Skip to main content

Threats Tagged 'cve-2026-52947'

View all threats tagged with 'cve-2026-52947'. Filter and sort to focus on specific types of threats.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Tag: cve-2026-52947

Threats Tagged 'cve-2026-52947'

Click on any threat for detailed analysis and mitigation recommendations

0

The kernel packages contain the Linux kernel, the core of any Linux operating system. Security Fix(es): * kernel: EDAC/bluefield: Fix potential integer overflow (CVE-2024-53161) * kernel: wifi: mac80211: Discard Beacon frames to non-broadcast address (CVE-2025-71127) * kernel: KVM: nSVM: Always use vmcb01 in VMLOAD/VMSAVE emulation (CVE-2026-43133) * kernel: net: qrtr: fix refcount saturation and potential UAF in qrtr_port_remove (CVE-2026-52947) * kernel: wifi: nl80211: reject oversized EMA RNR lists (CVE-2026-53182) * kernel: blk-cgroup: fix UAF in __blkcg_rstat_flush() (CVE-2026-63802) * kernel: scsi: scsi_transport_fc: Widen FPIN pname walker counter to u32 (CVE-2026-63889) * kernel: wifi: mac80211: capture fast-RX rate before mesh reuses skb->cb (CVE-2026-64117) * kernel: Linux kernel: ath9k Wi-Fi driver use-after-free vulnerability leading to system crash (CVE-2026-68363) * kernel: dm-verity: fix buffer overflow in FEC calculation (CVE-2026-72098) * kernel: scsi: libiscsi_tcp: Bound SCSI Response data segment to the connection buffer (CVE-2026-74556) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Join the discussion
0

The kernel-rt packages provide the Real Time Linux Kernel, which enables fine-tuning for systems with extremely high determinism requirements. Security Fix(es): * kernel: EDAC/bluefield: Fix potential integer overflow (CVE-2024-53161) * kernel: wifi: mac80211: Discard Beacon frames to non-broadcast address (CVE-2025-71127) * kernel: KVM: nSVM: Always use vmcb01 in VMLOAD/VMSAVE emulation (CVE-2026-43133) * kernel: net: qrtr: fix refcount saturation and potential UAF in qrtr_port_remove (CVE-2026-52947) * kernel: wifi: nl80211: reject oversized EMA RNR lists (CVE-2026-53182) * kernel: blk-cgroup: fix UAF in __blkcg_rstat_flush() (CVE-2026-63802) * kernel: scsi: scsi_transport_fc: Widen FPIN pname walker counter to u32 (CVE-2026-63889) * kernel: wifi: mac80211: capture fast-RX rate before mesh reuses skb->cb (CVE-2026-64117) * kernel: Linux kernel: ath9k Wi-Fi driver use-after-free vulnerability leading to system crash (CVE-2026-68363) * kernel: net: qrtr: restrict socket creation to the initial network namespace (CVE-2026-68294) * kernel: dm-verity: fix buffer overflow in FEC calculation (CVE-2026-72098) * kernel: scsi: libiscsi_tcp: Bound SCSI Response data segment to the connection buffer (CVE-2026-74556) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Join the discussion

This Red Hat security advisory addresses multiple vulnerabilities and bug fixes in the Linux kernel packages for Red Hat Enterprise Linux 8 and 9. The update includes fixes for a denial of service vulnerability in the qla2xxx SCSI driver (CVE-2025-68745) and numerous other security issues affecting Bluetooth, DRM, SCTP, Wi-Fi, and other kernel subsystems. The advisory also contains bug fixes and enhancements unrelated to security. The kernel update is rated as important by Red Hat and requires a system reboot to apply.

Join the discussion

This Red Hat security advisory addresses multiple vulnerabilities and bug fixes in the Linux kernel, including a denial of service vulnerability in the qla2xxx SCSI driver (CVE-2025-68745) and numerous other issues affecting various kernel subsystems such as Bluetooth, DRM, SCTP, Wi-Fi, and more. The advisory covers security fixes, bug fixes, and enhancements for Red Hat Enterprise Linux 9 and related components. A patch is available to remediate these issues.

