[{"key": "CVE-2026-59690", "cve": "CVE-2026-59690", "lang": "en", "title": "CVE-2026-59690", "summary": "A Missing Authorization vulnerability in Progress Software LoadMaster, ECS Connection Manager, Object Scale Connection Manager, MOVEit WAF, and Multi Tenant allows an authenticated attacker with low privileges to perform privileged administrative operations via the REST API that should not be accessible to their permission level, potentially resulting in a system compromise.", "product": "Progress Software LoadMaster", "category": "cve", "source": "NVD", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-59690", "card": "CVE-2026-59690.webp?v=1785159583", "takeaways": ["CVSS 3.1 : 8.0 HIGH", "Vector: AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"], "ts": 1785158302, "exploited": 0, "has_score": 1, "created": 1785159442, "updated": 1785159442, "exploited_text": 0, "poc": 0, "score": 8.0, "kev": 0, "flags": []}, {"key": "CVE-2026-59689", "cve": "CVE-2026-59689", "lang": "en", "title": "CVE-2026-59689", "summary": "An Incorrect Authorization vulnerability in Progress Software LoadMaster, ECS Connection Manager, Object Scale Connection Manager, and MOVEit WAF allows an authenticated attacker with low privileges to escalate privileges to root on the affected appliance, potentially resulting in full system compromise.", "product": "Progress Software LoadMaster", "category": "cve", "source": "NVD", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-59689", "card": "CVE-2026-59689.webp?v=1785159583", "takeaways": ["CVSS 3.1 : 8.0 HIGH", "Vector: AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"], "ts": 1785158302, "exploited": 0, "has_score": 1, "created": 1785159442, "updated": 1785159442, "exploited_text": 0, "poc": 0, "score": 8.0, "kev": 0, "flags": []}, {"key": "CVE-2026-59688", "cve": "CVE-2026-59688", "lang": "en", "title": "CVE-2026-59688", "summary": "An OS Command Injection vulnerability in Progress Software LoadMaster, ECS Connection Manager, Object Scale Connection Manager, and MOVEit WAF allows an authenticated attacker with high privileges to execute arbitrary operating system commands on the affected appliance via the backup restore functionality, potentially resulting in complete system compromise.", "product": "Progress Software LoadMaster", "category": "cve", "source": "NVD", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-59688", "card": "CVE-2026-59688.webp?v=1785159583", "takeaways": ["CVSS 3.1 : 8.4 HIGH", "Vector: AV:A/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H"], "ts": 1785158302, "exploited": 0, "has_score": 1, "created": 1785159442, "updated": 1785159442, "exploited_text": 0, "poc": 0, "score": 8.4, "kev": 0, "flags": []}, {"key": "CVE-2026-59687", "cve": "CVE-2026-59687", "lang": "en", "title": "CVE-2026-59687", "summary": "An OS Command Injection vulnerability in Progress Software LoadMaster, ECS Connection Manager, Object Scale Connection Manager, and MOVEit WAF allows an authenticated attacker with high privileges to execute arbitrary operating system commands on the affected appliance via the Geo Location management interface, potentially resulting in complete system compromise.", "product": "Progress Software LoadMaster", "category": "cve", "source": "NVD", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-59687", "card": "CVE-2026-59687.webp?v=1785159583", "takeaways": ["CVSS 3.1 : 8.4 HIGH", "Vector: AV:A/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H"], "ts": 1785158302, "exploited": 0, "has_score": 1, "created": 1785159442, "updated": 1785159442, "exploited_text": 0, "poc": 0, "score": 8.4, "kev": 0, "flags": []}, {"key": "CVE-2026-59686", "cve": "CVE-2026-59686", "lang": "en", "title": "CVE-2026-59686", "summary": "An OS Command Injection vulnerability in Progress Software LoadMaster, ECS Connection Manager, Object Scale Connection Manager, and MOVEit WAF allows an authenticated attacker with high privileges to execute arbitrary operating system commands on the affected appliance via the management interface, potentially resulting in complete system compromise.", "product": "Progress Software LoadMaster", "category": "cve", "source": "NVD", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-59686", "card": "CVE-2026-59686.webp?v=1785159584", "takeaways": ["CVSS 3.1 : 8.4 HIGH", "Vector: AV:A/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H"], "ts": 1785158301, "exploited": 0, "has_score": 1, "created": 1785159442, "updated": 