Threats Tagged 'cve-2026-43206'
View all threats tagged with 'cve-2026-43206'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'cve-2026-43206'
Click on any threat for detailed analysis and mitigation recommendations
This update for the SUSE Linux Enterprise Kernel 6.12.0-160000.7.1 fixes various security issues. The following security issues were fixed: - CVE-2026-23161: mm/shmem, swap: fix race of truncate and swap entry split (bsc#1259134). - CVE-2026-23449: net/sched: teql: Fix double-free in teql_master_xmit (bsc#1262213). - CVE-2026-31629: nfc: llcp: add missing return after LLCP_CLOSED checks (bsc#1263791). - CVE-2026-31759: usb: ulpi: fix double free in ulpi_register_interface() error path (bsc#1264078). - CVE-2026-43077: crypto: algif_aead - Fix minimum RX size check for decryption (bsc#1265306). - CVE-2026-43109: x86: shadow stacks: proper error handling for mmap lock (bsc#1269282). - CVE-2026-43110: wifi: brcmfmac: validate bsscfg indices in IF events (bsc#1264483). - CVE-2026-43206: drm/amdkfd: Fix out-of-bounds write in kfd_event_page_set() (bsc#1266668). - CVE-2026-46037: ipv4: icmp: validate reply type before using icmp_pointers (bsc#1267362). - CVE-2026-46242: eventpoll: fix ep_remove struct eventpoll / struct file UAF (bsc#1270300). - CVE-2026-46274: io-wq: check that the predecessor is hashed in io_wq_remove_pending() (bsc#1268624). - CVE-2026-46319: net/sched: act_ct: Only release RCU read lock after ct_ft (bsc#1268281). - CVE-2026-52923: ipc: limit next_id allocation to the valid ID range (bsc#1269034). - CVE-2026-52956: libceph: Fix potential out-of-bounds access in __ceph_x_decrypt() (bsc#1272139). - CVE-2026-52972: crypto: af_alg - Cap AEAD AD length to 0x80000000 (bsc#1269196). - CVE-2026-53133: RDMA/umem: Fix truncation for block sizes >= 4G (bsc#1269822). - CVE-2026-53182: wifi: nl80211: reject oversized EMA RNR lists (bsc#1269885). - CVE-2026-53205: accel/ivpu: Add bounds checks for firmware log indices (bsc#1269903). - CVE-2026-53224: sctp: validate embedded INIT chunk and address list lengths in cookie (bsc#1270023). - CVE-2026-53233: netdev: fix double-free in netdev_nl_bind_rx_doit() (bsc#1269803). - CVE-2026-53246: sctp: validate cached peer INIT chunk length in COOKIE_ECHO processing (bsc#1270024). - CVE-2026-64530: net/sched: cls_api: Handle TC_ACT_CONSUMED in tcf_qevent_hand (bsc#1271867). - CVE-2026-64600: xfs: resample the data fork mapping after cycling ILOCK (RefluXFS) (bsc#1271543). Join the discussion | GCVE Database | 08/26/2026, 16:20:27 UTC Added: 07/31/2026, 15:39:21 UTC |
0 This update for the SUSE Linux Enterprise Kernel 6.4.0-150600.23.112 fixes various security issues: The following security issues were fixed: - CVE-2025-40204,CVE-2026-53224,CVE-2026-53246: sctp: validate cached peer INIT chunk length in COOKIE_ECHO processing (bsc#1253437 bsc#1270023 bsc#1270024). - CVE-2026-31629: nfc: llcp: add missing return after LLCP_CLOSED checks (bsc#1263791). - CVE-2026-31759: usb: ulpi: fix double free in ulpi_register_interface() error path (bsc#1264078). - CVE-2026-43077: crypto: algif_aead - Fix minimum RX size check for decryption (bsc#1265306). - CVE-2026-43109: x86: shadow stacks: proper error handling for mmap lock (bsc#1269282). - CVE-2026-43206: drm/amdkfd: Fix out-of-bounds write in kfd_event_page_set() (bsc#1266668). - CVE-2026-46037: ipv4: icmp: validate reply type before using icmp_pointers (bsc#1267362). - CVE-2026-46242: eventpoll: fix ep_remove struct eventpoll / struct file UAF (bsc#1270300). - CVE-2026-46319: net/sched: act_ct: Only release RCU read lock after ct_ft (bsc#1268281). - CVE-2026-52923: ipc: limit next_id allocation to the valid ID range (bsc#1269034). - CVE-2026-52956: libceph: Fix potential out-of-bounds access in __ceph_x_decrypt() (bsc#1272139). - CVE-2026-52972: crypto: af_alg - Cap AEAD AD length to 0x80000000 (bsc#1269196). - CVE-2026-53133: RDMA/umem: Fix truncation for block sizes >= 4G (bsc#1269822). - CVE-2026-53182: wifi: nl80211: reject oversized EMA RNR lists (bsc#1269885). - CVE-2026-64530: net/sched: cls_api: Handle TC_ACT_CONSUMED in tcf_qevent_hand (bsc#1271867). - CVE-2026-64600: xfs: resample the data fork mapping after cycling ILOCK (RefluXFS) (bsc#1271543). Join the discussion | GCVE Database | 08/25/2026, 00:33:55 UTC Added: 07/18/2026, 11:21:51 UTC |
