Threats Tagged 'cve-2026-43414'
View all threats tagged with 'cve-2026-43414'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'cve-2026-43414'
Click on any threat for detailed analysis and mitigation recommendations
The kernel packages contain the Linux kernel, the core of any Linux operating system. Security Fix(es): * kernel: netfilter: conntrack: clamp maximum hashtable size to INT_MAX (CVE-2025-21648) * kernel: cachestat: fix page cache statistics permission checking (CVE-2025-21691) * kernel: ALSA: aloop: Fix racy access at PCM trigger (CVE-2026-23191) * kernel: mptcp: fix slab-use-after-free in __inet_lookup_established (CVE-2026-31669) * kernel: netfilter: nf_conntrack_helper: pass helper to expect cleanup (CVE-2026-43027) * kernel: RDMA/umem: Fix double dma_buf_unpin in failure path (CVE-2026-43128) * kernel: tcp: fix potential race in tcp_v6_syn_recv_sock() (CVE-2026-43198) * kernel: dlm: validate length in dlm_search_rsb_tree (CVE-2026-43125) * kernel: netfilter: flowtable: strictly check for maximum number of actions (CVE-2026-43329) * kernel: scsi: qla2xxx: Completely fix fcport double free (CVE-2026-43414) * kernel: ipv6: rpl: reserve mac_len headroom when recompressed SRH grows (CVE-2026-43501) * kernel: ALSA: aloop: Fix peer runtime UAF during format-change stop (CVE-2026-46090) * kernel: RDMA/rxe: Fix double free in rxe_srq_from_init (CVE-2026-45852) * kernel: RDMA/mlx4: Fix mis-use of RCU in mlx4_srq_event() (CVE-2026-46181) * kernel: sctp: revalidate list cursor after sctp_sendmsg_to_asoc() in SCTP_SENDALL (CVE-2026-46227) * kernel: RDMA/mlx5: Fix error path fall-through in mlx5_ib_dev_res_srq_init() (CVE-2026-46176) * kernel: exit: prevent preemption of oopsing TASK_DEAD task (CVE-2026-46173) * kernel: netfilter: nft_inner: Fix IPv6 inner_thoff desync (CVE-2026-46244) Bug Fix(es) and Enhancement(s): * iavf: during POD churn vlan filters may not be added for a vlan interface, spoofchk drops subsequent packets [rhel-9.6.z] (JIRA:RHEL-172991) * [rhel-9] WARNING: possible recursive locking detected - vmd_enable_domain+0x757/0x910 [rhel-9.6.z] (JIRA:RHEL-174469) * RHEL9.4 - s390/mm: Add missing secure storage access fixups [rhel-9.6.z] (JIRA:RHEL-183316) * drm/mgag200: 300 ms busy loop [rhel-9.6.z] (JIRA:RHEL-150177) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Join the discussion | GCVE Database | 07/01/2026, 09:48:13 UTC Added: 07/02/2026, 22:56:57 UTC |
The kernel packages contain the Linux kernel, the core of any Linux operating system. Security Fix(es): * kernel: rxrpc: fix RESPONSE authenticator parser OOB read (CVE-2026-31636) * kernel: ipv6: icmp: clear skb2->cb[] in ip6_err_gen_icmpv6_unreach() (CVE-2026-43038) * kernel: tcp: fix potential race in tcp_v6_syn_recv_sock() (CVE-2026-43198) * kernel: scsi: qla2xxx: Completely fix fcport double free (CVE-2026-43414) * kernel: RDMA/iwcm: Fix workqueue list corruption by removing work_list (CVE-2026-45898) * kernel: RDMA/mana: Remove user triggerable WARN_ON() in mana_ib_create_qp_rss() (CVE-2026-46117) * kernel: RDMA/mana: Validate rx_hash_key_len (CVE-2026-46145) * kernel: nvmet-tcp: fix race between ICReq handling and queue teardown (CVE-2026-46135) Bug Fix(es) and Enhancement(s): * Unexpected execmem SELinux denials after CVE-2026-46054 fix [rhel-10.2.z] (JIRA:RHEL-185117) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Join the discussion | GCVE Database | 06/25/2026, 23:21:52 UTC Added: 06/26/2026, 13:36:22 UTC |
