PatchSiren

Linux CVE debriefs · Page 60

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM Linux CVE published 2026-07-19

CVE-2026-64143

CVE-2026-64143 is a vulnerability in the Linux kernel related to the uniwill-laptop platform/x86 module. The charging limit feature can permanently damage the battery on some older models (~2020). Users of the Linux kernel should be aware of this vulnerability and take necessary precautions. The CVE record was published on 2026-07-19T16:17:56.243Z and has not been modified since then. This vulnerability h [truncated]

CRITICAL Linux CVE published 2026-07-19

CVE-2026-64142

The Linux kernel was vulnerable to a race condition in the ksmbd_durable_scavenger function, which could lead to use-after-free and list corruption issues. This vulnerability has been resolved by modifying the scavenger to properly handle durable handle expiration and preventing concurrent access to the m_fp_list. The fix involves stopping the reuse of fp->node, taking an explicit transient reference, and [truncated]

HIGH Linux CVE published 2026-07-19

CVE-2026-64141

A null pointer dereference vulnerability exists in ksmbd, a Linux kernel module. The vulnerability occurs when a TCP connection negotiates a fresh session with the same ClientGuid and issues a SMB2 CREATE with a lease context on a different inode. This can cause a kernel panic due to a null pointer dereference. The vulnerability was resolved in the Linux kernel repository. To mitigate this vulnerability, [truncated]

HIGH Linux CVE published 2026-07-19

CVE-2026-64140

A Linux kernel vulnerability, CVE-2026-64140, was resolved to address a null pointer dereference issue in proc_show_files(). The vulnerability arises when a SMB2 client opens a file with a durable v2 handle and then issues SMB2 SESSION_LOGOFF. During session reconnection, the file pointer remains registered in global_ft.idr until the durable scavenger fires. Reading /proc/fs/ksmbd/files during this window [truncated]

MEDIUM Linux CVE published 2026-07-19

CVE-2026-64139

A vulnerability in the Linux kernel's ksmbd module can cause a memory leak due to the improper handling of POSIX ACL entries. When the accumulated DACL size overflows, the code breaks out of the ACE-building loops without freeing the allocated struct smb_sid, leading to a memory leak. This can be exploited by a malicious or malformed file with enough POSIX ACL entries to trip the overflow check, providing [truncated]

HIGH Linux CVE published 2026-07-19

CVE-2026-64138

A vulnerability was found in the Linux kernel, specifically in the ksmbd module, which provides a SMB/CIFS server. The issue has been resolved by introducing a helper function, smb_validate_ntsd_sid(), to safely validate Owner SID and Group SID inside the NT Security Descriptor retrieved from the parent directory. This change helps prevent potential security issues during ACL inheritance. The vulnerabilit [truncated]

HIGH Linux CVE published 2026-07-19

CVE-2026-64137

The Linux kernel vulnerability CVE-2026-64137 requires CAP_NET_ADMIN for CIFS SWN netlink operations to prevent unauthorized local processes from sending notifications or joining multicast groups. This vulnerability affects Linux kernel-based systems, particularly those using CIFS. The intended sender of CIFS_GENL_CMD_SWN_NOTIFY is the cifs.witness helper, but the generic-netlink operation currently has n [truncated]

CRITICAL Linux CVE published 2026-07-19

CVE-2026-64136

A vulnerability in the Linux kernel has been resolved. The smb: client: protect tc_count increment in smb2_find_smb_sess_tcon_unlocked() Commit 96c4af418586 (cifs: Fix locking usage for tcon fields) refactored cifs code to change cifs_tcp_ses_lock for tc_lock around tc_count changes. There was missing lock around tc_count increment inside smb2_find_smb_sess_tcon_unlocked(). This vulnerability may impact t [truncated]

MEDIUM Linux CVE published 2026-07-19

CVE-2026-64135

A Linux kernel vulnerability, CVE-2026-64135, was resolved by widening the blackbox-info buffer to I2C_SMBUS_BLOCK_MAX. The hwmon: (pmbus/adm1266) driver had a 5-byte stack buffer that was passed to i2c_smbus_read_block_data() to retrieve the 4-byte BLACKBOX_INFO response. However, i2c_smbus_read_block_data() does not honor caller buffer sizes and can overflow the buffer if the device returns a block leng [truncated]

HIGH Linux CVE published 2026-07-19

CVE-2026-64134

A Linux kernel vulnerability, CVE-2026-64134, was resolved in the ALSA: pcm component. The bug involved a bogus iov_iter setup for silencing, leading to a NULL dereference on RISC-V architectures. This issue was addressed by handling the NULL data case in interleaved_copy(). The vulnerability has a medium defensive priority, and Linux kernel maintainers, developers, and users who rely on the ALSA: pcm com [truncated]