This update for the SUSE Linux Enterprise Kernel 6.4.0-150700.53.16 fixes various security issues: The following security issues were fixed: - CVE-2025-40204,CVE-2026-53224,CVE-2026-53246: sctp: validate cached peer INIT chunk length in COOKIE_ECHO processing (bsc#1253437 bsc#1270023 bsc#1270024). - CVE-2025-40204: sctp: Fix MAC comparison to be constant-time (bsc#1253437). - CVE-2026-23240: Amend fix for CVE-2026-23240 ('tls: Fix race condition in tls_sw_cancel_work_tx()') (bsc#1262404). - CVE-2026-23449: net/sched: teql: Fix double-free in teql_master_xmit (bsc#1262213). - CVE-2026-31629: nfc: llcp: add missing return after LLCP_CLOSED checks (bsc#1263791). - CVE-2026-31759: usb: ulpi: fix double free in ulpi_register_interface() error path (bsc#1264078). - CVE-2026-43077: crypto: algif_aead - Fix minimum RX size check for decryption (bsc#1265306). - CVE-2026-43109: x86: shadow stacks: proper error handling for mmap lock (bsc#1269282). - CVE-2026-43110: wifi: brcmfmac: validate bsscfg indices in IF events (bsc#1264483). - CVE-2026-43206: drm/amdkfd: Fix out-of-bounds write in kfd_event_page_set() (bsc#1266668). - CVE-2026-46037: ipv4: icmp: validate reply type before using icmp_pointers (bsc#1267362). - CVE-2026-46242: eventpoll: fix ep_remove struct eventpoll / struct file UAF (bsc#1270300). - CVE-2026-46274: io-wq: check that the predecessor is hashed in io_wq_remove_pending() (bsc#1268624). - CVE-2026-46319: net/sched: act_ct: Only release RCU read lock after ct_ft (bsc#1268281). - CVE-2026-52923: ipc: limit next_id allocation to the valid ID range (bsc#1269034). - CVE-2026-52956: libceph: Fix potential out-of-bounds access in __ceph_x_decrypt() (bsc#1272139). - CVE-2026-52972: crypto: af_alg - Cap AEAD AD length to 0x80000000 (bsc#1269196). - CVE-2026-53133: RDMA/umem: Fix truncation for block sizes >= 4G (bsc#1269822). - CVE-2026-53182: wifi: nl80211: reject oversized EMA RNR lists (bsc#1269885). - CVE-2026-64530: net/sched: cls_api: Handle TC_ACT_CONSUMED in tcf_qevent_hand (bsc#1271867). - CVE-2026-64600: xfs: resample the data fork mapping after cycling ILOCK (RefluXFS) (bsc#1271543). Join the discussion | GCVE Database | 08/24/2026, 14:04:12 UTC Added: 07/18/2026, 11:37:01 UTC |
The kernel packages contain the Linux kernel, the core of any Linux operating system. Security Fix(es): * kernel: drm/amdkfd: Fix out-of-bounds write in kfd_event_page_set() (CVE-2026-43206) * kernel: drm/amdgpu: Refactor amdgpu_gem_va_ioctl for Handling Last Fence Update and Timeline Management v4 (CVE-2026-43237) * kernel: crypto: pcrypt - Fix handling of MAY_BACKLOG requests (CVE-2026-43493) * kernel: udf: fix partition descriptor append bookkeeping (CVE-2026-45991) * kernel: drm/amdkfd: Fix watch_id bounds checking in debug address watch v2 (CVE-2026-45878) * kernel: smb/client: fix out-of-bounds read in symlink_data() (CVE-2026-46185) * kernel: sched/psi: fix race between file release and pressure write (CVE-2026-52991) * kernel: drm/amdkfd: Fix buffer overflow in SDMA queue checkpoint/restore on GFX11 (CVE-2026-53143) * kernel: drm/amd/display: Clamp VBIOS HDMI retimer register count to array size (CVE-2026-53136) * kernel: drm/amd/display: Use krealloc_array() in dal_vector_reserve() (CVE-2026-53329) * kernel: drm/i915/gem: Fix phys BO pread/pwrite with offset (CVE-2026-53356) * kernel: drm/amdgpu: zero-initialize GART table on allocation (CVE-2026-53374) * kernel: drm/i915: Fix