PatchSiren

Linux CVE debriefs · Page 55

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

Review Linux CVE published 2026-08-05

CVE-2026-64571

The Linux kernel has a vulnerability in the p54_rx_eeprom_readback() function, which does not validate the RX frame length. This can cause a buffer overflow when a malicious USB device sends a short frame with a truncated payload. The vulnerability affects Linux kernel deployments and requires immediate attention. Affected product or component is the Linux kernel, specifically the p54_rx_eeprom_readback() [truncated]

HIGH Linux CVE published 2026-08-05

CVE-2026-64570

A double-free vulnerability was found in the Linux kernel's mac80211 subsystem. The vulnerability occurs in the ieee80211_set_fils_discovery() function, where it calls kfree_rcu() on the old template before allocating a replacement. If the allocation fails, it returns -ENOMEM while the link->u.ap.fils_discovery still points to the object already queued for freeing. This can cause a double-free error when [truncated]

Review Linux CVE published 2026-08-05

CVE-2026-64569

The Linux kernel vulnerability, CVE-2026-64569, exists in the mpls_valid_fib_dump_req() function when CONFIG_INET is not set. An unprivileged user can trigger a NULL dereference through an RTM_GETROUTE dump for AF_MPLS with strict checking and no RTA_OIF, potentially leading to a denial of service. Linux kernel developers and administrators should verify and apply patches, restrict access to RTM_GETROUTE, [truncated]

HIGH Linux CVE published 2026-08-05

CVE-2026-64568

A double-free vulnerability was found in the Linux kernel's mac80211 subsystem, specifically in the ieee80211_set_unsol_bcast_probe_resp function. This issue occurs when the function attempts to allocate a new template but fails, leading to a double-free of the old template. The vulnerability can cause a denial-of-service (DoS) attack or potentially allow an attacker to execute arbitrary code. The affecte [truncated]

HIGH Linux CVE published 2026-08-05

CVE-2026-64567

A flaw was found in the Linux kernel's btrfs free space cache loading logic. When loading a v1 free space cache, the code does not validate the number of entries and bitmaps read from disk, leading to a potential out-of-bounds read. This could cause a denial of service or potentially execute arbitrary code with elevated privileges. The affected product is the Linux kernel, and the vulnerability class is r [truncated]

CRITICAL Linux CVE published 2026-08-05

CVE-2026-64566

A vulnerability in the Linux kernel has been resolved, which could cause memory corruption and potentially trigger a panic. The issue arises from the iptfs_skb_add_frags() function not propagating the SKBFL_SHARED_FRAG flag when copying frag references from the source frag walk into a new SKB. This oversight can lead to memory corruption when a nested transport-mode SA decrypts in place, as the new inner [truncated]

Review Linux CVE published 2026-08-04

CVE-2026-64565

The CVE-2026-64565 vulnerability is related to a heap-buffer-overflow in the ims_pcu_process_data() function of the Linux kernel. The function processes incoming URB data byte by byte but fails to check if the read_pos index exceeds IMS_PCU_BUF_SIZE. This could allow an attacker to overwrite the read_pos itself to arbitrarily control the index, leading to a heap buffer overflow. The manipulated read_pos i [truncated]

CRITICAL Linux CVE published 2026-08-04

CVE-2026-64564

A vulnerability in the Linux kernel's SCTP implementation has been addressed. The issue arises from the improper handling of ASCONF chunks, specifically when processing DEL-IP operations. This can lead to a use-after-free vulnerability, allowing for potential crashes or code execution. The fix involves rejecting DEL-IP operations that target the transport the ASCONF is being processed against.

HIGH Linux CVE published 2026-08-04

CVE-2026-64563

A use-after-free vulnerability was found in the Linux kernel's rhashtable implementation. The rhashtable_walk_next function can dereference a stale pointer, leading to a potential crash or code execution. This vulnerability affects Linux kernel developers and users, network administrators, and security teams responsible for managing Linux-based systems. They should review the affected scope, assess potent [truncated]

HIGH Linux CVE published 2026-07-29

CVE-2026-64560

A use-after-free vulnerability was found in the Linux kernel's posix-cpu-timers functionality. This issue is related to a non-leader exec() race that can result in a use-after-free (UAF) vulnerability. The vulnerability arises from a race condition in the posix_cpu_timer_del() and sys_timer_delete() functions in the Linux kernel. This can result in a use-after-free (UAF) vulnerability, allowing an attacke [truncated]

