| CVE-2026-10681 |
SMP race in `thread_idx_alloc()` lets concurrent `k_object_alloc(K_OBJ_THREAD)` callers share a kernel-object permission slot |
25.07.2026 |
6.5 |
| CVE-2026-66011 |
ImageMagick before 7.1.2-27 Memory Leak via Invalid CLI Options |
25.07.2026 |
|
| CVE-2026-66012 |
SiYuan before v3.7.2 Unauthenticated Administrator Takeover via MCP |
25.07.2026 |
|
| CVE-2026-66013 |
OpenRemote before 1.26.2 Authentication Bypass via Console Registration |
25.07.2026 |
|
| CVE-2026-64523 |
net/handshake: Take a long-lived file reference at submit |
25.07.2026 |
|
| CVE-2026-64524 |
drm/hyperv: validate resolution_count and fix WIN8 fallback |
25.07.2026 |
|
| CVE-2026-64525 |
xfrm: move policy_bydst RCU sync from per-netns .exit to .pre_exit |
25.07.2026 |
|
| CVE-2026-64526 |
ethtool: tsconfig: fix missing ethnl_ops_complete() |
25.07.2026 |
|
| CVE-2026-64527 |
drm/hyperv: validate VMBus packet size in receive callback |
25.07.2026 |
|
| CVE-2026-64528 |
tty: serial: samsung: Remove redundant port lock acquisition in rx helpers |
25.07.2026 |
|
| CVE-2026-64529 |
crypto: qat - remove unused character device and IOCTLs |
25.07.2026 |
|
| CVE-2026-64256 |
xfs: don't wrap around quota ids in dqiterate |
25.07.2026 |
|
| CVE-2026-64257 |
smb: client: reject overlapping data areas in SMB2 responses |
25.07.2026 |
|
| CVE-2026-64258 |
fuse-uring: remove request-less entries from ent_w_req_queue to fix NULL deref |
25.07.2026 |
|
| CVE-2026-64259 |
fuse-uring: make a fuse_req on SQE commit only findable after memcpy |
25.07.2026 |
|
| CVE-2026-64260 |
fuse-uring: Avoid queue->stopped races and set/read that value under lock |
25.07.2026 |
|
| CVE-2026-64261 |
fuse-uring: Avoid use-after-free in fuse_uring_async_stop_queues |
25.07.2026 |
|
| CVE-2026-64262 |
fuse-uring: end fuse_req on io-uring cancel task work |
25.07.2026 |
|
| CVE-2026-64263 |
fuse-uring: fix moving cancelled entry to ent_in_userspace list |
25.07.2026 |
|
| CVE-2026-64264 |
fuse-uring: fix EFAULT clobber in fuse_uring_commit |
25.07.2026 |
|
| CVE-2026-64265 |
fuse: clear intr_entry in fuse_resend and fuse_remove_pending_req |
25.07.2026 |
|
| CVE-2026-64266 |
fuse: re-lock request before returning from fuse_ref_folio() |
25.07.2026 |
|
| CVE-2026-64267 |
fuse: avoid 32-bit prune notification count wrap |
25.07.2026 |
|
| CVE-2026-64268 |
RDMA/siw: bound Read Response placement to the RREAD length |
25.07.2026 |
|
| CVE-2026-64269 |
RDMA/rtrs-srv: Bound RDMA-Write length to chunk size in rdma_write_sg |
25.07.2026 |
|
| CVE-2026-64270 |
Input: mms114 - reject an oversized device packet size |
25.07.2026 |
|
| CVE-2026-64271 |
Input: touchwin - reset the packet index on every complete packet |
25.07.2026 |
|
| CVE-2026-64272 |
Input: mms114 - fix touch indexing for MMS134S and MMS136 |
25.07.2026 |
|
| CVE-2026-64273 |
Input: iforce - bound the device-reported force-feedback effect index |
25.07.2026 |
|
| CVE-2026-64274 |
Input: goodix - clamp the device-reported contact count |
25.07.2026 |
|
| CVE-2026-64275 |
Input: elan_i2c - prevent division by zero and arithmetic underflow |
25.07.2026 |
|
| CVE-2026-64276 |
Input: synaptics-rmi4 - bound the F30 keymap to the GPIO/LED count |
25.07.2026 |
|
| CVE-2026-64277 |
Input: synaptics-rmi4 - bound the F3A keymap to the GPIO count |
25.07.2026 |
|
| CVE-2026-64278 |
i2c: imx-lpi2c: mark I2C adapter when hardware is powered down |
25.07.2026 |
|
| CVE-2026-64279 |
i2c: core: fix adapter deregistration race |
25.07.2026 |
|
| CVE-2026-64280 |
fpga: dfl-afu: validate DMA mapping length in afu_dma_map_region() |
25.07.2026 |
|
| CVE-2026-64281 |
