These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.
A vulnerability was found in the Linux kernel, specifically in the mt76 module's mt76_sta_add function. This issue can lead to list corruption, potentially allowing an attacker to cause a denial of service. The vulnerability was resolved by adding a publish check in mt76_sta_add to avoid reinitializing the wcid->poll_list. Users of the Linux kernel, particularly those using the mt76 module, should be awar [truncated]
A vulnerability in the Linux kernel's mac802154 llsec implementation can lead to data corruption and potential use-after-free issues due to in-place cryptographic operations on shared skb data. This vulnerability affects Linux kernel versions that have not been patched. The vulnerability was discovered by 0sec using automated source analysis. The fix involves calling skb_cow_data() before performing in-pl [truncated]
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-19T12:16:56.337Z and has not been modified since then. This vulnerability affects the Linux kernel, specifically the sk_msg component. The issue relates to the sg.copy bitmap not being properly synchronized during SG transforms, potentially exposing externally backed entries as writable ctx->data. T [truncated]
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-19T12:16:56.230Z and has not been modified since then. This vulnerability affects the Linux kernel, specifically in the net: ip_gre module, requiring CAP_NET_ADMIN in the device netns for changelink. The vulnerability has been resolved with a patch. Linux kernel users and administrators should revie [truncated]
The Linux kernel has a vulnerability that has been resolved in the apparmor module. The vulnerability relates to the implicit connection of TCP fast open sendmsg. When using sendmsg()/sendto() with MSG_FASTOPEN, it combines the connect(2) and write(2) operations, opening a connection in the SYN state. The apparmor_socket_sendmsg() function only checks AA_MAY_SEND, allowing a profile that grants send but d [truncated]
The Linux kernel was vulnerable to a use-after-free issue in the AppArmor component. The vulnerability was caused by a missing check for zero reference count in the aa_replace_profiles function. This could lead to a use-after-free error when the function tried to access a profile that had already been removed. The issue was resolved by introducing a new function aa_get_profile_loaddata_not0, which checks [truncated]
The Linux kernel was vulnerable to a use-after-free issue in the fbdev subsystem. The vulnerability was resolved by clearing pointers to the old modelist before freeing it. This issue affected the Linux kernel's fbdev subsystem, which is used for framebuffer devices. The vulnerability had a medium defensive priority. The fbdev subsystem is a critical component of the Linux kernel, responsible for managing [truncated]
The Linux kernel was vulnerable to a GCOV instrumentation issue, causing concurrent access crashes due to the merging of global branch counters with loop induction variables. This was addressed by adding -fprofile-update=prefer-atomic to CFLAGS_GCOV, preventing the compiler from merging counters with loop induction variables and fixing the observed concurrent-access crash. The vulnerability was discovered [truncated]
A vulnerability was found in the Linux kernel, specifically in the keyctl_pkey_params_get_2() function. The length for the internal output buffer is calculated incorrectly, which can result in an overflow when a too small buffer is provided. The bug was fixed by allocating the internal output with the size of the maximum length of the cryptographic primitive instead of the caller-provided size. This vulne [truncated]
CVE-2026-63823 is a use-after-free vulnerability in the Linux kernel, specifically in the request_key_auth payload in instantiate paths. This vulnerability could potentially allow an attacker to cause a denial-of-service or execute arbitrary code. The vulnerability exists due to a use-after-free error in the request_key() and KEYCTL_INSTANTIATE_IOV functions. Linux kernel developers and maintainers, Linux [truncated]
A vulnerability has been resolved in the Linux kernel, specifically in the ath11k module. The issue arises during the unbinding of the device, where a double free warning occurs due to the release of buffers dp->tx_ring[i].tx_status. This happens when there is an error during some initialization related to firmware. The vulnerability has a medium defensive priority and users of the Linux kernel, particula [truncated]
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-19T12:16:55.203Z and has not been modified since then. The Linux kernel vulnerability, CVE-2026-63821, is related to the rtw88 USB driver. When the rtw_usb_write_port() function fails to submit a USB Request Block (URB), the completion callback is never executed, resulting in memory leaks of allocat [truncated]
A Linux kernel vulnerability was resolved, affecting f2fs_read_data_large_folio(). The issue allowed a read bio to remain unsubmitted across multiple readahead folios if an error occurred before blocks were added to the bio. This can lead to readers waiting indefinitely on locked folios. The vulnerability has been publicly disclosed and Linux kernel users and maintainers should be aware of this vulnerabil [truncated]
The Linux kernel has a vulnerability in the f2fs_recover_orphan_inodes() function, which trusts the orphan block entry_count when replaying orphan inodes from the checkpoint pack. A corrupted entry_count larger than F2FS_ORPHANS_PER_BLOCK makes the recovery loop read past the ino[] array and interpret footer or following data as inode numbers, potentially causing a kernel panic. The vulnerability was reso [truncated]
A Linux kernel vulnerability, CVE-2026-63817, was resolved by validating compress cache inode only when enabled. The issue relates to the f2fs file system and its handling of compressed page cache inodes. When the compress_cache mount option is disabled, the max_nid value is outside the valid inode range. A corrupted directory entry pointing to ino == max_nid would be rejected by f2fs_check_nid_range(). H [truncated]
