4d ago
2026-07-26 07:16Z
CRIT

CVE-2026-64530 — Linux: In the Linux kernel, the following vulnerability has been resolved: net/sched: cls_api: Handle TC_ACT_CONSUMED

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-64530

In the Linux kernel, the following vulnerability has been resolved: net/sched: cls_api: Handle TC_ACT_CONSUMED in tcf_qevent_handle tcf_classify() can return TC_ACT_CONSUMED while the skb is held by the defragmentation engine (e.g. act_ct on out-of-order fragments). When that happens the skb is no longer owned by the caller and must not be touched again. tcf_qevent_handle() did not handle TC_ACT_CONSUMED: it fell through the switch and returned the skb to the caller as if CVSSv3.1 9.8 (CRITICAL) · EPSS 7th percentile

TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
5d ago
2026-07-26 02:16Z
HIGH

CVE-2026-15962 — Fluent: The Fluent Forms Pro Add On Pack plugin for WordPress is vulnerable to PHP

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-15962

The Fluent Forms Pro Add On Pack plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 6.2.6 via deserialization of untrusted input. This makes it possible for authenticated attackers, with Subscriber-level access and above, to inject a PHP Object. The additional presence of a POP chain allows attackers to change user passwords and potentially take over administrator accounts. Note: This can only be exploited if user update integrati CVSSv3.1 8.8 (HIGH)

CWECWE 502VNDFluentTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
5d ago
2026-07-25 11:17Z
CRIT

CVE-2026-66012 — SiYuan: before v3.7.2 contains a missing authorization vulnerability in the POST /mcp kernel endpoint

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-66012

SiYuan before v3.7.2 contains a missing authorization vulnerability in the POST /mcp kernel endpoint, which is gated only by a general auth check (model.CheckAuth) with no admin-role or read-only enforcement. This exposes 31 MCP tools, including a file tool with list/read/write/delete/rename/copy actions across the entire workspace. When the Publish server is enabled in anonymous mode (Conf.Publish.Enable=true and Conf.Publish.Auth.Enable=false), the Publish reverse proxy att CVSSv3.1 10.0 (CRITICAL)

CWECWE 862VNDSiyuanTYPVulnerability
10.0
CVSS v3.1
100
Edit Score
5d ago
2026-07-25 10:17Z
CRIT

CVE-2026-64523 — Linux: In the Linux kernel, the following vulnerability has been resolved: net/handshake: Take a long-lived

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-64523

In the Linux kernel, the following vulnerability has been resolved: net/handshake: Take a long-lived file reference at submit handshake_nl_accept_doit() needs the file pointer backing req->hr_sk->sk_socket to survive the window between handshake_req_next() and the subsequent FD_PREPARE() and get_file(). The submit-side sock_hold() does not provide that. sk_refcnt keeps struct sock alive, but struct socket is owned by sock->file: when the consumer fputs the last file refere CVSSv3.1 9.8 (CRITICAL) · EPSS 11th percentile

TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
5d ago
2026-07-25 10:17Z
HIGH

CVE-2026-64522 — Linux: In the Linux kernel, the following vulnerability has been resolved: net/mlx5e: Fix eswitch mode

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-64522

In the Linux kernel, the following vulnerability has been resolved: net/mlx5e: Fix eswitch mode block underflow on IPsec acquire SA mlx5e_xfrm_add_state() handles acquire-flow temporary SAs by allocating software state and skipping hardware offload setup. That path jumps to the common success label before taking the eswitch mode block. After tunnel-mode validation was moved earlier, the common success label unconditionally calls mlx5_eswitch_unblock_mode(). For acquire SAs CVSSv3.1 8.8 (HIGH) · EPSS 11th percentile

TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
5d ago
2026-07-25 10:17Z
HIGH

CVE-2026-64520 — Linux: In the Linux kernel, the following vulnerability has been resolved: firmware: arm_ffa: Bound PARTITION_INFO_GET_REGS

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-64520

In the Linux kernel, the following vulnerability has been resolved: firmware: arm_ffa: Bound PARTITION_INFO_GET_REGS copies The register-based PARTITION_INFO_GET path trusted the firmware-provided indices when copying partition descriptors into the caller buffer. Reject inconsistent counts or index progressions so the copy loop cannot write past the allocated array. (fixed cur_idx when exactly one descriptor in the first fragment) CVSSv3.1 8.4 (HIGH) · EPSS 11th percentile

TYPVulnerability
8.4
CVSS v3.1
92
Edit Score
5d ago
2026-07-25 10:17Z
HIGH

CVE-2026-64516 — Linux: Subtract this from the FW size to make sure there is no out of

