These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.
The Linux kernel was vulnerable to an out-of-bounds read in HCP header parsing. A malicious NFC peer could send a 0-byte HCP frame that passes through the SHDLC layer and reaches the nfc_hci_recv_from_llc() and nci_hci_data_received_cb() functions, causing an out-of-bounds heap read of packet->header. The issue was fixed by adding a pskb_may_pull() check at the entry of each function before packet->header [truncated]
A Linux kernel vulnerability was resolved, addressing an issue with xfrm route MIGRATE notifications. The vulnerability was announced via a CVE record published on 2026-07-19T16:17:09.373Z and has not been modified since then. The NVD entry is currently Received. The issue involves the xfrm_send_migrate() function in net/xfrm/xfrm_user.c and pfkey_send_migrate() in net/key/af_key.c, which hardcoded &init_ [truncated]
A Linux kernel vulnerability allows a connection to be prematurely terminated using a crafted TCP RST packet with an invalid sequence number. The issue arises from the TCP conntrack state machine's failure to validate packet direction and ensure a matching SYN was sent in the opposite direction. This makes connection teardown easier than intended. The vulnerability is particularly concerning for network a [truncated]
A vulnerability was found in the Linux kernel, specifically in the xfrm: esp component. The ESP out-of-place fast path appends the trailer in esp_output_head() before esp_output_tail() allocates the destination page frag. The head-side gate currently checks skb->data_len and tailen separately, but the tail code allocates a single destination frag from the combined post-trailer skb->data_len. This issue ma [truncated]
The Linux kernel vulnerability CVE-2026-63911 has been resolved. The issue involved the IPTFS mode data not being properly reinitialized when cloning Security Associations (SAs), which could lead to use-after-free and double-free errors. The fix ensures that the runtime state of cloned SAs is reset. This vulnerability affects Linux kernel-based systems, and system administrators and security teams should [truncated]
The Linux kernel had a vulnerability in dma-buf where a use-after-free (UAF) issue could occur in the dma_buf_fd() tracepoint. This happened because the file descriptor became live before the tracepoint ran, allowing a racing close() to free the dma_buf, which the tracepoint then dereferenced. The fix involved splitting FD_ADD() into get_unused_fd_flags() and fd_install(), and emitting the tracepoint betw [truncated]
A vulnerability was found in the Linux kernel's ksmbd implementation. The bug was introduced by a commit that transposed a bounds check, leading to a dead code condition. This resulted in an out-of-bounds (OOB) read past the pntsd allocation during SMB2_CREATE operations. The issue was resolved by properly transposing the comparison to require at least 16 bytes. The vulnerability has a high impact on Linu [truncated]
A vulnerability was found in the Linux kernel's atmel_mxt_ts driver. The driver does not properly handle configuration files with object sizes larger than the driver's known mxt_obj_size. This can cause the driver to write to an adjacent instance or object, potentially leading to a denial of service or code execution. The vulnerability has been resolved with an updated boundary check to skip extra bytes correctly.
A double free vulnerability was found in the Linux kernel's uio_pci_generic_sva module. The vulnerability occurs when the uio_pci_sva device is allocated with devm_kzalloc() in probe(), but then explicitly freed with kfree() on both the probe() error path and in remove(). This can lead to a double free, as devm_kzalloc() allocations are automatically freed when the device is detached. The affected product [truncated]
A use-after-free vulnerability was found in the Linux kernel's usb: musb: omap2430. The vulnerability occurs in the omap2430_probe() function where of_node_put(np) is called prematurely, leading to a use-after-free if the node's reference count drops to zero. This issue affects users of the Linux kernel with usb: musb: omap2430 enabled. The vulnerability has been resolved by moving the of_node_put() calls [truncated]
A use-after-free bug was found in the Linux kernel's usbip: vudc module. The bug occurs due to a race condition in the vudc_remove function. This could potentially lead to a denial of service or code execution. The bug was introduced due to improper handling of the vudc structure during removal, allowing the timer to access memory after it has been freed.