svcrdma: wake sq waiters when the transport closes |
25.07.2026 |
|
| CVE-2026-64282 |
KVM: arm64: Don't leak PFN when kvm_translate_vncr() races MMU notifier |
25.07.2026 |
|
| CVE-2026-64283 |
KVM: guest_memfd: Treat memslot binding offset+size as unsigned values |
25.07.2026 |
|
| CVE-2026-64284 |
KVM: x86: Ensure vendor's exit handler runs before fastpath userspace exits |
25.07.2026 |
|
| CVE-2026-64285 |
KVM: SEV: Pin source page for write when adding CPUID data for SNP guest |
25.07.2026 |
|
| CVE-2026-64286 |
KVM: arm64: Clear __hyp_running_vcpu when flushing the pKVM hyp vCPU |
25.07.2026 |
|
| CVE-2026-64287 |
KVM: arm64: Bound used_lrs when flushing the pKVM hyp vCPU |
25.07.2026 |
|
| CVE-2026-64288 |
KVM: arm64: nv: Avoid dereferencing NULL VNCR pseudo-TLB |
25.07.2026 |
|
| CVE-2026-64289 |
iommufd: Set upper bounds on cache invalidation entry_num and entry_len |
25.07.2026 |
|
| CVE-2026-64290 |
iommufd: Break the loop on failure in iommufd_fault_fops_read() |
25.07.2026 |
|
| CVE-2026-64291 |
iommufd: Set veventq_depth upper bound |
25.07.2026 |
|
| CVE-2026-64292 |
iommufd: Move vevent memory allocation outside spinlock |
25.07.2026 |
|
| CVE-2026-64293 |
iommufd: Use sizeof(*hdr) instead of sizeof(hdr) in veventq read |
25.07.2026 |
|
| CVE-2026-64294 |
mm: do file ownership checks with the proper mount idmap |
25.07.2026 |
|
| CVE-2026-64295 |
mm: page_ext: add count limit to page_ext_iter_next to prevent invalid PFN access |
25.07.2026 |
|
| CVE-2026-64296 |
exfat: bound uniname advance in exfat_find_dir_entry() |
25.07.2026 |
|
| CVE-2026-64297 |
module: decompress: check return value of module_extend_max_pages() |
25.07.2026 |
|
| CVE-2026-64298 |
NFSv4: include MAY_WRITE in open permission mask for O_TRUNC |
25.07.2026 |
|
| CVE-2026-64299 |
tracing: Prevent out-of-bounds read in glob matching |
25.07.2026 |
|
| CVE-2026-64300 |
perf/aux: Fix page UAF in map_range() |
25.07.2026 |
|
| CVE-2026-64301 |
regulator: scmi: fix of_node refcount leak in scmi_regulator_probe() |
25.07.2026 |
|
| CVE-2026-64302 |
x86/mm: Fix freeing of PMD-sized vmemmap pages |
25.07.2026 |
|
| CVE-2026-64303 |
spi: fsl-lpspi: terminate the RX channel on TX prepare failure path |
25.07.2026 |
|
| CVE-2026-64304 |
crypto: qat - validate RSA CRT component lengths |
25.07.2026 |
|
| CVE-2026-64305 |
crypto: qat - protect service table iterations with service_lock |
25.07.2026 |
|
| CVE-2026-64306 |
crypto: drbg - Fix returning success on failure in CTR_DRBG |
25.07.2026 |
|
| CVE-2026-64307 |
crypto: ccp - Do not initialize SNP for ioctl(SNP_CONFIG) |
25.07.2026 |
|
| CVE-2026-64308 |
crypto: ccp - Do not initialize SNP for ioctl(SNP_VLEK_LOAD) |
25.07.2026 |
|
| CVE-2026-64309 |
crypto: ccp - Do not initialize SNP for ioctl(SNP_COMMIT) |
25.07.2026 |
|
| CVE-2026-64310 |
crypto: ccp - Do not initialize SNP for SEV ioctls |
25.07.2026 |
|
| CVE-2026-64311 |
crypto: loongson - Remove broken and unused loongson-rng |
25.07.2026 |
|
| CVE-2026-64312 |
crypto: pcrypt - restore callback for non-parallel fallback |
25.07.2026 |
|
| CVE-2026-64313 |
crypto: ecc - Fix carry overflow in vli multiplication |
25.07.2026 |
|
| CVE-2026-64314 |
crypto: chacha20poly1305 - validate poly1305 template argument |
25.07.2026 |
|
| CVE-2026-64315 |
crypto: caam - use print_hex_dump_devel to guard key hex dumps |
25.07.2026 |
|
| CVE-2026-64316 |
crypto: caam - use print_hex_dump_devel to guard key hex dumps |
25.07.2026 |
|
| CVE-2026-64317 |
isofs: bound Rock Ridge symlink components to the SL record |
25.07.2026 |
|
| CVE-2026-64318 |
partitions: aix: bound the pp_count scan to the ppe array |
25.07.2026 |