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-64516

In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu/vce1: Fix VCE 1 firmware size and offsets The VCPU BO contains the actual FW at an offset, but it was not calculated into the VCPU BO size. Subtract this from the FW size to make sure there is no out of bounds access. Make sure the stack and data offsets are aligned to the 32K TLB size. Check that the FW microcode actually fits in the space that is reserved for it. (cherry picked from commit c CVSSv3.1 8.8 (HIGH) · EPSS 10th percentile

TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
728 × 90 / responsive · programmatic ad slot
5d ago
2026-07-25 10:17Z
HIGH

CVE-2026-64515 — Linux: This is incorrect for two reasons: - if the original defragmentation was needed, it

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-64515

In the Linux kernel, the following vulnerability has been resolved: wifi: mac80211: fix MLE defragmentation If either reconf or EPCS multi-link element (MLE) is contained in a non-transmitted profile, the defragmentation routine is called with a pointer to the defragmented copy, but the original elements. This is incorrect for two reasons: - if the original defragmentation was needed, it will not find the correct data - if the original frame is at a higher address, th CVSSv3.1 8.3 (HIGH) · EPSS 11th percentile

TYPVulnerability
8.3
CVSS v3.1
92
Edit Score
5d ago
2026-07-25 10:17Z
HIGH

CVE-2026-64490 — Linux: A buggy or malicious device can therefore trigger out-of-bounds access by advertising an invalid

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-64490

In the Linux kernel, the following vulnerability has been resolved: ALSA: virtio: Validate control metadata from the device virtio-snd control handling trusts the device-provided control type and value count returned by the device. That metadata is then used directly to index g_v2a_type_map[] in virtsnd_kctl_info(), and to size loops and memcpy() operations in virtsnd_kctl_get() and virtsnd_kctl_put() against fixed-size virtio_snd_ctl_value and snd_ctl_elem_value arrays. CVSSv3.1 8.4 (HIGH) · EPSS 11th percentile

TYPVulnerability
8.4
CVSS v3.1
92
Edit Score
5d ago
2026-07-25 10:17Z
HIGH

CVE-2026-64475 — Linux: In the Linux kernel, the following vulnerability has been resolved: vfio/pci: Release the VGA

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-64475

In the Linux kernel, the following vulnerability has been resolved: vfio/pci: Release the VGA arbiter client on register_device() failure The re-order in the Fixes commit below displaced vfio_pci_vga_init() as the last failure point of what is now vfio_pci_core_register_device() without introducing an unwind for the VGA arbiter registration. In current kernels this is mostly benign because vfio_pci_set_decode() only uses pci_dev state, but the original failure path could l CVSSv3.1 8.8 (HIGH) · EPSS 13th percentile

TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
5d ago
2026-07-25 10:17Z
HIGH

CVE-2026-64467 — Linux: In the Linux kernel, the following vulnerability has been resolved: rust_binder: use a u64

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-64467

In the Linux kernel, the following vulnerability has been resolved: rust_binder: use a u64 stride when cleaning up the offsets array Allocation's Drop walks the offsets array (binder_size_t = u64 entries), cleaning up the objects, but it used usize instead of u64 for both the stride and the per-entry read. On 64-bit kernels (usize == u64) this is harmless, but on 32-bit kernels it walks the 8-byte entries in 4-byte steps, iterating an N-entry array 2N times, and reads the CVSSv3.1 8.8 (HIGH) · EPSS 11th percentile

TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
5d ago
2026-07-25 10:17Z
CRIT

CVE-2026-64459 — Linux: In the Linux kernel, the following vulnerability has been resolved: tcp: restore RCU grace

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-64459

In the Linux kernel, the following vulnerability has been resolved: tcp: restore RCU grace period in tcp_ao_destroy_sock Commit 51e547e8c89c ("tcp: Free TCP-AO/TCP-MD5 info/keys without RCU") removed the call_rcu() callback from tcp_ao_destroy_sock(), arguing that "the destruction of info/keys is delayed until the socket destructor" and therefore "no one can discover it anymore". That argument does not hold for the call site in tcp_connect() (net/ipv4/tcp_output.c:4327-433 CVSSv3.1 9.8 (CRITICAL) · EPSS 11th percentile

TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
5d ago
2026-07-25 10:17Z
CRIT

CVE-2026-64450 — Linux: In the Linux kernel, the following vulnerability has been resolved: tipc: fix out-of-bounds read

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-64450

In the Linux kernel, the following vulnerability has been resolved: tipc: fix out-of-bounds read in broadcast Gap ACK blocks A broadcast PROTOCOL/STATE_MSG can carry a Gap ACK blocks record in its data area. tipc_get_gap_ack_blks() only verifies that the record's len field is self-consistent with its ugack_cnt/bgack_cnt counts (sz == struct_size(p, gacks, ugack_cnt + bgack_cnt)); it does not check that the record actually fits in the message data area, msg_data_sz(). The u CVSSv3.1 9.1 (CRITICAL) · EPSS 13th percentile