HIGH Linux CVE published 2026-07-19

CVE-2026-64133

A potential OOB array access vulnerability was found in the Linux kernel's ALSA asihpi component. The vulnerability is caused by the find_control() function accessing the array with the given index blindly, which may lead to an OOB array access. A sanity check has been added to prevent this. This vulnerability can be exploited by an attacker to potentially execute arbitrary code or cause a denial of servi [truncated]

CRITICAL Linux CVE published 2026-07-19

CVE-2026-64132

A use-after-free vulnerability was found in the Linux kernel's IPv6 IOAM (In-Situ OAM) implementation. The issue arises from the failure to refresh the hdr pointer after skb_ensure_writable() is called, which may reallocate the skb's data buffer and invalidate existing pointers. This vulnerability can lead to a use-after-free condition when hdr->opt_len is passed to ioam6_event(). The affected product is [truncated]

MEDIUM Linux CVE published 2026-07-19

CVE-2026-64131

A Linux kernel vulnerability was resolved, addressing a spurious warning when unmapping device-private/exclusive pages. The issue arose from incorrect usage of vma_is_anonymous() in the unmap path, leading to warnings during process teardown. This vulnerability affects Linux kernel developers, administrators, and users of Linux-based systems. The issue was resolved by ensuring proper checks for anonymous folios.

MEDIUM Linux CVE published 2026-07-19

CVE-2026-64130

A Linux kernel vulnerability, CVE-2026-64130, was resolved by decoupling __GFP_ZEROTAGS from __GFP_ZERO to fix initialization of tags of the huge zero folio with init_on_free. The vulnerability affects the Linux kernel and could potentially expose uninitialized tags. The fix ensures that tags are properly initialized for the huge zero folio. Linux kernel developers and maintainers, as well as users of Lin [truncated]

MEDIUM Linux CVE published 2026-07-19

CVE-2026-64129

A spinlock leak vulnerability was found in the Linux kernel's migrate_vma_insert_huge_pmd_page function. When check_stable_address_space() fails after acquiring the PMD spinlock, the code jumps to the abort label, bypassing the spin_unlock() call, causing a deadlock. The issue was resolved by changing the goto target from abort to unlock_abort to ensure the spinlock is always released on this error path. [truncated]

MEDIUM Linux CVE published 2026-07-19

CVE-2026-64128

A Linux kernel vulnerability was resolved, affecting Bluetooth ISO functionality. The issue involves handling ISO_END frames without prior ISO_START frames, potentially causing a crash. This debrief provides an overview of CVE-2026-64128, its technical details, and defensive recommendations. The vulnerability is related to the Linux kernel's Bluetooth ISO implementation, which did not properly handle ISO_ [truncated]

MEDIUM Linux CVE published 2026-07-19

CVE-2026-64127

A vulnerability was found in the Linux kernel's Bluetooth L2CAP ecred_reconfigure feature. The issue arises from a commit that converted an on-stack request PDU to a packed struct, but did not adjust the size and source-pointer arguments to l2cap_send_cmd(). This leads to the transmission of 8 bytes from the kernel stack, leaking a kernel stack address to the paired Bluetooth peer. The intended fields are [truncated]

HIGH Linux CVE published 2026-07-19

CVE-2026-64126

A Linux kernel Bluetooth MGMT vulnerability allows for out-of-bounds data access. The issue arises from the MGMT_OP_ADD_EXT_ADV_DATA command, which is registered as variable-length but fails to validate its length properly. This can lead to slab-out-of-bounds reads and potentially allow attackers to read sensitive data. The vulnerability requires CAP_NET_ADMIN in the initial user namespace. The impact of [truncated]

CRITICAL Linux CVE published 2026-07-19

CVE-2026-64125

The Linux kernel was vulnerable to a bug in the bcmgenet driver that could cause RX traffic to stop flowing while the link stays up. This issue has been resolved. The vulnerability affected the GENET hardware and was triggered when MAC EEE became active. The fix ensures that RBUF_EEE_EN and RBUF_PM_EN remain disabled across resets, preventing the RX path from breaking.

HIGH Linux CVE published 2026-07-19

CVE-2026-64124

The Linux kernel has a vulnerability, CVE-2026-64124, that has been resolved. The vulnerability was in the net: devmem component, where dma-buf bind was not properly checked for page-aligned size or SG length. This could lead to out-of-bounds reads and desyncs between num_niovs and the gen_pool region. The issue has been addressed by rejecting such binds with -EINVAL.

