): Out-of-bounds read/write in sev_es_string_io() - malicious SEV-ES guest corrupts host memoryHighFeb 18, 2022- polkit: Local privilege escalation via polkit_system_bus_name_get_creds_sync() raceHighFeb 16, 2022
- polkit (pkexec): PwnKit: local privilege escalation to root via argv handlingHighJan 28, 2022
- Linux kernel (af_packet): Double free in packet_set_ring(), local privilege escalationHighJan 26, 2022
Xen on AMD-Vi (AMD IOMMU) - ACPI IVMD unity-map page permissions: Xen honours ACPI-described IOMMU unity mappings butMediumAug 27, 2021
Xen on AMD-Vi - IOMMU page mapping permissions: Second of the XSA-378 IOMMU page-mapping issues on AMD-Vi. IncorrectMediumAug 27, 2021
Xen on AMD-Vi - IOMMU page mapping permissions: Third of the XSA-378 AMD-Vi mapping issues. Same practical consequenceMediumAug 27, 2021- Linux kernel (seq_file / fs layer): Sequoia: size_t-to-int conversion in the filesystem layer, local root on defaultHighJul 20, 2021
- Linux kernel (netfilter x_tables): Heap out-of-bounds write in xt_compat_target_from_user()HighJul 7, 2021
Xen - x86 IOMMU command timeout detection and handling: Xen's IOMMU command timeout handling is inappropriate, so IOMMUHighJun 30, 2021
Xen on x86 - speculative vulnerabilities with bare 32-bit PV guests: Bare (non-shim) 32-bit PV guests run in ring 1, anMediumJun 11, 2021- Linux kernel (eBPF verifier): eBPF ALU32 bitwise-op bounds tracking flawHighJun 4, 2021
KVM: Improper handling of VM_IO/VM_PFNMAP vmas in KVM lets a guest bypass read-only checksHighMay 26, 2021
Microsoft Hyper-V: vmswitch fails to validate guest OID requestsCriticalMay 11, 2021- Linux kernel (overlayfs, Ubuntu patch): OverlayFS file-capability privilege escalationHighApr 17, 2021
- VMware ESXi (OpenSLP): OpenSLP heap overflow - the ESXiArgs ransomware entry point that mass-encrypted thousandsHighFeb 24, 2021
sudo: Baron Samedit: heap overflow in sudo argument parsing, root from any local accountHighJan 26, 2021- Linux kernel (drivers/nvme/host): The NVMe/RDMA initiator destroys the queue pair before the connection manager ID, soCritical2021
- Linux kernel (net/tls): KTLS stored a negative errno into the socket error field where a positive value is expected. ACritical2021
- Linux kernel (net/smc): The early link-group cleanup path deletes the list head instead of the link group, so the groupCritical2021
- Linux kernel (net/tls): When a NIC with active kTLS offload goes down, the offload teardown freed the TLS context whileHigh2021
- Linux kernel (net/smc): The CDC send-completion handler takes a lock inside an smc_sock that close() has already freedHigh2021
Linux kernel (arch/x86/kvm/mmu): The TDP MMU skipped invalid roots when unmapping a GFN range, so KVM could still holdHigh2021- Linux kernel (drivers/nvme/target): When the target's peer-to-peer memory pool runs dry, it still tries to return theHigh2021
Linux kernel (arch/x86/kvm): A failed RSM leaves the vCPU's SMM flag and the MMU role out of sync, so KVM resolves aMedium2021
Linux kernel (arch/x86/kvm): The guard against accessing bytes 4-15 of an emulated APIC register was dropped, andMedium2021- Linux kernel (drivers/pci/hotplug): A power fault on a PCIe hotplug slot latches a sticky status bit that the hardirqMedium2021
- Linux kernel (drivers/iommu/amd): On AMD hosts, switching a device's IOMMU group between a DMA domain and an identityMedium2021
20206
- AMD Radeon Kernel Mode driver - Escape 0x2000c00 call handler: A low-privileged attacker can drive the RadeonHighNov 15, 2021
- VMware ESXi (OpenSLP): Use-after-free in OpenSLP on port 427 - unauthenticated remote code execution on the hypervisorCriticalOct 20, 2020
Xen - x86 PV guest denial of service via SYSENTER: SYSENTER leaves state sanitisation to software, and on AMD hardwareMediumSep 23, 2020- Intel CPU (SRBDS / CrossTalk): Special Register Buffer Data SamplingMediumJun 15, 2020
