These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.
A vulnerability in the Linux kernel's drm/msm component has been resolved. The drm/msm component did not always recover the GPU, which could lead to a hung state and potential timeouts. The recover worker has been modified to always recover the GPU. This change addresses the issue by ensuring that the GPU is always recovered, even if there is no more work to do. The vulnerability could potentially impact [truncated]
The Linux kernel has a vulnerability in the drm/amdgpu/vce component that could result in a bad address being written to in FW. The issue is resolved by preventing partial address patches. This vulnerability affects Linux kernel users and administrators, who should review the patches and apply them to their systems. The CVE record was published on 2026-07-19T11:16:38.623Z and has not been modified since t [truncated]
The Linux kernel was vulnerable to a speculative execution issue in the GART TLB, which could lead to the GPU using stale, garbage PTE entries. This was caused by the GART table not being zero-initialized after allocation. The issue was resolved by calling memset_io() to zero-initialize the GART table with gart_pte_flags immediately after allocation.
A vulnerability was found in the Linux kernel, related to the handling of Virtual Memory Areas (VMAs) during the mmap_prepare action. The mmap_prepare hook functionality allows invoking mmap_prepare() from the mmap() hook of existing 'stacked' drivers. However, when mmap() is invoked, it passes a not-fully-established VMA pointer, which is detached. Attempting to unmap a VMA in this state can cause proble [truncated]
The Linux kernel has a resolved vulnerability, CVE-2026-53372, related to iommu/vt-d. The kernel lacks dirty tracking support on nested domains attached to PASID, which could lead to lost dirty pages. To address this, the attachment is blocked early if the nesting parent domain is configured for dirty tracking. This change helps maintain data integrity by ensuring that dirty pages are properly handled. Af [truncated]
The Linux kernel vulnerability, CVE-2026-53371, is related to the RDMA/ionic component. The node_desc sysfs read is not properly bounded, which could lead to reading past the end of the node_desc array. This issue is triggerable by userspace. The CVE record was published on 2026-07-19T09:17:02.260Z and has not been modified since then. Linux kernel users and administrators should review and apply patches [truncated]
The Linux kernel was vulnerable to an issue in the perf/x86/intel component, specifically with ACR mask validation and configuration. The vulnerability has been resolved through several changes, including improving user space ACR mask validation, handling invalid ACR masks, and clearing stale hardware ACR masks. The changes address these issues by dropping invalid bits, continuing to iterate through all A [truncated]
The Linux kernel has been updated to address a vulnerability in the f2fs file system. The vulnerability, which has been resolved, relates to the incorrect usage of nat_entry flags, potentially causing fsck inconsistencies. The issue arises from f2fs_need_dentry_mark() reading nat_entry flags without mutual exclusion with the checkpoint path, leading to incorrect inode block marking states. Users and admin [truncated]
A vulnerability was found in the Linux kernel. The per-task avdcache was incorrectly saving and reusing the audited vector computed by avc_audit_required() rather than recomputing based on the currently requested permissions and distinguishing the denied versus allowed cases. This results in some permission checks not being audited, such as directory write checks after a previously cached directory search [truncated]
A Linux kernel vulnerability, CVE-2026-53366, was resolved in the ipv4 paged allocation path. The issue arose from incorrect accounting of fraggap in the paged allocation branch of __ip_append_data(). This vulnerability affects Linux kernel deployments and may impact Linux distribution vendors and users of Linux systems. The vulnerability was caused by incorrect calculation of alloclen and pagedlen, leadi [truncated]
A vulnerability in the Linux kernel's handling of AMD Zen 2 processors could allow improper sharing of resources in the operation cache (op cache), leading to instruction corruption. The issue stems from insufficient isolation of shared resources in the microarchitectural op cache on AMD Zen 2 CPUs. The kernel has been patched to enforce proper resource isolation, preventing cross-thread or improper shari [truncated]
The Linux kernel has a vulnerability related to handling tunneled traffic on IPV6_CSUM GSO fallback. This vulnerability arises because NETIF_F_IPV6_CSUM only advertises support for checksum offload of packets without IPv6 extension headers. Packets with extension headers must fall back onto software checksumming. The fix extends the check to correctly handle tunneled packets. System administrators and use [truncated]
The Linux kernel was vulnerable to an information leak in the IPv6 Neighbor Discovery (NDISC) implementation. When processing Router Advertisements with user options, the kernel builds an RTM_NEWNDUSEROPT netlink message. However, the nduseroptmsg struct has three padding fields that are never zeroed, potentially leaking kernel data. The vulnerability has been patched. Affected systems include those runni [truncated]
A vulnerability was found in the Linux kernel's net: sched: cls_api. The tc_chain_fill_node function did not initialize the tcm_info field of struct tcmsg, leading to a potential info-leak of 4 bytes of kernel heap memory to userspace. The vulnerability has been patched. Linux kernel versions 4.19 through 7.0 rc6 are potentially affected. Users of these versions should review and apply patches provided by [truncated]
A HIGH severity vulnerability was found in the Linux kernel, with a CVSS score of 7.8. The vulnerability has been resolved with a patch. Users should update to the latest kernel version to mitigate the risk. The vulnerability is in the crypto: authencesn component of the Linux kernel. When decrypting data that is not in-place (src != dst), there is no need to save the high-order sequence bits in dst as it [truncated]
A vulnerability was found in the Linux kernel, specifically in the regsafe() function for pointers to packets. The function could return true when it should not, potentially leading to the current state with a valid packet range not being explored. This issue has been resolved with a fix applied to the kernel. The vulnerability has a CVSS score of 7.8 and is classified as HIGH severity. Users and administ [truncated]
A vulnerability has been resolved in the Linux kernel's netfilter: x_tables component. The issue did not ensure that names are nul-terminated before feeding them to functions that expect c-strings. This vulnerability has been patched in various kernel versions. Users of Linux kernel versions 4.5 to 6.19.12, and 7.0 rc1 to rc6 should review their systems for potential exposure and apply patches from Linux [truncated]
A use-after-free vulnerability was discovered in the Linux kernel, specifically in the netfilter component. The vulnerability occurs when the nf_conntrack_helper_unregister function fails to properly clean up expectations belonging to the helper being unregistered, leading to a use-after-free condition. This can cause a crash or potentially allow an attacker to execute arbitrary code. The vulnerability ha [truncated]
A vulnerability has been resolved in the Linux kernel related to netfilter: ctnetlink, where the expect NAT fields are not properly zeroed when CTA_EXPECT_NAT is absent. This issue can lead to stale data being dumped to userspace, potentially causing information disclosure or other security issues. The vulnerability has been patched, and users are advised to apply the patches as soon as possible.