The kernel packages contain the Linux kernel, the core of any Linux operating system. Security Fix(es): * kernel: can: isotp: fix tx.buf use-after-free in isotp_sendmsg() (CVE-2026-31474) * kernel: mptcp: fix slab-use-after-free in __inet_lookup_established (CVE-2026-31669) * kernel: xen/privcmd: fix double free via VMA splitting (CVE-2026-31787) * kernel: Bluetooth: hci_sync: fix stack buffer overflow in hci_le_big_create_sync (CVE-2026-31772) * kernel: bnxt_en: Fix RSS context delete logic (CVE-2026-43260) * kernel: ALSA: usb-audio: Add sanity check for OOB writes at silencing (CVE-2026-43279) * kernel: scsi: qla2xxx: Completely fix fcport double free (CVE-2026-43414) * kernel: net/sched: act_pedit: extend the writable skb range per key (CVE-2026-46331) * kernel: gfs2: Fix use-after-free in iomap inline data write path (CVE-2026-45984) * kernel: Bluetooth: hci_event: fix potential UAF in SSP passkey handlers (CVE-2026-46056) * kernel: wifi: mac80211: drop stray 'static' from fast-RX rx_result (CVE-2026-46152) * kernel: RDMA/mana: Remove user triggerable WARN_ON() in mana_ib_create_qp_rss() (CVE-2026-46117) * kernel: RDMA/mana: Validate rx_hash_key_len (CVE-2026-46145) * kernel: wifi: mac80211: remove station if connection prep fails (CVE-2026-46125) * kernel: exit: prevent preemption of oopsing TASK_DEAD task (CVE-2026-46173) * kernel: wifi: mac80211: use safe list iteration in radar detect work (CVE-2026-46166) * kernel: nvmet-tcp: fix race between ICReq handling and queue teardown (CVE-2026-46135) Bug Fix(es) and Enhancement(s): * RHEL9.4 - s390/ap: Expose ap_bindings_complete_count counter via sysfs [rhel-9.8.z] (JIRA:RHEL-166048) * [RHEL 9.8] Hung tasks during both suspend and hibernate operations on systems with Intel E810 NICs [rhel-9.8.z] (JIRA:RHEL-175699) * DPLL: Add support for pin operational state [rhel-9.8.z] (JIRA:RHEL-175820) * DPLL: Add support for fractional frequency offset between pin and device [rhel-9.8.z] (JIRA:RHEL-175823) * ibmveth Adapter Freeze with Small MSS [rhel-9.8.z] (JIRA:RHEL-178308) * RHEL9.4 - s390/mm: Add missing secure storage access fixups [rhel-9.8.z] (JIRA:RHEL-183317) * rbd: eliminate a race in lock_dwork draining on unmap [rhel-9.8.z] (JIRA:RHEL-183130) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Join the discussion | GCVE Database | 06/22/2026, 10:59:06 UTC Added: 07/18/2026, 11:23:40 UTC |
The kernel packages contain the Linux kernel, the core of any Linux operating system. Security Fix(es): * kernel: can: isotp: fix tx.buf use-after-free in isotp_sendmsg() (CVE-2026-31474) * kernel: mptcp: fix slab-use-after-free in __inet_lookup_established (CVE-2026-31669) * kernel: rxrpc: Fix RxGK token loading to check bounds (CVE-2026-31641) * kernel: xen/privcmd: fix double free via VMA splitting (CVE-2026-31787) * kernel: Buffer overflow in drivers/xen/sys-hypervisor.c (CVE-2026-31786) * kernel: net: mana: fix use-after-free in add_adev() error path (CVE-2026-43056) * kernel: Bluetooth: hci_sync: fix stack buffer overflow in hci_le_big_create_sync (CVE-2026-31772) * kernel: bnxt_en: Fix RSS context delete logic (CVE-2026-43260) * kernel: crypto: caam - fix overflow on long hmac keys (CVE-2026-43330) * kernel: net/sched: act_pedit: extend the writable skb range per key (CVE-2026-46331) * kernel: Bluetooth: hci_event: fix potential UAF