|
| CVE-2026-64319 |
nvmet-auth: validate reply message payload bounds against transfer length |
25.07.2026 |
|
| CVE-2026-64320 |
nvmet: fix pre-auth out-of-bounds heap read in Discovery Get Log Page |
25.07.2026 |
|
| CVE-2026-64321 |
nvme: target: rdma: fix ndev refcount leak on queue connect |
25.07.2026 |
|
| CVE-2026-64322 |
udf: validate sparing table length as an entry count, not a byte count |
25.07.2026 |
|
| CVE-2026-64323 |
udf: validate VAT header length against the VAT inode size |
25.07.2026 |
|
| CVE-2026-64324 |
udf: validate free block extents against the partition length |
25.07.2026 |
|
| CVE-2026-64325 |
wifi: mt76: mt7921/mt7925: fix NULL dereference in CSA beacon |
25.07.2026 |
|
| CVE-2026-64326 |
block: skip sync_blockdev() on surprise removal in bdev_mark_dead() |
25.07.2026 |
|
| CVE-2026-64327 |
usb: gadget: f_fs: Initialize epfile->in early to fix endpoint direction checks |
25.07.2026 |
|
| CVE-2026-64328 |
usb: gadget: f_fs: Fix DMA fence leak |
25.07.2026 |
|
| CVE-2026-64329 |
usb: typec: ucsi: ccg: Fix use-after-free of ucsi on remove |
25.07.2026 |
|
| CVE-2026-64330 |
usb: typec: tcpm: Validate SVID index in svdm_consume_modes() |
25.07.2026 |
|
| CVE-2026-64331 |
usbip: vudc: fix NULL deref in vep_dequeue() |
25.07.2026 |
|
| CVE-2026-64332 |
USB: ulpi: fix memory leak on registration failure |
25.07.2026 |
|
| CVE-2026-64333 |
USB: serial: digi_acceleport: fix write buffer corruption |
25.07.2026 |
|
| CVE-2026-64334 |
USB: serial: digi_acceleport: fix hard lockup on disconnect |
25.07.2026 |
|
| CVE-2026-64335 |
USB: serial: digi_acceleport: fix broken rx after throttle |
25.07.2026 |
|
| CVE-2026-64336 |
USB: serial: keyspan_pda: fix information leak |
25.07.2026 |
|
| CVE-2026-64337 |
usb: mtu3: unmap request DMA on queue failure |
25.07.2026 |
|
| CVE-2026-64338 |
USB: misc: uss720: unregister parport on probe failure |
25.07.2026 |
|
| CVE-2026-64339 |
usb: misc: usbio: bound bulk IN response length to the received transfer |
25.07.2026 |
|
| CVE-2026-64340 |
USB: legousbtower: fix use-after-free on disconnect race |
25.07.2026 |
|
| CVE-2026-64341 |
USB: iowarrior: fix use-after-free on disconnect race |
25.07.2026 |
|
| CVE-2026-64342 |
USB: iowarrior: fix use-after-free on disconnect |
25.07.2026 |
|
| CVE-2026-64343 |
USB: ldusb: fix use-after-free on disconnect race |
25.07.2026 |
|
| CVE-2026-64344 |
USB: idmouse: fix use-after-free on disconnect race |
25.07.2026 |
|
| CVE-2026-64345 |
usb: gadget: f_printer: take kref only for successful open |
25.07.2026 |
|
| CVE-2026-64346 |
usb: gadget: udc: Fix use-after-free in gadget_match_driver |
25.07.2026 |
|
| CVE-2026-64347 |
usb: gadget: composite: fix dead empty check in the USB_DT_OTG handler |
25.07.2026 |
|
| CVE-2026-64348 |
usb: free iso schedules on failed submit |
25.07.2026 |
|
| CVE-2026-64349 |
usb: dwc3: fix dwc3_readl() and dwc3_writel() calls in dwc3_ulpi_setup() |
25.07.2026 |
|
| CVE-2026-64350 |
usb: cdnsp: fix stream context array leak in cdnsp_alloc_stream_info() |
25.07.2026 |
|
| CVE-2026-64351 |
net: usb: kalmia: bound RX frame length in kalmia_rx_fixup() |
25.07.2026 |
|
| CVE-2026-64352 |
bpf: Allow LPM map access from sleepable BPF programs |
25.07.2026 |
|
| CVE-2026-64353 |
bpf: Keep dynamic inner array lookups nullable |
25.07.2026 |
|
| CVE-2026-64354 |
bpf: Validate BTF repeated field counts before expansion |
25.07.2026 |
|
| CVE-2026-64355 |
bpf: Reject fragmented frames in devmap |
25.07.2026 |
|
| CVE-2026-64356 |
xfs: fix memory leak in xfs_dqinode_metadir_create() |
25.07.2026 |
|
| CVE-2026-64357 |
xfs: fix exchmaps reservation limit check |