HIGH Linux CVE published 2026-07-19

CVE-2026-64123

The Linux kernel was vulnerable to a use-after-free issue in the HSR node table. When HSR node-list and node-status generic-netlink operations ran under rcu_read_lock(), they could hold a struct hsr_node pointer across hsr_dellink(), leading to a slab-use-after-free when the reader copied node->macaddress_A. The issue was resolved by deferring the node table free until after RCU readers using list_del_rcu [truncated]

CRITICAL Linux CVE published 2026-07-19

CVE-2026-64122

CVE-2026-64122 is a use-after-free vulnerability in the Linux kernel's mlx5e_tx_reporter_timeout_recover function. The vulnerability occurs when the function accesses sq->netdev after mlx5e_safe_reopen_channels() has torn down and freed the channel. This can cause a KASAN splat, indicating a use-after-free error. Linux kernel users and administrators should be aware of this vulnerability and take steps to [truncated]

HIGH Linux CVE published 2026-07-19

CVE-2026-64121

The Linux kernel was vulnerable to a slab-out-of-bounds read issue. The vulnerability was in the ifb (Intermediate Functional Block) network device driver. The ifb_dev_init() function allocated memory for tx_private based on the number of transmit queues (num_tx_queues). However, the ethtool stats callbacks used real_num_rx_queues and real_num_tx_queues, which could be different from num_tx_queues for asy [truncated]

MEDIUM Linux CVE published 2026-07-19

CVE-2026-64120

A Linux kernel vulnerability, CVE-2026-64120, was resolved, involving a NULL pointer dereference in phy_reply_size due to unchecked kstrdup() failures in phy_prepare_data(). The fix requires adding proper NULL checks for all kstrdup() calls and implementing a centralized error handling path. Linux kernel maintainers and users, as well as vulnerability researchers, should review and apply the fix. The vuln [truncated]

MEDIUM Linux CVE published 2026-07-19

CVE-2026-64119

The Linux kernel vulnerability CVE-2026-64119 is a use-after-free issue in the l2tp_session_unhash function. An unprivileged local user can cause a host CPU to be indefinitely pinned by issuing specific L2TP commands concurrently. This vulnerability is due to the use of list_del_init in l2tp_session_unhash, which leaves the deleted entry's next/prev pointers self-pointing. As a result, list_for_each_entry [truncated]

HIGH Linux CVE published 2026-07-19

CVE-2026-64118

A vulnerability in the Linux kernel has been resolved. The issue, identified as CVE-2026-64118, relates to a double free in the qed_cxt_tables_alloc() function. If one of the later PF or VF CID bitmap allocations fails, qed_cid_map_alloc() jumps to cid_map_fail and frees the previously allocated CID bitmaps before returning an error. Subsequently, qed_cxt_tables_alloc() calls qed_cxt_mngr_free(), which in [truncated]

HIGH Linux CVE published 2026-07-19

CVE-2026-64117

The Linux kernel was vulnerable to a use-after-free condition in the mac80211 subsystem. The vulnerability occurred when the ieee80211_invoke_fast_rx() function read RX status through IEEE80211_SKB_RXCB(skb), which aliases the same skb->cb storage that ieee80211_rx_mesh_data() reuses as IEEE80211_TX_INFO. This could lead to a KASAN slab-use-after-free in ieee80211_prepare_and_rx_handle. The vulnerability [truncated]

HIGH Linux CVE published 2026-07-19

CVE-2026-64116

A vulnerability has been resolved in the Linux kernel, specifically in the ipv6_hop_ioam() function. The function accesses __in6_dev_get(skb->dev)->cnf.ioam6_enabled without validating the returned idev pointer, which can lead to a NULL pointer dereference during interface teardown. This vulnerability affects users of the Linux kernel who should be aware and take necessary precautions. The vulnerability h [truncated]

HIGH Linux CVE published 2026-07-19

CVE-2026-64115

The Linux kernel CVE-2026-64115 vulnerability has been resolved. The issue was related to a use-after-free (UAF) condition in the vsock/vmci connection handshake process. A patch has been applied to treat peer RST like any other unexpected packet type, returning an error and preventing the UAF condition. This change ensures that the pending socket is removed from the listener's pending_links synchronously [truncated]

HIGH Linux CVE published 2026-07-19

CVE-2026-64114

The Linux kernel vulnerability CVE-2026-64114 allows for an out-of-bounds access due to a malformed IPv4 header with an Internet Header Length (ihl) less than 5. This can cause a host kernel panic when the packet is processed. The vulnerability is reachable by any caller with CAP_NET_RAW, including an unprivileged process in a user+net namespace on a kernel with CONFIG_USER_NS=y. The vulnerability has a h [truncated]