PatchSiren

Linux CVE debriefs · Page 64

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH Linux CVE published 2026-07-19

CVE-2026-64009

A Linux kernel vulnerability, CVE-2026-64009, was found in the xfrm component. The xfrm_state_mtu function returns a u32 value but performs arithmetic in unsigned modulo-2^32 space, leading to potential underflow. An attacker can exploit this by installing an IPv4 ESP tunnel SA with a large authentication key, configuring a small interface MTU, and setting XFRMA_TFCPAD to a large value. When a UDP datagra [truncated]

HIGH Linux CVE published 2026-07-19

CVE-2026-64008

A use-after-free vulnerability was found in the Linux kernel's Rocket IOCTL create_bo function. The vulnerability occurs when a GEM handle is created early and inserted into the file's IDR, but the object is freed without removing the handle from the IDR if certain operations fail. This leaves a dangling handle pointing to freed slab memory, allowing for use-after-free (UAF) attacks. The fix moves drm_gem [truncated]

CRITICAL Linux CVE published 2026-07-19

CVE-2026-64007

A vulnerability in the Linux kernel has been patched. The vulnerability is related to the netfilter synproxy component. An issue was found with the synproxy_tstamp_adjust function, which could lead to a checksum update being written to the wrong location, resulting in either a write to freed slab memory or a packet being sent with an incorrect checksum. This issue could allow an attacker to cause a denial [truncated]

Review Linux CVE published 2026-07-19

CVE-2026-64006

A vulnerability was found in the Linux kernel's netfilter: nf_tables. The issue is related to dst corruption in the same register operation. This vulnerability can lead to incorrect calculations and potentially cause problems with packet filtering and processing. Users of the Linux kernel should be aware of this issue and take steps to mitigate it.

HIGH Linux CVE published 2026-07-19

CVE-2026-64005

A vulnerability in the Linux kernel has been resolved. The vulnerability is related to the re-initialization of smc hashtables, which can lead to a corrupted list. The re-initialization is unnecessary and can be removed. The affected product is the Linux kernel. The vulnerability has been resolved by removing the unnecessary re-initialization of smc hashtables.

HIGH Linux CVE published 2026-07-19

CVE-2026-64004

A vulnerability was found in the Linux kernel's net/iucv component. The issue is related to locking in the .getsockopt function. An AF_IUCV HIPER user can potentially crash the kernel by racing recvmsg() with getsockopt(SO_MSGSIZE), leading to a NULL pointer dereference oops. The vulnerability has a high impact, and system administrators should be aware of the potential impact and take necessary actions t [truncated]

HIGH Linux CVE published 2026-07-19

CVE-2026-64003

CVE-2026-64003 is a Linux kernel vulnerability affecting the SCSI core. The issue arises from scsi_run_host_queues() not running queues for all non-SDEV_DEL devices, potentially leaving requests stuck and causing device removal to hang. The fix involves modifying scsi_run_host_queues() to run against more devices, excluding only those in the SDEV_DEL state or for which a reference cannot be acquired. This [truncated]

Review Linux CVE published 2026-07-19

CVE-2026-64001

A use-after-free vulnerability was found in the Linux kernel's ALSA pcm OSS implementation. When snd_pcm_oss_proc_write() encounters an error while duplicating the task name, it frees the already linked setup entry, potentially leaving setup_list pointing to freed memory. A subsequent OSS device open could then dereference this stale list entry. The vulnerability affects Linux kernel developers and mainta [truncated]

CRITICAL Linux CVE published 2026-07-19

CVE-2026-64000

A vulnerability was found in the Linux kernel related to the handling of supervision frames in the HSR protocol. The issue arises from the potential for an out-of-bounds access when a truncated frame is received. The fix involves ensuring that the entire TLV header is linearized before access. This vulnerability could potentially impact the availability and integrity of systems using the HSR protocol. Use [truncated]

Review Linux CVE published 2026-07-19

CVE-2026-63999

The Linux kernel was vulnerable to a memory leak issue in the ethtool RSS functionality. The vulnerability occurred when the get_rxfh() function failed, causing a memory leak of the indirection table and hash key buffer allocated by rss_get_data_alloc(). This issue has been resolved. Affected Linux kernel deployments should review and apply patches. The vulnerability has a medium defensive priority.

