PatchSiren

Linux CVE debriefs · Page 59

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM Linux CVE published 2026-07-19

CVE-2026-64174

A Linux kernel vulnerability was resolved in cfg80211_merge_profile(), part of the wifi: cfg80211 module. The vulnerability allowed a specially-crafted malicious beacon to cause excessive time spent in cfg80211_merge_profile(). This could potentially lead to denial-of-service (DoS) attacks. Linux kernel maintainers, Linux distribution vendors, and users of Linux-based systems should be aware of this vulne [truncated]

MEDIUM Linux CVE published 2026-07-19

CVE-2026-64173

A vulnerability in the Linux kernel has been resolved. The issue involves the tracing subsystem, specifically the handling of memory allocation failures for tracing map elements. This vulnerability affects Linux kernel developers and maintainers, Linux distribution vendors, and users of Linux-based systems who apply kernel updates. The issue has been resolved in the kernel, and users should review and app [truncated]

HIGH Linux CVE published 2026-07-19

CVE-2026-64172

The Linux kernel's KVM: SVM has a vulnerability affecting Hygon Family 18h CPUs, which are derived from AMD Family 17h silicon. The erratum #1235 causes hardware to read a stale IsRunning=1 bit during ICR write emulation, leading to a failure in generating an AVIC_IPI_FAILURE_TARGET_NOT_RUNNING VM-Exit on the sending vCPU. This results in KVM missing the required wakeup of blocking target vCPUs, causing h [truncated]

MEDIUM Linux CVE published 2026-07-19

CVE-2026-64171

The Linux kernel was found to have a vulnerability in the i2c: tegra component. A patch has been applied to fix a pm_runtime leak on mutex_lock failure. If tegra_i2c_mutex_lock() fails, the function returns without calling pm_runtime_put(), causing a runtime PM reference leak. This prevents the device from entering runtime suspend. The vulnerability has a medium defensive priority, and Linux kernel users [truncated]

MEDIUM Linux CVE published 2026-07-19

CVE-2026-64170

The Linux kernel was found to have a vulnerability in the spi: qup driver. The issue arises when DMA setup fails during probe, and the driver falls back to PIO mode. However, the DMA channel pointers are not cleared on setup failure, which can lead to dereferencing an error pointer or attempting to release a channel a second time on later probe errors or driver unbind. This vulnerability affects Linux ker [truncated]

MEDIUM Linux CVE published 2026-07-19

CVE-2026-64169

The Linux kernel was vulnerable to an error pointer dereference issue in the spi: ep93xx driver. The driver would fall back to PIO mode if DMA setup failed during probe, but failed to clear DMA channel pointers, potentially leading to errors on later probe attempts or driver unbind. The issue was resolved by ensuring DMA channel pointers are cleared in case of setup failure. This vulnerability affects Lin [truncated]

MEDIUM Linux CVE published 2026-07-19

CVE-2026-64168

The Linux kernel was found to have a vulnerability in the spi: sprd driver. The issue arises when DMA setup fails during probe, and the driver falls back to PIO mode. However, the driver did not properly handle the dma.enabled flag, leading to potential error pointer dereference or attempting to release a DMA channel a second time. This vulnerability has been resolved through a series of commits.

MEDIUM Linux CVE published 2026-07-19

CVE-2026-64167

The Linux kernel vulnerability CVE-2026-64167 has been resolved by skipping KHO for crash kernel. The vulnerability was caused by kho_fill_kimage() unconditionally populating the kimage with KHO metadata for every kexec image type, which can be problematic for crash kernels. This can cause issues as crash kernels run in a small reserved region and the KHO scratch areas can sit outside it, leading to fault [truncated]

MEDIUM Linux CVE published 2026-07-19

CVE-2026-64166

A vulnerability in the Linux kernel has been resolved. The firmware: arm_ffa: Check for NULL FF-A ID table while driver registration. The bus match callback assumes that every FF-A driver provides an id_table and dereferences it unconditionally. Enforce that contract at registration time so a buggy client driver cannot crash the bus during match. This vulnerability affects users of the Linux kernel who sh [truncated]

MEDIUM Linux CVE published 2026-07-19

CVE-2026-64165

A Linux kernel vulnerability, CVE-2026-64165, was resolved by moving early initialization code into standard machine initialization to prevent crashes due to memory management subsystem not being initialized. This vulnerability affects Linux kernel users, particularly those using ARM Integrator/CP devices. The vulnerability was caused by a call to syscon_regmap_lookup_by_compatible in intcp_init_early, wh [truncated]

MEDIUM Linux CVE published 2026-07-19

CVE-2026-64163

A vulnerability in the Linux kernel has been resolved. The kprobes sanity tests fail and eventually crash the kernel when run twice due to leftover data from previous test runs. The tests define several kprobes and kretprobes as static variables that are preserved across test runs. After register_kprobe and unregister_kprobe, a kprobe contains some leftover data that must be cleared before the kprobe can [truncated]

CRITICAL Linux CVE published 2026-07-19

CVE-2026-64162

A vulnerability was found in the Linux kernel. The idpf: fix read_dev_clk_lock spinlock init in idpf_ptp_init() vulnerability has been resolved. In idpf_ptp_init(), read_dev_clk_lock is initialized after ptp_schedule_worker() had already been called (and after idpf_ptp_settime64() could reach the lock). The PTP aux worker fires immediately upon scheduling and can call into idpf_ptp_read_src_clk_reg_direct [truncated]

MEDIUM Linux CVE published 2026-07-19

CVE-2026-64161

A Linux kernel vulnerability was addressed in the net: ti: icssm-prueth driver. The issue involved a potential eth_ports_node leak in the probe function. The error path on of_property_read_u32() failure inside icssm_prueth_probe() returned without putting eth_ports_node, which was acquired before the for_each_child_of_node() loop. This vulnerability affects Linux kernel users and administrators, who shoul [truncated]

CRITICAL Linux CVE published 2026-07-19

CVE-2026-64160

The Linux kernel has a vulnerability that could potentially allow for tearing in ->remote_i_size and ->zero_point. This issue has been resolved by copying i_size_read() and i_size_write() and using the same seqcount as for i_size. The vulnerability affects Linux kernel users and administrators, who should be aware of this issue and take necessary precautions. The fix involves updating Linux kernel to the [truncated]

MEDIUM Linux CVE published 2026-07-19

CVE-2026-64159

The Linux kernel was vulnerable to an issue in the netfs module, which could allow for incorrect updates to the zero point in netfs_release_folio() when there is uncommitted data in the pagecache beyond the folio being released but the on-server EOF is in this folio. This could lead to read-gaps on folio failing with a short read if the FMODE_READ check is commented out in netfs_perform_write(). The fix a [truncated]

HIGH Linux CVE published 2026-07-19

CVE-2026-64158

A Linux kernel vulnerability, CVE-2026-64158, was resolved, involving netfs performance optimization, write streaming, which was being disabled under certain conditions, including when a file descriptor was opened with O_RDWR. The fix removes the O_RDWR check, allowing streaming writes even when reading might occur. This change addresses issues with xfstest generic/522 and ensures optimal performance in s [truncated]

MEDIUM Linux CVE published 2026-07-19

CVE-2026-64157

A Linux kernel vulnerability, CVE-2026-64157, was resolved. The issue was with the netfs_invalidate_folio() function, which incorrectly modified the dirty region of a streaming-write page during partial invalidation. This could lead to data integrity issues if not properly patched. Linux kernel users and maintainers should review and apply patches.

MEDIUM Linux CVE published 2026-07-19

CVE-2026-64156

A vulnerability was found in the Linux kernel's netfs and afs components. The issue is related to write skipping in dir/link writepages. The fix involves modifying netfs_write_single() and afs_single_writepages() to better handle skipped writes due to lock contention and WB_SYNC_NONE. This change ensures that if a skip occurs, the inode is re-marked as the VFS may have cleared the mark. The vulnerability [truncated]

MEDIUM Linux CVE published 2026-07-19

CVE-2026-64155

A vulnerability was found in the Linux kernel's ath11k component. The issue involves error path leaks in certain WMI WOW calls. Specifically, the code did not properly handle return values from ath11k_wmi_cmd_send, leading to potential memory leaks in error scenarios. This vulnerability has been resolved through kernel updates. The affected product is the Linux kernel, and the vulnerability class is relat [truncated]

MEDIUM Linux CVE published 2026-07-19

CVE-2026-64154

A reference leak vulnerability was found in the Linux kernel's drm/msm/adreno component. The vulnerability is due to a missing of_node_put() call in the a6xx_gpu_init() function, which can cause a reference leak when an error occurs. This issue can potentially lead to a denial of service. The vulnerability can be mitigated by applying the patch provided by the Linux kernel community. Affected Linux kernel [truncated]

HIGH Linux CVE published 2026-07-19

CVE-2026-64153

A Linux kernel vulnerability, CVE-2026-64153, was resolved by fixing the iommu_map_sgtable() return value check to avoid incorrect warnings. The patch changes the handling of negative return values in error cases. This fix impacts Linux kernel users and maintainers who should review and apply the patch to prevent potential issues. The vulnerability has a high severity score and requires immediate attention.