25.07.2026 |
|
| CVE-2026-64358 |
media: mtk-jpeg: cancel workqueue on release for supported platforms only |
25.07.2026 |
|
| CVE-2026-64359 |
nilfs2: reject CLEAN_SEGMENTS ioctl with out-of-range segment numbers |
25.07.2026 |
|
| CVE-2026-64360 |
hfs/hfsplus: zero-initialize buffer in hfs_bnode_read |
25.07.2026 |
|
| CVE-2026-64361 |
hfs/hfsplus: fix u32 overflow in check_and_correct_requested_length |
25.07.2026 |
|
| CVE-2026-64362 |
HID: lg-g15: cancel pending work on remove to fix a use-after-free |
25.07.2026 |
|
| CVE-2026-64363 |
HID: appleir: fix UAF on pending key_up_timer in remove() |
25.07.2026 |
|
| CVE-2026-64364 |
HID: multitouch: fix out-of-bounds bit access on mt_io_flags |
25.07.2026 |
|
| CVE-2026-64365 |
HID: letsketch: fix UAF on inrange_timer at driver unbind |
25.07.2026 |
|
| CVE-2026-64366 |
HID: wacom: fix slab-out-of-bounds write in wacom_wac_queue_insert |
25.07.2026 |
|
| CVE-2026-64367 |
HID: hid-goodix-spi: validate report size to prevent stack buffer overflow |
25.07.2026 |
|
| CVE-2026-64368 |
mm/slab: do not limit zeroing to orig_size when only red zoning is enabled |
25.07.2026 |
|
| CVE-2026-64369 |
s390: Revert support for DCACHE_WORD_ACCESS |
25.07.2026 |
|
| CVE-2026-64370 |
posix-cpu-timers: Fix pid refcount leak in do_cpu_nanosleep() error path |
25.07.2026 |
|
| CVE-2026-64371 |
proc: protect ptrace_may_access() with exec_update_lock (part 1) |
25.07.2026 |
|
| CVE-2026-64372 |
cpufreq: pcc: fix use-after-free and double free in _OSC evaluation |
25.07.2026 |
|
| CVE-2026-64373 |
cpufreq: Fix hotplug-suspend race during reboot |
25.07.2026 |
|
| CVE-2026-64374 |
sched/rt: Have RT_PUSH_IPI be default off for non PREEMPT_RT |
25.07.2026 |
|
| CVE-2026-64375 |
proc: protect ptrace_may_access() with exec_update_lock (FD links) |
25.07.2026 |
|
| CVE-2026-64376 |
firmware_loader: fix device reference leak in firmware_upload_register() |
25.07.2026 |
|
| CVE-2026-64377 |
cpufreq: qcom-cpufreq-hw: Fix possible double free |
25.07.2026 |
|
| CVE-2026-64378 |
writeback: fix race between cgroup_writeback_umount() and inode_switch_wbs() |
25.07.2026 |
|
| CVE-2026-64379 |
smb: client: mask server-provided mode to 07777 in modefromsid |
25.07.2026 |
|
| CVE-2026-64380 |
smb: client: harden POSIX SID length parsing |
25.07.2026 |
|
| CVE-2026-64381 |
smb: client: Fix next buffer leak in receive_encrypted_standard() |
25.07.2026 |
|
| CVE-2026-64382 |
smb: client: fix double-free in SMB2_open() replay |
25.07.2026 |
|
| CVE-2026-64383 |
smb: client: fix double-free in SMB2_flush() replay |
25.07.2026 |
|
| CVE-2026-64384 |
smb: client: fix change notify replay double-free |
25.07.2026 |
|
| CVE-2026-64385 |
smb: client: fix double-free in SMB2_ioctl() replay |
25.07.2026 |
|
| CVE-2026-64386 |
smb: client: fix query_info() replay double-free |
25.07.2026 |
|
| CVE-2026-64387 |
smb: client: fix query directory replay double-free |
25.07.2026 |
|
| CVE-2026-64388 |
smb/client: fix chown/chgrp with SMB3 POSIX Extensions |
25.07.2026 |
|
| CVE-2026-64389 |
ksmbd: validate NTLMv2 response before updating session key |
25.07.2026 |
|
| CVE-2026-64390 |
ksmbd: track the connection owning a byte-range lock |
25.07.2026 |
|
| CVE-2026-64391 |
ksmbd: use opener credentials for ADS I/O |
25.07.2026 |
|
| CVE-2026-64392 |
ksmbd: use opener credentials for delete-on-close |
25.07.2026 |
|
| CVE-2026-64393 |
ksmbd: run set info with opener credentials |
25.07.2026 |
|
| CVE-2026-64394 |
ksmbd: add a WRITE_DAC/WRITE_OWNER check to SMB2 SET_INFO SECURITY |
25.07.2026 |
|
| CVE-2026-64395 |
ksmbd: require source read access for duplicate extents |
