PatchSiren

Linux CVE debriefs · Page 66

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH Linux CVE published 2026-07-19

CVE-2026-63946

A use-after-free vulnerability was found in the Linux kernel's Bluetooth ISO module. The iso_recv_frame function reads the conn->sk pointer under the iso_conn_lock but releases the lock before using the sk pointer, with no reference held. This can cause a concurrent iso_sock_kill() to free the sk pointer in that window, leading to a use-after-free issue on sk->sk_state and sock_queue_rcv_skb(). The vulner [truncated]

HIGH Linux CVE published 2026-07-19

CVE-2026-63945

A vulnerability was found in the Linux kernel's Bluetooth ISO implementation. The issue arises from a race condition in the `iso_sock_clear_timer` function, which can lead to a NULL pointer dereference or use-after-free. This vulnerability has been resolved by serializing `iso_sock_clear_timer` with the socket lock. The affected product is the Linux kernel, and the vulnerability class is related to a race [truncated]

HIGH Linux CVE published 2026-07-19

CVE-2026-63944

A use-after-free vulnerability was found in the Linux kernel's Bluetooth subsystem. The vulnerability occurs in the hci_le_create_cis_sync function, where a concurrent disconnect can free the hci_conn between the unlock and the dereference, causing a use-after-free read. This vulnerability can be exploited by an attacker to potentially execute arbitrary code or cause a denial of service. Linux kernel deve [truncated]

Review Linux CVE published 2026-07-19

CVE-2026-63943

CVE-2026-63943 is a Linux kernel vulnerability in the xpad module, allowing for out-of-bounds access. A malicious controller can send a packet with a short length, causing the issue. The fix calculates the offset and checks bounds against the packet length. Linux kernel users and maintainers should assess and apply patches. The vulnerability has a high impact on Linux kernel systems, and defenders should [truncated]

HIGH Linux CVE published 2026-07-19

CVE-2026-63942

A race condition vulnerability was found in the Linux kernel's parport subsystem. The parport subsystem registers port devices before they are fully initialised, which can result in client drivers attaching to ports that are not completely initialised or are being torn down. This can cause a crash when the port and client drivers are built as modules and loaded around the same time during boot. The vulner [truncated]

HIGH Linux CVE published 2026-07-19

CVE-2026-63941

The Linux kernel was vulnerable to an issue where a VHE guest hypervisor could improperly update the ZCR_EL2 register, potentially allowing L2 guests to access vector lengths they should not have access to. This was due to KVM handling ZCR_EL2 and ZCR_EL1 updates differently, leading to potential statefulness issues with the ZCR_EL2.LEN field. The fix moves vector length capping to the restore points, ens [truncated]

CRITICAL Linux CVE published 2026-07-19

CVE-2026-63940

The Linux kernel vulnerability CVE-2026-63940 involves KVM and SEV. The fix ignores Port I/O requests of length '0' to prevent underflow issues and allows for warning on attempts to configure the scratch area with len==0. This vulnerability affects Linux kernel users and administrators, who should review and apply patches to prevent potential issues with KVM and SEV functionality. The CVE record was publi [truncated]

CRITICAL Linux CVE published 2026-07-19

CVE-2026-63939

The Linux kernel has a vulnerability in KVM SEV, where the max length of the in-GHCB scratch area is not computed correctly. This vulnerability affects the KVM SEV component of the Linux kernel and could lead to buffer overflows when handling PSC requests. The vulnerability has a medium defensive priority. Linux kernel users and KVM administrators should review their configurations to ensure they are secu [truncated]

CRITICAL Linux CVE published 2026-07-19

CVE-2026-63938

A vulnerability in the Linux kernel has been addressed, specifically in the KVM and SEV components. The vulnerability is related to checking PSC request indices against the actual size of the buffer. The CVE record was published on 2026-07-19T16:17:12.323Z and has not been modified since then. This issue could potentially allow for security issues if the guest provided a pointer that isn't exactly at the [truncated]

HIGH Linux CVE published 2026-07-19

CVE-2026-63937

A vulnerability was found in the Linux kernel related to KVM: SEV. The vulnerability is resolved by using READ_ONCE() when reading entries/indices from the guest-accessible Page State Change buffer to defend against TOCTOU bugs. This change helps prevent Time-of-Check-to-Time-of-Use (TOCTOU) attacks by ensuring that the values read are not modified during the read operation. System administrators and secu [truncated]