Join the discussion

The kernel packages contain the Linux kernel, the core of any Linux operating system. Security Fix(es): * kernel: KVM: nSVM: Always use vmcb01 in VMLOAD/VMSAVE emulation (CVE-2026-43133) * kernel: ipv6: prevent possible UaF in addrconf_permanent_addr() (CVE-2026-43339) * kernel: crypto: pcrypt - Fix handling of MAY_BACKLOG requests (CVE-2026-43493) * kernel: tcp: call sk_data_ready() after listener migration (CVE-2026-46015) * kernel: scsi: target: configfs: Bound snprintf() return in tg_pt_gp_members_show() (CVE-2026-46149) * kernel: inet: RAW sockets using IPPROTO_RAW MUST drop incoming ICMP (CVE-2026-46266) * kernel: flow_dissector: do not dissect PPPoE PFC frames (CVE-2026-46306) * kernel: Revert "net/smc: Introduce TCP ULP support" (CVE-2026-46330) * kernel: netfilter: conntrack: remove sprintf usage (CVE-2026-53002) * kernel: net: guard timestamp cmsgs to real error queue skbs (CVE-2026-53223) * kernel: ipv6: mcast: Fix use-after-free when processing MLD queries (CVE-2026-53275) * kernel: ipv4: account for fraggap on the paged allocation path (CVE-2026-53366) * kernel: net: mana: Fix TOCTOU double-fetch of hwc_msg_id from DMA buffer (CVE-2026-64034) * kernel: rhashtable: clear stale iter->p on table restart (CVE-2026-64563) * kernel: smb: client: fix double-free in SMB2_close() replay (CVE-2026-64597) * kernel: nvmet-rdma: handle inline data with a nonzero offset (CVE-2026-72129) * kernel: net: bridge: stop fast-leave after deleting a port group (CVE-2026-74480) Bug Fix(es) and Enhancement(s): * KSM to deduplicate only zero pages [rhel-9.8.z] (JIRA:RHEL-249161) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Join the discussion

In the Linux kernel, the following vulnerability has been resolved: net: qrtr: fix refcount saturation and potential UAF in qrtr_port_remove In qrtr_port_remove(), the socket reference count is decremented via __sock_put() before the port is removed from the qrtr_ports XArray and before the RCU grace period elapses. This breaks the fundamental RCU update paradigm. It exposes a race window where a concurrent RCU reader (such as qrtr_reset_ports() or qrtr_port_lookup()) can obtain a pointer to the socket from the XArray, and attempt to call sock_hold() on a socket whose reference count has already dropped to zero. This exact race condition was hit during syzkaller fuzzing, leading to the following refcount saturation warning and a potential Use-After-Free: refcount_t: saturated; leaking memory. WARNING: CPU: 3 PID: 1273 at lib/refcount.c:22 refcount_warn_saturate+0xae/0x1d0 Modules linked in: qrtr(+) bochs drm_shmem_helper ... Call Trace: <TASK> qrtr_reset_ports net/qrtr/af_qrtr.c:768 [inline] [qrtr] __qrtr_bind.isra.0+0x48b/0x570 net/qrtr/af_qrtr.c:805 [qrtr] qrtr_bind+0x17d/0x210 net/qrtr/af_qrtr.c:901 [qrtr] kernel_bind+0xe4/0x120 net/socket.c:3592 qrtr_ns_init+0x1a6/0x380 net/qrtr/ns.c:715 [qrtr] qrtr_proto_init+0x3b/0xff0 net/qrtr/af_qrtr.c:169 [qrtr] do_one_initcall+0xf5/0x5e0 init/main.c:1283 ... </TASK> Fix this by deferring the reference count decrement until after the xa_erase() and the synchronize_rcu() complete. (Note: The v1 of this patch incorrectly replaced __sock_put() with sock_put(). As Simon Horman pointed out, the callers of qrtr_port_remove() still hold a reference to the socket, so freeing the socket memory here would lead to a subsequent UAF in the caller. Thus, the __sock_put() is kept, but only repositioned to close the RCU race.)

Join the discussion

To determine the support lifecycle for your software, see the Microsoft Support Lifecycle: https://support.microsoft.com/lifecycle

Join the discussion

Showing 1 to 7 of 7 results

Filters:Tag: cve-2026-52947
Page 1 of 1
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses