2026-07-19
2026-07-19 16:17Z
HIGH

CVE-2026-64115 — Linux: One second later vsock_pending_work() observed is_pending=true and performed full cleanup: vsock_remove_pending() then the two

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-64115

In the Linux kernel, the following vulnerability has been resolved: vsock/vmci: fix UAF when peer resets connection during handshake vmci_transport_recv_connecting_server() returned err = 0 for a peer RST in its default switch arm: err = pkt->type == VMCI_TRANSPORT_PACKET_TYPE_RST ? 0 : -EINVAL; That made vmci_transport_recv_listen() skip vsock_remove_pending(), leaving the pending socket on the listener's pending_links with sk_state = TCP_CLOSE while destroy: still drop CVSSv3.1 8.8 (HIGH)

TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-07-19
2026-07-19 16:17Z
CRIT

CVE-2026-64113 — Linux: In the Linux kernel, the following vulnerability has been resolved: ixgbevf: fix use-after-free in

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-64113

In the Linux kernel, the following vulnerability has been resolved: ixgbevf: fix use-after-free in VEPA multicast source pruning ixgbevf_clean_rx_irq() prunes frames whose source MAC matches the VF's own address (VEPA multicast workaround) by freeing the skb and continuing to the next descriptor: dev_kfree_skb_irq(skb); continue; The skb pointer is declared outside the while loop and persists across iterations. Because the continue skips the "skb = NULL" reset at CVSSv3.1 9.8 (CRITICAL)

TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-07-19
2026-07-19 16:17Z
HIGH

CVE-2026-64109 — Linux: In the Linux kernel, the following vulnerability has been resolved: af_unix: Fix UAF read

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-64109

In the Linux kernel, the following vulnerability has been resolved: af_unix: Fix UAF read of tail->len in unix_stream_data_wait() unix_stream_data_wait() does skb_peek_tail(&sk->sk_receive_queue) without holding any lock that prevents SKBs on that queue from being dequeued and freed. This has been the case since commit 79f632c71bea ("unix/stream: fix peeking with an offset larger than data in queue"). The first consequence of this is that the pointer comparison `tail != las CVSSv3.1 8.8 (HIGH)

TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-07-19
2026-07-19 16:17Z
CRIT

CVE-2026-64106 — Linux: In the Linux kernel, the following vulnerability has been resolved: KVM: arm64: vgic-its: Reject

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-64106

In the Linux kernel, the following vulnerability has been resolved: KVM: arm64: vgic-its: Reject restored DTE with out-of-range num_eventid_bits Userspace can restore an ITS Device Table Entry whose Size field encodes more EventID bits than the virtual ITS supports. The live MAPD path rejects that state, but vgic_its_restore_dte() accepts it and stores the out-of-range value in dev->num_eventid_bits. Reject restored DTEs with num_eventid_bits > VITS_TYPER_IDBITS before al CVSSv3.1 9.0 (CRITICAL)

TYPVulnerability
9.0
CVSS v3.1
95
Edit Score
2026-07-19
2026-07-19 16:17Z
HIGH

CVE-2026-64104 — Linux: In the Linux kernel, the following vulnerability has been resolved: virt: sev-guest: Explicitly leak

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-64104

In the Linux kernel, the following vulnerability has been resolved: virt: sev-guest: Explicitly leak pages in unknown state When set_memory_{encrypted,decrypted}() fail, the user cannot know at which point the function failed, meaning that the pages are left in an unknown state from the point of view of the caller. Since the pages may be left in an unencrypted state, they are not suitable for general use, and cannot be returned safely to the buddy allocator. Avoid the issu CVSSv3.1 8.7 (HIGH)

TYPVulnerability
8.7
CVSS v3.1
94
Edit Score
2026-07-19
2026-07-19 16:17Z
CRIT

CVE-2026-64102 — Linux: KASAN under a KUnit harness that drives the real kernel TCP receive path --

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-64102

In the Linux kernel, the following vulnerability has been resolved: RDMA/siw: Reject MPA FPDU length underflow before signed receive math A malicious connected siw peer can send an iWARP FPDU whose MPA length field (c_hdr->mpa_len, 16 bit big-endian, peer-controlled) is smaller than the fixed DDP/RDMAP header for the announced opcode. Soft-iWARP parses the full header in siw_get_hdr() based on iwarp_pktinfo[opcode] .hdr_len, but never compares mpa_len against that header le CVSSv3.1 9.8 (CRITICAL)

TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-07-19
2026-07-19 16:17Z
HIGH

CVE-2026-64096 — Linux: In the Linux kernel, the following vulnerability has been resolved: batman-adv: mcast: fix use-after-free

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-64096

In the Linux kernel, the following vulnerability has been resolved: batman-adv: mcast: fix use-after-free in orig_node RCU release batadv_mcast_purge_orig() removes entries from RCU-protected hlists but does not wait for an RCU grace period before returning. Concurrent RCU readers may still accesses references to those entries at the point of removal. RCU-protected readers trying to operate on entries like orig->mcast_want_all_ipv6_node will then access already freed memory CVSSv3.1 8.8 (HIGH)

TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
728 × 90 / responsive · programmatic ad slot
2026-07-19
2026-07-19 16:17Z
HIGH

CVE-2026-64093 — Linux: In the Linux kernel, the following vulnerability has been resolved: batman-adv: tp_meter: directly shut

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-64093

In the Linux kernel, the following vulnerability has been resolved: batman-adv: tp_meter: directly shut down timer on cleanup batadv_tp_sender_cleanup() was calling timer_delete_sync() followed by timer_delete() to guard against the timer handler re-arming itself between the two calls. This double-deletion hack relied on the sending status being set to 0 to suppress re-arming. Replace both calls with a single timer_shutdown_sync(). This function both waits for any running CVSSv3.1 8.8 (HIGH)

TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-07-19
2026-07-19 16:17Z
CRIT

CVE-2026-64091 — Linux: In the Linux kernel, the following vulnerability has been resolved: batman-adv: tt: fix TOCTOU

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-64091

In the Linux kernel, the following vulnerability has been resolved: batman-adv: tt: fix TOCTOU race for reported vlans The local TT based TVLV is generated by first checking the number of VLANs which have at least one TT entry. A new buffer with the correct size for the VLANs is then allocated. Only then, the list of VLANs s used to fill the VLAN entries in the buffer. During this time, the meshif_vlan_list_lock is held. But the actual number of TT entries of each VLAN can CVSSv3.1 9.8 (CRITICAL)

TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-07-19
2026-07-19 16:17Z
CRIT

CVE-2026-64089 — Linux: In the Linux kernel, the following vulnerability has been resolved: batman-adv: tt: fix negative

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-64089

In the Linux kernel, the following vulnerability has been resolved: batman-adv: tt: fix negative last_changeset_len batadv_piv_tt::last_changeset_len len was declared as s16, but the field is never intended to hold a negative value. When a value greater than 32767 is assigned, it wraps to a negative signed integer. In batadv_send_my_tt_response(), last_changeset_len is temporarily widened to s32. The incorrectly negative s16 value propagates into the s32, causing batadv_tt CVSSv3.1 9.8 (CRITICAL)

TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-07-19
2026-07-19 16:17Z
HIGH

CVE-2026-64088 — Linux: In the Linux kernel, the following vulnerability has been resolved: batman-adv: tt: fix negative

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-64088

In the Linux kernel, the following vulnerability has been resolved: batman-adv: tt: fix negative tt_buff_len batadv_orig_node::tt_buff_len was declared as s16, but the field is never intended to hold a negative value. When a value greater than 32767 is assigned, it wraps to a negative signed integer. In batadv_send_other_tt_response(), tt_buff_len is temporarily widened to s32. The incorrectly negative s16 value propagates into the s32, causing batadv_tt_prepare_tvlv_globa CVSSv3.1 8.8 (HIGH)

TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-07-19
2026-07-19 16:17Z
HIGH

CVE-2026-64081 — Linux: Use the validated offset and size values for both kmemdup() and the UUID parsing

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-64081

In the Linux kernel, the following vulnerability has been resolved: firmware: arm_ffa: Validate framework notification message layout Framework notifications carry an indirect message in the shared RX buffer. Validate the reported offset and size before using them, reject zero-length payloads, and ensure that any non-header payload starts at the UUID field rather than in the middle of the message header. Use the validated offset and size values for both kmemdup() and the U CVSSv3.1 8.4 (HIGH)