1785159442, "exploited_text": 0, "poc": 0, "score": 8.4, "kev": 0, "flags": []}, {"key": "CVE-2026-12991", "cve": "CVE-2026-12991", "lang": "en", "title": "CVE-2026-12991", "summary": "The lack of cryptographic mechanisms to ensure the integrity and authenticity of communications in Ghost Robotics' Vision 60 robot (APK v5.5.0) exposes the system to man-in-the-middle attacks. An attacker located on the local network can use ARP spoofing and selective traffic blocking techniques to intercept and manipulate packets between the legitimate operator and the robot. This allows the attacker to disconnect the original controller, establish unauthorized communications, and prevent the operator from regaining control of the device, seriously compromising the confidentiality, integrity, and availability (CIA) of operations.", "product": "Ghost Robotics Vision 60", "category": "cve", "source": "NVD", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-12991", "card": "CVE-2026-12991.webp?v=1785159584", "takeaways": ["CVSS 4.0 : 8.7 HIGH", "Vector: AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"], "ts": 1785158212, "exploited": 0, "has_score": 1, "created": 1785159442, "updated": 1785159442, "exploited_text": 0, "poc": 0, "score": 8.7, "kev": 0, "flags": []}, {"key": "CVE-2026-12990", "cve": "CVE-2026-12990", "lang": "en", "title": "CVE-2026-12990", "summary": "An access control vulnerability in the mobile app (APK v5.5.0) for Ghost Robotics' Vision 60 robot allows multiple simultaneous sessions to run without proper client validation or session integrity checks. An attacker with a modified version of the app can connect to the robot during an active, legitimate session. This allows the attacker to bypass control restrictions, intercept sensitive information (such as real-time video), and partially interact with the system unnoticed and without disconnecting the legitimate user, compromising confidentiality and operational security.", "product": "Ghost Robotics Vision 60", "category": "cve", "source": "NVD", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-12990", "card": "CVE-2026-12990.webp?v=1785159584", "takeaways": ["CVSS 4.0 : 7.7 HIGH", "Vector: AV:A/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"], "ts": 1785158212, "exploited": 0, "has_score": 1, "created": 1785159442, "updated": 1785159442, "exploited_text": 0, "poc": 0, "score": 7.7, "kev": 0, "flags": []}, {"key": "CVE-2026-12989", "cve": "CVE-2026-12989", "lang": "en", "title": "CVE-2026-12989", "summary": "A lack of authentication in the mobile app (APK v5.5.0) for Ghost Robotics' Vision 60 robot allows an unauthenticated attacker connected to the device's internal Wi-Fi network to gain unrestricted access to the web administration interface and the HTTP API. Due to the lack of authorization mechanisms, the attacker can view real-time camera feeds, control the robot’s movements, manage sensors (GPS, RTK, SAM, LIDAR), and execute critical operational commands (Play, Pause, Stop, E-Stop). Successful exploitation completely compromises the confidentiality, integrity, and physical security of the system.", "product": "Ghost Robotics Vision 60", "category": "cve", "source": "NVD", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-12989", "card": "CVE-2026-12989.webp?v=1785159584", "takeaways": ["CVSS 4.0 : 8.7 HIGH", "Vector: AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"], "ts": 1785158211, "exploited": 0, "has_score": 1, "created": 1785159442, "updated": 1785159442, "exploited_text": 0, "poc": 0, "score": 8.7, "kev": 0, "flags": []}, {"key": "CVE-2026-58662", "cve": "CVE-2026-58662", "lang": "en", "title": "CVE-2026-58662", "summary": "Improper Validation of Specified Quantity in Input, Out-of-bounds Read vulnerability in Apache Thrift C++ bindings.\n\nThis issue affects Apache Thrift: before 0.24.0.\n\nUsers are recommended to upgrade to version 0.24.0, which fixes the issue.", "product": "Apache Software Foundation Apache Thrift", "category": "cve", "source": "NVD", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-58662", "card": "CVE-2026-58662.webp?v=1785155582", "takeaways": ["CVSS 4.0 : 8.7 HIGH", "Vector: AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N"], "ts": 1785154606, "exploited": 0, "has_score": 1, "created": 1785155450, "updated": 1785159442, "exploited_text": 0, "poc": 0, "score": 8.7, "kev": 0, "flags": []}, {"key": "CVE-2026-58389", "cve": "CVE-2026-58389", "lang": "en", "title": "CVE-2026-58389", "summary": "Allocation of Resources Without Limits or Throttling vulnerability in Apache Thrift Rust bindings.