Threats Tagged 'cve-2026-45970'
View all threats tagged with 'cve-2026-45970'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'cve-2026-45970'
Click on any threat for detailed analysis and mitigation recommendations
0 A vulnerability in the Linux kernel's IOMMU Shared Virtual Addressing (SVA) on x86 allows stale page table entries to persist after kernel page table pages are freed, causing use-after-free or write-after-free conditions. This can lead to privilege escalation or data corruption. The issue is mitigated by disabling SVA on affected systems until a patch is applied. A fix introducing deferred freeing of kernel page table pages to safely invalidate IOMMU caches is available and should be applied via system updates and reboot. Join the discussion | GCVE Database | 10/01/2026, 11:27:21 UTC Added: 07/16/2026, 10:40:03 UTC |
The kernel packages contain the Linux kernel, the core of any Linux operating system. Security Fix(es): * kernel: smc: Fix use-after-free in __pnet_find_base_ndev() (CVE-2025-40064) * kernel: Linux kernel: Denial of Service due to memory leak in tpm2_load_cmd (CVE-2025-71147) * kernel: bonding: alb: fix UAF in rlb_arp_recv during bond up/down (CVE-2026-45970) * kernel: smb/client: fix out-of-bounds read in symlink_data() (CVE-2026-46185) * kernel: Bluetooth: hci_ldisc: Clear HCI_UART_PROTO_INIT on error (CVE-2026-53073) * kernel: pNFS: Fix use-after-free in pnfs_update_layout() (CVE-2026-63800) * kernel: nfsd: fix posix_acl leak on SETACL decode failure (CVE-2026-53397) * kernel: exfat: fix potential use-after-free in exfat_find_dir_entry() (CVE-2026-63808) * kernel: nfsd: release layout stid on setlease failure (CVE-2026-53399) * kernel: NFSv4/flexfiles: reject zero filehandle version count (CVE-2026-53392) * kernel: KEYS: fix overflow in keyctl_pkey_params_get_2() (CVE-2026-63824) * kernel: NFSv4/pNFS: reject zero-length r_addr in nfs4_decode_mp_ds_addr (CVE-2026-53391) * kernel: scsi: target: iscsi: Validate CHAP_R length before base64 decode (CVE-2026-63886) * kernel: ipv4: free net->ipv4.sysctl_local_reserved_ports after unregister_net_sysctl_table() (CVE-2026-64002) * kernel: net: mana: validate rx_req_idx to prevent out-of-bounds array access (CVE-2026-64018) * kernel: scsi: target: iscsi: Bound iscsi_encode_text_output() appends to rsp_buf (CVE-2026-63887) * kernel: smb: client: fix query directory replay double-free (CVE-2026-64387) * kernel: Kernel: Remote out-of-bounds write in RDMA/siw (CVE-2026-64268) * kernel: crypto: qat - fix VF2PF work teardown race in adf_disable_sriov() (CVE-2026-64438) * kernel: crypto: qat - validate RSA CRT component lengths (CVE-2026-64304) * kernel: NFSv4: include MAY_WRITE in open permission mask for O_TRUNC (CVE-2026-64298) * kernel: ALSA: virtio: Validate control metadata from the device (CVE-2026-64490) * kernel: AMD-SN-7061: Safe RET Interrupt Vulnerability (CVE-2026-68480) * kernel: Linux kernel: Arbitrary code execution via userfaultfd shadow stack manipulation (CVE-2026-68166) * kernel: iomap: fix out-of-bounds bitmap_set() with zero-length range (CVE-2026-68145) * kernel: locking/rt: Fix the incorrect RCU protection in rt_spin_unlock() (CVE-2026-72069) * kernel: nvmet-auth: reject short AUTH_RECEIVE buffers (CVE-2026-72130) Bug Fix(es) and Enhancement(s): * [RHEL 9] TPM becomes completely unresponsive and requires a full reboot to clear [rhel-9.8.z] (JIRA:RHEL-213940) * RT scheduler livelock caused by missing backport of 94894c9c477e [rhel-9.8.z] (JIRA:RHEL-240634) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Join the discussion | GCVE Database | 09/04/2026, 02:32:58 UTC Added: 06/09/2026, 10:24:57 UTC |
