PatchSiren

Linux CVE debriefs · Page 58

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH Linux CVE published 2026-07-24

CVE-2026-64219

A high-severity vulnerability, CVE-2026-64219, was found in the Linux kernel. The issue involves a stack buffer overflow and out-of-bounds access in the dc_process_dmub_aux_transfer_async function. This function improperly validates payload length and link_index, potentially leading to a stack buffer overflow via memcpy and an out-of-bounds access. To address this, a runtime check was added to ensure payl [truncated]

HIGH Linux CVE published 2026-07-24

CVE-2026-64218

The Linux kernel has a vulnerability in the batman-adv module, specifically in the bla component, which can lead to a use-after-free vulnerability. This vulnerability is related to a report_work leak on backbone_gw purge. The vulnerability has a HIGH CVSS score of 7.8. Users of Linux kernel with batman-adv module enabled should be aware of this vulnerability and review the official advisory for affected s [truncated]

HIGH Linux CVE published 2026-07-24

CVE-2026-64217

A HIGH severity vulnerability was found in the Linux kernel, with a CVSS score of 7.8. The vulnerability is related to the netfs: Fix overrun check in netfs_extract_user_iter() function. This issue can lead to memory corruption if iov_iter_extract_pages() overfills pages[], potentially allowing for arbitrary code execution. Linux kernel users and administrators should be aware of this vulnerability and ta [truncated]

CRITICAL Linux CVE published 2026-07-24

CVE-2026-64216

A vulnerability has been identified in the Linux kernel, specifically in the netfs_unlock_abandoned_read_pages() function. This function accesses the index of folios it wants to unlock and compares it to rreq->no_unlock_folio to prevent unlocking a folio being read for netfs_perform_write() or netfs_write_begin(). However, since netfs_unlock_abandoned_read_pages() is called after NETFS_RREQ_IN_PROGRESS is [truncated]

MEDIUM Linux CVE published 2026-07-24

CVE-2026-64215

The Linux kernel was vulnerable to a NULL pointer dereference in the drm/msm/a6xx component. The vulnerability, now resolved, was caused by not checking the return value of kzalloc() in the a8xx_hfi_send_perf_table function. This issue could lead to a system crash or potential code execution if exploited. Linux kernel developers and administrators should verify their systems for potential exposure and app [truncated]

MEDIUM Linux CVE published 2026-07-24

CVE-2026-64214

A kernel panic occurs when handling machine check exceptions from real mode due to accessing preempt_count in arch_irq_work_raise(). The crash is caused by redundant preempt_disable|enable() calls in arch_irq_work_raise(). This issue arises from a combination of factors, including exception handling in real mode and race conditions while raising irq work. The panic can be resolved by removing these redund [truncated]

MEDIUM Linux CVE published 2026-07-24

CVE-2026-64213

A concurrency issue in the Linux kernel's hwmon lm90 driver can cause an interrupt storm when an alert interrupt occurs concurrently with a sysfs write operation. This issue arises because lm90_alert() executes in the smbus alert context and calls lm90_update_confreg() to disable the hardware alert line without acquiring hwmon_lock. Concurrently, sysfs write operations hold hwmon_lock, temporarily modify [truncated]

MEDIUM Linux CVE published 2026-07-24

CVE-2026-64211

The Linux kernel vulnerability CVE-2026-64211 relates to the SRCU (srcu) implementation, specifically how it handles workqueue handlers on CPUs that have never been online. This can cause system hangs, particularly on s390 systems. The fix involves preventing the queuing of workqueue handlers on CPUs that have not yet come online. The vulnerability was resolved through kernel updates. System administrator [truncated]

HIGH Linux CVE published 2026-07-24

CVE-2026-64210

A vulnerability in the Linux kernel's net/mlx5e: xsk component allows for an unlocked write to ICOSQ, potentially leading to a high severity issue. The vulnerability was introduced due to a race condition when triggering an ICOSQ interrupt on a new CPU during affinity changes. This can cause errors in the ICOSQ CQE. The issue was noticed in the wild with a splat indicating a Bad OP in ICOSQ CQE and an Err [truncated]

HIGH Linux CVE published 2026-07-23

CVE-2026-64600

A vulnerability in the Linux kernel's xfs resample data fork mapping has been resolved. The issue arises from the xfs_reflink_fill_cow_hole and xfs_reflink_fill_delalloc functions, which cycle the ILOCK to grab a transaction, causing the mappings to become stale. This leads to inaccurate values being returned in *shared, potentially allowing directio writes to proceed with a stale data fork mapping. The a [truncated]

MEDIUM Linux CVE published 2026-07-20

CVE-2026-64207

A vulnerability in the Linux kernel's net/sched component has been addressed. The DualPI2 qdisc does not properly account for GSO backlog, leading to a potential NULL pointer dereference in QFQ's qfq_choose_next_agg() and qfq_dequeue(). This issue affects Linux kernel developers, administrators, and users of Linux-based systems. The vulnerability has a medium severity and could allow for denial of service [truncated]

HIGH Linux CVE published 2026-07-20

CVE-2026-64206

CVE-2026-64206 is a HIGH severity Linux kernel vulnerability affecting Bluetooth L2CAP. The vulnerability was resolved by reordering locking and work cancellation in l2cap_conn_del(). This change prevents a potential deadlock between l2cap_conn_del() and process_pending_rx(). The issue was found by static analysis tool and manually reviewed against the current tree.

MEDIUM Linux CVE published 2026-07-20

CVE-2026-64192

The Linux kernel vulnerability, CVE-2026-64192, arises from the BPF LSM not being explicitly enabled at boot time when CONFIG_BPF_LSM=y is set. This leads to an uninitialized BPF inode security blob offset, causing issues with BPF_MAP_TYPE_INODE_STORAGE map creation and updates, potentially resulting in a kernel panic. System administrators and users running Linux kernels with BPF LSM enabled but not expl [truncated]

HIGH Linux CVE published 2026-07-20

CVE-2026-64191

A local user with access to /dev/i2c-* can exploit CVE-2026-64191, a HIGH severity vulnerability in the Linux kernel I2C stub, to cause a stack-out-of-bounds read or write. The bug exists because i2c-stub implements .smbus_xfer directly, bypassing I2C_SMBUS_BLOCK_MAX validation. This vulnerability can be mitigated by rejecting transfers with invalid length. Users running Linux kernel with I2C stub enabled [truncated]

MEDIUM Linux CVE published 2026-07-20

CVE-2026-64190

A race condition vulnerability was found in the Linux kernel's team device driver. The bug occurs when a mode change is concurrent with transmit on the team device, leading to a NULL pointer dereference and a potential kernel crash. The vulnerability requires CAP_NET_ADMIN privileges to exploit. This issue arises from a race between team_xmit() and __team_change_mode(), where the latter clears team->ops, [truncated]

HIGH Linux CVE published 2026-07-20

CVE-2026-64189

A use-after-free vulnerability was found in the Linux kernel's netfilter ipset subsystem. The vulnerability occurs when the dump path reads the array outside any RCU reader, allowing a concurrent ip_set_create() to grow the array, publish the new array, call synchronize_net(), and then kvfree() the old one. This can cause a use-after-free when the dump paths still index into the old array. The vulnerabili [truncated]

HIGH Linux CVE published 2026-07-20

CVE-2026-64188

A use-after-free vulnerability was discovered in the Linux kernel's rmnet module. The rmnet_dellink() function removes an endpoint from the hash table and immediately frees it, but RCU readers on the receive path may still hold a reference to the endpoint and dereference it after the memory has been freed. This issue can lead to a crash or potentially allow an attacker to execute arbitrary code. The vulne [truncated]

MEDIUM Linux CVE published 2026-07-20

CVE-2026-64187

A vulnerability was found in the Linux kernel's XFS file system. The issue occurs when a crafted log item with no regions is committed, causing a null pointer dereference during recovery. This happens when the first operation of a transaction is a bare transaction header with no regions added. The commit handlers and reordering logic read the item's buffer, which is null, leading to a fault.

HIGH Linux CVE published 2026-07-19

CVE-2026-64186

The Linux kernel was found to have a latent out-of-bounds access vulnerability in the IOMMU debugfs. This was due to the use of kstrtou32_from_user() which could result in a negative integer being used as an offset. The vulnerability has been resolved by replacing kstrtou32_from_user() with kstrtos32_from_user() and adding checks for negative values. The AMD IOMMU debugfs implementation was vulnerable to [truncated]

MEDIUM Linux CVE published 2026-07-19

CVE-2026-64185

A vulnerability in the Linux kernel has been resolved. The issue occurs when sysfs_update_group() is called for a named group and create_files() fails, causing internal_create_group() to remove the group directory. This can lead to the silent destruction of a sysfs group that the caller did not create. The directory remains empty after remove_files() is called inside create_files(), but can be repopulated [truncated]

MEDIUM Linux CVE published 2026-07-19

CVE-2026-64184

A Linux kernel vulnerability, CVE-2026-64184, was resolved by addressing a reference leak in damon_sysfs_memcg_path_to_id(). The issue was discovered and fixed by calling mem_cgroup_iter_break() before breaking the mem_cgroup_iter() loop. This vulnerability affects Linux kernel users and maintainers, who should assess and apply the fix to prevent potential reference leaks. The vulnerability has a medium p [truncated]

MEDIUM Linux CVE published 2026-07-19

CVE-2026-64183

The Linux kernel has been updated to address a vulnerability where ACPI PRM calls could occur before the EFI runtime workqueue was allocated, leading to NULL pointer dereferences. This was resolved by splitting off the workqueue allocation into its own postcore initcall. The update ensures that EFI runtime calls, including PRM calls, are accessible to all code running at subsys_initcall() level. System ad [truncated]

MEDIUM Linux CVE published 2026-07-19

CVE-2026-64182

A Linux kernel vulnerability, CVE-2026-64182, was found in the drivers/base/memory module. The vulnerability causes a memory block reference leak in poison accounting due to memblk_nr_poison_inc() and memblk_nr_poison_sub() not dropping references to the memory block device after lookup. This issue can potentially lead to memory leaks and denial-of-service attacks. Linux kernel maintainers, Linux distribu [truncated]

HIGH Linux CVE published 2026-07-19

CVE-2026-64181

The Linux kernel vulnerability CVE-2026-64181 relates to the handling of missing support for pmd_special()/pud_special() in the __vm_normal_page() function. This issue can cause warnings and bugs when reclaim calls shrink_huge_zero_folio_scan(). The problem was exposed through a specific commit and is related to CONFIG_ARCH_SUPPORTS_PMD_PFNMAP, which is never enabled on any 32-bit architecture. Affected p [truncated]

MEDIUM Linux CVE published 2026-07-19

CVE-2026-64180

A Linux kernel vulnerability, CVE-2026-64180, was found in the memory_hotplug module. The issue causes a memory block reference leak when removing memory blocks and their altmaps. This occurs because the remove_memory_blocks_and_altmaps() function looks up each memory block using find_memory_block(), acquiring a reference to the memory block device. However, this reference is never dropped, resulting in a [truncated]

MEDIUM Linux CVE published 2026-07-19

CVE-2026-64179

A potential memory leak vulnerability was found in the Linux kernel's wwan iosm ipc_imem_init() function. The CVE record was published on 2026-07-19T16:18:00.277Z and has not been modified since then. The vulnerability is caused by the memory allocated in ipc_protocol_init() not being freed on error paths. Linux kernel users and administrators should review and apply patches for this vulnerability. The vu [truncated]

HIGH Linux CVE published 2026-07-19

CVE-2026-64178

A use-after-free (UAF) vulnerability was found in the Linux kernel's Bluetooth bnep module. The bnep_add_connection() function did not properly synchronize access to the dev->name field, allowing a concurrent bnep_del_connection() thread to free the net_device. This issue requires CAP_NET_ADMIN capability and a tight race window, making it difficult to exploit. The vulnerability has limited security impac [truncated]

MEDIUM Linux CVE published 2026-07-19

CVE-2026-64177

A Linux kernel vulnerability, CVE-2026-64177, was resolved by disabling bottom halves (BH) around forwarded sk_receive_skb() to prevent inconsistent lock state and potential self-deadlock. This fix addresses a critical issue in the Linux kernel's networking receive path, ensuring the stability and security of affected systems. Linux kernel users and maintainers should be aware of this vulnerability and en [truncated]

HIGH Linux CVE published 2026-07-19

CVE-2026-64176

The Linux kernel vulnerability CVE-2026-64176 was resolved in the wifi: iwlwifi: mvm: fix driver-set TX rates on old devices. This fix addresses an issue with TX rates being set incorrectly on old devices such as 7265D, potentially causing warnings when reported back from the device as having been used. The vulnerability was caused by a change in the iwlwifi driver that led to incorrect TX rates being set [truncated]

HIGH Linux CVE published 2026-07-19

CVE-2026-64175

A Linux kernel vulnerability, CVE-2026-64175, was resolved to address a firmware crash issue in iwlwifi. The vulnerability caused a tight dequeue-send-fail-free loop under high-throughput conditions, leading to CPU cycle waste and memory pressure from slab fragmentation. The fix adds a guard to stop all TX during firmware restart, similar to existing guards in the RX path and TXQ allocation worker. This c [truncated]