in SSP passkey handlers (CVE-2026-46056) * kernel: wifi: mac80211: drop stray 'static' from fast-RX rx_result (CVE-2026-46152) * kernel: wifi: mac80211: remove station if connection prep fails (CVE-2026-46125) * kernel: exit: prevent preemption of oopsing TASK_DEAD task (CVE-2026-46173) * kernel: wifi: mac80211: use safe list iteration in radar detect work (CVE-2026-46166) Bug Fix(es) and Enhancement(s): * RHEL10.0 - s390/ap: Expose ap_bindings_complete_count counter via sysfs [rhel-10.2.z] (JIRA:RHEL-166047) * RHEL9.5 crash due to lpfc NULL ndlp->vport [rhel-10.2.z] (JIRA:RHEL-171774) * objtool static_call check blocks build of out-of-tree livepatch modules on RHEL 10.2 GA kernels ? missing upstream revert f495054bd12e (JIRA:RHEL-178495) * ibmveth Adapter Freeze with Small MSS [rhel-10.2.z] (JIRA:RHEL-179723) * rbd: eliminate a race in lock_dwork draining on unmap [rhel-10.2.z] (JIRA:RHEL-183127) * RHEL10.0 - s390/mm: Add missing secure storage access fixups [rhel-10.2.z] (JIRA:RHEL-183319) * [RHEL10.2.z] Enable Pretimeout Watchdog Panic Functionality on x86 (JIRA:RHEL-182299) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Join the discussion | GCVE Database | 06/20/2026, 00:28:45 UTC Added: 06/21/2026, 15:44:28 UTC |
0 The kernel packages contain the Linux kernel, the core of any Linux operating system. Security Fix(es): * kernel: proc: use the same treatment to check proc_lseek as ones for proc_read_iter et.al (CVE-2025-38653) * kernel: nbd: defer config unlock in nbd_genl_connect (CVE-2025-68366) * kernel: smb: client: fix OOB reads parsing symlink error response (CVE-2026-31613) * kernel: smb: client: validate the whole DACL before rewriting it in cifsacl (CVE-2026-31709) * kernel: netfilter: flowtable: strictly check for maximum number of actions (CVE-2026-43329) * kernel: Bluetooth: hci_sync: Fix UAF in le_read_features_complete (CVE-2026-43322) * kernel: Linux kernel: smb: client: reject userspace cifs.spnego descriptions (CVE-2026-46243) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Join the discussion | GCVE Database | 06/04/2026, 15:55:35 UTC Added: 05/29/2026, 21:02:27 UTC |
A critical vulnerability (CVE-2026-43414) in the Linux kernel's SCSI subsystem (qla2xxx driver) involving a double free of fcport objects has been resolved. This flaw occurs in the qla24xx_els_dcmd_iocb() function where fcport is freed twice, potentially leading to system compromise. The issue affects many versions of the linux-aws kernel prior to the fixed releases. A high-severity CVSS 3.1 score of 9.8 is assigned. Official patches are available and included in Linux kernel updates version 6.17.0-1019.19 and later. Users should update and reboot to apply the fixes. The vulnerability is not known to be exploited in the wild. Join the discussion | GCVE Database | 05/08/2026, 15:16:00 UTC Added: 07/16/2026, 10:38:46 UTC |
0 CVE-2026-43414 is a medium severity vulnerability related to a double free issue in the fcport component of the qla2xxx SCSI driver. The vulnerability affects Microsoft products including Azure Linux kernel version 3.0. No detailed technical information or exploitation details are provided. There is no CVSS score assigned to this vulnerability. No patch or remediation information is currently available. Join the discussion | GCVE Database | 05/02/2026, 00:00:00 UTC Added: 05/26/2026, 20:58:55 UTC |
Showing 1 to 7 of 7 results