The kernel packages contain the Linux kernel, the core of any Linux operating system. Security Fix(es): * kernel: s390/cpum_sf: Handle CPU hotplug remove during sampling (CVE-2024-57849) * kernel: smc91x: fix broken irq-context in PREEMPT_RT (CVE-2025-71132) * kernel: bonding: alb: fix UAF in rlb_arp_recv during bond up/down (CVE-2026-45970) * kernel: zram: fix use-after-free in zram_bvec_write_partial() (CVE-2026-53185) * kernel: pNFS: Fix use-after-free in pnfs_update_layout() (CVE-2026-63800) * kernel: nfsd: fix posix_acl leak on SETACL decode failure (CVE-2026-53397) * kernel: nfsd: release layout stid on setlease failure (CVE-2026-53399) * kernel: NFSv4/flexfiles: reject zero filehandle version count (CVE-2026-53392) * kernel: NFSv4/pNFS: reject zero-length r_addr in nfs4_decode_mp_ds_addr (CVE-2026-53391) * kernel: net: mana: validate rx_req_idx to prevent out-of-bounds array access (CVE-2026-64018) * kernel: Kernel: Remote out-of-bounds write in RDMA/siw (CVE-2026-64268) * kernel: NFSv4: include MAY_WRITE in open permission mask for O_TRUNC (CVE-2026-64298) * kernel: AMD-SN-7061: Safe RET Interrupt Vulnerability (CVE-2026-68480) * kernel: net: ipv6: use-after-free in fib6_rule_suppress due to stale res->rt6 pointer (CVE-2026-74581) Bug Fix(es) and Enhancement(s): * qede: build_skb failure causes off-by-one BD ring corruption and kernel panic [rhel-8.10.z] (JIRA:RHEL-193045) * powerpc/pseries: lparcfg - fix kbuf[] underflow (JIRA:RHEL-240144) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Join the discussion | GCVE Database | 09/03/2026, 04:54:40 UTC Added: 09/03/2026, 15:16:44 UTC |
The kernel-rt packages provide the Real Time Linux Kernel, which enables fine-tuning for systems with extremely high determinism requirements. Security Fix(es): * kernel: s390/cpum_sf: Handle CPU hotplug remove during sampling (CVE-2024-57849) * kernel: smc91x: fix broken irq-context in PREEMPT_RT (CVE-2025-71132) * kernel: bonding: alb: fix UAF in rlb_arp_recv during bond up/down (CVE-2026-45970) * kernel: zram: fix use-after-free in zram_bvec_write_partial() (CVE-2026-53185) * kernel: pNFS: Fix use-after-free in pnfs_update_layout() (CVE-2026-63800) * kernel: nfsd: fix posix_acl leak on SETACL decode failure (CVE-2026-53397) * kernel: nfsd: release layout stid on setlease failure (CVE-2026-53399) * kernel: NFSv4/flexfiles: reject zero filehandle version count (CVE-2026-53392) * kernel: NFSv4/pNFS: reject zero-length r_addr in nfs4_decode_mp_ds_addr (CVE-2026-53391) * kernel: net: mana: validate rx_req_idx to prevent out-of-bounds array access (CVE-2026-64018) * kernel: Kernel: Remote out-of-bounds write in RDMA/siw (CVE-2026-64268) * kernel: NFSv4: include MAY_WRITE in open permission mask for O_TRUNC (CVE-2026-64298) * kernel: AMD-SN-7061: Safe RET Interrupt Vulnerability (CVE-2026-68480) * kernel: net: ipv6: use-after-free in fib6_rule_suppress due to stale res->rt6 pointer (CVE-2026-74581) Bug Fix(es) and Enhancement(s): * qede: build_skb failure causes off-by-one BD ring corruption and kernel panic [rhel-8.10.z] (JIRA:RHEL-193045) * powerpc/pseries: lparcfg - fix kbuf[] underflow (JIRA:RHEL-240144) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Join the discussion | GCVE Database | 09/03/2026, 04:15:14 UTC Added: 09/03/2026, 15:16:44 UTC |