The Linux kernel was vulnerable to an out-of-bounds read issue in the netfilter component. The vulnerability was caused by the ctnetlink component not properly handling the helper name provided by userspace for new expectations. This could allow an attacker to read kernel memory bytes off the expectation boundary. The existing master conntrack helper should be used, and any other helper provided by usersp [truncated]
A vulnerability has been identified in the Linux kernel, specifically in the netfilter component of nf_tables. This vulnerability involves the rejection of immediate NF_QUEUE verdicts. The nf_tables is a packet filtering framework that provides a more flexible and efficient way to filter packets than the traditional iptables. NF_QUEUE is a verdict that queues the packet for user-space processing. However, [truncated]
A double free vulnerability was found in the Linux kernel's net/x25 module. When alloc_skb fails in x25_queue_rx_frame, it calls kfree_skb(skb) and returns an error. This error propagates, and x25_backlog_rcv calls kfree_skb(skb) again if x25_process_rx_frame returns 0, leading to a potential double free of the same skb. This issue has significant impact on Linux kernel security and requires immediate att [truncated]
CVE-2026-31768 is a Linux kernel bug in the ti-adc161s626 IIO ADC driver where spi_read() used stack memory instead of DMA-safe storage. The upstream fix replaces that buffer handling with a DMA-safe u8[] buffer and adjusts the byte conversion logic accordingly. NVD rates the issue High (CVSS 7.8) with local attack requirements, no user interaction, and high impacts to confidentiality, integrity, and availability.
A HIGH severity vulnerability was found in the Linux kernel's iio: gyro: mpu3050 driver, with a CVSS score of 7.8. The vulnerability has been resolved by moving iio_device_register() to the correct location in the probe function to prevent race conditions. This change ensures that the device is properly registered and reduces the risk of exploitation. Users and administrators of affected Linux kernel vers [truncated]
A vulnerability was found in the Linux kernel. The br_nd_send() function did not properly validate ND option lengths, which could cause the parser to advance beyond the computed option span or use a too-short source LLADDR option payload. This vulnerability has been resolved by validating option lengths against the remaining NS option area before advancing, and only reading source LLADDR when the option i [truncated]
The Linux kernel was vulnerable to a critical issue in the bridge component. The br_nd_send function did not properly linearize the network packet before parsing neighbour discovery options, potentially allowing for out-of-bounds data access. This issue has been resolved with multiple patches available. System administrators and users of Linux kernel versions 4.15 through 7.0-rc6 should be aware of this v [truncated]
A use-after-free vulnerability was found in the Linux kernel's IPv6 flowlabel handling. When a concurrent reader accesses the `/proc/net/ip6_flowlabel` file while a flowlabel's option block is being freed, it can lead to a crash. This issue has been resolved by deferring the free of exclusive flowlabel options until RCU teardown. The vulnerability affects Linux kernel versions 3.9 through 7.0-rc6.
The Linux kernel has a vulnerability that has been resolved. The vulnerability is related to the netfilter component, specifically in the ip6t_rt module. The vulnerability occurs when the addrnr value exceeds IP6T_RT_HOPS in the rt_mt6_check function. This can lead to a potential denial of service or code execution. Affected users should apply patches from Linux kernel stable branches and restrict access [truncated]
A MEDIUM severity vulnerability was found in the Linux kernel's xfrm_user module. The vulnerability is caused by an info leak in the build_report() function, where the xfrm_user_report structure has padding bytes that are not zeroed out before being copied to userspace, leading to sensitive information disclosure. This issue can allow local attackers to gain sensitive information about the system's kernel [truncated]
A MEDIUM severity vulnerability, CVE-2026-31670, was found in the Linux kernel. This issue allows userspace to create an unlimited number of rfkill events without consuming them, potentially leading to an out-of-memory situation. The kernel has been updated to limit the number of pending rfkill events to a large number, preventing such abuses. System administrators should review their kernel versions and [truncated]