Review Linux CVE published 2026-07-19

CVE-2026-63997

A vulnerability was found in the Linux kernel related to the ethtool module. The issue involves avoiding leaking a netdev ref on module flash errors. Specifically, the module_flash_fw_schedule() function is missing undo for setting the 'in_progress' flag and taking the netdev reference. To address this, delay taking these actions; the device can't disappear while holding rtnl_lock. This vulnerability coul [truncated]

HIGH Linux CVE published 2026-07-19

CVE-2026-63996

The Linux kernel ethtool vulnerability CVE-2026-63996 has been resolved. The vulnerability was related to the ethtool cmis feature, which did not properly handle long replies from SFP modules, potentially leading to out-of-bounds writes. The fix adds a check to ensure the reply length matches the expected length. This vulnerability affects Linux kernel-based systems using ethtool. System administrators an [truncated]

HIGH Linux CVE published 2026-07-19

CVE-2026-63995

The Linux kernel was vulnerable to an out-of-bounds write issue in the ethtool CMIS firmware update code. The code did not validate the start_cmd_payload_size from the module's FW Management Features CDB reply before using it for memcpy. This could allow a malicious module or corrupted response to cause an out-of-bounds write. The destination buffer is 112 bytes (ETHTOOL_CMIS_CDB_LPL_MAX_PL_LENGTH - 8). L [truncated]

CRITICAL Linux CVE published 2026-07-19

CVE-2026-63994

A Linux kernel vulnerability, CVE-2026-63994, was resolved by loading network headers after skb_cow() in iptunnel_pmtud_build_icmp[v6](). The issue involved caching ip_hdr() and ipv6_hdr() before an skb_cow() call, which can reallocate skb->head, potentially leading to a use-after-free (UAF). The fix initializes local variables after the skb_cow() call and removes unnecessary skb_reset_network_header() ca [truncated]

CRITICAL Linux CVE published 2026-07-19

CVE-2026-63993

A use-after-free vulnerability was found in the Linux kernel's vxlan implementation. The issue arises when skb_tunnel_check_pmtu() changes skb->head, causing a previously cached ip_hdr() value to point to freed memory. This can lead to unexpected behavior or crashes when the cached value is reused. The vulnerability has been resolved by using ip_hdr(skb) directly, as seen in other parts of the Linux kernel.

CRITICAL Linux CVE published 2026-07-19

CVE-2026-63992

A Linux kernel vulnerability, CVE-2026-63992, was resolved. The issue arises in the iptunnel_pmtud_check_icmp() function, where an out-of-bound access can occur when the skb transport header is not set. The fix accesses the ICMP header based on the IPv4 network header, ensuring the icmp->type is present in the skb linear part. This vulnerability affects Linux kernel deployments, and maintainers, developer [truncated]

Review Linux CVE published 2026-07-19

CVE-2026-63991

A vulnerability was found in the Linux kernel's Bluetooth 6lowpan implementation. The send_mcast_pkt() function did not check the return value of skb_clone(), which can lead to a NULL pointer dereference. This issue has been resolved with a NULL check after skb_clone(). The vulnerability affects Linux kernel users and administrators, especially those using Bluetooth 6lowpan. The issue has a high impact on [truncated]

Review Linux CVE published 2026-07-19

CVE-2026-63990

The Linux kernel has a vulnerability that has been resolved. The bonding driver did not properly handle CAN devices, leading to a kernel paging request crash. This occurs because a virtual CAN device (vxcan) is being enslaved to a bonding master, causing the bonding driver to mutate and modify the network device states to fit an Ethernet-like aggregation model. However, CAN devices operate on a completely [truncated]

Review Linux CVE published 2026-07-19

CVE-2026-63989

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-19T16:17:18.260Z and has not been modified since then. The Linux kernel vulnerability CVE-2026-63989 is related to the bridge: Fix sleep in atomic context in netlink path. The issue arises from the bridge lock being held around br_setport(), causing a sleeping function to be called from an invalid c [truncated]

Review Linux CVE published 2026-07-19

CVE-2026-63988

A Linux kernel vulnerability, CVE-2026-63988, was resolved to address a sleep in atomic context issue in the sysfs path. The brport_store() function acquired the bridge lock, which caused a problem as it processed attributes that did not require the bridge lock. This resulted in a splat due to a sleeping function called from an invalid context. The fix reduced the scope of the bridge lock to only take it [truncated]