25.07.2026 |
|
| CVE-2026-64396 |
ksmbd: fix UAF of struct file_lock in SMB2_LOCK deferred-lock cancellation |
25.07.2026 |
|
| CVE-2026-64397 |
ksmbd: serialize QUERY_DIRECTORY requests per file |
25.07.2026 |
|
| CVE-2026-64398 |
ksmbd: add a permission check for FSCTL_SET_ZERO_DATA |
25.07.2026 |
|
| CVE-2026-64399 |
ksmbd: add permission checks for FSCTL_DUPLICATE_EXTENTS_TO_FILE |
25.07.2026 |
|
| CVE-2026-64400 |
ksmbd: prevent path traversal bypass by restricting caseless retry |
25.07.2026 |
|
| CVE-2026-64401 |
smb: client: resolve SWN tcon from live registrations |
25.07.2026 |
|
| CVE-2026-64402 |
coresight: ultrasoc-smb: Fix OOB write in smb_sync_perf_buffer() |
25.07.2026 |
|
| CVE-2026-64403 |
Bluetooth: L2CAP: validate option length before reading conf opt value |
25.07.2026 |
|
| CVE-2026-64404 |
Bluetooth: ISO: avoid NULL deref of conn in iso_conn_big_sync() |
25.07.2026 |
|
| CVE-2026-64405 |
Bluetooth: hci_conn: Fix null ptr deref in hci_abort_conn() |
25.07.2026 |
|
| CVE-2026-64406 |
Bluetooth: fix UAF in bt_accept_dequeue() |
25.07.2026 |
|
| CVE-2026-64407 |
Bluetooth: btnxpuart: Fix out-of-bounds firmware read in nxp_recv_fw_req_v3() |
25.07.2026 |
|
| CVE-2026-64408 |
Bluetooth: bnep: pin L2CAP connection during netdev registration |
25.07.2026 |
|
| CVE-2026-64409 |
Bluetooth: btmtksdio: fix infinite loop in btmtksdio_txrx_work() |
25.07.2026 |
|
| CVE-2026-64410 |
netfilter: flowtable: IPIP tunnel hardware offload is not yet support |
25.07.2026 |
|
| CVE-2026-64411 |
netfilter: ebtables: terminate table name before find_table_lock() |
25.07.2026 |
|
| CVE-2026-64412 |
netfilter: ebtables: module names must be null-terminated |
25.07.2026 |
|
| CVE-2026-64413 |
netfilter: ebtables: zero chainstack array |
25.07.2026 |
|
| CVE-2026-64414 |
netfilter: handle unreadable frags |
25.07.2026 |
|
| CVE-2026-64415 |
mm/swap: add cond_resched() in swap_reclaim_full_clusters to prevent softlockup |
25.07.2026 |
|
| CVE-2026-64416 |
mm: swap_cgroup: fix NULL deref in lookup_swap_cgroup_id on swapless host |
25.07.2026 |
|
| CVE-2026-64417 |
mm: shrinker: fix NULL pointer dereference in debugfs |
25.07.2026 |
|
| CVE-2026-64418 |
mm: shrinker: fix shrinker_info teardown race with expansion |
25.07.2026 |
|
| CVE-2026-64419 |
mm/shrinker: do not hold RCU lock in shrinker_debugfs_count_show() |
25.07.2026 |
|
| CVE-2026-64420 |
mfd: cros_ec: Delay dev_set_drvdata() until probe success |
25.07.2026 |
|
| CVE-2026-64421 |
media: nxp: imx8-isi: Fix use-after-free on remove |
25.07.2026 |
|
| CVE-2026-64422 |
net: ipv4: bound TCP reordering sysctl writes and MTU probe sizes |
25.07.2026 |
|
| CVE-2026-64423 |
ipv4: igmp: remove multicast group from hash table on device destruction |
25.07.2026 |
|
| CVE-2026-64424 |
netpoll: fix a use-after-free on shutdown path |
25.07.2026 |
|
| CVE-2026-64425 |
io_uring/io-wq: re-check IO_WQ_BIT_EXIT for each linked work item |
25.07.2026 |
|
| CVE-2026-64426 |
io_uring/nop: fix file reference leak with IOSQE_FIXED_FILE |
25.07.2026 |
|
| CVE-2026-64427 |
HID: logitech-dj: Fix maxfield check in DJ short report validation |
25.07.2026 |
|
| CVE-2026-64428 |
gpio: sch: use raw_spinlock_t in the irq startup path |
25.07.2026 |
|
| CVE-2026-64429 |
gpio: eic-sprd: use raw_spinlock_t in the irq startup path |
25.07.2026 |
|
| CVE-2026-64430 |
NTB: epf: Avoid calling pci_irq_vector() from hardirq context |
25.07.2026 |
|
| CVE-2026-64431 |
ntfs: avoid calling post_write_mst_fixup() for invalid index_block |
25.07.2026 |
|
| CVE-2026-64432 |
fs/ntfs3: validate Dirty Page Table capacity in log_replay copy_lcns |
25.07.2026 |
