MontaVista continually monitors the security community and customers for threats. We follow the community on CVE scoring (NVD) and set fix priority accordingly for affected products. Please view the following CVEs that have been remediated or are in process by clicking the CVE Year to the left or use the CVE Filters below.
For reporting Known Exploitable Vulnerabilities (KEV) or new Security Vulnerabilities, please see our Vulnerability Response Policy or email our PSIRT team. Messages and attachments should be encrypted using PGP and a MontaVista PSIRT PGP key, which is available for download here.
| CVE | Score | Severity | Package | Description | Published |
|---|---|---|---|---|---|
| CVE-2026-90153 |
8.1 (i)
| HIGH | kernel | In the Linux kernel, the following vulnerability has been resolved:ksmbd: bound smb_check_perm_dacl() ACE walks by DACL sizesmb_check_perm_dacl() validates that the DACL fits inside the NTsecurity descriptor, but then bounds its two ACE walks by theremaining NTSD length (acl_size) rather than the DACL's declaredsize (pdacl_size).When pdacl->size is smaller than the trailing NTSD buffer, bytesafter the declared DACL boundary - still inside the stored securitydescriptor - are parsed as ACEs during access checks. A craftedDACL can place an access-granting ACE beyond pdacl->size, and thecurrent code accepts it during SMB2_CREATE access validation, whileparse_dacl() and smb_inherit_dacl() stop at pdacl_size.Bound both ACE walks by pdacl_size to match the DACL boundarysemantics used elsewhere in the server.Validation:- semantic KUnit harness shows the post-boundary ACE is selected before the fix and rejected (EACCES) after it- linux master (7.2-rc6), x86_64 | 2026-09-17 |
| CVE-2026-90149 |
7.5 (i)
| HIGH | kernel | In the Linux kernel, the following vulnerability has been resolved:NFSv4/flexfiles: fix NULL dereference for NFSv4.0 data serversflexfiles accepts NFSv4.0 data servers, but two NFSv4 code paths assumethe data server client has a session. Unlike NFSv4.1+, an NFSv4.0 clienthas no session (clp->cl_session is NULL; it uses clp->cl_slot_tbl), soI/O to a v4.0 flexfiles DS oopses: - nfs4_init_ds_session() dereferences clp->cl_session->session_state while seeding the DS lease. It also only seeds cl_lease_time when NFS4_SESSION_INITING is set; without a session that never happens, so cl_lease_time stays 0 and nfs4_renew_state() busy-loops, requeuing every 5 seconds. Seed the lease whenever there is no session and return before touching session state. - ff_layout_async_handle_error_v4() dereferences clp->cl_session->fc_slot_table on every DS I/O error. Fall back to the v4.0 transport slot table (clp->cl_slot_tbl) when there is no session. | 2026-09-17 |
| CVE-2026-90146 |
7.8 (i)
| HIGH | kernel | In the Linux kernel, the following vulnerability has been resolved:bpf, xdp: move offload check into dev_xdp_install()bpf_xdp_link_update() calls dev_xdp_install() directly and skipsdev_xdp_attach(), so the checks in dev_xdp_attach() do not run. A user canmake an XDP link with a normal program and then swap in an offloaded ordevice-bound program with BPF_LINK_UPDATE, which puts it on the softwarepath.dev_xdp_install() is the one place all three paths go through:"ip link set xdp" and BPF_LINK_CREATE reach it via dev_xdp_attach(), andBPF_LINK_UPDATE calls it directly. So move the program checks (offloaded,bound to another device, device-bound in generic mode, native vs generic,DEVMAP and CPUMAP) there, and keep only the netlink-flag check(XDP_FLAGS_UPDATE_IF_NOEXIST) in dev_xdp_attach(). | 2026-09-17 |
| CVE-2026-90145 |
7.1 (i)
| HIGH | kernel | In the Linux kernel, the following vulnerability has been resolved:hinic3: Fix skb linearization mismatch and drop skb when skb_checksum_help() failedPreviously, hinic3_send_one_skb() cached the skb fragment count beforecalling hinic3_tx_offload(). If hinic3_tx_csum() falls back toskb_checksum_help() for unsupported tunnel packets, the skb may belinearized. Continuing to build the TX descriptor with the stalefragment count leads to a descriptor mismatch, which can triggerout-of-bounds DMA reads or IOMMU faults.Furthermore, the old code ignored the return value of skb_checksum_help(),transmitting corrupted packets with incomplete checksums upon failure.Fix this by:1. Moving the hinic3_tx_offload() call before calculating 'num_sge' to ensure the correct fragment count is used if the SKB is linearized.2. Propagating skb_checksum_help() errors and returning HINIC3_TX_OFFLOAD_INVALID to properly drop the skb. | 2026-09-17 |
| CVE-2026-90143 |
7.8 (i)
