These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.
A use-after-free vulnerability was found in the Linux kernel's ixgbevf driver. The vulnerability occurs when the driver prunes frames whose source MAC matches the VF's own address, leading to a use-after-free in NAPI softirq context. This issue arises from the skb pointer being declared outside the while loop and persisting across iterations. When the skb is freed and the loop continues, the next iteratio [truncated]
A race condition vulnerability was found in the Linux kernel's rbd (RADOS Block Device) module. The vulnerability occurs when the lock_dwork task is canceled and requeued, potentially leading to unexpected behavior after the image is unmapped. This could result in a use-after-free error, causing the system to crash or potentially execute arbitrary code. The vulnerability can be triggered when a new I/O re [truncated]
A Linux kernel vulnerability, CVE-2026-64111, has been resolved. The issue involves holding cred_guard_mutex for lsm_set_self_attr() to address a security concern related to synchronization and potential race conditions in the Linux Security Module (LSM) functionality. This change ensures proper synchronization and prevents potential security issues. System administrators and security teams should review [truncated]
A potential skb leak has been resolved in the Linux kernel's igc driver. The vulnerability occurred when igc_fpe_init_tx_descriptor() failed, causing an allocated skb to be leaked. This issue has been addressed by using dev_kfree_skb_any() on failure. The vulnerability affects the Linux kernel's igc driver, which is used for Intel Ethernet controllers. The vulnerability class is related to memory leaks, a [truncated]
A use-after-free (UAF) vulnerability was found in the Linux kernel's af_unix component. The unix_stream_data_wait() function does not hold a lock that prevents SKBs on the sk_receive_queue from being dequeued and freed, leading to a potential UAF read of tail->len. This issue was introduced in commit 79f632c71bea and has been fixed by removing the read of tail->len. The fix is not suitable for kernels bef [truncated]
A null-ptr dereference vulnerability exists in the Linux kernel ASoC codecs pcm512x driver. The pcm512x_overclock_xxx_put() function is defined as a general mixer kcontrol instead of a DAPM kcontrol, causing a NULL pointer dereference when accessing struct snd_soc_dapm_context via snd_soc_dapm_kcontrol_to_dapm(). This issue arises from incorrect kcontrol definition, leading to potential system crashes or [truncated]
This PatchSiren debrief covers CVE-2026-64105, a vulnerability in the Linux kernel related to KVM: arm64: vgic. The issue involves freeing private_irqs when initialization fails after allocation. Users of Linux kernel with KVM: arm64: vgic enabled should be aware of this vulnerability and review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance.
A vulnerability was found in the Linux kernel, specifically in the virt: sev-guest component. The CVE record was published on 2026-07-19T16:17:51.677Z and has not been modified since then. The NVD entry is currently Received. The vulnerability occurs when set_memory_{encrypted,decrypted}() fails, leaving pages in an unknown state. To address this issue, the code was modified to never free the pages and in [truncated]
A use-after-free vulnerability was found in the Linux kernel's isci driver. The ISCI completion tasklet is not properly killed during device removal, allowing for a use-after-free condition. This issue can potentially allow an attacker to execute arbitrary code or cause a denial of service. The vulnerability is located in the isci_host_deinit() function, where the tasklet_kill() call is missing after wait_for_stop().
A vulnerability in the Linux kernel's RDMA/siw component can be exploited by a malicious peer to cause a use-after-free error. The vulnerability is due to a missing check for the MPA length field in the iWARP FPDU header. This oversight allows an attacker to send a malformed FPDU that can cause the kernel to parse the header incorrectly, leading to a use-after-free error. The vulnerability has been addres [truncated]
A vulnerability was found in the Linux kernel's fwctl subsystem. The fwctl core allocates a device-specific RPC input buffer with fwctl_rpc.in_len and passes it to the driver callback. However, the pdsfc_fw_rpc() function casts the buffer to struct fwctl_rpc_pds and calls pdsfc_validate_rpc() without checking if the input buffer is large enough to contain the structure. This can lead to a buffer overflow [truncated]
A deadlock vulnerability was found in the Linux kernel's drm/msm component. The vulnerability occurs when kswapd0 holding fs_reclaim calls the MSM shrinker, which calls dma_resv_lock, acquiring fs_reclaim and resulting in a deadlock. The issue is resolved by using dma_resv_trylock() instead. This change prevents the deadlock by avoiding the acquisition of fs_reclaim while holding reservation_ww_class_acqu [truncated]
CVE-2026-64099 is a use-after-free vulnerability in the Linux kernel's drm/v3d component. The vulnerability occurs in the CPU job ioctl's fail label, where kvfree() is called on cpu_job's timestamp and performance query arrays after v3d_job_cleanup(), which drops the job's last reference and frees cpu_job. This results in a use-after-free and a NULL dereference on the early v3d_job_init() failure path. Ad [truncated]
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-19T16:17:50.843Z and has not been modified since then. This vulnerability affects the Linux kernel's drm/virtio component, specifically the virtio_gpu_cursor_plane_update() and virtio_gpu_resource_flush() functions. These functions lock the framebuffer BO's dma_resv via virtio_gpu_array_lock_resv() [truncated]
The Linux kernel has a vulnerability that has been resolved in the drm/amd/display component. The vulnerability involves validating GPIO pin LUT table size before iterating. An out-of-bounds read can occur if the VBIOS reports a structuresize larger than the actual mapped data. Linux kernel users and maintainers should be aware of this vulnerability and take necessary actions to protect their systems. The [truncated]