\n\nThis issue affects Apache Thrift: before 0.24.0.\n\nUsers are recommended to upgrade to version 0.24.0, which fixes the issue.", "product": "Apache Software Foundation Apache Thrift", "category": "cve", "source": "NVD", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-58389", "card": "CVE-2026-58389.webp?v=1785155581", "takeaways": ["CVSS 4.0 : 8.7 HIGH", "Vector: AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N"], "ts": 1785154606, "exploited": 0, "has_score": 1, "created": 1785155450, "updated": 1785159442, "exploited_text": 0, "poc": 0, "score": 8.7, "kev": 0, "flags": []}, {"key": "CVE-2026-55971", "cve": "CVE-2026-55971", "lang": "en", "title": "CVE-2026-55971", "summary": "Heap-based Buffer Overflow vulnerability in Apache Thrift C++ bindings.\n\nThis issue affects Apache Thrift: before 0.24.0.\n\nUsers are recommended to upgrade to version 0.24.0, which fixes the issue.", "product": "Apache Software Foundation Apache Thrift", "category": "cve", "source": "NVD", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-55971", "card": "CVE-2026-55971.webp?v=1785155581", "takeaways": ["CVSS 4.0 : 9.3 CRITICAL", "Vector: AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"], "ts": 1785154606, "exploited": 0, "has_score": 1, "created": 1785155450, "updated": 1785159442, "exploited_text": 0, "poc": 0, "score": 9.3, "kev": 0, "flags": []}, {"key": "CVE-2026-55969", "cve": "CVE-2026-55969", "lang": "en", "title": "CVE-2026-55969", "summary": "Integer Overflow or Wraparound vulnerability in Apache Thrift C++, c_glib, Go, netstd, Delphi and Haxe bindings.\n\nThis issue affects Apache Thrift: before 0.24.0.\n\nUsers are recommended to upgrade to version 0.24.0, which fixes the issue.", "product": "Apache Software Foundation Apache Thrift", "category": "cve", "source": "NVD", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-55969", "card": "CVE-2026-55969.webp?v=1785155582", "takeaways": ["CVSS 4.0 : 8.7 HIGH", "Vector: AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N"], "ts": 1785154605, "exploited": 0, "has_score": 1, "created": 1785155450, "updated": 1785159442, "exploited_text": 0, "poc": 0, "score": 8.7, "kev": 0, "flags": []}, {"key": "CVE-2026-55968", "cve": "CVE-2026-55968", "lang": "en", "title": "CVE-2026-55968", "summary": "Inefficient Algorithmic Complexity, Allocation of Resources Without Limits or Throttling vulnerability in Apache Thrift Node.js bindings.\n\nThis issue affects Apache Thrift: before 0.24.0.\n\nUsers are recommended to upgrade to version 0.24.0, which fixes the issue.", "product": "Apache Software Foundation Apache Thrift", "category": "cve", "source": "NVD", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-55968", "card": "CVE-2026-55968.webp?v=1785155582", "takeaways": ["CVSS 4.0 : 8.7 HIGH", "Vector: AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N"], "ts": 1785154605, "exploited": 0, "has_score": 1, "created": 1785155450, "updated": 1785159442, "exploited_text": 0, "poc": 0, "score": 8.7, "kev": 0, "flags": []}, {"key": "CVE-2026-49158", "cve": "CVE-2026-49158", "lang": "en", "title": "CVE-2026-49158", "summary": "Improper Handling of Highly Compressed Data (Data Amplification) vulnerability in Apache Thrift Ruby bindings.\n\nThis issue affects Apache Thrift: before 0.24.0.\n\nUsers are recommended to upgrade to version 0.24.0, which fixes the issue.", "product": "Apache Software Foundation Apache Thrift", "category": "cve", "source": "NVD", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-49158", "card": "CVE-2026-49158.webp?v=1785155582", "takeaways": ["CVSS 3.1 : 7.5 HIGH", "Vector: AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"], "ts": 1785154605, "exploited": 0, "has_score": 1, "created": 1785155450, "updated": 1785159442, "exploited_text": 0, "poc": 0, "score": 7.5, "kev": 0, "flags": []}, {"key": "CVE-2026-48586", "cve": "CVE-2026-48586", "lang": "en", "title": "CVE-2026-48586", "summary": "Improper Handling of Highly Compressed Data (Data Amplification) vulnerability in Apache Thrift C++, Java, Python, Go, D, C/GLib bindings.\n\nThis issue affects Apache Thrift: before 0.24.0.