TYPVulnerability
8.4
CVSS v3.1
92
Edit Score
2026-07-19
2026-07-19 16:17Z
CRIT

CVE-2026-64080 — Linux: This keeps the existing callback execution model while removing the use-after-free window in both

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-64080

In the Linux kernel, the following vulnerability has been resolved: firmware: arm_ffa: Snapshot notifier callbacks under lock Both notification handlers currently look up a notifier callback under notify_lock, drop the lock, and then dereference the returned notifier entry. A concurrent unregister can delete and free that entry in the gap, leaving the handler to dereference stale memory. Copy the callback pointer and callback data while notify_lock is still held and invoke CVSSv3.1 9.3 (CRITICAL)

TYPVulnerability
9.3
CVSS v3.1
97
Edit Score
2026-07-19
2026-07-19 16:17Z
CRIT

CVE-2026-64069 — Linux: In the Linux kernel, the following vulnerability has been resolved: netfs: Fix cancellation of

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-64069

In the Linux kernel, the following vulnerability has been resolved: netfs: Fix cancellation of a DIO and single read subrequests When the preparation of a new subrequest for a read fails, if the subrequest has already been added to the stream->subrequests list, it can't simply be put and abandoned as the collector may see it. Also, if it hasn't been queued yet, it has two outstanding refs that both need to be put. Both DIO read and single-read dispatch fail at this; furth CVSSv3.1 9.8 (CRITICAL)

TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-07-19
2026-07-19 16:17Z
CRIT

CVE-2026-64068 — Linux: In the Linux kernel, the following vulnerability has been resolved: netfs: Fix missing locking

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-64068

In the Linux kernel, the following vulnerability has been resolved: netfs: Fix missing locking around retry adding new subreqs Fix netfs_retry_read_subrequests() and netfs_retry_write_stream() to take the appropriate lock when adding extra subrequests into stream->subrequests. CVSSv3.1 9.8 (CRITICAL)

TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-07-19
2026-07-19 16:17Z
CRIT

CVE-2026-64067 — Linux: In the Linux kernel, the following vulnerability has been resolved: netfs: Fix missing barriers

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-64067

In the Linux kernel, the following vulnerability has been resolved: netfs: Fix missing barriers when accessing stream->subrequests locklessly The list of subrequests attached to stream->subrequests is accessed without locks by netfs_collect_read_results() and netfs_collect_write_results(), and then they access subreq->flags without taking a barrier after getting the subreq pointer from the list. Relatedly, the functions that build the list don't use any sort of write barri CVSSv3.1 9.8 (CRITICAL)

TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-07-19
2026-07-19 16:17Z
CRIT

CVE-2026-64066 — Linux: In the Linux kernel, the following vulnerability has been resolved: netfs: Fix netfs_read_to_pagecache() to

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-64066

In the Linux kernel, the following vulnerability has been resolved: netfs: Fix netfs_read_to_pagecache() to pause on subreq failure Fix netfs_read_to_pagecache() so that it pauses the generation of new subrequests if an already-issued subrequest fails. CVSSv3.1 9.8 (CRITICAL)

TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-07-19
2026-07-19 16:17Z
CRIT

CVE-2026-64061 — Linux: The bug was found by KASAN detecting a UAF on the generic/075 xfstest in

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-64061

In the Linux kernel, the following vulnerability has been resolved: netfs: Fix early put of sink folio in netfs_read_gaps() Fix netfs_read_gaps() to release the sink page it uses after waiting for the request to complete. The way the sink page is used is that an ITER_BVEC-class iterator is created that has the gaps from the target folio at either end, but has the sink page tiled over the middle so that a single read op can fill in both gaps. The bug was found by KASAN det CVSSv3.1 9.8 (CRITICAL)

TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-07-19
2026-07-19 16:17Z
CRIT

CVE-2026-64056 — Linux: In the Linux kernel, the following vulnerability has been resolved: net: ethernet: cortina: Make

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-64056

In the Linux kernel, the following vulnerability has been resolved: net: ethernet: cortina: Make RX SKB per-port The SKB used to assemble packets from fragments in gmac_rx() is static local, but the Gemini has two ethernet ports, meaning there can be races between the ports on a bad day if a device is using both. Make the RX SKB a per-port variable and carry it over between invocations in the port struct instead. Zero the pointer once we call napi_gro_frags(), on error (a CVSSv3.1 9.8 (CRITICAL)

TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-07-19
2026-07-19 16:17Z
CRIT

CVE-2026-64055 — Linux: In the Linux kernel, the following vulnerability has been resolved: net: ethernet: cortina: Carry

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-64055

In the Linux kernel, the following vulnerability has been resolved: net: ethernet: cortina: Carry over frag counter The gmac_rx() NAPI poll function assembles packets in an SKB from a ring buffer. If the ring buffer gets completely emptied during a poll cycle, we exit gmac_rx(), but the packet is not yet completely assembled in the SKB, yet the fragment counter frag_nr is reset to zero on the next invocation. Solve this by making the RX fragment counter a part of the port CVSSv3.1 9.8 (CRITICAL)

TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-07-19
2026-07-19 16:17Z
CRIT

CVE-2026-64047 — Linux: In the Linux kernel, the following vulnerability has been resolved: net: tls: fix off-by-one

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-64047

In the Linux kernel, the following vulnerability has been resolved: net: tls: fix off-by-one in sg_chain entry count for wrapped sk_msg ring When an sk_msg scatterlist ring wraps (sg.end < sg.start), tls_push_record() chains the tail portion of the ring to the head using sg_chain(). An extra entry in the sg array is reserved for this: struct sk_msg_sg { [...] /* The extra two elements: * 1) used for chaining the front and sections when the list b CVSSv3.1 9.8 (CRITICAL)

TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-07-19
2026-07-19 16:17Z
CRIT

CVE-2026-64046 — Linux: In the Linux kernel, the following vulnerability has been resolved: net: tls: prevent chain-after-chain

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-64046

In the Linux kernel, the following vulnerability has been resolved: net: tls: prevent chain-after-chain in plain text SG Sashiko points out that if end = 0 (start != 0) the current code will create a chain link to content type right after the wrap link: This would create a chain where the wrap link points directly to another chain link. The scatterlist API sg_next iterator does not recursively resolve consecutive chain links. meaning this is illegal input to crypto. CVSSv3.1 9.8 (CRITICAL)

TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-07-19
2026-07-19 16:17Z
HIGH

CVE-2026-64045 — Linux: In the Linux kernel, the following vulnerability has been resolved: ovpn: tcp - use

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-64045

In the Linux kernel, the following vulnerability has been resolved: ovpn: tcp - use cached peer pointer in ovpn_tcp_close() ovpn_tcp_close() loads the ovpn_socket via rcu_dereference_sk_user_data() under rcu_read_lock(), takes a reference on sock->peer, caches the peer pointer in a local, and drops the read lock. It then passes sock->peer (rather than the cached local) to ovpn_peer_del(), re-dereferencing the ovpn_socket after the RCU read section has ended. Unlike ovpn_tc CVSSv3.1 8.4 (HIGH)

TYPVulnerability
8.4
CVSS v3.1
92
Edit Score
2026-07-19
2026-07-19 16:17Z
HIGH

CVE-2026-64042 — Linux: In the Linux kernel, the following vulnerability has been resolved: vfio/pci: Check BAR resources

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-64042

In the Linux kernel, the following vulnerability has been resolved: vfio/pci: Check BAR resources before exporting a DMABUF A DMABUF exports access to BAR resources and, although they are requested at startup time, we need to ensure they really were reserved before exporting. Otherwise, it's possible to access unreserved resources through the export. Add a check to the DMABUF-creation path. CVSSv3.1 8.8 (HIGH)

TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-07-19
2026-07-19 16:17Z
CRIT

CVE-2026-64037 — Linux: This floods the TX ring with ~1024 micro-frames (the rest are purged), creating a

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-64037

In the Linux kernel, the following vulnerability has been resolved: wifi: iwlwifi: mld: fix TSO segmentation explosion when AMSDU is disabled When the TLC notification disables AMSDU for a TID, the MLD driver sets max_tid_amsdu_len to the sentinel value 1. The TSO segmentation path in iwl_mld_tx_tso_segment() checks for zero but not for this sentinel, allowing it to reach the num_subframes calculation: num_subframes = (max_tid_amsdu_len + pad) / (subf_len + pad) CVSSv3.1 9.8 (CRITICAL)

TYPVulnerability
9.8
CVSS v3.1
99
Edit Score