The kernel packages contain the Linux kernel, the core of any Linux operating system. Security Fix(es): * kernel: seccomp: passthrough uretprobe systemcall without filtering (CVE-2025-21834) * kernel: ip6_tunnel: use skb_vlan_inet_prepare() in __ip6_tnl_rcv() (CVE-2026-23003) * kernel: netfilter: nf_tables: Fix for duplicate device in netdev hooks (CVE-2026-43454) * kernel: netfilter: nfnetlink_cthelper: fix OOB read in nfnl_cthelper_dump_table() (CVE-2026-43450) * kernel: bonding: alb: fix UAF in rlb_arp_recv during bond up/down (CVE-2026-45970) * kernel: ip6_gre: Use cached t->net in ip6erspan_changelink() (CVE-2026-46120) * kernel: iommu/amd: Fix clone_alias() to use the original device's devid (CVE-2026-53053) * kernel: NFSD: fix nfs4_file access extra count in nfsd4_add_rdaccess_to_wrdeleg (CVE-2026-53026) * kernel: zram: fix use-after-free in zram_bvec_write_partial() (CVE-2026-53185) * kernel: USB: serial: io_ti: fix heap overflow in get_manuf_info() (CVE-2026-53196) * kernel: mm/huge_memory: update file PMD counter before folio_put() (CVE-2026-53189) * kernel: mm/list_lru: drain before clearing xarray entry on reparent (CVE-2026-53153) * kernel: pNFS: Fix use-after-free in pnfs_update_layout() (CVE-2026-63800) * kernel: nfsd: fix posix_acl leak on SETACL decode failure (CVE-2026-53397) * kernel: nfsd: release layout stid on setlease failure (CVE-2026-53399) * kernel: NFSv4/flexfiles: reject zero filehandle version count (CVE-2026-53392) * kernel: NFSv4/pNFS: reject zero-length r_addr in nfs4_decode_mp_ds_addr (CVE-2026-53391) * kernel: net: mana: validate rx_req_idx to prevent out-of-bounds array access (CVE-2026-64018) * kernel: smb: client: protect tc_count increment in smb2_find_smb_sess_tcon_unlocked() (CVE-2026-64136) * kernel: netfilter: ipset: fix race between dump and ip_set_list resize (CVE-2026-64189) * kernel: nvmet: fix pre-auth out-of-bounds heap read in Discovery Get Log Page (CVE-2026-64320) * kernel: crypto: qat - fix VF2PF work teardown race in adf_disable_sriov() (CVE-2026-64438) * kernel: crypto: qat - validate RSA CRT component lengths (CVE-2026-64304) * kernel: NFSv4: include MAY_WRITE in open permission mask for O_TRUNC (CVE-2026-64298) * kernel: ALSA: virtio: Validate control metadata from the device (CVE-2026-64490) * kernel: mm: shrinker: fix shrinker_info teardown race with expansion (CVE-2026-64418) * kernel: smb: client: fix change notify replay double-free (CVE-2026-64384) * kernel: Input: synaptics-rmi4 - bound the F3A keymap to the GPIO count (CVE-2026-64277) * kernel: Input: synaptics-rmi4 - bound the F30 keymap to the GPIO/LED count (CVE-2026-64276) * kernel: AMD-SN-7061: Safe RET Interrupt Vulnerability (CVE-2026-68480) * kernel: mm/khugepaged: write all dirty file folios when collapsing (CVE-2026-68086) * kernel: Linux kernel: Arbitrary code execution via userfaultfd shadow stack manipulation (CVE-2026-68166) * kernel: locking/rt: Fix the incorrect RCU protection in rt_spin_unlock() (CVE-2026-72069) * kernel: nvmet-auth: reject short AUTH_RECEIVE buffers (CVE-2026-72130) Bug Fix(es) and Enhancement(s): * RHEL 10: s390: Revert support for DCACHE_WORD_ACCESS [rhel-10.2.z] (JIRA:RHEL-188180) * qede: build_skb failure causes off-by-one BD ring corruption and kernel panic [rhel-10.2.z] (JIRA:RHEL-193043) * ss core dumped when there is an SCTP session [rhel-10.2.z] (JIRA:RHEL-212393) * [RHEL-10.2.z] Intel CWF: CPU is unable to obtain cstate1 on idle system (JIRA:RHEL-218627) * RHEL10.0 - s390/pfault: Fix virtual vs physical address confusion [rhel-10.2.z] (JIRA:RHEL-222507) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Join the discussion | GCVE Database | 09/01/2026, 08:34:59 UTC Added: 09/03/2026, 15:16:47 UTC |