A use-after-free (UAF) issue was found in the Linux kernel's f2fs filesystem implementation. The vulnerability occurs when the `F2FS_IOC_GARBAGE_COLLECT_RANGE` ioctl is used, leading to a potential UAF issue on `f2fs_inode_info.atomic_inode`. This issue can cause an operational impact on Linux kernel users and administrators. The vulnerability class is related to a use-after-free issue in the `f2fs_inode_ [truncated]
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-19T12:16:54.527Z and has not been modified since then. This vulnerability affects the Linux kernel's f2fs file system, specifically when the flexible_inline_xattr feature is enabled. An attacker-controlled i_inline_xattr_size value from a crafted image can cause an out-of-bounds read in f2fs_fill_de [truncated]
The Linux kernel's f2fs filesystem has a vulnerability in its ACL validation. The f2fs_acl_count() function only validates the aggregate ACL xattr length, allowing a malformed ACL to place ACL_USER or ACL_GROUP in a slot with insufficient bytes. This can cause a slab-out-of-bounds read when trying to access the e_id field. The vulnerability was resolved by adding additional validation checks in f2fs_acl_f [truncated]
A Linux kernel vulnerability, CVE-2026-63813, involves a race condition in the f2fs file system. The issue arises from a reverted commit 'f2fs: remove non-uptodate folio from the page cache in move_data_block' (9609dd704725a40cd63d915f2ab6c44248a44598). This commit introduced a race that can cause a kernel panic, especially when the f2fs partition is almost full. The vulnerability allows for a page to be [truncated]
A Linux kernel vulnerability, CVE-2026-63811, was resolved by changing how copy-on-write (COW) data is read during atomic writes. The issue arose because f2fs_write_begin() used the COW inode for reading previously written data, leading to a mismatch in encryption contexts. This caused a general protection fault when attempting to decrypt pagecache blocks. The fix involves using the original inode for rea [truncated]
A Linux kernel vulnerability, CVE-2026-63810, was resolved by unregistering the bdev pseudo-filesystem to prevent userspace interference. The bug caused a NULL pointer dereference when attempting to access files using the move_mount() system call. This vulnerability affects Linux kernel users and administrators, who should ensure they are running a patched kernel to prevent potential NULL pointer derefere [truncated]
The Linux kernel was vulnerable to a memory corruption issue due to improper deallocation of a temporary sysctl buffer. The buffer was allocated using kvzalloc(), which may fall back to vmalloc() for large allocations, but was freed using kfree(). This could corrupt memory. The issue was resolved by using kvfree() to safely handle both kmalloc and kvzalloc()/vmalloc allocations. The bug was first flagged [truncated]
A use-after-free vulnerability was found in the Linux kernel's exfat_find_dir_entry() function. The buffer_head obtained from exfat_get_dentry() was released before the fall-through TYPE_EXTEND branch read the directory entry, potentially leading to a use-after-free condition. This vulnerability can be triggered by a crafted exFAT image with long filenames and same-hash collisions, forcing the TYPE_EXTEND [truncated]
A Linux kernel vulnerability was resolved in KVM: x86/mmu, ensuring a hugepage is in by slot before checking the max mapping level. This prevents an out-of-bounds access to the slot's lpage_info. The vulnerability was found in the Linux kernel's KVM: x86/mmu and could lead to an out-of-bounds access to the slot's lpage_info if the base gfn of the shadow page was not contained within the target memslot.
The Linux kernel was updated to address a vulnerability in KVM's ioeventfd datamatch handling. A BUG_ON() that could be triggered by a guest was replaced with a call to get_unaligned() to safely handle potentially-unaligned accesses. This change prevents undefined behavior in C and ensures KVM can handle store operations that split a page and hit emulated MMIO on the second page. The update is relevant to [truncated]
A Linux kernel vulnerability, CVE-2026-63805, was resolved by fixing an argument issue in the nx_crypto_ctx_exit function. The vulnerability arose from nx_crypto_ctx_shash_exit calling nx_crypto_ctx_exit with an incorrect type, leading to a kernel access of bad area oops. This issue was triggered by hardlink(1) using AF_ALG. The vulnerability affects Linux kernel users and maintainers, who should ensure t [truncated]
A use-after-free vulnerability was found in the Linux kernel's gfs2_qd_dealloc function. The function accesses the superblock object after it has been freed, leading to potential crashes or code execution. This vulnerability can be triggered during unmount when gfs2_quota_cleanup is called, disposing of quota objects via call_rcu and then waiting on sd_kill_wait with a 60-second timeout. If the timeout ex [truncated]
A use-after-free vulnerability was discovered in the Linux kernel's hdlc_ppp module. The vulnerability occurs when the detach_hdlc_protocol function frees the hdlc state without synchronizing the per-proto timers, leading to a potential use-after-free condition. This vulnerability can be triggered by an attacker to execute arbitrary code or cause a denial of service. The vulnerability was introduced due t [truncated]
A use-after-free vulnerability was found in the Linux kernel's blk-cgroup subsystem. When multiple blkgs in the same blkcg are released concurrently, a use-after-free can occur. The race happens when one blkg's __blkcg_rstat_flush() removes another blkg's iostat entries via llist_del_all(). The second blkg sees an empty list and proceeds to free itself while the first is still iterating over its entries. [truncated]
A slab-use-after-free vulnerability was found in the Linux kernel's tipc tipc_aead_decrypt_done function. This issue occurs when the decrypt path of the tipc crypto functionality does not take a reference on the network namespace, leading to a use-after-free condition when the namespace is torn down. The vulnerability allows for potential remote code execution or denial-of-service attacks. Linux kernel de [truncated]