PatchSiren

Linux CVE debriefs · Page 57

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH Linux CVE published 2026-07-24

CVE-2026-64251

A use-after-free vulnerability was found in the Linux kernel's pwrseq core. The issue arises from inconsistent reference counting in seq_file callbacks. The vulnerability has been resolved by making the reference counting consistent across all seq_file callbacks, matching the standard pattern used by PCI and SCSI. This fix ensures that the Linux kernel's pwrseq core is secure and reliable.

MEDIUM Linux CVE published 2026-07-24

CVE-2026-64250

The Linux kernel vulnerability CVE-2026-64250 is related to the LoongArch architecture. When the kernel fails to report a dying CPU to RCU in the stop_this_cpu() function, it can cause a hang during reboot or shutdown. This issue arises because the CPU is marked offline for the scheduler but RCU still expects a quiescent state. A patch has been applied to resolve this issue. Users of the Linux kernel, esp [truncated]

HIGH Linux CVE published 2026-07-24

CVE-2026-64249

The Linux kernel has a use-after-free vulnerability in the FPGA region handling, specifically in the child_regions_with_firmware() function. This issue arises from improper handling of child_region memory, leading to a use-after-free error. The vulnerability has been addressed through multiple kernel commits. Linux kernel developers and maintainers, Linux distribution vendors, and users of Linux-based sys [truncated]

MEDIUM Linux CVE published 2026-07-24

CVE-2026-64248

The Linux kernel vulnerability, CVE-2026-64248, involves a problem with reporting dying CPUs to RCU in stop_this_cpu(). This issue was noticed on several Realtek MIPS switch SoCs during a kernel bump downstream in OpenWrt from 6.18.33 to 6.18.34. The patch has been backported to various kernel versions, including 6.1, 6.6, 6.12, 6.18, 7.0, and 7.1. The vulnerability allows for a medium severity impact wit [truncated]

HIGH Linux CVE published 2026-07-24

CVE-2026-64247

A HIGH severity vulnerability was found in the Linux kernel, specifically in the KVM (Kernel-based Virtual Machine) x86 hyper-v module. The vulnerability is related to the handling of sparse banks when querying VP (Virtual Processor) IDs. When checking if a VP ID is included in a sparse bank set, the code does not properly bound the bank index, leading to an out-of-bounds read. This could potentially lead [truncated]

HIGH Linux CVE published 2026-07-24

CVE-2026-64246

A use-after-free vulnerability was found in the linkstation_poweroff_init() function of the Linux kernel. The issue arises from the incorrect placement of of_node_put(dn), which should be moved after the of_match_node() call that still requires the node pointer. This ensures the node reference is correctly released after use. The vulnerability allows for potential local privilege escalation and has been a [truncated]

HIGH Linux CVE published 2026-07-24

CVE-2026-64245

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-24T16:16:53.917Z and has not been modified since then. The NVD entry is currently Received. This vulnerability affects the Linux kernel, specifically the fbdev modedb component. The vulnerability class is a use-after-free error. The likely operational impact is a potential system crash or code execu [truncated]

MEDIUM Linux CVE published 2026-07-24

CVE-2026-64244

A vulnerability was found in the Linux kernel's handling of memory blocks in the drivers/base/memory module. The vulnerability has been resolved by delaying the assignment of mem->altmap until after __add_memory_block() has succeeded. This change prevents a WARN_ON(mem->altmap) when device_unregister() is called due to __add_memory_block() failure at xa_store(). The issue arises when __add_memory_block() [truncated]

HIGH Linux CVE published 2026-07-24

CVE-2026-64243

A HIGH severity vulnerability was found in the Linux kernel, specifically in the ASoC: codecs: simple-mux component. The vulnerability is related to an incorrect enum control bounds check, which could allow an attacker to store an invalid mux state. This issue has a CVSS score of 7.1 and is classified as HIGH severity. Users of the Linux kernel, particularly those using the ASoC: codecs: simple-mux compon [truncated]

HIGH Linux CVE published 2026-07-24

CVE-2026-64242

A double-free vulnerability was found in the Linux kernel's usb gadget driver for net2280 devices. When the probe function encounters an error, it calls net2280_remove(), which drops the gadget reference with usb_put_gadget(). However, the explicit kfree(dev) call afterwards can free the same object again, leading to a double-free issue. This vulnerability affects Linux kernel versions 5.10 to 5.10.259, 5 [truncated]