\n\nUsers are recommended to upgrade to version 0.24.0, which fixes the issue.", "product": "Apache Software Foundation Apache Thrift", "category": "cve", "source": "NVD", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-48586", "card": "CVE-2026-48586.webp?v=1785155583", "takeaways": ["CVSS 4.0 : 8.7 HIGH", "Vector: AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N"], "ts": 1785154604, "exploited": 0, "has_score": 1, "created": 1785155450, "updated": 1785159442, "exploited_text": 0, "poc": 0, "score": 8.7, "kev": 0, "flags": []}, {"key": "CVE-2026-48145", "cve": "CVE-2026-48145", "lang": "en", "title": "CVE-2026-48145", "summary": "Improper Validation of Certificate with Host Mismatch vulnerability in Apache Thrift C++ bindings.\n\nThis issue affects Apache Thrift: before 0.24.0.\n\nUsers are recommended to upgrade to version 0.24.0, which fixes the issue.", "product": "Apache Software Foundation Apache Thrift", "category": "cve", "source": "NVD", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-48145", "card": "CVE-2026-48145.webp?v=1785155583", "takeaways": ["CVSS 4.0 : 8.2 HIGH", "Vector: AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N"], "ts": 1785154604, "exploited": 0, "has_score": 1, "created": 1785155450, "updated": 1785159442, "exploited_text": 0, "poc": 0, "score": 8.2, "kev": 0, "flags": []}, {"key": "CVE-2026-48144", "cve": "CVE-2026-48144", "lang": "en", "title": "CVE-2026-48144", "summary": "Improper Validation of Certificate with Host Mismatch vulnerability in Apache Thrift c_glib bindings.\n\nThis issue affects Apache Thrift: before 0.24.0.\n\nUsers are recommended to upgrade to version 0.24.0, which fixes the issue.", "product": "Apache Software Foundation Apache Thrift", "category": "cve", "source": "NVD", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-48144", "card": "CVE-2026-48144.webp?v=1785155583", "takeaways": ["CVSS 4.0 : 9.1 CRITICAL", "Vector: AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N"], "ts": 1785154604, "exploited": 0, "has_score": 1, "created": 1785155450, "updated": 1785159442, "exploited_text": 0, "poc": 0, "score": 9.1, "kev": 0, "flags": []}, {"key": "CVE-2026-43871", "cve": "CVE-2026-43871", "lang": "en", "title": "CVE-2026-43871", "summary": "Loop with Unreachable Exit Condition ('Infinite Loop') vulnerability in Apache Thrift Python, Go, PHP and Java bindings.This issue affects Apache Thrift: before 0.24.0.\n\nUsers are recommended to upgrade to version 0.24.0, which fixes the issue.", "product": "Apache Software Foundation Apache Thrift", "category": "cve", "source": "NVD", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-43871", "card": "CVE-2026-43871.webp?v=1785155582", "takeaways": ["CVSS 4.0 : 8.7 HIGH", "Vector: AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N"], "ts": 1785154604, "exploited": 0, "has_score": 1, "created": 1785155450, "updated": 1785159442, "exploited_text": 0, "poc": 0, "score": 8.7, "kev": 0, "flags": []}, {"key": "CVE-2026-41608", "cve": "CVE-2026-41608", "lang": "en", "title": "CVE-2026-41608", "summary": "Improper Handling of Highly Compressed Data (Data Amplification) vulnerability in Apache Thrift Python bindings.\n\nThis issue affects Apache Thrift: before 0.24.0.\n\nUsers are recommended to upgrade to version 0.24.0, which fixes the issue.", "product": "Apache Software Foundation Apache Thrift", "category": "cve", "source": "NVD", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-41608", "card": "CVE-2026-41608.webp?v=1785155582", "takeaways": [], "ts": 1785154604, "exploited": 0, "has_score": 0, "created": 1785155450, "updated": 1785159442, "exploited_text": 0, "poc": 0, "score": 0.0, "kev": 0, "flags": []}, {"key": "CVE-2026-12495", "cve": "CVE-2026-12495", "lang": "en", "title": "CVE-2026-12495", "summary": "Denial-of-service (DoS) vulnerability due to a stack buffer overflow in the http_gdpr_decrypt function of the Mercusys MB115-4G device's web interface. An unauthenticated attacker could exploit this vulnerability by sending a specially crafted request to the /cgi/login endpoint, causing memory corruption and the httpd process to crash, resulting in a denial of service for the web administration service.", "product": "Mercusys MB115-4G", "category": "cve", "source": "NVD", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-12495", "card": "CVE-2026-12495.webp?v=1785155583", "takeaways": ["CVSS 4.0 : 9.2 CRITICAL", "Vector: AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"], "ts": 1785154601, "exploited": 0, "has_score": 1, "created": 1785155450, "updated": 1785159442, "exploited_text": 0, "poc": 0, "score": 9.2, "kev": 0, "flags": []}, {"key": "CVE-2026-17527", "cve": "CVE-2026-17527", "lang": "en", "title": "CVE-2026-17527", "summary": "In