Review Linux CVE published 2026-07-19

CVE-2026-63936

The Linux kernel was vulnerable to an unchecked return value issue in the mt6359 driver, which could lead to unpredictable measurement results or potential stack data leakage if a read operation failed. The vulnerability is now resolved, and Linux kernel users and maintainers should be aware of this issue to ensure they are using the patched version. The vulnerability has been resolved by initializing val [truncated]

Review Linux CVE published 2026-07-19

CVE-2026-63935

A division by zero vulnerability exists in the Linux kernel's iio: adc: nxp-sar-adc driver. The vulnerability is triggered when a user writes a zero or negative value to the sampling_frequency sysfs attribute. This can cause a division by zero in the kernel. The vulnerability has been resolved by adding a validation check for the sampling frequency value before using it as a divisor. Linux kernel users an [truncated]

Review Linux CVE published 2026-07-19

CVE-2026-63934

The Linux kernel was found to have a vulnerability in the iio: gyro: itg3200 driver. The itg3200_read_all_channels() function incorrectly wrote i2c data into the wrong stack location, resulting in both a functional bug and an information leak. The bug was resolved by removing the spurious '&' operator. This vulnerability affects users of the Linux kernel with the iio: gyro: itg3200 driver enabled. The vul [truncated]

Review Linux CVE published 2026-07-19

CVE-2026-63933

A PatchSiren debrief for CVE-2026-63933, a division by zero vulnerability in the Linux kernel's iio: gyro: adis16260 driver. The vulnerability occurs when a user writes a zero value to the sampling_frequency sysfs attribute, triggering a division by zero in the kernel. Users of Linux kernel versions with the iio: gyro: adis16260 driver should validate and apply patches to prevent potential local denial-of [truncated]

Review Linux CVE published 2026-07-19

CVE-2026-63932

A vulnerability was found in the Linux kernel's iio: chemical: mhz19b module. The mhz19b_receive_buf() function appends each serdev chunk into the fixed MHZ19B_CMD_SIZE receive buffer and advances buf_idx by len without checking that the chunk fits in the remaining space. This can lead to a buffer overflow. The issue has been resolved by resetting the reply state before each command and rejecting oversize [truncated]

Review Linux CVE published 2026-07-19

CVE-2026-63931

A division by zero vulnerability exists in the Linux kernel's iio: chemical: scd30 driver. The vulnerability is triggered when a user writes a zero fractional part to the sampling_frequency sysfs attribute, causing a division by zero in the kernel. This issue has been resolved by adding a zero check for val2 before using it as a divisor when setting the sampling frequency. Linux kernel users and administr [truncated]

HIGH Linux CVE published 2026-07-19

CVE-2026-63930

A use-after-free vulnerability was found in the Linux kernel's iio buffer hw-consumer. The issue arises in the err_put_buffers cleanup path of iio_hw_consumer_alloc(), where list_for_each_entry() is used to iterate through buffers while calling iio_buffer_put() which can free the current buffer if refcount drops to 0. The list_for_each_entry() loop macro then evaluates buf->head.next to continue iteration [truncated]

Review Linux CVE published 2026-07-19

CVE-2026-63929

The Linux kernel was vulnerable to a DMA fence leak in the iio_buffer_enqueue_dmabuf() function, caused by a missing dma_fence_put() call after dma_resv_add_fence(). This resulted in a permanent leak of one kmalloc-128 allocation per buffer enqueue. The vulnerability was resolved by calling dma_fence_put() after dma_resv_add_fence(), transferring ownership of the fence to the DMA reservation object. This [truncated]

Review Linux CVE published 2026-07-19

CVE-2026-63928

A vulnerability in the Linux kernel's USB: serial: omninet driver has been resolved. The driver has a memory corruption issue with small endpoints, which can be exploited by a malicious device reporting a smaller endpoint max packet size than expected, potentially leading to user-controlled slab corruption. To address this, ensure that bulk-out buffers are at least as large as the hardcoded transfer size [truncated]

HIGH Linux CVE published 2026-07-19

CVE-2026-63927

A use after free vulnerability was found in the Linux kernel's dwc2 USB driver. The vulnerability occurs when the driver attempts to access a freed URB (USB Request Block) object. This can lead to a crash or potentially allow an attacker to execute arbitrary code. The vulnerability has been resolved through a series of commits in the Linux kernel repository. Linux kernel developers and maintainers, Linux [truncated]