potential UAF in TTM object purge (CVE-2026-63884) * kernel: scsi: target: iscsi: Validate CHAP_R length before base64 decode (CVE-2026-63886) * kernel: memfd: deny writeable mappings when implying SEAL_WRITE (CVE-2026-63952) * kernel: scsi: target: iscsi: Fix CRC overread and double-free in iscsit_handle_text_cmd() (CVE-2026-63888) * kernel: blk-mq: pop cached request if it is usable (CVE-2026-64017) * kernel: drm/amdgpu: fix amdgpu_hmm_range_get_pages (CVE-2026-63879) * kernel: drm/amd/display: Validate payload length and link_index in dc_process_dmub_aux_transfer_async (CVE-2026-64219) * kernel: smb: client: fix double-free in SMB2_open() replay (CVE-2026-64382) * kernel: smb: client: mask server-provided mode to 07777 in modefromsid (CVE-2026-64379) * kernel: smb: client: fix query_info() replay double-free (CVE-2026-64386) * kernel: posix-cpu-timers: Prevent UAF caused by non-leader exec() race (CVE-2026-64560) * kernel: smb/client: handle overlapping allocated ranges in fallocate (CVE-2026-68388) Bug Fix(es) and Enhancement(s): * CLONE - RHEL 10.2.z xfs: fix exchange-range reflink flag clearing issue with INO1_WRITTEN (JIRA:RHEL-223954) * vhost: reset the vring metadata cache on vring reconfiguration [rhel-10.2.z] (JIRA:RHEL-224545) * cifs: periodic IO errors when rename races with lease break [rhel-10.2.z] (JIRA:RHEL-235459) * cifs: smb1 directory listings from xp server returning EINVAL and EIO [rhel-10.2.z] (JIRA:RHEL-235812) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Join the discussion | GCVE Database | 08/20/2026, 06:35:01 UTC Added: 07/18/2026, 11:20:14 UTC |
The kernel-rt packages provide the Real Time Linux Kernel, which enables fine-tuning for systems with extremely high determinism requirements. Security Fix(es): * kernel: mm/slub: avoid accessing metadata when pointer is invalid in object_err() (CVE-2025-39902) * kernel: drm/amdkfd: Fix out-of-bounds write in kfd_event_page_set() (CVE-2026-43206) * kernel: crypto: ccp - copy IV using skcipher ivsize (CVE-2026-53016) * kernel: drm/amd/display: Clamp VBIOS HDMI retimer register count to array size (CVE-2026-53136) * kernel: drm/amd/display: Use krealloc_array() in dal_vector_reserve() (CVE-2026-53329) * kernel: drm/amdgpu: zero-initialize GART table on allocation (CVE-2026-53374) * kernel: drm/i915: Fix potential UAF in TTM object purge (CVE-2026-63884) * kernel: drm/amdgpu: fix amdgpu_hmm_range_get_pages (CVE-2026-63879) * kernel: drm/amd/display: Validate payload length and link_index in dc_process_dmub_aux_transfer_async (CVE-2026-64219) * kernel: can:bcm: arbitrary kernel code execution leading to escalate privileges (CVE-2026-17523) Bug Fix(es) and Enhancement(s): * Backport "sched/deadline: Fix bandwidth reclaim equation in GRUB" to RHEL 8.10 (JIRA:RHEL-189997) * vhost: reset the vring metadata cache on vring reconfiguration [rhel-8.10.z] (JIRA:RHEL-224556) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Join the discussion | GCVE Database | 08/17/2026, 15:39:26 UTC Added: 07/31/2026, 15:41:08 UTC |
In the Linux kernel, the following vulnerability has been resolved: efivarfs: Fix memory leak of efivarfs_fs_info in fs_context error paths When processing mount options, efivarfs allocates efivarfs_fs_info (sfi) early in fs_context initialization. However, sfi is associated with the superblock and typically freed when the superblock is destroyed. If the fs_context is released (final put) before fill_super is called—such as on error paths or during reconfiguration—the sfi structure would leak, as ownership never transfers to the superblock. Implement the .free callback in efivarfs_context_ops to ensure any allocated sfi is properly freed if the fs_context is torn down before fill_super, preventing this memory leak. Join the discussion | GCVE Database | 08/16/2025, 12:15:00 UTC Added: 06/24/2026, 17:00:23 UTC |
Showing 1 to 6 of 6 results