PatchSiren

Linux CVE debriefs · Page 56

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

CRITICAL Linux CVE published 2026-07-27

CVE-2026-64535

A vulnerability was found in the Linux kernel, specifically in the nvmet-tcp module. When data digest is enabled on an NVMe/TCP connection and a digest mismatch occurs on a non-final H2C_DATA PDU during an R2T-based data transfer, the digest error handler calls nvmet_req_uninit() but does not mark the command as completed. This can lead to a double percpu_ref_put against a single percpu_ref_get when the s [truncated]

CRITICAL Linux CVE published 2026-07-27

CVE-2026-64534

A vulnerability in the Linux kernel's nvmet-tcp has been resolved. The issue involves a data digest mismatch detection in nvmet_tcp_try_recv_ddgst(), leading to an unconditional call to nvmet_req_uninit(). This causes a refcount underflow if the command arrived via nvmet_tcp_handle_req_failure() path and nvmet_req_init() returned false. The vulnerability has a high impact on Linux kernel users and adminis [truncated]

HIGH Linux CVE published 2026-07-27

CVE-2026-64533

The Linux kernel has a vulnerability in the fs/ntfs3: validate lcns_follow in log_replay conversion. This vulnerability has been resolved. The vulnerability affects users of the Linux kernel who use the ntfs3 filesystem. The vulnerability allows an attacker to access memory beyond the bounds of the allocated restart table buffer, potentially leading to a denial-of-service or code execution. The vulnerabil [truncated]

HIGH Linux CVE published 2026-07-27

CVE-2026-64532

A vulnerability was found in the Linux kernel's ntfs3 filesystem implementation. The vulnerability is related to the handling of NTFS_DE view.data_off in the UpdateRecordData{Root,Allocation} functions. The memmove destination is calculated using e->view.data_off, which comes from an on-disk NTFS_DE inside an INDEX_ROOT or INDEX_BUFFER. However, the existing checks do not validate view.data_off + dlen aga [truncated]

HIGH Linux CVE published 2026-07-27

CVE-2026-64531

A vulnerability in the Linux kernel has been resolved. The net: openvswitch module rejects oversized nested action attributes. This change prevents potential issues with structurally different streams being walked during validation and teardown. Users of the Linux kernel, particularly those using Open vSwitch, should review the provided patches and ensure their systems are updated.

CRITICAL Linux CVE published 2026-07-26

CVE-2026-64530

A vulnerability in the Linux kernel's net/sched: cls_api has been resolved. The tcf_qevent_handle function did not handle TC_ACT_CONSUMED, leading to a use-after-free (UAF) vulnerability. This issue occurs when the skb is held by the defragmentation engine and tcf_classify returns TC_ACT_CONSUMED. The vulnerability has been addressed, but Linux kernel users and administrators, network operators, and secur [truncated]

HIGH Linux CVE published 2026-07-26

CVE-2024-14040

A Linux kernel vulnerability, CVE-2024-14040, was resolved by increasing the next hop weight from u8 to u16. This change addresses issues with ECMP weights in CLOS networks, allowing for higher weight ratios. The update was done in two steps to ensure type correctness and prevent numerical errors. The UAPI for configuring nexthop group members was also adjusted to accommodate the new weight field. Old use [truncated]

HIGH Linux CVE published 2026-07-25

CVE-2026-64515

The Linux kernel was vulnerable to a wifi: mac80211 MLE defragmentation issue. The vulnerability has been resolved. Affected products include Linux kernel deployments. The vulnerability class is related to wifi: mac80211 MLE defragmentation. The likely operational impact is disruption of wifi services. Source-confidence limits are based on CVE and NVD details. This issue requires immediate attention from [truncated]

Review Linux CVE published 2026-07-25

CVE-2026-64514

A vulnerability in the Linux kernel's userfaultfd feature has been addressed. The userfaultfd_must_wait() and userfaultfd_huge_must_wait() functions read the PTE without taking the page table lock and apply pte_write() / huge_pte_write() to it, potentially leading to undefined results on swap or migration entries. This can cause problems with userfaultfd's functionality, potentially leading to system cras [truncated]

Review Linux CVE published 2026-07-25

CVE-2026-64512

The Linux kernel has been updated to address a vulnerability that could potentially lead to undefined behavior. The vulnerability, tracked as CVE-2026-64512, involves a UBSAN warning caused by field misuse in the ACPI CPPC (Collaborative Processor Performance Control) code. The issue arises from the definition of reg->access_width changing depending on the reg->space_id type, specifically when using ACPI_ [truncated]