HIGH Linux CVE published 2026-07-19

CVE-2026-64152

A vulnerability was found in the Linux kernel's iommu. When iommu_debug is enabled, an unmap error occurs. The issue arises from the map error flow calling iommu_unmap(), which in turn calls iommu_debug_unmap_begin()/iommu_debug_unmap_end(). However, since this is an error path and the map flow never established the original iommu_debug_map(), it malfunctions. To address this, the unmap error handling was [truncated]

HIGH Linux CVE published 2026-07-19

CVE-2026-64151

The Linux kernel was found to have a vulnerability related to the iommupt driver, specifically involving checking for missing PAGE_SIZE in the pgsize_bitmap. This vulnerability has been resolved with a patch that lifts the PT_WARN_ON to the if branch and skips the fast path. The issue could potentially affect Linux kernel users and administrators, as it relates to the handling of page sizes in the iommu d [truncated]

CRITICAL Linux CVE published 2026-07-19

CVE-2026-64150

The Linux kernel has a vulnerability that has been resolved in netfilter: nft_inner: release local_lock before re-enabling softirqs. In the error path, local_bh_enable() is called before local_unlock_nested_bh(). This vulnerability affects Linux kernel users and administrators, who should review their systems for potential impact. The issue involves the nft_inner module, where a local_lock is not released [truncated]

MEDIUM Linux CVE published 2026-07-19

CVE-2026-64149

A Linux kernel vulnerability, CVE-2026-64149, was resolved by moving the dma_map_resource() sanity check into debug code to prevent false positives for MMIO regions. The check was using pfn_valid(), which does not ensure that a PFN is backed by RAM, causing a WARNING on Raspberry Pi 4 during spi_bcm2835 probe. This change affects users of Linux kernel, particularly those using ARM64 with SPARSEMEM and Ras [truncated]

HIGH Linux CVE published 2026-07-19

CVE-2026-64148

The Linux kernel was vulnerable to an error handling issue in the pds_core module, specifically in the pdsc_devcmd_wait function. This function could return stale success status instead of an error in two scenarios: when the firmware crashes and when a command times out. The issue has been resolved by checking the running status first and returning -ENXIO in case of a firmware crash, and by returning -ETI [truncated]

MEDIUM Linux CVE published 2026-07-19

CVE-2026-64147

A Linux kernel vulnerability, CVE-2026-64147, was resolved in pds_core, addressing a debugfs_lookup dentry leak and error handling issue. This vulnerability affects Linux kernel users and administrators, who should be aware of the potential impact on their systems. The vulnerability has a medium defensive priority, and defenders should review the official CVE record and NVD entry for more information.

MEDIUM Linux CVE published 2026-07-19

CVE-2026-64146

A Linux kernel vulnerability, CVE-2026-64146, was found in the erofs module. The issue arises from a metabuf leak during inode xattr initialization. This vulnerability was resolved by consolidating cleanup at out_unlock in the erofs_init_inode_xattrs function. The vulnerability affects Linux kernel users and administrators, who should ensure their systems are updated with the latest kernel patches. The ex [truncated]

HIGH Linux CVE published 2026-07-19

CVE-2026-64145

A vulnerability was found in the Linux kernel's wilc1000 wifi driver. The issue occurs when the wilc_wlan_firmware_download() function fails to free a dma_buffer on early bus acquire failure, leading to a potential memory leak. This vulnerability has been resolved, but the exact impact and affected systems are not clearly stated. Linux kernel developers and users, especially those using the wilc1000 wifi [truncated]

MEDIUM Linux CVE published 2026-07-19

CVE-2026-64144

A Linux kernel vulnerability was resolved in the Bluetooth btmtk component. The issue involves a potential urb->setup_packet leak in error paths. Specifically, the setup_packet of the control urb is not freed if usb_submit_urb fails or the submitted urb is killed. A fix was added to free the setup_packet in these two error paths. This vulnerability affects Linux kernel maintainers and users, Bluetooth com [truncated]