A vulnerability was found in the Linux kernel's USBTMC driver. The driver does not check if the URB actual_length is enough to fit the headers of notification messages, which can cause an out-of-bounds read or consume stale leftover data from a previous notification. This issue affects users of Linux kernel versions with the USBTMC driver. The fix checks if actual_data contains enough bytes for the header [truncated]
A Linux kernel vulnerability was resolved, affecting USB: serial: cypress_m8. The issue involves validating interrupt packet headers in cypress_read_int_callback(). This vulnerability can lead to out-of-bounds header-byte reads when dealing with malformed short reports. The fix checks for the presence of the expected header before reading it and resubmits the interrupt URB through the existing retry path. [truncated]
A vulnerability was found in the Linux kernel's digi_acceleport USB serial driver. The driver did not perform adequate checks on bulk-out buffer sizes, which could lead to out-of-bounds memory accesses or slab corruption if a malicious device reported smaller buffers than expected. This issue affects users of Linux systems with the digi_acceleport USB serial driver. The vulnerability has been publicly dis [truncated]
A vulnerability was found in the Linux kernel, specifically in the USB: serial: keyspan driver. The vulnerability is caused by a missing sanity check on the size of usa49wg indat transfers, which could allow an attacker to parse stale or uninitialised slab data. This issue has been resolved by adding the missing sanity check. Users of the Linux kernel should review their deployments and ensure they apply [truncated]
A vulnerability in the Linux kernel's USB: serial: mxuport functionality has been resolved. The vulnerability could allow user-controlled slab corruption if a malicious device reports a smaller size. The fix ensures that the bulk-out endpoint max packet size is at least eight bytes. This vulnerability affects users of the Linux kernel with USB: serial: mxuport functionality. The vulnerability has a medium [truncated]
A vulnerability in the Linux kernel has been resolved. The USB: serial: mct_u232 driver overrides the maximum transfer size for a specific device which only accepts 16 byte packets for its 32 byte bulk-out endpoint. This could lead to memory corruption if a malicious device reports a smaller endpoint max packet size than expected. The vulnerability has a medium defensive priority, and users of the Linux k [truncated]
A vulnerability was found in the Linux kernel related to the USB: serial: mct_u232 driver. The driver is missing a sanity check on the size of interrupt-in transfers, which could allow parsing of stale or uninitialised slab data, potentially leaking it to user space. This vulnerability has been resolved with the addition of the missing sanity check. Affected users should review and apply the official patc [truncated]
A vulnerability was found in the Linux kernel's USB gadget composite driver. The WebUSB GET_URL handler in composite_setup() is vulnerable to an integer underflow when handling the wLength parameter. This can cause a slab-out-of-bounds error and potentially lead to arbitrary code execution. The vulnerability can be triggered by a single SETUP packet against any gadget with webusb/use=1 and a landingPage c [truncated]
A Linux kernel vulnerability was resolved, affecting the usb gadget f_fs component. The bug allowed uninitialized slab residue to be delivered to the FunctionFS daemon on short ep0 OUT control transfers. This vulnerability can be reached from the FunctionFS device node, which in real deployments is owned by the privileged gadget daemon. Linux host stacks normally reject short-wLength control OUTs before t [truncated]
The Linux kernel was vulnerable to a use-after-free issue in the FunctionFS (f_fs) USB gadget driver, specifically in the DMABUF handling code. When a DMABUF was detached or the file was released, the code failed to properly synchronize the cancellation of DMABUF requests with their completion, leading to a potential use-after-free error. An attacker with control over the FunctionFS device node, typically [truncated]
The Linux kernel was vulnerable to a property leak and out-of-bounds read due to a u32 wrap in the tb_property_entry_valid() function. A malicious XDomain peer could exploit this by providing a specially crafted value and length, allowing them to read attacker-directed memory past the allocation. This vulnerability could potentially allow an attacker to access sensitive information. The Linux kernel maint [truncated]
The Linux kernel was vulnerable to a size_t underflow issue in the thunderbolt property handling code. The vulnerability was resolved by rejecting directory lengths less than 4. This fix prevents potential out-of-bounds reads and walks. The issue was caused by the __tb_property_parse_dir() function not properly validating directory lengths, leading to two distinct out-of-bounds conditions. The fix ensures [truncated]
The Linux kernel was vulnerable to a stack exhaustion issue in the thunderbolt property parsing logic. A crafted peer could trigger this without authentication by chaining DIRECTORY entries into a back-reference loop. This vulnerability affects systems with untrusted XDomain peers connected via Thunderbolt, such as hosts, docks, or inline inspectors. Operators of such systems should take immediate action [truncated]
CVE-2026-63890 is a vulnerability in the Linux kernel's FCoE (Fibre Channel over Ethernet) implementation. An unauthenticated L2 peer on the FCoE control VLAN could hang the initiator indefinitely by emitting a specially crafted FIP CVL frame. The vulnerability has been resolved by tightening the outer dlen guard to reject descriptors with dlen < sizeof(struct fip_desc). This change prevents an attacker f [truncated]
The Linux kernel has a vulnerability in the scsi: scsi_transport_fc module. An adjacent Fibre Channel fabric actor can trigger a non-return in the generic FC transport by delivering an FPIN ELS frame to an lpfc or qla2xxx Linux initiator. This vulnerability can be exploited by a compromised switch or fabric controller, or as a same-zone N_Port on a fabric that permits source spoofing. The vulnerability is [truncated]
A Linux kernel vulnerability was resolved in the SCSI target iscsi module. The bug fixes prevent a CRC overread and double-free in iscsit_handle_text_cmd(). This vulnerability affects Linux kernel maintainers and users, particularly those using the SCSI target iscsi module. The vulnerability has a high defensive priority due to its potential impact on system stability and security.
The Linux kernel was vulnerable to a heap overrun condition in the iscsi_encode_text_output() function. This function did not check the remaining buffer capacity when concatenating 'key=value' records into the login->rsp_buf buffer, leading to a potential heap overrun. The fix introduces a static helper function, iscsi_encode_text_record(), which uses snprintf() with a per-call bounds check against the re [truncated]
A Linux kernel vulnerability, CVE-2026-63886, was resolved by adding validation for CHAP_R length before base64 decoding to prevent buffer overflows. This vulnerability was found in the SCSI target iscsi implementation. The chap_server_compute_hash function did not validate the length of CHAP_R before passing it to chap_base64_decode, potentially leading to buffer overflows. The fix adds length validation [truncated]
A vulnerability in the Linux kernel has been patched. The flaw, tracked as CVE-2026-63885, relates to a race condition in the drm/gem component. The issue arises between the change_handle and handle_delete operations, potentially allowing a concurrent drm_gem_handle_delete to free the GEM object while a new handle's IDR entry still references it. To address this, the old handle's IDR entry is set to NULL [truncated]