Threats Tagged 'cve-2026-46176'
View all threats tagged with 'cve-2026-46176'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'cve-2026-46176'
Click on any threat for detailed analysis and mitigation recommendations
The kernel packages contain the Linux kernel, the core of any Linux operating system. Security Fix(es): * kernel: netfilter: conntrack: clamp maximum hashtable size to INT_MAX (CVE-2025-21648) * kernel: cachestat: fix page cache statistics permission checking (CVE-2025-21691) * kernel: ALSA: aloop: Fix racy access at PCM trigger (CVE-2026-23191) * kernel: mptcp: fix slab-use-after-free in __inet_lookup_established (CVE-2026-31669) * kernel: netfilter: nf_conntrack_helper: pass helper to expect cleanup (CVE-2026-43027) * kernel: RDMA/umem: Fix double dma_buf_unpin in failure path (CVE-2026-43128) * kernel: tcp: fix potential race in tcp_v6_syn_recv_sock() (CVE-2026-43198) * kernel: dlm: validate length in dlm_search_rsb_tree (CVE-2026-43125) * kernel: netfilter: flowtable: strictly check for maximum number of actions (CVE-2026-43329) * kernel: scsi: qla2xxx: Completely fix fcport double free (CVE-2026-43414) * kernel: ipv6: rpl: reserve mac_len headroom when recompressed SRH grows (CVE-2026-43501) * kernel: ALSA: aloop: Fix peer runtime UAF during format-change stop (CVE-2026-46090) * kernel: RDMA/rxe: Fix double free in rxe_srq_from_init (CVE-2026-45852) * kernel: RDMA/mlx4: Fix mis-use of RCU in mlx4_srq_event() (CVE-2026-46181) * kernel: sctp: revalidate list cursor after sctp_sendmsg_to_asoc() in SCTP_SENDALL (CVE-2026-46227) * kernel: RDMA/mlx5: Fix error path fall-through in mlx5_ib_dev_res_srq_init() (CVE-2026-46176) * kernel: exit: prevent preemption of oopsing TASK_DEAD task (CVE-2026-46173) * kernel: netfilter: nft_inner: Fix IPv6 inner_thoff desync (CVE-2026-46244) Bug Fix(es) and Enhancement(s): * iavf: during POD churn vlan filters may not be added for a vlan interface, spoofchk drops subsequent packets [rhel-9.6.z] (JIRA:RHEL-172991) * [rhel-9] WARNING: possible recursive locking detected - vmd_enable_domain+0x757/0x910 [rhel-9.6.z] (JIRA:RHEL-174469) * RHEL9.4 - s390/mm: Add missing secure storage access fixups [rhel-9.6.z] (JIRA:RHEL-183316) * drm/mgag200: 300 ms busy loop [rhel-9.6.z] (JIRA:RHEL-150177) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Join the discussion | GCVE Database | 07/01/2026, 09:48:13 UTC Added: 07/02/2026, 22:56:57 UTC |
The kernel packages contain the Linux kernel, the core of any Linux operating system. Security Fix(es): * kernel: ALSA: usb-audio: Add sanity check for OOB writes at silencing (CVE-2026-43279) * kernel: ALSA: aloop: Fix peer runtime UAF during format-change stop (CVE-2026-46090) * kernel: RDMA/vmw_pvrdma: Fix double free on pvrdma_alloc_ucontext() error path (CVE-2026-46189) * kernel: RDMA/mlx5: Fix error path fall-through in mlx5_ib_dev_res_srq_init() (CVE-2026-46176) Bug Fix(es) and Enhancement(s): * CLONE - [RHEL 10.2 Bug] qla2xxx flash image validation failure [rhel-10.2.z] (JIRA:RHEL-181887) * tegra-se fixes and updates [rhel-10.2.z] (JIRA:RHEL-182759) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Join the discussion | GCVE Database | 06/30/2026, 20:09:58 UTC Added: 07/02/2026, 22:58:29 UTC |