A use-after-free vulnerability was found in the batman-adv module of the Linux kernel. The batadv_mcast_purge_orig() function removes entries from RCU-protected hlists without waiting for an RCU grace period, allowing concurrent RCU readers to access already freed memory. This issue can lead to system crashes or code execution. Linux kernel maintainers and users, as well as network administrators, should [truncated]
A vulnerability was found in the Linux kernel's batman-adv module. The bla.num_requests counter was not being updated atomically, allowing for a double decrement error. This could lead to incorrect request tracking and potential issues with the batman-adv module. The issue was addressed by ensuring atomic updates to the counter and related state variables. Linux kernel users and administrators should be a [truncated]
The Linux kernel has a vulnerability in the batman-adv: bla module that can cause a NULL-ptr deref for claim via dropped interface. This vulnerability has been resolved. The vulnerability is related to a NULL-ptr deref for claim via dropped interface without rtnl_lock held, which can cause a hardif to be retrieved as primary interface of a meshif, but then getting decoupled from the mesh interface. Users [truncated]
The Linux kernel was updated to address a vulnerability in the batman-adv module's tp_meter component. The issue involved a double-deletion hack used to prevent timer re-arming, which was replaced with a single call to timer_shutdown_sync(). This change waits for any running timer callback to complete and permanently disarms the timer, making re-arming prevention unconditional and self-documenting. Linux [truncated]
A vulnerability in Linux kernel's batman-adv tp_meter component has been identified, which may lead to a tp_vars reference leak in receiver shutdown. This issue arises from flawed logic coordinating the release of tp_vars references between batadv_tp_receiver_shutdown() and batadv_tp_stop_all(). Specifically, if the receiver shutdown timer had already expired when batadv_tp_stop_all() attempted to rearm i [truncated]
A PatchSiren debrief for CVE-2026-64091 based on the supplied Linux kernel source corpus. The CVE record was published on 2026-07-19T16:17:49.967Z and has not been modified since then. The vulnerability is related to a TOCTOU (Time-of-Check-to-Time-of-Use) race condition for reported VLANs in the batman-adv module of the Linux kernel. This issue arises from the way the local TT based TVLV is generated, wh [truncated]
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-19T16:17:49.837Z and has not been modified since then. CVE-2026-64090 relates to a Linux kernel vulnerability in batman-adv, specifically avoiding empty VLAN responses in the TT to prevent TT request storms. The fix ensures consistency in TT responses, both directly and indirectly, through global TT [truncated]
PatchSiren debrief for CVE-2026-64089, a vulnerability in the Linux kernel. The batman-adv module in the Linux kernel has a vulnerability in the tt component. This vulnerability is caused by a type confusion issue with the last_changeset_len field. The field is declared as a signed 16-bit integer (s16) but can hold values greater than 32767, causing it to wrap to a negative signed integer. This issue can [truncated]
A vulnerability in the Linux kernel's batman-adv module has been addressed. The issue involves the tt_buff_len field, which was declared as an s16 but could hold values greater than 32767, causing it to wrap to a negative signed integer. This led to a type confusion issue in batadv_send_other_tt_response(), resulting in batadv_tt_prepare_tvlv_global_data() allocating a full-sized buffer but only populatin [truncated]
The Linux kernel has been patched for a vulnerability in hwmon: (pmbus/adm1266) that rejects implausible blackbox record_count. This issue could lead to an out-of-bounds read if a device reports a record_count greater than 32. The fix caps record_count at ADM1266_BLACKBOX_MAX_RECORDS and returns -EIO for larger values. This vulnerability affects users of the Linux kernel, particularly those using the hwmo [truncated]
A Linux kernel vulnerability, CVE-2026-64086, was resolved by adjusting the read buffer size in the adm1266_pmbus_block_xfer function to prevent buffer overflow. The vulnerability was caused by an insufficient read buffer size, which could cause a buffer overflow when receiving a max-length block response with a PEC byte. The issue was resolved by increasing the read buffer size to ADM1266_PMBUS_BLOCK_MAX [truncated]
A Linux kernel vulnerability, CVE-2026-64085, was resolved by containing the fix in the caller without changing the helper signature. The hwmon: (pmbus/adm1266) bounce blackbox records through a protocol-sized buffer. The fix involves reading each record into a 255-byte local bounce buffer that matches the helper's maximum output, validating the returned length, and only then copying exactly ADM1266_BLACK [truncated]
The Linux kernel was found to have a vulnerability in the hwmon: (pmbus/adm1266) module. The issue was caused by an incorrect upper bound in the adm1266_gpio_get_multiple() function, leading to out-of-bounds reads and writes. This vulnerability has been resolved by substituting ADM1266_PDIO_NR for the constant. The vulnerability affects Linux kernel users and administrators, particularly those using the h [truncated]
The Linux kernel was vulnerable to a stack information leak in the hwmon pmbus/adm1266 component. A device returning a short block-read response could leak a few bits of kernel stack per request. This vulnerability could allow an attacker to obtain sensitive information about the kernel stack. The hwmon pmbus/adm1266 component did not properly handle short block-read responses in the GPIO accessors, leadi [truncated]
CVE-2026-64082 is a Linux kernel vulnerability that has been resolved. The vulnerability involves register corruption from uninitialized cregs on error. The issue arises from the unconditional call to cregs_to_regs() in compat_riscv_gpr_set() and compat_restore_sigcontext(), even when user_regset_copyin() or __copy_from_user() fails, respectively. This leads to the corruption of the target task's pt_regs [truncated]