HIGH Linux CVE published 2026-07-29

CVE-2026-64558

The CVE-2026-64558 vulnerability involves a buffer length check issue in the Linux kernel's pkey_pckmo handler implementation. This vulnerability has been resolved with an explicit length check in the key_to_protkey() handler function to prevent buffer overflow. The vulnerability affects Linux kernel deployments, and users should review their systems for potential exposure and apply patches or mitigations [truncated]

HIGH Linux CVE published 2026-07-29

CVE-2026-64557

A use-after-free vulnerability was found in the Linux kernel's Bluetooth L2CAP. The vulnerability occurs when the `l2cap_sock_new_connection_cb()` function returns a channel after releasing the parent socket lock, allowing another task to accept and free the child socket before the callback dereferences it. This issue has been resolved by reworking the `->new_connection()` operation to have the core own t [truncated]

HIGH Linux CVE published 2026-07-27

CVE-2026-64554

A use-after-free write vulnerability was found in the Linux kernel's netfilter bridge functionality. The br_ip6_fragment() function dereferences a stale pointer, leading to a potential kernel panic. This vulnerability affects the Linux kernel's netfilter bridge module, specifically in the br_ip6_fragment() function. The function gets a pointer into the skb head from ip6_find_1stfragopt(), then calls skb_c [truncated]

Review Linux CVE published 2026-07-27

CVE-2026-64553

The CVE-2026-64553 vulnerability is an information leak in the Linux kernel's psample component. The issue arises from improper handling of padding in the PSAMPLE_ATTR_DATA attribute. This vulnerability was resolved through a series of commits to the Linux kernel. Affected product deployments should be reviewed for exposure, and owners should be assigned for follow-up. The vulnerability has a significant [truncated]

HIGH Linux CVE published 2026-07-27

CVE-2026-64552

The Linux kernel's virtio-net component has a vulnerability that allows for an out-of-bounds write past the static frag array and a NULL frag handed up the rx path. A malicious virtio backend can announce a length that exploits this vulnerability, potentially leading to a denial of service or code execution. The vulnerability is due to a loose length check in the receive_big() function, which allows for a [truncated]

CRITICAL Linux CVE published 2026-07-27

CVE-2026-64551

The Linux kernel's SCTP implementation has a vulnerability that allows for the leakage of uninitialized memory when an ERROR chunk with a STALE_COOKIE cause is received in the COOKIE_ECHOED state. This occurs because the STALE_COOKIE cause length is not validated before reading the staleness field. The vulnerability has a high CVSS score of 9.1 and can be exploited by an unprivileged process using a raw S [truncated]

HIGH Linux CVE published 2026-07-27

CVE-2026-64550

The Linux kernel has a vulnerability in the Qualcomm rmnet driver. When ingress deaggregation is disabled, the rmnet_map_ingress_handler function passes the skb straight to __rmnet_map_ingress_handler, skipping length validation. This allows a short frame to be read out of bounds, causing a slab-out-of-bounds read. The vulnerability affects Linux kernel versions and can be used to cause a denial of servic [truncated]

Review Linux CVE published 2026-07-27

CVE-2026-64549

The Linux kernel has a vulnerability in the Bluetooth bpa10x component. The bpa10x_setup() function sends a vendor command and passes the response to bt_dev_info() and hci_set_fw_info() without checking the length, potentially leading to an out-of-bounds read of adjacent slab memory. This could result in sensitive data being leaked into the kernel log and firmware-info debugfs file.

HIGH Linux CVE published 2026-07-27

CVE-2026-64548

The Linux kernel has a vulnerability in the bpf_msg_push_data() function, which can lead to an out-of-bounds memcpy due to an undersized allocation. This occurs when the scatterlist ring is full or nearly full, and a crafted len can wrap the sum to a small value. The vulnerability has been resolved by adding an overflow check before the allocation. System administrators and users of Linux-based systems, p [truncated]

HIGH Linux CVE published 2026-07-27

CVE-2026-64547

The Linux kernel vulnerability CVE-2026-64547 was resolved in the net: usb: net1080 driver. The issue involved validating packet_len before accessing the pad byte in rx_fixup. A malicious NetChip 1080 device could send a short frame with a large even packet_len, causing a slab-out-of-bounds read. The fix rejects frames when packet_len >= skb->len before reading.