The kernel packages contain the Linux kernel, the core of any Linux operating system. Security Fix(es): * kernel: drm/amd/display: Do not skip unrelated mode changes in DSC validation (CVE-2026-31488) * kernel: ipv6: icmp: clear skb2->cb[] in ip6_err_gen_icmpv6_unreach() (CVE-2026-43038) * kernel: netfilter: flowtable: strictly check for maximum number of actions (CVE-2026-43329) * kernel: ALSA: aloop: Fix peer runtime UAF during format-change stop (CVE-2026-46090) * kernel: selinux: fix overlayfs mmap() and mprotect() access checks (CVE-2026-46054) * kernel: RDMA/iwcm: Fix workqueue list corruption by removing work_list (CVE-2026-45898) * kernel: RDMA/vmw_pvrdma: Fix double free on pvrdma_alloc_ucontext() error path (CVE-2026-46189) * kernel: RDMA/mlx5: Fix error path fall-through in mlx5_ib_dev_res_srq_init() (CVE-2026-46176) Bug Fix(es) and Enhancement(s): * [RHEL-9.8.z]: Update the mlx5 drivers to v6.19 (JIRA:RHEL-169057) * iavf: during POD churn vlan filters may not be added for a vlan interface, spoofchk drops subsequent packets [rhel-9.8.z] (JIRA:RHEL-172993) * nf_conntrack_sctp: vtag corruption with late INIT in ESTABLISHED state across conntrack zones [rhel-9.8.z] (JIRA:RHEL-178273) * sched/fair: Skip sched_balance_running cmpxchg when balance is not due [rhel-9.8.z] (JIRA:RHEL-182776) * [REGRESSION] ISST-Spyre: Jenkins workload causes soft lock warning to appear on screen. Workload hangs. [rhel-9.8.z] (JIRA:RHEL-183183) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Join the discussion | GCVE Database | 06/29/2026, 06:16:27 UTC Added: 07/18/2026, 11:23:34 UTC |
The kernel packages contain the Linux kernel, the core of any Linux operating system. Security Fix(es): * kernel: drm/amd/display: Do not skip unrelated mode changes in DSC validation (CVE-2026-31488) * kernel: ipv6: icmp: clear skb2->cb[] in ip6_err_gen_icmpv6_unreach() (CVE-2026-43038) * kernel: netfilter: flowtable: strictly check for maximum number of actions (CVE-2026-43329) * kernel: ALSA: aloop: Fix peer runtime UAF during format-change stop (CVE-2026-46090) * kernel: selinux: fix overlayfs mmap() and mprotect() access checks (CVE-2026-46054) * kernel: RDMA/iwcm: Fix workqueue list corruption by removing work_list (CVE-2026-45898) * kernel: RDMA/vmw_pvrdma: Fix double free on pvrdma_alloc_ucontext() error path (CVE-2026-46189) * kernel: RDMA/mlx5: Fix error path fall-through in mlx5_ib_dev_res_srq_init() (CVE-2026-46176) Bug Fix(es) and Enhancement(s): * [RHEL-9.8.z]: Update the mlx5 drivers to v6.19 (JIRA:RHEL-169057) * iavf: during POD churn vlan filters may not be added for a vlan interface, spoofchk drops subsequent packets [rhel-9.8.z] (JIRA:RHEL-172993) * nf_conntrack_sctp: vtag corruption with late INIT in ESTABLISHED state across conntrack zones [rhel-9.8.z] (JIRA:RHEL-178273) * sched/fair: Skip sched_balance_running cmpxchg when balance is not due [rhel-9.8.z] (JIRA:RHEL-182776) * [REGRESSION] ISST-Spyre: Jenkins workload causes soft lock warning to appear on screen. Workload hangs. [rhel-9.8.z] (JIRA:RHEL-183183) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Join the discussion | GCVE Database | 06/29/2026, 06:16:27 UTC Added: 06/24/2026, 17:00:22 UTC |