MEDIUM Linux CVE published 2026-07-24

CVE-2026-64241

The Linux kernel's gpio: rockchip driver has multiple issues that have been resolved, including a debounce clock reference leak, an unregistered chained IRQ handler, and an IRQ domain leak. These issues can lead to resource leaks and potential local privilege escalation attacks. The CVE record was published on 2026-07-24T16:16:53.443Z and has not been modified since then. The NVD entry is currently Analyz [truncated]

MEDIUM Linux CVE published 2026-07-24

CVE-2026-64240

A vulnerability was found in the Linux kernel's media rc igorplugusb driver. The driver incorrectly passed a pointer to a pointer as the setup packet to usb_fill_control_urb(), leading to the USB core interpreting random memory bytes as the setup packet. This could trigger an invalid bRequestType and a control direction warning. The issue arises from a change in the control request storage from an embedde [truncated]

MEDIUM Linux CVE published 2026-07-24

CVE-2026-64238

A deadlock vulnerability was found in the Linux kernel's gpio shared proxy's parent removal. The issue arises from a wide critical section in the gpio shared code that protects the offset field, potentially leading to a deadlock. The fix involves shortening the critical section to only protect the offset when it's being read. This vulnerability affects Linux kernel users and administrators, who should app [truncated]

HIGH Linux CVE published 2026-07-24

CVE-2026-64237

A Linux kernel vulnerability was resolved, affecting the elan_i2c input module. The vulnerability involves improper validation of firmware size before use, potentially leading to out-of-bounds reads. This issue has significant implications for Linux kernel users and maintainers, who must review and apply patches to prevent potential out-of-bounds reads in the elan_i2c input module. The vulnerability highl [truncated]

MEDIUM Linux CVE published 2026-07-24

CVE-2026-64236

A vulnerability in the Linux kernel's i2c Davinci driver can cause a division by zero when the 'clock-frequency' property is missing from the device tree. The driver incorrectly used a default frequency defined in kHz instead of Hz, leading to a deterministic kernel panic. This issue arises from a mismatch in unit handling, where the fallback frequency was defined in kHz (100) but expected in Hz. The fix [truncated]

HIGH Linux CVE published 2026-07-24

CVE-2026-64235

A HIGH severity vulnerability was found in the Linux kernel, specifically in the x86/ftrace component. The vulnerability is related to the handling of dynamic trampolines and call depth tracking. When CONFIG_CALL_DEPTH_TRACKING is enabled on an x86 retbleed-affected platform, registering a dynamic ftrace trampoline can cause a crash on the first call into the traced function. The crash occurs due to a pag [truncated]

MEDIUM Linux CVE published 2026-07-24

CVE-2026-64234

The CVE-2026-64234 vulnerability in the Linux kernel, classified as a denial of service (DoS) issue with a CVSS score of 5.5 and a severity of MEDIUM, has been addressed by adding a check for dma_alloc_coherent() failure. This change prevents a potential NULL pointer dereference in dma_handle_rx(). The fix involves properly releasing DMA channels and the PCI device reference using a goto ladder if the all [truncated]

MEDIUM Linux CVE published 2026-07-24

CVE-2026-64233

A race condition vulnerability was found in the Linux kernel's USB gadget UVC function. A privileged userspace process could trigger a use-after-free by concurrently modifying the extension units list while binding the gadget UDC. This has been resolved by holding the opts->lock across XU walks in uvc_function_bind. The vulnerability affects Linux kernel versions 6.3 to 7.1rc5. To mitigate, apply patches [truncated]

CRITICAL Linux CVE published 2026-07-24

CVE-2026-64232

A critical vulnerability, CVE-2026-64232, has been resolved in the Linux kernel. The issue arises from improper handling of integrity segments in blk_insert_cloned_request, which can lead to a BUG_ON error upon dispatch. This vulnerability affects Linux kernel-based systems and can be exploited remotely. The vulnerability has a CVSS score of 9.8 and a severity of CRITICAL.

MEDIUM Linux CVE published 2026-07-24

CVE-2026-64231

The Linux kernel has a vulnerability that could allow for out-of-bounds memory access. The issue arises from the drm/msm/dsi module not properly adjusting the size used for memory dumping to account for an internally adjusted IO address space on DSI 6G platforms. This could lead to access past the mapped region. The vulnerability is caused by the drm/msm/dsi module not lowering the ctrl_size by the io_off [truncated]

MEDIUM Linux CVE published 2026-07-24

CVE-2026-64229

The Linux kernel vulnerability CVE-2026-64229 relates to broadcast TLB flush handling when PCID is disabled. This issue can lead to a general protection fault. The vulnerability has been resolved by making X86_FEATURE_INVLPGB dependent on X86_FEATURE_PCID. Linux kernel developers and maintainers, Linux distribution vendors, and users of Linux-based systems, especially those using AMD CPUs that support INV [truncated]

MEDIUM Linux CVE published 2026-07-24

CVE-2026-64228

A vulnerability was found in the Linux kernel's network ethtool phy functionality. When a PHY driver is unbound, the phydev->drv can become NULL while the phy_device remains attached to its net_device. This can cause a NULL dereference when ETHTOOL_MSG_PHY_GET is called. The issue arises from phy_remove() clearing phydev->drv without calling phy_detach().

MEDIUM Linux CVE published 2026-07-24

CVE-2026-64227

A Linux kernel vulnerability, CVE-2026-64227, was resolved by adding checks for ACPI_COMPANION() or ACPI_HANDLE() against NULL in 13 platform drivers handling core ACPI devices. The vulnerability affects Linux kernel deployments and requires verification of affected systems. The vulnerability has a medium defensive priority and requires updates to Linux kernel to the latest version, verification of Linux [truncated]

HIGH Linux CVE published 2026-07-24

CVE-2026-64226

A HIGH severity vulnerability was found in the Linux kernel, with a CVSS score of 7.8. The vulnerability is related to a use-after-free (UAF) issue in the scx_root_enable_workfn() function. This issue arises when put_task_struct() is called before scx_error() dereferences p->comm and p->pid, potentially leading to a UAF error if the iterator's reference is the last drop and the task is freed synchronously.

HIGH Linux CVE published 2026-07-24

CVE-2026-64225

The Linux kernel was vulnerable to an out-of-bounds array access issue in the octeontx2-af CGX component. The cgx_speed_mbps array has 13 elements, but RESP_LINKSTAT_SPEED can yield values from 0 to 15. If a value >= 13 is returned, it causes an out-of-bounds array access. A bounds check has been added, and if the index is out of range, the speed defaults to 0.

HIGH Linux CVE published 2026-07-24

CVE-2026-64224

A double-free vulnerability was found in the Linux kernel's OcteonTX2 representor driver. The vulnerability occurs in the `rvu_rep_rsrc_init()` function, which allocates queue memory before calling `otx2_init_hw_resources()`. If `otx2_init_hw_resources()` fails, it unwinds the partially initialized resources, but the representor error path then calls `otx2_free_hw_resources()` again, leading to a double-f [truncated]

HIGH Linux CVE published 2026-07-24

CVE-2026-64223

A HIGH severity vulnerability was found in the Linux kernel, specifically in the mac80211 component. The vulnerability is related to the consumption of negotiated TTLM maps. The CVE record was published on 2026-07-24T16:16:50.197Z and has not been modified since then. This vulnerability can lead to an out-of-bounds read, which can be detected by KUnit + KASAN with an exact-sized element allocation. The vu [truncated]

HIGH Linux CVE published 2026-07-24

CVE-2026-64222

A HIGH severity vulnerability, CVE-2026-64222, was found in the Linux kernel. The vulnerability is caused by a double free of pool->stack on AQ init failure. This could potentially lead to a denial of service or code execution. The bug was first flagged by an experimental analysis tool and manual inspection confirms that the bug is still present in v7.1-rc3.

HIGH Linux CVE published 2026-07-24

CVE-2026-64221

The Linux kernel vulnerability CVE-2026-64221 has been resolved. The issue was related to the spi: ti-qspi driver, which fell back to PIO mode if DMA setup failed during probe. The patch ensures that the DMA channel pointer is cleared when buffer allocation fails, preventing a use-after-free error. This vulnerability has a CVSS score of 7.8 and is considered HIGH severity. System administrators and users [truncated]

MEDIUM Linux CVE published 2026-07-24

CVE-2026-64220

A vulnerability in the Linux kernel has been resolved. The device property subsystem did not properly initialize the secondary pointer of firmware nodes, which could lead to dereferences of uninitialized memory. This issue affects Linux kernel versions 5.11 through 7.1 rc4 and could potentially cause crashes or code execution. Linux kernel developers, Linux distribution maintainers, and organizations usin [truncated]