|
| CVE-2026-64433 |
Bluetooth: MGMT: Fix UAF of hci_conn_params in add_device_complete |
25.07.2026 |
|
| CVE-2026-64434 |
Bluetooth: L2CAP: Fix UAF in channel timeout by holding conn ref |
25.07.2026 |
|
| CVE-2026-64435 |
audit: Fix data races of skb_queue_len() readers on audit_queue |
25.07.2026 |
|
| CVE-2026-64436 |
net: af_key: initialize alg_key_len for IPComp states |
25.07.2026 |
|
| CVE-2026-64437 |
ksmbd: fix use-after-free of a deferred file_lock on SMB2_CLOSE then SMB2_CANCEL |
25.07.2026 |
|
| CVE-2026-64438 |
crypto: qat - fix VF2PF work teardown race in adf_disable_sriov() |
25.07.2026 |
|
| CVE-2026-64439 |
crypto: krb5 - filter out async aead implementations at alloc |
25.07.2026 |
|
| CVE-2026-64440 |
staging: rtl8723bs: fix OOB write in HT_caps_handler() |
25.07.2026 |
|
| CVE-2026-64441 |
staging: rtl8723bs: fix OOB reads in rtw_get_sec_ie(), rtw_get_wapi_ie(), and rtw_get_wps_attr() |
25.07.2026 |
|
| CVE-2026-64442 |
staging: rtl8723bs: fix OOB reads in IE loops in issue_assocreq() and join_cmd_hdl() |
25.07.2026 |
|
| CVE-2026-64443 |
staging: rtl8723bs: fix OOB read in update_beacon_info() IE loop |
25.07.2026 |
|
| CVE-2026-64444 |
staging: rtl8723bs: fix OOB read in OnAssocRsp() IE loop |
25.07.2026 |
|
| CVE-2026-64445 |
staging: rtl8723bs: fix WEP length underflow and OOB read in OnAuth() |
25.07.2026 |
|
| CVE-2026-64446 |
staging: rtl8723bs: fix heap buffer overflow in rtw_cfg80211_set_wpa_ie() |
25.07.2026 |
|
| CVE-2026-64447 |
staging: media: ipu7: fix double-free and use-after-free in error paths |
25.07.2026 |
|
| CVE-2026-64448 |
smb: client: restrict implied bcc[0] exemption to responses without data area |
25.07.2026 |
|
| CVE-2026-64449 |
staging: vme_user: bound slave read/write to the kern_buf size |
25.07.2026 |
|
| CVE-2026-64450 |
tipc: fix out-of-bounds read in broadcast Gap ACK blocks |
25.07.2026 |
|
| CVE-2026-64451 |
tracing: Fix NULL pointer dereference in func_set_flag() |
25.07.2026 |
|
| CVE-2026-64452 |
6lowpan: fix NHC entry use-after-free on error path |
25.07.2026 |
|
| CVE-2026-64453 |
usb: misc: usbio: fix disconnect UAF in client teardown |
25.07.2026 |
|
| CVE-2026-64454 |
usb: dwc3: run gadget disconnect from sleepable suspend context |
25.07.2026 |
|
| CVE-2026-64455 |
USB: chaoskey: Fix slab-use-after-free in chaoskey_release() |
25.07.2026 |
|
| CVE-2026-64456 |
hwrng: virtio: clamp device-reported used.len at copy_data() |
25.07.2026 |
|
| CVE-2026-64457 |
virtio_pci: fix vq info pointer lookup via wrong index |
25.07.2026 |
|
| CVE-2026-64458 |
mm/damon/ops-common: handle extreme intervals in damon_hot_score() |
25.07.2026 |
|
| CVE-2026-64459 |
tcp: restore RCU grace period in tcp_ao_destroy_sock |
25.07.2026 |
|
| CVE-2026-64460 |
PCI/IOV: Skip VF Resizable BAR restore on read error |
25.07.2026 |
|
| CVE-2026-64461 |
PCI: mediatek: Fix IRQ domain leak when port fails to enable |
25.07.2026 |
|
| CVE-2026-64462 |
PCI: altera: Fix resource leaks on probe failure |
25.07.2026 |
|
| CVE-2026-64463 |
usb: typec: tcpci_rt1711h: unregister TCPCI port with devres |
25.07.2026 |
|
| CVE-2026-64464 |
xhci: sideband: fix ring sg table pages leak |
25.07.2026 |
|
| CVE-2026-64465 |
usb: xhci: Fix sleep in atomic context in xhci_free_streams() |
25.07.2026 |
|
| CVE-2026-64466 |
rust_binder: clear freeze listener on node removal |
25.07.2026 |
|
| CVE-2026-64467 |
rust_binder: use a u64 stride when cleaning up the offsets array |
25.07.2026 |
|
| CVE-2026-64468 |
binder: fix UAF in binder_free_transaction() |
25.07.2026 |
|
| CVE-2026-64469 |
binder: fix UAF in binder_thread_release() |
25.07.2026 |
|