- Linux i915 GPU kernel driver: A use-after-free in the i915 GPU kernel driver. The general shape is that a GPU object isHighJan 14, 2020
IBM Spectrum Scale kernel module: An unauthenticated local trigger takes down the Spectrum Scale kernel module and withHigh2020
20195
Xen on AMD - x86 HVM pagetable height update: AMD HVM guest OS users can trigger a data-structure access during aHighDec 11, 2019
Xen through 4.12.x - passed-through PCI devices left able to DMA into host memory after being handed to an untrustedMediumOct 31, 2019- Intel x86-64 CPUs (Ivy Bridge onward); Windows and Linux kernel entry paths: The kernel's syscall/interrupt entry pathMediumSep 3, 2019
- Linux kernel (ptrace): Broken permission and object lifetime handling for PTRACE_TRACEME, local rootHighJul 17, 2019
- Intel i915 graphics kernel-mode driver for Linux (< 5.0): Insufficient input validation in the i915 kernel-mode driverHighMay 17, 2019
20185
- Linux kernel mlx5_ib (create QP response): mlx5_ib_create_qp_resp is never initialized in create_qp_common, so creatingLowJul 26, 2019
- Intel CPU (MDS / ZombieLoad): Microarchitectural Fill Buffer Data SamplingMediumMay 30, 2019
- Linux i915 GPU kernel driver (execbuffer2 ioctl): The execbuffer2 ioctl accepted a userspace-supplied address withoutHighMar 21, 2019
- Intel CPU (L1TF / Foreshadow-NG): L1 Terminal Fault: a guest reads any data present in the L1 data cache, includingMediumAug 14, 2018
IBM GPFS kernel module (mmap path): An unprivileged user panics the kernel on a GPFS node just by mmap-ing a file onMedium2018
20166
- Linux kernel (mm, COW): Dirty COW: privilege escalation via MAP_PRIVATE COW breakageHighNov 10, 2016
- QEMU VGA device model (hw/display/vga.c) - banked access to video memory: 'Dark Portal' - the guest sets the VGA bankHigh2016
Xen x86 PV pagetable update fast paths (arch/x86/mm.c): A 32-bit PV guest administrator gains full host privileges byHigh2016- Linux kernel VFIO drivers/vfio/pci/vfio_pci.c - VFIO_DEVICE_SET_IRQS ioctl: A state-machine confusion inHigh2016
- Linux kernel VFIO drivers/vfio/pci/vfio_pci_intrs.c - MSI/MSI-X allocation: Sibling of CVE-2016-9083 in the sameHigh2016
- Linux kernel RDS net/rds/recv.c - rds_inc_info_copy: A structure member is left uninitialised before the RDS messageHigh2016
20158
- ABRT: symlink attack on predictable core-dump paths gives local users root on RHEL hostsHighDec 7, 2015
- libuser: direct /etc/passwd rewrites can corrupt the account database and chain to local rootMediumAug 11, 2015
QEMU / KVM / Xen (VENOM): VENOM: out-of-bounds write in the virtual Floppy Disk ControllerLowMay 13, 2015
QEMU xen_pt PCI passthrough config-space mediation (Xen 3.3.x-4.5.x): The device model failed to mediate guest writesHigh2015
Xen qemu-xen-traditional device model hw/pt-msi.c (MSI-X passthrough): Buffer overflow on the MSI-X table write pathHigh2015
Linux KVM (arch/x86/kvm/svm.c, vmx.c) and Xen 4.3.x-4.6.x - #AC exception handling: A guest raises alignment-checkMedium2015
Xen PCI passthrough - device memory/IO decoding and host memory initialisation: With memory and I/O decoding leftMedium2015
Xen 3.3.x-4.5.x and Linux kernel through 3.19.1 - PCI command register access for assigned devices: A tenant clears theMedium2015
20134
Xen libxl (xenlight) PCI passthrough device setup: The toolstack hands a bus-mastering-capable PCI device to an HVMHigh2013
Xen Intel VT-d IOMMU page-table handling for PCI passthrough: An inverted boolean means Xen clears a present IOMMUHigh2013
Xen AMD-Vi (AMD IOMMU) interrupt remapping table handling: On AMD-Vi platforms Xen used a single interrupt remappingMedium2013
Intel VT-d interrupt remapping engine as used by Xen 3.3.x-4.3.x: Proof that interrupt remapping is not a completeMedium2013