0 The kernel packages contain the Linux kernel, the core of any Linux operating system.Security Fix(es): kernel: smc: Fix use-after-free in __pnet_find_base_ndev() (CVE-2025-40064) kernel: smc: Use __sk_dst_get() and dst_dev_rcu() in smc_clc_prfx_match() (CVE-2025-40168) kernel: Linux kernel: Denial of Service in libceph OSD client due to unreset sparse-read state (CVE-2026-23136) kernel: netfilter: ctnetlink: ensure safe access to master conntrack (CVE-2026-43116) kernel: xfs: fix freemap adjustments when adding xattrs to leaf blocks (CVE-2026-43158) kernel: mm/page_alloc: clear page->private in free_pages_prepare() (CVE-2026-43303) kernel: net/sched: act_pedit: extend the writable skb range per key (CVE-2026-46331) kernel: Linux kernel: Use-After-Free in net/gro due to improper handling of zerocopy skbs (CVE-2026-46323) kernel: Linux kernel: smb: client: reject userspace cifs.spnego descriptions (CVE-2026-46243) kernel: RDMA/iwcm: Fix workqueue list corruption by removing work_list (CVE-2026-45898) kernel: wifi: mac80211: remove station if connection prep fails (CVE-2026-46125) kernel: wifi: mac80211: use safe list iteration in radar detect work (CVE-2026-46166) Bug Fix(es) and Enhancement(s): [RHEL-9] Performance impact of CVE-2025-38085 [rhel-9.6.z] (JIRA:RHEL-161145) libceph: CEPH_CRYPTO_AES256KRB5 (--key-type aes256k) support [rhel-9.6.z] (JIRA:RHEL-168926) [ice] 3 of 4 ports "Failed to set LAN Tx queue context, error: -22" [rhel-9.6.z] (JIRA:RHEL-175439) Kernel panic while shutting down ice driver due to use-after-free [rhel-9.6.z] (JIRA:RHEL-177524) rbd: eliminate a race in lock_dwork draining on unmap [rhel-9.6.z] (JIRA:RHEL-183129) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Join the discussion | GCVE Database | 08/20/2026, 09:40:57 UTC Added: 07/21/2026, 20:03:37 UTC |
This update for the SUSE Linux Enterprise Kernel 6.12.0-160000.34.1 fixes various security issues The following security issues were fixed: - CVE-2026-45970: bonding: alb: fix UAF in rlb_arp_recv during bond up/down (bsc#1267206). - CVE-2026-46120: ip6_gre: Use cached t->net in ip6erspan_changelink() (bsc#1267893). - CVE-2026-46173: exit: prevent preemption of oopsing TASK_DEAD task (bsc#1267723). - CVE-2026-46227: sctp: revalidate list cursor after sctp_sendmsg_to_asoc() in SCTP_SENDALL (bsc#1267698). - CVE-2026-52909: ip6_vti: set netns_immutable on the fallback device (bsc#1268662). - CVE-2026-52943: net: skbuff: fix missing zerocopy reference in pskb_carve helpers (bsc#1269023). - CVE-2026-53362: ipv6: account for fraggap on the paged allocation path (bsc#1269495). Join the discussion | GCVE Database | 07/20/2026, 12:22:28 UTC Added: 07/18/2026, 11:18:50 UTC |
This update for the SUSE Linux Enterprise Kernel 6.12.0-160000.32.1 fixes various security issues The following security issues were fixed: - CVE-2026-31505: iavf: fix out-of-bounds writes in iavf_get_ethtool_stats() (bsc#1263094). - CVE-2026-31533: net/tls: fix use-after-free in -EBUSY error path of tls_do_encryption (bsc#1262759). - CVE-2026-31586: mm: blk-cgroup: fix use-after-free in cgwb_release_workfn() (bsc#1263177). - CVE-2026-31685: netfilter: ip6t_eui64: reject invalid MAC header for all packets (bsc#1263670). - CVE-2026-43025: netfilter: ctnetlink: ignore explicit helper on new expectations (bsc#1264253). - CVE-2026-43027: netfilter: nf_conntrack_helper: pass helper to expect cleanup (bsc#1264252). - CVE-2026-43037: ip6_tunnel: clear skb2->cb[] in ip4ip6_err() (bsc#1265197). - CVE-2026-43120: RDMA/irdma: Fix double free related to rereg_user_mr (bsc#1264567). - CVE-2026-43190: netfilter: xt_tcpmss: check remaining length before reading optlen (bsc#1264849). - CVE-2026-43366: io_uring/kbuf: check if target buffer list is still legacy on recycle (bsc#1265117). - CVE-2026-43494: RDS zerocopy