containerized-data-importer (CDI), the aggregated cdi.kubevirt.io:view ClusterRole, intended to provide read-only access to CDI resources, includes a rule granting create on the datavolumes/source subresource. CDI's DataVolume clone authorization accepts this permission as sufficient to authorize cloning the contents of any PVC the caller can name, without requiring write access to the source namespace. A user or service account bound to the view role, commonly granted cluster-wide via ClusterRoleBinding, who also has ordinary write access (edit/admin) to any single namespace, can use this to exfiltrate the contents of any PVC in the cluster into a namespace they control, bypassing namespace isolation and the read-only guarantee of the view role.", "product": "Red Hat OpenShift Virtualization 4", "category": "cve", "source": "NVD", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-17527", "card": "CVE-2026-17527.webp?v=1785147588", "takeaways": ["CVSS 3.1 : 7.7 HIGH", "Vector: AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N"], "ts": 1785147397, "exploited": 0, "has_score": 1, "created": 1785147465, "updated": 1785159442, "exploited_text": 0, "poc": 0, "score": 7.7, "kev": 0, "flags": []}, {"key": "CVE-2026-17523", "cve": "CVE-2026-17523", "lang": "en", "title": "CVE-2026-17523", "summary": "A flaw was found in the kernel. An unprivileged local user can exploit this vulnerability to execute arbitrary code within the kernel, which leads to a local privilege escalation (LPE). This allows the attacker to gain root privileges and take full control of the affected system.", "product": "Red Hat Enterprise Linux 10", "category": "cve", "source": "NVD", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-17523", "card": "CVE-2026-17523.webp?v=1785147588", "takeaways": ["CVSS 3.1 : 7.8 HIGH", "Vector: AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"], "ts": 1785147396, "exploited": 0, "has_score": 1, "created": 1785147465, "updated": 1785159442, "exploited_text": 0, "poc": 0, "score": 7.8, "kev": 0, "flags": []}, {"key": "CVE-2026-65894", "cve": "CVE-2026-65894", "lang": "en", "title": "CVE-2026-65894", "summary": "This vulnerability exists in CP PLUS EZ-P21 IP Camera due to improper authentication of HTTP endpoints. A remote attacker could exploit this vulnerability by conducting brute-force attacks against HTTP endpoint on the targeted device.\n\n\n\nSuccessful exploitation of this vulnerability could allow an attacker to gain unauthorized access to live video snapshots from the targeted device.", "product": "CP-Plus EZ-P21 IP Camera", "category": "cve", "source": "NVD", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-65894", "card": "CVE-2026-65894.webp?v=1785141653", "takeaways": ["CVSS 4.0 : 8.7 HIGH", "Vector: AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N"], "ts": 1785140183, "exploited": 0, "has_score": 1, "created": 1785141530, "updated": 1785159442, "exploited_text": 0, "poc": 0, "score": 8.7, "kev": 0, "flags": []}, {"key": "CVE-2026-65893", "cve": "CVE-2026-65893", "lang": "en", "title": "CVE-2026-65893", "summary": "This vulnerability exists in CP PLUS EZ-P21 IP Camera due to an insecure debug feature enabled in the firmware.\n\nAn attacker with physical access could exploit this vulnerability by placing arbitrary code on removable media and triggering their execution through the debug mechanism.\n\n\n\nSuccessful exploitation of this vulnerability could allow an attacker to execute arbitrary code with elevated privileges on the targeted device.", "product": "CP-Plus EZ-P21 IP Camera", "category": "cve", "source": "NVD", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-65893", "card": "CVE-2026-65893.webp?v=1785141653", "takeaways": ["CVSS 4.0 : 7.0 HIGH", "Vector: AV:P/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"], "ts": 1785140183, "exploited": 0, "has_score": 1, "created": 1785141530, "updated": 1785159442, "exploited_text": 0, "poc": 0, "score": 7.0, "kev": 0, "flags": []}, {"key": "CVE-2026-64536", "cve": "CVE-2026-64536", "lang": "en", "title": "CVE-2026-64536", "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\nstaging: rtl8723bs: fix OOB reads in is_ap_in_tkip() IE loop\n\nThe loop in is_ap_in_tkip() iterates over IEs without verifying that\nenough bytes remain before dereferencing the IE header or its payload:\n\n- pIE->element_id and pIE->length are read without checking that\n  i + sizeof(*pIE)  data + 12,\n  which requires pIE->length >= 16.  