PatchSiren

Linux CVE debriefs · Page 78

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH Linux CVE published 2026-07-14

CVE-2025-71097

A vulnerability in the Linux kernel's IPv4 stack allows a reference count leak when using error routes with nexthop objects. This issue arises because error routes are not properly flushed when their nexthop object is deleted, leading to a reference count leak on the nexthop object and its associated device. This can cause issues such as preventing network interfaces from being properly removed.

HIGH Linux CVE published 2026-07-14

CVE-2025-71088

A MEDIUM severity vulnerability was found in the Linux kernel, specifically in the mptcp subsystem. The vulnerability is caused by a race condition that can lead to an inconsistent fallback status. The issue arises when a TCP subflow can process a simult-connect syn-ack packet after transitioning to the TCP_FIN1 state, bypassing the MPTCP fallback check. This can cause the msk socket to move to an inconsi [truncated]

MEDIUM Linux CVE published 2026-07-14

CVE-2025-71086

CVE-2025-71086 is a HIGH severity vulnerability in the Linux kernel, caused by an invalid array index in the rose_kill_by_device() function. This can lead to an invalid socket pointer dereference and leak references taken via sock_hold(). Affected systems include Linux kernel deployments. Linux kernel developers, Linux distribution maintainers, and users of Linux-based systems should review patch guidance [truncated]

HIGH Linux CVE published 2026-07-14

CVE-2025-71085

A Linux kernel vulnerability, CVE-2025-71085, was patched. The vulnerability was caused by an implicit integer cast in __skb_cow(), leading to a BUG_ON in pskb_expand_head(). This issue arises when calipso_skbuff_setattr() passes a negative headroom size to skb_cow(). The bug can be triggered using the 'netlabelctl' tool and a specially crafted PoC. Users of affected Linux kernel versions should apply pat [truncated]

MEDIUM Linux CVE published 2026-07-14

CVE-2025-71079

A deadlock vulnerability exists in the Linux kernel, specifically in the NFC (Near Field Communication) subsystem. The issue arises from a lock ordering inversion between device_lock and rfkill_global_mutex, which can lead to a deadlock scenario. This vulnerability has been resolved through a series of patches applied to the Linux kernel's NFC subsystem.

MEDIUM Linux CVE published 2026-07-14

CVE-2025-71075

The Linux kernel was vulnerable to a use-after-free condition in the aic94xx SCSI driver. The asd_pci_remove() function did not properly synchronize with pending tasklets before freeing the asd_ha structure, potentially leading to a use-after-free vulnerability when a device removal is triggered. The vulnerability has been resolved by adding tasklet_kill() before freeing the asd_ha structure, ensuring all [truncated]

HIGH Linux CVE published 2026-07-14

CVE-2025-71064

The Linux kernel was vulnerable to an issue where the hdev->htqp was allocated using hdev->num_tqps, while kinfo->tqp was allocated using kinfo->num_tqps. However, kinfo->num_tqps was set to the minimum of new_tqps and hdev->num_tqps, potentially causing some hdev->htqp[i] to remain uninitialized. This issue has been resolved by allocating hdev->htqp and kinfo->tqp using hdev->num_tqps, ensuring consisten [truncated]

MEDIUM Linux CVE published 2026-07-14

CVE-2025-68820

A vulnerability was found in the Linux kernel, specifically in the ext4 filesystem. The issue arises when ext4_get_inode_loc() fails and returns -EFSCORRUPTED, causing iloc.bh to remain set to NULL. This leads to a null pointer dereference in ext4_raw_inode(), called immediately after ext4_get_inode_loc(). The vulnerability was discovered by the Linux Verification Center (linuxtesting.org) using SVACE. Sy [truncated]

MEDIUM Linux CVE published 2026-07-14

CVE-2025-68818

A Linux kernel vulnerability, CVE-2025-68818, was resolved by reverting a commit in the scsi: qla2xxx driver that caused a NULL pointer dereference in target-mode. The commit being reverted added code to __qla2x00_abort_all_cmds() to call sp->done() without holding a spinlock, which resulted in a jump to an invalid pointer. This issue was later addressed by adding a spinlock back to prevent a race and cra [truncated]

MEDIUM Linux CVE published 2026-07-14

CVE-2025-68816

The Linux kernel was vulnerable to a security issue in the firmware tracer, which has been resolved by adding validation for format string parameters. This vulnerability could lead to crashes or other undefined behavior if the firmware provided malformed format strings. The issue has been fixed by adding a validation function, mlx5_tracer_validate_params(), to ensure that format specifiers in trace string [truncated]