0 The kernel packages contain the Linux kernel, the core of any Linux operating system. Security Fix(es): * kernel: mptcp: fix slab-use-after-free in __inet_lookup_established (CVE-2026-31669) * kernel: xen/privcmd: fix double free via VMA splitting (CVE-2026-31787) * kernel: Buffer overflow in drivers/xen/sys-hypervisor.c (CVE-2026-31786) * kernel: wifi: brcmfmac: validate bsscfg indices in IF events (CVE-2026-43110) * kernel: netfilter: flowtable: strictly check for maximum number of actions (CVE-2026-43329) * kernel: Bluetooth: hci_event: fix potential UAF in SSP passkey handlers (CVE-2026-46056) * kernel: wifi: mac80211: drop stray 'static' from fast-RX rx_result (CVE-2026-46152) * kernel: wifi: mac80211: remove station if connection prep fails (CVE-2026-46125) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Join the discussion | GCVE Database | 06/16/2026, 19:17:56 UTC Added: 06/17/2026, 10:00:56 UTC |
Red Hat Security Advisory: kernel-rt security updateCVE-2026-31669 0 The kernel-rt packages provide the Real Time Linux Kernel, which enables fine-tuning for systems with extremely high determinism requirements. Security Fix(es): * kernel: mptcp: fix slab-use-after-free in __inet_lookup_established (CVE-2026-31669) * kernel: xen/privcmd: fix double free via VMA splitting (CVE-2026-31787) * kernel: Buffer overflow in drivers/xen/sys-hypervisor.c (CVE-2026-31786) * kernel: wifi: brcmfmac: validate bsscfg indices in IF events (CVE-2026-43110) * kernel: netfilter: flowtable: strictly check for maximum number of actions (CVE-2026-43329) * kernel: Bluetooth: hci_event: fix potential UAF in SSP passkey handlers (CVE-2026-46056) * kernel: wifi: mac80211: drop stray 'static' from fast-RX rx_result (CVE-2026-46152) * kernel: wifi: mac80211: remove station if connection prep fails (CVE-2026-46125) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Join the discussion | GCVE Database | 06/16/2026, 18:39:11 UTC Added: 07/16/2026, 10:39:14 UTC |
A vulnerability in the Linux kernel's RDMA mlx5 driver (mlx5_ib_dev_res_srq_init function) causes error path fall-through when allocating shared receive queues (SRQs). This leads to use-after-free and double-free conditions, as well as dereferencing of invalid pointers. The issue has been fixed by correcting the error handling path to prevent these unsafe operations. This vulnerability has a high severity rating and affects specific Linux kernel versions used in Red Hat Enterprise Linux 9 and 10. Updates addressing this issue are available and should be applied with a system reboot. Join the discussion | GCVE Database | 05/28/2026, 12:30:31 UTC Added: 05/29/2026, 21:02:11 UTC |
In the Linux kernel, the following vulnerability has been resolved: RDMA/mlx5: Fix error path fall-through in mlx5_ib_dev_res_srq_init() mlx5_ib_dev_res_srq_init() allocates two SRQs, s0 and s1. When ib_create_srq() fails for s1, the error branch destroys s0 but falls through and unconditionally assigns the freed s0 and the ERR_PTR s1 to devr->s0 and devr->s1. This leads to several problems: the lock-free fast path checks "if (devr->s1) return 0;" and treats the ERR_PTR as already initialised; users in mlx5_ib_create_qp() dereference the freed SRQ or ERR_PTR via to_msrq(devr->s0)->msrq.srqn; and mlx5_ib_dev_res_cleanup() dereferences the ERR_PTR and double-frees s0 on teardown. Fix by adding the same `goto unlock` in the s1 failure path. Join the discussion | GCVE Database | 05/28/2026, 10:16:00 UTC Added: 07/17/2026, 10:20:07 UTC |
Showing 1 to 8 of 8 results