For WLAN_EID_RSN it compares\n  pIE->data + 8, requiring pIE->length >= 12.  Neither requirement\n  is checked.\n\nAdd the missing IE header and payload bounds checks and guard each\ndata access with an explicit pIE->length minimum, matching the\npattern established in update_beacon_info().", "product": "Linux", "category": "cve", "source": "NVD", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-64536", "card": "CVE-2026-64536.webp?v=1785141654", "takeaways": [], "ts": 1785140182, "exploited": 0, "has_score": 0, "created": 1785141530, "updated": 1785159442, "exploited_text": 0, "poc": 0, "score": 0.0, "kev": 0, "flags": []}, {"key": "CVE-2026-64535", "cve": "CVE-2026-64535", "lang": "en", "title": "CVE-2026-64535", "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\nnvmet-tcp: Fix potential UAF when ddgst mismatch\n\nShivam Kumar found via vulnerability testing:\nWhen data digest is enabled on an NVMe/TCP connection and a digest\nmismatch occurs on a non-final H2C_DATA PDU during an R2T-based\ndata transfer, the digest error handler in nvmet_tcp_try_recv_ddgst()\ncalls nvmet_req_uninit() — which performs percpu_ref_put() on the\nsubmission queue — but does NOT mark the command as completed. It\ndoes not set cqe->status, does not modify rbytes_done, and does not\nclear any flag. When the subsequent fatal error triggers queue\nteardown, nvmet_tcp_uninit_data_in_cmds() iterates all commands,\nchecks nvmet_tcp_need_data_in() for each one, and finds that the\nalready-uninited command still appears to need data (because\nrbytes_done  status == 0). It therefore calls\nnvmet_req_uninit() a second time on the same command — a double\npercpu_ref_put against a single percpu_ref_get.", "product": "Linux", "category": "cve", "source": "NVD", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-64535", "card": "CVE-2026-64535.webp?v=1785141654", "takeaways": [], "ts": 1785140182, "exploited": 0, "has_score": 0, "created": 1785141530, "updated": 1785159442, "exploited_text": 0, "poc": 0, "score": 0.0, "kev": 0, "flags": []}, {"key": "CVE-2026-64534", "cve": "CVE-2026-64534", "lang": "en", "title": "CVE-2026-64534", "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\nnvmet-tcp: check INIT_FAILED before nvmet_req_uninit in digest error path\n\nIn nvmet_tcp_try_recv_ddgst(), when a data digest mismatch is detected,\nnvmet_req_uninit() is called unconditionally. However, if the command\narrived via the nvmet_tcp_handle_req_failure() path, nvmet_req_init()\nhad returned false and percpu_ref_tryget_live() was never executed. The\nunconditional percpu_ref_put() inside nvmet_req_uninit() then causes a\nrefcount underflow, leading to a WARNING in\npercpu_ref_switch_to_atomic_rcu, a use-after-free diagnostic, and\neventually a permanent workqueue deadlock.\n\nCheck cmd->flags & NVMET_TCP_F_INIT_FAILED before calling\nnvmet_req_uninit(), matching the existing pattern in\nnvmet_tcp_execute_request().", "product": "Linux", "category": "cve", "source": "NVD", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-64534", "card": "CVE-2026-64534.webp?v=1785141654", "takeaways": [], "ts": 1785140182, "exploited": 0, "has_score": 0, "created": 1785141530, "updated": 1785159442, "exploited_text": 0, "poc": 0, "score": 0.0, "kev": 0, "flags": []}, {"key": "CVE-2026-64533", "cve": "CVE-2026-64533", "lang": "en", "title": "CVE-2026-64533", "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\nfs/ntfs3: validate lcns_follow in log_replay conversion\n\nlog_replay() converts DIR_PAGE_ENTRY_32 records into DIR_PAGE_ENTRY\nrecords when replaying version 0 restart tables.\n\nDuring this conversion, the memmove() length is derived directly from\nthe on-disk lcns_follow field:\n\n\tmemmove(&dp->vcn, &dp0->vcn_low,\n\t\t2 * sizeof(u64) +\n\t\t\t\tle32_to_cpu(dp->lcns_follow) * sizeof(u64));\n\ncheck_rstbl() validates restart table structure, but does not constrain\nper-entry lcns_follow values relative to the entry size. A malformed\nfilesystem image can provide an oversized lcns_follow value, causing\nthe conversion memmove() to access memory beyond the bounds of the\nallocated restart table buffer.\n\nThe same field is later used to bound iteration over page_lcns[],\nso validating lcns_follow during conversion also prevents downstream\nout-of-bounds access from the same malformed metadata.\n\nCompute the maximum valid lcns_follow from the already-validated\nrestart table entry size and reject entries that exceed this bound.