MEDIUM Linux CVE published 2026-07-14

CVE-2025-68814

A memory leak vulnerability was found in the Linux kernel's __io_openat_prep() function. The function allocates a struct filename using getname() but fails to clean up the memory when certain conditions are met, leading to a memory leak. The issue was resolved by setting the REQ_F_NEED_CLEANUP flag after a successful getname() call. This vulnerability affects Linux kernel users and administrators, who sho [truncated]

HIGH Linux CVE published 2026-07-14

CVE-2025-68803

A Linux kernel vulnerability CVE-2025-68803 was found in the NFSv4 file creation process. The issue occurs when an NFSv4 client sets an ACL with a named principal during file creation, but the ACL is not applied to the inode. This vulnerability violates RFC 8881 section 6.4.1.3. The vulnerability has a high defensive priority and requires immediate attention from system administrators and users of Linux k [truncated]

MEDIUM Linux CVE published 2026-07-14

CVE-2025-68798

A general protection fault (GPF) vulnerability was found in the Linux kernel's perf/x86/amd. The issue arises from a race condition that can cause cpuc->events[idx] to become NULL. This can be triggered by an NMI->throttle->x86_pmu_stop() sequence. To address this, a check for a NULL event was added in amd_pmu_enable_all() before enabling the event.

MEDIUM Linux CVE published 2026-07-14

CVE-2025-68788

A vulnerability in the Linux kernel's fsnotify subsystem has been addressed. The issue involves the generation of ACCESS/MODIFY events on child directories for special files, potentially allowing information exfiltration. The vulnerability has been resolved by aligning fsnotify events with the stat behavior of special files. This change ensures that users with no read access to a file but with read access [truncated]

MEDIUM Linux CVE published 2026-07-14

CVE-2025-68787

A memory leak vulnerability was found in the Linux kernel's netrom component. The vulnerability occurs in the nr_sendmsg() function, where a memory leak can occur when the sock_alloc_send_skb() function returns NULL. This can cause the system to run out of memory, leading to a denial of service. The vulnerability was reported by syzbot and fixed by freeing the skb before returning from the nr_sendmsg() function.

MEDIUM Linux CVE published 2026-07-14

CVE-2025-68782

A Linux kernel vulnerability, CVE-2025-68782, was resolved by resetting the t_task_cdb pointer in error cases to prevent NULL pointer dereferences. This vulnerability affects the Linux kernel SCSI target subsystem and could potentially allow attackers to cause a denial of service or execute arbitrary code. The fix ensures that the t_task_cdb pointer is reset to a default fixed-size buffer in case of alloc [truncated]

MEDIUM Linux CVE published 2026-07-14

CVE-2025-68776

A NULL pointer dereference vulnerability exists in the Linux kernel's net/hsr module. The vulnerability is caused by a lack of NULL checking after a call to __pskb_copy() in the prp_get_untagged_frame() function. If __pskb_copy() returns NULL, a subsequent call to skb_clone() with a NULL pointer will cause a crash. This vulnerability affects Linux kernel deployments and requires immediate attention from L [truncated]

MEDIUM Linux CVE published 2026-07-14

CVE-2025-68764

A vulnerability in the Linux kernel has been resolved, affecting NFS automounted filesystems. These filesystems do not properly inherit mount options such as 'ro', 'noexec', 'nodev', and 'sync'. This issue could potentially lead to security risks if not properly configured. Users of Linux kernel who utilize NFS automounted filesystems should review and update their configurations.

MEDIUM Linux CVE published 2026-07-13

CVE-2026-53365

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-13T18:16:28.433Z and has not been modified since then. The vulnerability affects the Linux kernel, specifically the vsock/virtio zerocopy completion for multi-skb sends. This issue allows for potential exploitation if not patched. The vulnerability arises when a large message is fragmented into mult [truncated]

MEDIUM Linux CVE published 2026-07-13

CVE-2026-53364

A memory leak vulnerability was found in the Linux kernel's Bluetooth hci_conn component. The hci_le_big_terminate() function allocates memory via kzalloc_obj but fails to free it under certain conditions, leading to a potential memory leak. This vulnerability affects the Linux kernel and could potentially be used by attackers to exploit the Bluetooth component. The vulnerability has been resolved, but Li [truncated]