attack aka PinTheft (bsc#1265945). - CVE-2026-43501: ipv6: rpl: reserve mac_len headroom when recompressed SRH grows (bsc#1266015). - CVE-2026-45970: bonding: alb: fix UAF in rlb_arp_recv during bond up/down (bsc#1267206). - CVE-2026-46120: ip6_gre: Use cached t->net in ip6erspan_changelink() (bsc#1267893). - CVE-2026-46173: exit: prevent preemption of oopsing TASK_DEAD task (bsc#1267723). - CVE-2026-46227: sctp: revalidate list cursor after sctp_sendmsg_to_asoc() in SCTP_SENDALL (bsc#1267698). - CVE-2026-46243: smb: client: reject userspace cifs.spnego descriptions (CIFSwitch) (bsc#1266265). - CVE-2026-52909: ip6_vti: set netns_immutable on the fallback device (bsc#1268662). - CVE-2026-52943: net: skbuff: fix missing zerocopy reference in pskb_carve helpers (bsc#1269023). - CVE-2026-53362: ipv6: account for fraggap on the paged allocation path (bsc#1269495). Join the discussion | GCVE Database | 07/20/2026, 09:52:57 UTC Added: 07/18/2026, 11:23:27 UTC |
This update for the SUSE Linux Enterprise Kernel 6.12.0-160000.32.1 fixes various security issues The following security issues were fixed: - CVE-2026-31505: iavf: fix out-of-bounds writes in iavf_get_ethtool_stats() (bsc#1263094). - CVE-2026-31533: net/tls: fix use-after-free in -EBUSY error path of tls_do_encryption (bsc#1262759). - CVE-2026-31586: mm: blk-cgroup: fix use-after-free in cgwb_release_workfn() (bsc#1263177). - CVE-2026-31685: netfilter: ip6t_eui64: reject invalid MAC header for all packets (bsc#1263670). - CVE-2026-43025: netfilter: ctnetlink: ignore explicit helper on new expectations (bsc#1264253). - CVE-2026-43027: netfilter: nf_conntrack_helper: pass helper to expect cleanup (bsc#1264252). - CVE-2026-43037: ip6_tunnel: clear skb2->cb[] in ip4ip6_err() (bsc#1265197). - CVE-2026-43120: RDMA/irdma: Fix double free related to rereg_user_mr (bsc#1264567). - CVE-2026-43190: netfilter: xt_tcpmss: check remaining length before reading optlen (bsc#1264849). - CVE-2026-43366: io_uring/kbuf: check if target buffer list is still legacy on recycle (bsc#1265117). - CVE-2026-43494: RDS zerocopy attack aka PinTheft (bsc#1265945). - CVE-2026-43501: ipv6: rpl: reserve mac_len headroom when recompressed SRH grows (bsc#1266015). - CVE-2026-45970: bonding: alb: fix UAF in rlb_arp_recv during bond up/down (bsc#1267206). - CVE-2026-46120: ip6_gre: Use cached t->net in ip6erspan_changelink() (bsc#1267893). - CVE-2026-46173: exit: prevent preemption of oopsing TASK_DEAD task (bsc#1267723). - CVE-2026-46227: sctp: revalidate list cursor after sctp_sendmsg_to_asoc() in SCTP_SENDALL (bsc#1267698). - CVE-2026-46243: smb: client: reject userspace cifs.spnego descriptions (CIFSwitch) (bsc#1266265). - CVE-2026-52909: ip6_vti: set netns_immutable on the fallback device (bsc#1268662). - CVE-2026-52943: net: skbuff: fix missing zerocopy reference in pskb_carve helpers (bsc#1269023). - CVE-2026-53362: ipv6: account for fraggap on the paged allocation path (bsc#1269495). Join the discussion | GCVE Database | 07/20/2026, 09:52:57 UTC Added: 06/29/2026, 22:11:24 UTC |
0 This security update for the SUSE Linux Enterprise Kernel 4.12.14-122.280 addresses multiple vulnerabilities affecting various kernel components including netfilter, ip6_tunnel, ALSA pcm, bonding, and SMB client. The fixes resolve issues such as invalid packet handling, use-after-free conditions, and improper user-space input acceptance. These vulnerabilities were collectively addressed in Live Patch 74 for SUSE Linux Enterprise 12 SP5. Join the discussion | GCVE Database | 07/15/2026, 19:04:03 UTC Added: 07/16/2026, 10:36:51 UTC |
Showing 1 to 10 of 11 results