MEDIUM Linux CVE published 2026-07-25

CVE-2026-64415

The Linux kernel was updated to address a softlockup vulnerability in the swap_reclaim_full_clusters function. This vulnerability was triggered during a stress test on a large arm64 machine with 320 CPUs, about 1TB memory, and an 8.6GB swap device under heavy load with a large number of full clusters on the swap device. The issue was caused by a lack of periodic cond_resched() calls during large full_clus [truncated]

HIGH Linux CVE published 2026-07-25

CVE-2026-64414

The Linux kernel's netfilter component has a vulnerability related to handling unreadable fragments. This vulnerability, tracked as CVE-2026-64414, affects the u32 module and can lead to errors when processing skb with unreadable fragments. The patch addresses this by implementing proper handling, including bailing out with hotdrop in such cases and restricting nfnetlink_queue and nfnetlink_log to the lin [truncated]

HIGH Linux CVE published 2026-07-25

CVE-2026-64412

A vulnerability in the Linux kernel's netfilter: ebtables module has been resolved. The module requires explicitly checking the length to ensure null-termination of module names, preventing potential issues with non-null terminated strings passed to request_module(). This vulnerability has been publicly disclosed and users of the Linux kernel should be aware of this issue and take necessary precautions.

HIGH Linux CVE published 2026-07-25

CVE-2026-64346

A Use-After-Free vulnerability was discovered in the Linux kernel's USB gadget subsystem. The vulnerability occurs when the udc structure is freed while still being accessed by the gadget_match_driver function, leading to a NULL pointer dereference. This issue arises from a race condition between usb_del_gadget and gadget_match_driver functions. The vulnerability impacts Linux kernel developers, maintaine [truncated]

HIGH Linux CVE published 2026-07-25

CVE-2026-64344

A use-after-free vulnerability was found in the Linux kernel's USB idmouse driver. The issue arises from the improper use of mutex_unlock() to manage the lifetime of objects, which can lead to accessing the mutex structure after the lock has been released. This vulnerability has been resolved by utilizing a kref to release the driver data, thereby preventing use-after-free when the release() function race [truncated]

HIGH Linux CVE published 2026-07-25

CVE-2026-64343

A use-after-free vulnerability was found in the Linux kernel's ldusb driver. The vulnerability occurs when the mutex_unlock() function is used to manage the lifetime of objects directly, which is not allowed. This can lead to a use-after-free error when the release() function races with the disconnect() function. The fix involves using a kref to release the driver data and avoid the use-after-free error. [truncated]

HIGH Linux CVE published 2026-07-25

CVE-2026-64342

A use-after-free vulnerability was found in the Linux kernel's USB iowarrior driver. Submitted write URBs are not stopped on close() and therefore need to be stopped unconditionally on disconnect() to avoid use-after-free in the completion handler. This vulnerability can be exploited by a local attacker to potentially execute arbitrary code or cause a denial of service. Linux kernel users and administrato [truncated]

MEDIUM Linux CVE published 2026-07-25

CVE-2026-64336

A Linux kernel vulnerability (CVE-2026-64336) was found in the USB: serial: keyspan_pda driver, which could lead to an information leak. The vulnerability has been resolved with several patches available. This vulnerability affects Linux kernel versions and could lead to potential information leaks if not patched. Users and administrators should assess their exposure and apply patches to prevent potential [truncated]

MEDIUM Linux CVE published 2026-07-25

CVE-2026-64335

A vulnerability has been resolved in the Linux kernel. The USB: serial: digi_acceleport driver had a broken rx after throttle issue. If the port is closed while throttled, the read urb is never resubmitted and the port will not receive any further data until the device is reconnected or the driver is rebound. Clearing the throttle flags and submitting the urb if needed when opening the port resolves the i [truncated]

MEDIUM Linux CVE published 2026-07-25

CVE-2026-64334

A vulnerability has been resolved in the Linux kernel, specifically in the USB: serial: digi_acceleport driver. The driver had a hard lockup issue on disconnect due to a persistent failure in submitting the OOB write urb. This could cause the driver to loop indefinitely with interrupts disabled, potentially leading to system instability. The issue can be triggered when open(), set_termios(), or close() ra [truncated]