HIGH Linux CVE published 2026-07-27

CVE-2026-64545

A NULL pointer dereference vulnerability was found in the Linux kernel's xdp_master_redirect function. The function dereferences the result of netdev_master_upper_dev_get_rcu without a NULL check, leading to a kernel panic when the receiving device has no upper-master adjacency. This vulnerability affects Linux systems using the xdp_master_redirect function in their network configurations. Administrators [truncated]

Review Linux CVE published 2026-07-27

CVE-2026-64544

A vulnerability in the Linux kernel's crypto: asymmetric_keys - fix OOB read in pefile_digest_pe_contents has been resolved. The vulnerability occurs when the addition of hashed_bytes and certs_size exceeds pelen, causing an unsigned subtraction to underflow. This underflow is then passed to crypto_shash_update(), which reads out of bounds and panics on unmapped vmalloc guard pages.

HIGH Linux CVE published 2026-07-27

CVE-2026-64543

A use-after-free vulnerability was found in the Linux kernel's TIPC subsystem. The `tipc_disc_rcv` function still accesses the `b->disc` discoverer after it has been freed in the `bearer_disable` function. This can cause a slab-use-after-free error. The vulnerability is reachable from an unprivileged user namespace and requires CONFIG_TIPC and CONFIG_TIPC_MEDIA_UDP to be enabled.

Review Linux CVE published 2026-07-27

CVE-2026-64542

A vulnerability in the Linux kernel's IPv6 implementation has been addressed. The issue, located in the `accept_untracked_na()` function, could lead to a NULL pointer dereference under certain conditions. This occurred when the function re-fetched the `inet6_dev` without a NULL check, even though its caller had already fetched and checked the device. A concurrent `addrconf_ifdown()` could clear `dev->ip6_ [truncated]

CRITICAL Linux CVE published 2026-07-27

CVE-2026-64541

A use-after-free vulnerability was found in the Linux kernel's SMC (System Management Controller) implementation. The smc_cdc_rx_handler() function does not hold a reference to the socket while processing a CDC (Connection-Directed Control) message, allowing a concurrent close() operation to free the socket, leading to a use-after-free error when the handler later attempts to access the socket.

HIGH Linux CVE published 2026-07-27

CVE-2026-64540

The Linux kernel vulnerability CVE-2026-64540 was resolved, involving an out-of-bounds read issue in the genelink_rx_fixup() function of the gl620a driver. A malicious device could send a short URB with a large packet length, causing the function to read past the end of the receive buffer and leak kernel heap contents. The issue is addressed by moving the skb_pull() call ahead of the copy and checking its result.

HIGH Linux CVE published 2026-07-27

CVE-2026-64539

A local user with CAP_NET_ADMIN owning an LE-only controller on the legacy advertising path can trigger a stack-out-of-bounds write in the Linux kernel's Bluetooth eir module. The vulnerability arises from the eir_create_adv_data function not properly checking the buffer size when prepending a 'Flags' AD structure and copying instance advertising data.

Review Linux CVE published 2026-07-27

CVE-2026-64538

A null-pointer dereference vulnerability was found in the Linux kernel's IPv6 implementation. The `fib6_nh_mtu_change` function did not check for a NULL `idev` pointer before dereferencing it, leading to a general protection fault. This issue can be triggered when the `addrconf_ifdown` function clears the `dev->ip6_ptr` with RCU_INIT_POINTER after `rt6_disable_ip` has released `tb6_lock`.

Review Linux CVE published 2026-07-27

CVE-2026-64537

The Linux kernel vulnerability CVE-2026-64537 has been resolved. The vulnerability was related to the bridge: cfm: reject invalid CCM interval at configuration time. The issue was that ccm_tx_work_expired() re-armed itself via queue_delayed_work() using the configured exp_interval converted by interval_to_us(). When exp_interval was BR_CFM_CCM_INTERVAL_NONE or out of range, interval_to_us() returned 0, ca [truncated]

HIGH Linux CVE published 2026-07-27

CVE-2026-64536

A vulnerability was found in the Linux kernel's rtl8723bs module. The loop in is_ap_in_tkip() iterates over IEs without verifying that enough bytes remain before dereferencing the IE header or its payload, leading to OOB reads. This issue affects Linux kernel developers and maintainers, users of Linux distributions that include the rtl8723bs module. The vulnerability has been resolved with the provided ke [truncated]