HIGH Linux CVE published 2026-07-19

CVE-2026-63925

A vulnerability was found in the Linux kernel's macsec implementation. The issue occurs when the packet number (pn) wraps around, allowing an attacker to replay frames indefinitely. This can happen when pn is U32_MAX and next_pn_halves.lower is also in the upper half, causing the XPN else-if condition to not fire and leaving next_pn_halves unchanged. As a result, an attacker can capture a legitimate frame [truncated]

CRITICAL Linux CVE published 2026-07-19

CVE-2026-63924

A vulnerability was found in the Linux kernel related to the handling of IPv6 extension headers. The issue arises when ipv6_hop_jumbo() calls pskb_trim_rcsum(), which can change skb pointers. If the nh pointer is not refreshed after this call, it can lead to unexpected behavior. The vulnerability has been resolved with a patch that ensures the nh pointer is recomputed after pskb_trim_rcsum() is called. Li [truncated]

HIGH Linux CVE published 2026-07-19

CVE-2026-63923

The Linux kernel was vulnerable to an out-of-bounds write issue in the octeontx2-af driver. The vulnerability was caused by a lack of bounds checking on the pcifunc field in the REP_EVENT_NOTIFY request body. This allowed an attacker to potentially cause a denial of service or execute arbitrary code. The vulnerability was addressed by adding bounds checking to the rvu_mbox_handler_rep_event_notify functio [truncated]

CRITICAL Linux CVE published 2026-07-19

CVE-2026-63922

A vulnerability has been resolved in the Linux kernel related to ipv6 exthdrs. The issue arises from the improper handling of the HAO option in the ip6_parse_tlv function, which can lead to the invalidation of the cached network header pointer. This can occur when ipv6_dest_hao calls pskb_expand_head for a cloned skb, potentially moving the skb head. The vulnerability has been addressed by refreshing nh a [truncated]

HIGH Linux CVE published 2026-07-19

CVE-2026-63921

CVE-2026-63921 is a Linux kernel vulnerability that has been resolved. The issue involves the ip6 vti and its handling of network namespaces. After a patch was applied, vti6_update() unlinks and relinks the tunnel through t->net. However, vti6_siocdevprivate() still uses dev_net(dev) for collision lookup, which can lead to issues when a tunnel is moved through IFLA_NET_NS_FD. This can cause SIOCCHGTUNNEL [truncated]

HIGH Linux CVE published 2026-07-19

CVE-2026-63920

The Linux kernel was vulnerable to an unprivileged slab-out-of-bounds read in the ipv6 extension header processing. The issue was caused by insufficient validation of the extension header length before copying to cmsg. This vulnerability could be triggered by an unprivileged user namespace via nftables payload-write expressions. The vulnerability was addressed by adding ipv6_get_exthdr_len() to validate t [truncated]

HIGH Linux CVE published 2026-07-19

CVE-2026-63919

A Linux kernel vulnerability, CVE-2026-63919, was resolved by holding the network namespace (netns) during deferred transport reinjection. The issue involved a struct net pointer stored in skb->cb, which was used later in xfrm_trans_reinject(). To fix this, a netns reference is taken when queuing deferred reinjection work and dropped after the callback completes. This change maintains the existing workque [truncated]

HIGH Linux CVE published 2026-07-19

CVE-2026-63918

A Linux kernel vulnerability, CVE-2026-63918, was resolved by changing l2tp_session_get_by_ifname to use refcount_inc_not_zero. This prevents a use-after-free condition when a session's refcount reaches zero between lookup and reference taking. The vulnerability affects the Linux kernel and could potentially allow an attacker to exploit the l2tp functionality. Linux kernel maintainers, developers, and use [truncated]

HIGH Linux CVE published 2026-07-19

CVE-2026-63917

A Linux kernel vulnerability was resolved, involving the ip6 and vti components. The issue arises from the incorrect use of dev_net(dev) and dev_net(t->dev) in vti6_changelink() and vti6_update(), leading to a stale entry in the creation netns and potential memory corruption. This vulnerability can be exploited by an unprivileged user namespace, allowing for cross-tenant scope on container hosts. System a [truncated]

HIGH Linux CVE published 2026-07-19

CVE-2026-63916

A Linux kernel vulnerability was resolved in the HID: wacom module. The vulnerability, CVE-2026-63916, involves an out-of-bounds write issue in the wacom_hid_set_device_mode() function. This function incorrectly assumes that the HID_DG_INPUTMODE usage is always located in the first field of the feature report, leading to potential out-of-bounds writes if HID_DG_INPUTMODE is located in a different field. T [truncated]