| CVE-2026-64470 |
Bluetooth: btusb: fix use-after-free on marvell probe failure |
25.07.2026 |
|
| CVE-2026-64471 |
Bluetooth: btusb: fix use-after-free on registration failure |
25.07.2026 |
|
| CVE-2026-64472 |
vfio/mlx5: Fix racy bitfields and tighten struct layout |
25.07.2026 |
|
| CVE-2026-64473 |
vfio: Remove device debugfs before releasing devres |
25.07.2026 |
|
| CVE-2026-64474 |
vfio: prevent infinite loop in vfio_mig_get_next_state() on blocked arc |
25.07.2026 |
|
| CVE-2026-64475 |
vfio/pci: Release the VGA arbiter client on register_device() failure |
25.07.2026 |
|
| CVE-2026-64476 |
vfio/pci: Latch disable_idle_d3 per device |
25.07.2026 |
|
| CVE-2026-64477 |
x86,fs/resctrl: Prevent out-of-bounds access while offlining CPU when SNC enabled |
25.07.2026 |
|
| CVE-2026-64478 |
ALSA: usb-audio: avoid kobject path lookup in DualSense match |
25.07.2026 |
|
| CVE-2026-64479 |
ALSA: seq: Fix uninitialised heap leak in snd_seq_event_dup() |
25.07.2026 |
|
| CVE-2026-64480 |
ALSA: ice1712: check snd_ctl_new1() return value |
25.07.2026 |
|
| CVE-2026-64481 |
ALSA: hda/cs35l41: Fix firmware load work teardown |
25.07.2026 |
|
| CVE-2026-64482 |
ALSA: gus: check snd_ctl_new1() return value |
25.07.2026 |
|
| CVE-2026-64483 |
ALSA: firewire: isight: bound the sample count to the packet payload |
25.07.2026 |
|
| CVE-2026-64484 |
ALSA: es1938: check snd_ctl_new1() return value |
25.07.2026 |
|
| CVE-2026-64485 |
ALSA: compress: Fix task creation error unwind |
25.07.2026 |
|
| CVE-2026-64486 |
ALSA: cmipci: check snd_ctl_new1() return value |
25.07.2026 |
|
| CVE-2026-64487 |
ALSA: caiaq: fix out-of-bounds read in the Traktor Kontrol S4 input parser |
25.07.2026 |
|
| CVE-2026-64488 |
ALSA: aoa: check snd_ctl_new1() return value |
25.07.2026 |
|
| CVE-2026-64489 |
ALSA: ymfpci: check snd_ctl_new1() return value |
25.07.2026 |
|
| CVE-2026-64490 |
ALSA: virtio: Validate control metadata from the device |
25.07.2026 |
|
| CVE-2026-64491 |
ALSA: usx2y: us144mkii: fix work UAF on disconnect |
25.07.2026 |
|
| CVE-2026-64492 |
iio: temperature: tmp006: use devm_iio_trigger_register |
25.07.2026 |
|
| CVE-2026-64493 |
iio: pressure: mpl115: fix runtime PM leak on read error |
25.07.2026 |
|
| CVE-2026-64494 |
iio: light: gp2ap002: fix runtime PM leak on read error |
25.07.2026 |
|
| CVE-2026-64495 |
iio: gyro: bmg160: bail out when bandwidth/filter is not in table |
25.07.2026 |
|
| CVE-2026-64496 |
iio: event: Fix event FIFO reset race |
25.07.2026 |
|
| CVE-2026-64497 |
iio: chemical: scd30: Cleanup initializations and fix sign-extension bug |
25.07.2026 |
|
| CVE-2026-64498 |
iio: buffer: hw-consumer: free scan_mask on buffer release |
25.07.2026 |
|
| CVE-2026-64499 |
iio: adc: ti-ads1119: fix PM reference leak in buffer preenable |
25.07.2026 |
|
| CVE-2026-64500 |
iio: adc: lpc32xx: Initialize completion before requesting IRQ |
25.07.2026 |
|
| CVE-2026-64501 |
iio: adc: ad_sigma_delta: fix CS held asserted and state leaks |
25.07.2026 |
|
| CVE-2026-64502 |
iio: adc: ad_sigma_delta: fix clear_pending_event for registerless devices |
25.07.2026 |
|
| CVE-2026-64503 |
iio: accel: kxsd9: fix runtime PM imbalance on write_raw() error |
25.07.2026 |
|
| CVE-2026-64504 |
iio: accel: bmc150: clamp the device-reported FIFO frame count |
25.07.2026 |
|
| CVE-2026-64505 |
usb: gadget: function: rndis: add length check for header |
25.07.2026 |
|
| CVE-2026-64506 |
wifi: rtw89: correct drop logic for malformed AMPDU frames |
25.07.2026 |
|
| CVE-2026-64507 |
x86/bugs: Enable IBPB flush on BPF JIT allocation |
25.07.2026 |
|
| CVE-2026-64508 |
bpf: Support for hardening against JIT spraying |