TYPVulnerability
9.1
CVSS v3.1
96
Edit Score
5d ago
2026-07-25 10:17Z
HIGH

CVE-2026-64448 — Linux: The resulting out-of-bounds reads are visible under KASAN when mounting against a non-conforming server

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-64448

In the Linux kernel, the following vulnerability has been resolved: smb: client: restrict implied bcc[0] exemption to responses without data area smb2_check_message() has a long-standing quirk that accepts a response whose calculated length is one byte larger than the bytes actually received ("server can return one byte more due to implied bcc[0]"). This was introduced to accommodate servers that omit the trailing bcc[0] overlap byte when no data area is present. However, CVSSv3.1 8.2 (HIGH) · EPSS 13th percentile

TYPVulnerability
8.2
CVSS v3.1
91
Edit Score
5d ago
2026-07-25 10:17Z
HIGH

CVE-2026-64445 — Linux: In the Linux kernel, the following vulnerability has been resolved: staging: rtl8723bs: fix WEP

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-64445

In the Linux kernel, the following vulnerability has been resolved: staging: rtl8723bs: fix WEP length underflow and OOB read in OnAuth() OnAuth() has two bugs in the shared-key authentication path. When the Privacy bit is set, rtw_wep_decrypt() is called without verifying that the frame is long enough to contain a valid WEP IV and ICV. Inside rtw_wep_decrypt(), length is computed as: length = len - WLAN_HDR_A3_LEN - iv_len and then passed as (length - 4) to crc32_l CVSSv3.1 8.8 (HIGH) · EPSS 18th percentile

TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
5d ago
2026-07-25 10:17Z
HIGH

CVE-2026-64444 — Linux: In the Linux kernel, the following vulnerability has been resolved: staging: rtl8723bs: fix OOB

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-64444

In the Linux kernel, the following vulnerability has been resolved: staging: rtl8723bs: fix OOB read in OnAssocRsp() IE loop The IE parsing loop in OnAssocRsp() advances by (pIE->length + 2) each iteration but only guards on i < pkt_len. When a malicious AP sends an AssocResponse whose last IE has only one byte remaining in the frame (the element_id byte lands at pkt_len-1), the loop reads pIE->length from pframe[pkt_len], which is one byte past the allocated receive buffer CVSSv3.1 8.1 (HIGH) · EPSS 12th percentile

TYPVulnerability
8.1
CVSS v3.1
91
Edit Score
5d ago
2026-07-25 10:17Z
HIGH

CVE-2026-64443 — Linux: In the Linux kernel, the following vulnerability has been resolved: staging: rtl8723bs: fix OOB

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-64443

In the Linux kernel, the following vulnerability has been resolved: staging: rtl8723bs: fix OOB read in update_beacon_info() IE loop The IE parsing loop in update_beacon_info() advances by (pIE->length + 2) each iteration but only guards on i < len. When a malicious AP sends a Beacon whose last IE has only one byte remaining in the frame (the element_id byte lands at len-1), the loop reads pIE->length from one byte past the allocated receive buffer. Additionally, even when CVSSv3.1 8.1 (HIGH) · EPSS 12th percentile

TYPVulnerability
8.1
CVSS v3.1
91
Edit Score
5d ago
2026-07-25 10:17Z
HIGH

CVE-2026-64442 — Linux: In the Linux kernel, the following vulnerability has been resolved: staging: rtl8723bs: fix OOB

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-64442

In the Linux kernel, the following vulnerability has been resolved: staging: rtl8723bs: fix OOB reads in IE loops in issue_assocreq() and join_cmd_hdl() Two IE parsing loops are missing the header bounds checks before they dereference pIE->length: - issue_assocreq() walks pmlmeinfo->network.ies to build the association request. If the stored IE data ends with only an element_id byte and no length byte, pIE->length is read one byte past the end of the buffer. - CVSSv3.1 8.1 (HIGH) · EPSS 13th percentile

TYPVulnerability
8.1
CVSS v3.1
91
Edit Score
5d ago
2026-07-25 10:17Z
HIGH

CVE-2026-64441 — Linux: In the Linux kernel, the following vulnerability has been resolved: staging: rtl8723bs: fix OOB

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-64441

In the Linux kernel, the following vulnerability has been resolved: staging: rtl8723bs: fix OOB reads in rtw_get_sec_ie(), rtw_get_wapi_ie(), and rtw_get_wps_attr() Three IE/attribute parsing functions have missing bounds checks. rtw_get_sec_ie() and rtw_get_wapi_ie() iterate over a raw IE buffer without verifying that the header bytes (tag + length) are within the remaining buffer before reading them. Additionally, rtw_get_sec_ie() compares the 4-byte WPA OUI at cnt+2 wi CVSSv3.1 8.8 (HIGH) · EPSS 12th percentile

TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
5d ago
2026-07-25 10:17Z
HIGH

CVE-2026-64440 — Linux: Because pIE->length is a raw u8 from an over-the-air 802.11 AssocResponse frame and is

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-64440

In the Linux kernel, the following vulnerability has been resolved: staging: rtl8723bs: fix OOB write in HT_caps_handler() HT_caps_handler() iterates pIE->length bytes and writes into HT_caps.u.HT_cap[], which is a fixed 26-byte array (sizeof struct HT_caps_element). Because pIE->length is a raw u8 from an over-the-air 802.11 AssocResponse frame and is never validated, a malicious AP can set it up to 255, causing up to 229 bytes of out-of-bounds writes into adjacent fields CVSSv3.1 8.1 (HIGH) · EPSS 13th percentile

TYPVulnerability
8.1
CVSS v3.1
91
Edit Score
5d ago
2026-07-25 10:17Z
CRIT

CVE-2026-64439 — Linux: KASAN report under UML+SLUB with a synthetic async aead backend bound to krb5->encrypt_name: BUG

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-64439

In the Linux kernel, the following vulnerability has been resolved: crypto: krb5 - filter out async aead implementations at alloc krb5_aead_encrypt(), krb5_aead_decrypt() in rfc3961_simplified.c and rfc8009_encrypt(), rfc8009_decrypt() in rfc8009_aes2.c set a NULL completion callback and treat any negative return from crypto_aead_{encrypt,decrypt}() as terminal, falling through to kfree_sensitive(buffer). When the encrypt_name resolves to an async AEAD instance the request CVSSv3.1 9.8 (CRITICAL) · EPSS 11th percentile

TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
5d ago
2026-07-25 10:17Z
HIGH

CVE-2026-64438 — Linux: This manifests as a use-after-free when KASAN is enabled: BUG: KASAN: null-ptr-deref in mutex_lock+0x76/0xe0

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-64438

In the Linux kernel, the following vulnerability has been resolved: crypto: qat - fix VF2PF work teardown race in adf_disable_sriov() The VF2PF interrupt handler queues PF-side response work that stores a raw pointer to per-VF state (struct adf_accel_vf_info). Currently, adf_disable_sriov() destroys per-VF mutexes and frees vf_info without stopping new VF2PF work or waiting for in-flight workers to complete. A concurrently scheduled or already queued worker can then derefer CVSSv3.1 8.8 (HIGH) · EPSS 13th percentile

TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
5d ago
2026-07-25 10:17Z
HIGH

CVE-2026-64437 — Linux: In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix use-after-free of

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-64437

In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix use-after-free of a deferred file_lock on SMB2_CLOSE then SMB2_CANCEL Commit f580d27e8928 ("ksmbd: fix use-after-free of a deferred file_lock on double SMB2_CANCEL") made smb2_cancel() skip a work whose state is KSMBD_WORK_CANCELLED, so its cancel_fn cannot be fired a second time. But KSMBD_WORK has three states (ACTIVE, CANCELLED, CLOSED), and the same freeing producer path is reached for CLOSED CVSSv3.1 8.8 (HIGH) · EPSS 12th percentile

TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
5d ago
2026-07-25 10:17Z
HIGH

CVE-2026-64435 — Linux: In the Linux kernel, the following vulnerability has been resolved: audit: Fix data races

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-64435

In the Linux kernel, the following vulnerability has been resolved: audit: Fix data races of skb_queue_len() readers on audit_queue Multiple readers access audit_queue.qlen via skb_queue_len() without holding the queue lock or using READ_ONCE(), while kauditd writes to this field via the skb_dequeue() → __skb_unlink() path with WRITE_ONCE() protected by a spinlock. This constitutes data races. All affected skb_queue_len(&audit_queue) call sites: - kauditd_thread() wait_e CVSSv3.1 8.2 (HIGH) · EPSS 13th percentile

TYPVulnerability
8.2
CVSS v3.1
91
Edit Score
5d ago
2026-07-25 10:17Z
HIGH

CVE-2026-64434 — Linux: If the connection is torn down while the timer is running or pending, chan->conn

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-64434

In the Linux kernel, the following vulnerability has been resolved: Bluetooth: L2CAP: Fix UAF in channel timeout by holding conn ref l2cap_chan_timeout() runs asynchronously and accesses chan->conn. If the connection is torn down while the timer is running or pending, chan->conn can be freed, leading to a use-after-free when the timer worker attempts to lock conn->lock: | BUG: KASAN: slab-use-after-free in instrument_atomic_read_write include/linux/instrumented.h:112 [inli CVSSv3.1 8.8 (HIGH) · EPSS 11th percentile

TYPVulnerability
8.8
CVSS v3.1
94
Edit Score