HIGH Linux CVE published 2026-07-25

CVE-2026-64333

A vulnerability was found in the Linux kernel's USB serial digi_acceleport driver. The digi_write_inb_command() function did not properly handle write urb timeouts, leading to potential write buffer corruption. This issue has been resolved by adding a missing return on timeout and waiting indefinitely when no timeout has been specified. The vulnerability affects Linux kernel maintainers, Linux distributio [truncated]

MEDIUM Linux CVE published 2026-07-25

CVE-2026-64262

A Linux kernel vulnerability, CVE-2026-64262, was resolved by fuse-uring: end fuse_req on io-uring cancel task work. When io_uring delivers task work with tw.cancel set, fuse_uring_send_in_task() takes the cancel branch, assigns -ECANCELED, and falls through to fuse_uring_send(). However, this path does not discharge the ring entry's owning reference to the fuse_req. As a result, the fuse_req stays linked [truncated]

HIGH Linux CVE published 2026-07-25

CVE-2026-64259

A Linux kernel vulnerability, CVE-2026-64259, was resolved by moving fuse_uring_add_to_pq() after copy operations to prevent use-after-free races. Malicious userspace could not find the request until all preparation work was completed. This change also avoided a forward declaration and facilitated easier backporting to older kernels. The vulnerability affects Linux kernel users and administrators, who sho [truncated]

MEDIUM Linux CVE published 2026-07-25

CVE-2026-64258

A vulnerability was found in the Linux kernel, specifically in the fuse-uring subsystem. The issue could lead to a NULL dereference if a copy into the userspace ring buffer fails. This occurs when a request-less entry is left on ent_w_req_queue in FRRS_FUSE_REQ state. The fix involves taking the entry off ent_w_req_queue and changing its state from FRRS_FUSE_REQ to FRRS_INVALID before terminating the requ [truncated]

CRITICAL Linux CVE published 2026-07-25

CVE-2026-64257

The Linux kernel has been found to have a vulnerability that could allow an attacker to send overlapping data areas in SMB2 responses. This could potentially lead to issues with the handling of such responses. The vulnerability is related to the handling of SMB2 responses in the Linux kernel, specifically in the __smb2_calc_size() function. The kernel maintainers have resolved this issue by tracking data [truncated]

MEDIUM Linux CVE published 2026-07-25

CVE-2026-64256

A vulnerability was found in the Linux kernel, specifically in the handling of quota IDs in the dqiterate function. This issue could potentially lead to unintended behavior due to the possibility of quota IDs wrapping around. The vulnerability has been resolved through a patch that prevents quota ID wrapping by casting to u64. System administrators and security teams responsible for Linux kernel-based sys [truncated]

HIGH Linux CVE published 2026-07-24

CVE-2026-64255

A HIGH severity vulnerability was found in the Linux kernel's wifi iwlwifi mld. The vulnerability is caused by the use of ffs(ba_data->sta_mask) - 1 to derive a station ID without checking that sta_mask is non-zero. When sta_mask is zero, ffs() returns 0 and the subtraction wraps to 0xFFFFFFFF, causing an out-of-bounds access on fw_id_to_link_sta[]. This issue affects Linux kernel users and administrators [truncated]

MEDIUM Linux CVE published 2026-07-24

CVE-2026-64254

The Linux kernel has a vulnerability that has been resolved. The vulnerability is related to the NTB (Non-Transparent Bridging) driver, specifically in the epf (Enhanced Performance Framework) module. When the BAR_PEER_SPAD and BAR_CONFIG share one PCI BAR, the module teardown path ends up calling pci_iounmap() on the same iomem with some offset, which is unnecessary and triggers a kernel warning.

MEDIUM Linux CVE published 2026-07-24

CVE-2026-64253

A vulnerability has been identified in the Linux kernel, specifically in the fork process where the PF_BLOCK_TS flag is not properly cleared. This flag is set when the current process's plug is non-NULL and is cleared when the plug is finished and set to NULL. However, in the copy_process function, this flag is inherited from the parent process while the child's plug is reset to NULL, potentially leading [truncated]

MEDIUM Linux CVE published 2026-07-24

CVE-2026-64252

The Linux kernel was vulnerable to a situation where the initial console buffer could land in the XKPHYS 64-bit memory segment in 64-bit configurations. This could cause unpredictable behavior, such as a kernel crash, when the console output handler is called from a kernel thread other than the initial one. The issue arises when no final console driver has been enabled in the configuration, causing the in [truncated]