HIGH Linux CVE published 2026-07-19

CVE-2026-63987

A Linux kernel vulnerability was resolved, affecting the ethtool coalesce feature. The issue arises from unbounded index 'i' in ethnl_update_profile(), writing new_profile[i++] without checks, leading to potential out-of-bounds access. This vulnerability could allow an attacker to execute arbitrary code or cause a denial of service. Linux kernel maintainers, ethtool developers, and users of Linux systems [truncated]

Review Linux CVE published 2026-07-19

CVE-2026-63986

A vulnerability was found in the Linux kernel's ethtool tsinfo functionality. When the ethnl_tsinfo_prepare_dump() function fails, it does not start a genlmsg, and therefore, there's nothing to cancel. However, the current implementation passes an error pointer to genlmsg_cancel(), which could cause a crash. This issue has been resolved in the kernel. System administrators and security teams should review [truncated]

HIGH Linux CVE published 2026-07-19

CVE-2026-63985

The Linux kernel was vulnerable to an issue in the ethtool EEPROM Netlink fallback path. The fallback_set_params() function did not validate that the offset + length stayed within the eeprom_len, which could lead to surprises in both drivers and device FW. This has been resolved by adding the missing offset + length validation to fallback_set_params(), mirroring the ioctl. The issue could lead to unexpect [truncated]

CRITICAL Linux CVE published 2026-07-19

CVE-2026-63984

CVE-2026-63984 is a vulnerability in the Linux kernel's IPv6 RPL implementation. The ipv6_rpl_srh_decompress() function incorrectly calculates the hdrlen field, leading to a potential buffer overflow. This vulnerability has been resolved in the Linux kernel. The vulnerability affects the Linux kernel's handling of IPv6 RPL packets, specifically in the decompression of the routing header. The incorrect cal [truncated]

Review Linux CVE published 2026-07-19

CVE-2026-63983

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-19T16:17:17.490Z and has not been modified since then. CVE-2026-63983 is a vulnerability in the Linux kernel's net/sched component that allows for packet duplication, potentially leading to stack or memory exhaustion. The vulnerability has been resolved by using the skb tc_depth field to prevent dup [truncated]

Review Linux CVE published 2026-07-19

CVE-2026-63982

A vulnerability in the Linux kernel has been resolved, related to network scheduling. The issue involves a mirred loop in ingress and egress traffic. When mirred redirects to ingress, the loop state is lost due to packet deferral into the backlog and the clearing of the sched_mirred_dev array. This can lead to undetected loops, potentially causing significant operational impact. Linux kernel users and adm [truncated]

Review Linux CVE published 2026-07-19

CVE-2026-63981

The Linux kernel was vulnerable to a stack overflow attack due to a bypass of the recursion limit in the act_mirred function. This vulnerability could be exploited by an unprivileged user via user namespaces. The vulnerability was caused by the act_mirred function not properly incrementing a recursion counter before calling tcf_blockcast, allowing for an unbounded recursion loop and potential stack overflow.

HIGH Linux CVE published 2026-07-19

CVE-2026-63980

A vulnerability was found in the Linux kernel's net/handshake component. The issue arises from the use of a plain spin_lock in handshake_req_cancel, which can lead to a deadlock when a process-context thread holds the lock and a softirq invokes the cancel path. To address this, all hn->hn_lock acquisitions have been converted from spin_lock/spin_unlock to spin_lock_bh/spin_unlock_bh. This change ensures t [truncated]

CRITICAL Linux CVE published 2026-07-19

CVE-2026-63979

A vulnerability was found in the Linux kernel's handshake component. The issue arises from a race condition between handshake_req_next() and handshake_nl_accept_doit(), allowing a consumer to release the sock->file, leading to a potential NULL read or use-after-free error. The fix involves handing off a pinned file reference to accept_doit. This vulnerability affects Linux kernel developers and maintainer [truncated]

CRITICAL Linux CVE published 2026-07-19

CVE-2026-63978

A Linux kernel vulnerability, CVE-2026-63978, was resolved by fixing a handshake net namespace exit issue. The problem arose from reversed arguments in list_splice_init() within handshake_net_exit(), causing pending handshake requests to not be torn down when the net namespace is destroyed. This fix addresses list-corruption races and ensures proper drain of pending requests.