| HIGH | kernel | In the Linux kernel, the following vulnerability has been resolved:net: kcm: Hold RCU read lock while running BPF parserkcm_parse_func_strparser() calls bpf_prog_run_pin_on_cpu() whichprevents CPU migration, but does not establish an RCU read-sidecritical section. Consequently, BPF map operations can triggerWARN_ON_ONCE(!bpf_rcu_lock_held()) when called from the KCM strparserprogram.Hold the RCU read lock while running the program. | 2026-09-17 |
| CVE-2026-90142 |
7.8 (i)
| HIGH | kernel | In the Linux kernel, the following vulnerability has been resolved:virtio_net: Fix resize of the RX ringWhen a AF_XDP socket is attached, the virtnet_rx_resizeshould resize the rq->xsk_buffs XSK buffer array. Otherwise,when the size grows, the virtnet_rx_resume() causes a writepast the end of the array. This is easily reproducable with ethtool -G ens3 rx 32 ./xdpsock -i eth0 -q 0 -r -z & ethtool -G eth0 rx 256 | 2026-09-17 |
| CVE-2026-90141 |
7.3 (i)
| HIGH | kernel | In the Linux kernel, the following vulnerability has been resolved:ipvs: fix integer overflow in ftp helper port/address parsingip_vs_ftp_get_addrport() accumulates decimal digits into a __u16(hport) and into unsigned char (p[]) without checking for overflow.A crafted FTP PASV/EPSV response with an over-long port or addressoctet wraps the value, so the helper configures the data connectionwith a truncated port/address.The netfilter conntrack FTP helper had the same defect, fixed incommit 2b413fc689ba ("netfilter: nf_conntrack_ftp: avoid u16overflows"). Apply the equivalent fix here: widen the port accumulatorto u32 and reject values above 65535, and reject address octets above255. | 2026-09-17 |
| CVE-2026-90137 |
7.7 (i)
| HIGH | kernel | In the Linux kernel, the following vulnerability has been resolved:platform/x86: hp-bioscfg: fix password encoding bounds checkThe password PSWD_ENCODINGS parser reads password_obj[elem + pos_values]while copying the supported password encodings from the ACPI package.The outer loop only guarantees that elem is within password_obj_count.The encoding count is bounded by MAX_ENCODINGS_SIZE, but that does notguarantee that the ACPI package contains enough entries for allelem + pos_values accesses.A malformed package can therefore declare a non-zero encoding countwithout providing enough string objects, causing the parser to read pastthe ACPI package array and pass an out-of-bounds string pointer andlength to hp_convert_hexstr_to_str().Add the same computed-index bounds check used by the other offset-basedpackage parsing loops before reading password_obj[elem + pos_values]. | 2026-09-17 |
| CVE-2026-90133 |
7.8 (i)
| HIGH | kernel | In the Linux kernel, the following vulnerability has been resolved:ntfs: Fix index_root heap OOB write in ntfs_ir_to_ib()ntfs_ir_to_ib copies all entries from index_root into a freshly allocatedindex_block_size-byte buffer without verifying that the entries fit in theavailable space. The entries in index_root may be larger than the usableentry space in the index block.This can cause OOB writes past the end of the allocation.The validator ntfs_index_root_inconsistent() checks that entries areself-consistent within the IR value, but never cross-checks them againstindex_block_size. There is no bounds check in ntfs_ir_to_ib() before thememcpy.Fixing this at the sink in ntfs_ir_to_ib() sincentfs_index_root_inconsistent() validates the logical consistency ofindex_root as a structure and a root with large entries is a structurallyvalid root. The bug is a size conflict of ntfs_ir_to_ib().Also, the validator is called once per inode load inntfs_read_locked_inode() while ntfs_ir_to_ib() is only called during areparent, a check there adds no overhead to the common path.Moreover, even a future call path that bypasses the validator would stillbe protected.With NULL as first parameter of ntfs_error(), the volume error flag isnever set by this call, so the device name will be absent from the errormessage. In any case, that the caller, ntfs_ir_reparent(), prints an errormessage that includes the device name on NULL returns.I think this is the best solution available without adding'struct super_block *sb' as a parameter to ntfs_ir_to_ib().This heap out-of-bounds write is triggered by a crafted filesystem image,which is not in the kernel threat model, anyway, fixing memory errors wouldbe nice to keep things secure. | 2026-09-17 |
| CVE-2026-90132 |
7.1 (i)
| HIGH | kernel | In the Linux kernel, the following vulnerability has been resolved:ntfs: reject unprivileged writes to reserved $LX* xattrsReject setxattr of the reserved $LXUID, $LXGID, $LXMOD and $LXDEV namesfrom userspace unless the caller has CAP_SYS_ADMIN. | 2026-09-17 |