25.07.2026 |
|
| CVE-2026-64509 |
rust: block: fix GenDisk cleanup paths |
25.07.2026 |
|
| CVE-2026-64510 |
ACPI: NFIT: core: Fix acpi_nfit_init() error cleanup |
25.07.2026 |
|
| CVE-2026-64511 |
ACPI: NFIT: core: Fix possible NULL pointer dereference |
25.07.2026 |
|
| CVE-2026-64512 |
ACPI: CPPC: Suppress UBSAN warning caused by field misuse |
25.07.2026 |
|
| CVE-2026-64513 |
KVM: x86: Unconditionally recompute CR8 intercept on PPR update |
25.07.2026 |
|
| CVE-2026-64514 |
userfaultfd: gate must_wait writability check on pte_present() |
25.07.2026 |
|
| CVE-2026-64515 |
wifi: mac80211: fix MLE defragmentation |
25.07.2026 |
|
| CVE-2026-64516 |
drm/amdgpu/vce1: Fix VCE 1 firmware size and offsets |
25.07.2026 |
|
| CVE-2026-64517 |
drm/xe/gsc: Fix double-free of managed BO in error path |
25.07.2026 |
|
| CVE-2026-64518 |
tcp: Fix out-of-bounds access for twsk in tcp_ao_established_key(). |
25.07.2026 |
|
| CVE-2026-64519 |
NFSD: Fix infinite loop in layout state revocation |
25.07.2026 |
|
| CVE-2026-64520 |
firmware: arm_ffa: Bound PARTITION_INFO_GET_REGS copies |
25.07.2026 |
|
| CVE-2026-64521 |
pinctrl: meson: amlogic-a4: fix deadlock issue |
25.07.2026 |
|
| CVE-2026-64522 |
net/mlx5e: Fix eswitch mode block underflow on IPsec acquire SA |
25.07.2026 |
|
| CVE-2026-16766 |
Catalyst::View::Wkhtmltopdf versions before 0.6.1 for Perl allow shell command injection (RCE) via PDF render options |
25.07.2026 |
|
| CVE-2026-10818 |
WPForms Pro <= 1.10.1.1 - Unauthenticated Arbitrary File Write via Chunked Upload Init/Finalize Ordering |
25.07.2026 |
8.1 |
| CVE-2026-15425 |
Yoast SEO <= 28.0 - Authenticated (Author+) Stored Cross-Site Scripting via Post Slug (post_name) |
25.07.2026 |
6.4 |
| CVE-2026-14955 |
Checkout Field Editor for WooCommerce (Pro) <= 3.7.7 - Authenticated (Subscriber+) Path Traversal to Arbitrary File Read via 'thwcfe_legacy_file' Parameter |
25.07.2026 |
6.5 |
| CVE-2026-66373 |
|
25.07.2026 |
7.5 |
| CVE-2026-66374 |
|
25.07.2026 |
8.1 |
| CVE-2026-66337 |
Libsoup: libsoup: heap buffer over-read via integer underflow in soup_filter_input_stream_read_until() |
24.07.2026 |
|
| CVE-2026-66338 |
Libsoup: libsoup: http request smuggling via permissive chunk-size parsing in soup_body_input_stream_read_chunked() |
24.07.2026 |
|
| CVE-2026-66339 |
Libsoup: libsoup: proxy credentials leak to destination server via proxy-authorization header in connect tunnels |
24.07.2026 |
|
| CVE-2026-16280 |
GPU DDK - Integer overflow in _PMRLogicalOffsetToPhysicalOffset |
24.07.2026 |
|
| CVE-2026-60134 |
Weintek cMT3092X Reliance on Cookies without Validation and Integrity Checking in a Security Decision |
24.07.2026 |
8.8 |
| CVE-2026-60135 |
Weintek cMT3092X Incorrect User Management |
24.07.2026 |
6.5 |
| CVE-2026-61886 |
Weintek cMT3092X Plaintext Storage of a Password |
24.07.2026 |
6.5 |
| CVE-2026-61892 |
Weintek cMT3092X Incorrect Permission Assignment for Critical Resource |
24.07.2026 |
8.8 |
| CVE-2026-55985 |
Tycon Systems TPDIN-Monitor-WEB2 Cleartext Storage of Sensitive Information |
24.07.2026 |
4.3 |
| CVE-2026-61884 |
Tycon Systems TPDIN-Monitor-WEB2 Authentication Bypass Using an Alternate Path or Channel |
24.07.2026 |
9.8 |
| CVE-2025-71408 |
NLTK < 3.9.3 Eval Injection via collocations.py Command-Line Arguments |
25.07.2026 |
|
| CVE-2026-66039 |
FFmpeg MACE6 Audio Decoder Heap Out-of-Bounds Write via CAF File |
24.07.2026 |
|
| CVE-2026-66040 |
FFmpeg Heap Out-of-Bounds Write via PNG/APNG eXIf Encoder |
24.07.2026 |
|
| CVE-2026-66041 |
FFmpeg 7.0 - 8.1.2 Heap Out-of-Bounds Write via vf_quirc Filter |
25.07.2026 |
|