CRITICAL Linux CVE published 2026-07-10

CVE-2026-53363

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-10T12:17:22.983Z and has not been modified since then. CVE-2026-53363 is a vulnerability in the Linux kernel's xfrm and iptfs components. The iptfs_consume_frags() function fails to propagate the SKBFL_SHARED_FRAG flag when transferring paged fragments from one socket buffer to another. This can cau [truncated]

HIGH Linux CVE published 2026-07-04

CVE-2026-53360

A vulnerability in the Linux kernel's KVM SEV feature allows a malicious SNP guest to corrupt host kernel heap memory and leak host heap layout information. The issue arises from the failure to enforce the use of the GHCB's shared buffer for the software scratch area when using GHCB v2+. This can be exploited to perform out-of-bounds reads and writes, leading to heap corruption and information disclosure.

HIGH Linux CVE published 2026-07-04

CVE-2026-53359

CVE-2026-53359 is a use-after-free vulnerability in the KVM x86 shadow paging functionality. The vulnerability arises from a mismatch between stored and computed GFNs (Guest Physical Addresses) in shadow paging, which can be triggered by changing a PDE (Page Directory Entry) mapping from outside the guest and then deleting a memslot. The bug was fixed by a commit that addresses the shadow paging mismatch. [truncated]

HIGH Linux CVE published 2026-07-02

CVE-2026-53358

A HIGH severity vulnerability was found in the Linux kernel Bluetooth L2CAP. The vulnerability has been resolved by using a channel timer to close channels in cleanup_listen(). This change ensures the correct lock order is maintained, preventing potential exploitation. Linux kernel users with Bluetooth L2CAP support should apply patches to mitigate this vulnerability. The patch modifies the Bluetooth L2CA [truncated]

HIGH Linux CVE published 2026-07-02

CVE-2026-53357

CVE-2026-53357 is a use-after-free vulnerability in the Linux kernel's Bluetooth subsystem. The vulnerability exists in the l2cap_sock_cleanup_listen() function, which is called when a listening socket is closed. A concurrent HCI disconnect can trigger the l2cap_conn_del() function, which frees the child socket and its l2cap_chan. The cleanup_listen() function then uses both, resulting in a use-after-free error.

HIGH Linux CVE published 2026-07-01

CVE-2026-53356

A HIGH severity vulnerability was found in the Linux kernel, specifically in the drm/i915/gem component. The vulnerability is related to phys BO pread/pwrite with offset. The sg_page() function returns a struct page pointer, not a void pointer, causing incorrect scaling in pread/pwrite operations for phys BO. This could lead to accessing incorrect parts of the BO when a non-zero offset is used. The last i [truncated]

CRITICAL Linux CVE published 2026-07-01

CVE-2026-53355

A vulnerability has been resolved in the Linux kernel, specifically in the net: rds module. The RDS IB connection teardown path is written so it can run during partial startup and on repeated shutdown attempts. It uses NULL pointers to distinguish resources that are still owned from resources that have already been released. When rds_ib_setup_qp() fails after allocating i_sends but before allocating i_rec [truncated]

HIGH Linux CVE published 2026-07-01

CVE-2026-53354

The Linux kernel has a vulnerability related to the ARM64_WORKAROUND_REPEAT_TLBI workaround for mitigating TLBI errata on various Arm CPUs. This issue affects the completion of memory accesses translated by an invalidated TLB entry but does not affect the actual invalidation of TLB entries. The vulnerability has been resolved by enabling the ARM64_WORKAROUND_REPEAT_TLBI workaround for affected CPUs and up [truncated]

MEDIUM Linux CVE published 2026-07-01

CVE-2026-53353

A vulnerability has been resolved in the Linux kernel, specifically in the hsr_addr_is_self() function. The function previously triggered a warning when the hsr->self_node was cleared, but this warning has been removed due to the possibility of a window where the device is still found but hsr->self_node is not set. This change prevents potential denial-of-service (DoS) attacks that could be triggered by t [truncated]

MEDIUM Linux CVE published 2026-07-01

CVE-2026-53352

A race condition vulnerability was found in the Linux kernel's signal handling mechanism. When a multi-threaded process receives a stop signal, the JOBCTL_PENDING_MASK is not properly cleared for the calling thread, leading to a warning and potential system instability. This issue arises from the zap_other_threads function failing to clear the JOBCTL_PENDING_MASK for the calling thread when aborting a pen [truncated]