\nReuse the existing t16/t32 scratch variables already declared in\nlog_replay() to avoid introducing new declarations.", "product": "Linux", "category": "cve", "source": "NVD", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-64533", "card": "CVE-2026-64533.webp?v=1785141654", "takeaways": [], "ts": 1785140182, "exploited": 0, "has_score": 0, "created": 1785141530, "updated": 1785159442, "exploited_text": 0, "poc": 0, "score": 0.0, "kev": 0, "flags": []}, {"key": "CVE-2026-64532", "cve": "CVE-2026-64532", "lang": "en", "title": "CVE-2026-64532", "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\nfs/ntfs3: bound NTFS_DE view.data_off in UpdateRecordData{Root,Allocation}\n\nIn do_action()'s UpdateRecordDataRoot (fslog.c:3489) and\nUpdateRecordDataAllocation (fslog.c:3697) cases, the memmove\ndestination is `Add2Ptr(e, le16_to_cpu(e->view.data_off))`,\nwhere e->view.data_off comes from an on-disk NTFS_DE inside\nan INDEX_ROOT or INDEX_BUFFER.  Neither case validates\nview.data_off + dlen against e->size; the existing\ncheck_if_index_root / check_if_alloc_index helpers walk the\nentry chain and validate the entry's offset, but not its\ninternal view fields.\n\nThe neighbouring read sites (e.g., fs/ntfs3/index.c when\niterating view entries) check view.data_off + view.data_size\n size.  Apply the same bound at the two memmove sites.\n\nReproduced under UML+KASAN on mainline 8d90b09e6741 via\npr_warn-only probe instrumentation: with view.data_off forced\nto 0xFFFC, the memmove writes 32 bytes past the end of the\nNTFS_DE.\n\nThis is similar in shape to Pavitra Jha's 2026-05-02 patch\n\"fs/ntfs3: prevent oob in case UpdateRecordDataRoot\"\n( ) which\nproposes calling ntfs3_bad_de_range(); that helper does not\nexist in mainline.  This pat", "product": "Linux", "category": "cve", "source": "NVD", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-64532", "card": "CVE-2026-64532.webp?v=1785141653", "takeaways": [], "ts": 1785140182, "exploited": 0, "has_score": 0, "created": 1785141530, "updated": 1785159442, "exploited_text": 0, "poc": 0, "score": 0.0, "kev": 0, "flags": []}, {"key": "CVE-2026-64531", "cve": "CVE-2026-64531", "lang": "en", "title": "CVE-2026-64531", "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet: openvswitch: reject oversized nested action attrs\n\nOpen vSwitch stores generated flow actions as nlattrs, whose nla_len\nfield is u16. Commit a1e64addf3ff (\"net: openvswitch: remove\nmisbehaving actions length check\") allowed the total sw_flow_actions\nstream to grow beyond 64 KiB, which is valid, but also removed the last\nguard preventing a generated nested action attribute from exceeding\nU16_MAX.\n\nAn oversized generated container can thus be closed with a truncated\nnla_len. A later dump or teardown then walks a structurally different\nstream than the one that was validated. In particular, an oversized\nnested CLONE/CT action may cause subsequent bytes in the generated\nstream to be interpreted as independent actions.\n\nKeep the larger total-action-stream behavior, but make nested action\nclose reject generated containers that do not fit in nla_len, and return\nthe error through all callers. For recursive SAMPLE, CLONE, DEC_TTL, and\nCHECK_PKT_LEN builders, trim resource-owning action-list tails in reverse\nconstruction order before discarding failed wrappers, so resources copied\ninto the rejected tails are released be", "product": "Linux", "category": "cve", "source": "NVD", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-64531", "card": "CVE-2026-64531.webp?v=1785141653", "takeaways": [], "ts": 1785140182, "exploited": 0, "has_score": 0, "created": 1785141530, "updated": 1785159442, "exploited_text": 0, "poc": 0, "score": 0.0, "kev": 0, "flags": []}, {"key": "CVE-2026-14837", "cve": "CVE-2026-14837", "lang": "en", "title": "CVE-2026-14837", "summary": "Multiple Lenze products are affected by an improper signature verification vulnerability in the SSH enablement mechanism. A low-privileged local attacker can bypass verification of the SSH enable file signature and enable SSH access on the device. Successful exploitation may result in unauthorized administrative access and complete system compromise.", "product": "Lenze c430", "category": "cve", "source": "NVD", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-14837", "card": "CVE-2026-14837.webp?v=1785141654", "takeaways": ["CVSS 4.0 : 8.5 HIGH", "Vector: AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N", "CVSS 3.1 : 7.8 HIGH"], "ts": 1785140177, "exploited": 0, "has_score": 1, "created": 1785141530, "updated": 1785159442, "exploited_text": 0, "poc": 0, "score": 8.5, "kev": 0, "flags": []}, {"key": "CVE-2026-9830", "cve": "CVE-2026-9830", "lang": "en", "title": "CVE-2026-9830", "summary": "The bookingpress-appointment-booking-pro WordPress plugin before 5.7.3 does not correctly invoke its REST permission callback, leaving every route in one of its API namespaces reachable without authentication and allowing unauthenticated attackers to read customer booking data and modify other users' bookings.", "product": "bookingpress-appointment-booking-pro", "category": "cve", "source": "NVD", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-9830", "card": "CVE-2026-9830.webp?v=1785137667", "takeaways": [], "ts": 1785136590, "exploited": 0, "has_score": 0, "created": 1785137492, "updated": 1785159442, "exploited_text": 0, "poc": 0, "score": 0.0, "kev": 0, "flags": []}, {"key": "CVE-2026-66412", "cve": "CVE-2026-66412", "lang": "en", "title": "CVE-2026-66412", "summary": "Leantime 3.6.2 and prior contains a broken access control vulnerability that allows authenticated users to read milestone data from projects they are not assigned to by supplying arbitrary integer milestone IDs to the tickets.getMilestone JSON-RPC endpoint. Attackers can enumerate integer milestone IDs through the JSON-RPC API to access project planning information, milestone titles, descriptions, and timelines across all projects on the instance regardless of project membership.", "product": "Leantime", "category": "cve", "source": "NVD", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-66412", "card": "CVE-2026-66412.webp?v=1785137667", "takeaways": ["CVSS 4.0 : 7.1 HIGH", "Vector: AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N", "CVSS 3.1 : 6.5 MEDIUM"], "ts": 1785136590, "exploited": 0, "has_score": 1, "created": 1785137492, "updated": 1785159442, "exploited_text": 0, "poc": 0, "score": 7.1, "kev": 0, "flags": []}, {"key": "CVE-2026-14827", "cve": "CVE-2026-14827", "lang": "en", "title": "CVE-2026-14827", "summary": "The Calendar WordPress plugin before 1.3.18 does not properly escape a user-supplied event field before outputting it inside an HTML attribute on a public-facing page, allowing users with the Contributor role to inject arbitrary JavaScript that executes in the browser of anyone viewing the calendar.", "product": "Calendar", "category": "cve", "source": "NVD", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-14827", "card": "CVE-2026-14827.webp?v=1785137668", "takeaways": [], "ts": 1785136586, "exploited": 0, "has_score": 0, "created": 1785137492, "updated": 1785159442, "exploited_text": 0, "poc": 0, "score": 0.0, "kev": 0, "flags": []}, {"key": "CVE-2026-14820", "cve": "CVE-2026-14820", "lang": "en", "title": "CVE-2026-14820", "summary": "The Quiz and Survey Master (QSM)  WordPress plugin before 11.1.3 does not implement rate limiting or standard failed-login auditing on its front-end credential-check functionality and returns distinct responses for valid and invalid accounts, allowing unauthenticated attackers to enumerate valid usernames and to brute-force passwords while bypassing brute-force protection Quiz and Survey Master (QSM)  WordPress plugin before 11.1.3.", "product": "Quiz and Survey Master (QSM)", "category": "cve", "source": "NVD", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-14820", "card": "CVE-2026-14820.webp?v=1785137667", "takeaways": [], "ts": 1785136586, "exploited": 0, "has_score": 0, "created": 1785137492, "updated": 1785159442, "exploited_text": 0, "poc": 0, "score": 0.0, "kev": 0, "flags": []}, {"key": "CVE-2026-14568", "cve": "CVE-2026-14568", "lang": "en", "title": "CVE-2026-14568", "summary": "The User Frontend: AI Powered Frontend Post Submission, User Directory, User Profile, Membership & User Registration WordPress plugin before 4.3.8 does not correctly verify ownership before deleting an attachment, allowing unauthenticated attackers to permanently delete author-less attachments such as guest uploads and User Frontend: AI Powered Frontend Post Submission, User Directory, User Profile, Membership & User Registration WordPress plugin before 4.3.8-installed placeholder media.", "product": "User Frontend: AI Powered Frontend Post ", "category": "cve", "source": "NVD", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-14568", "card": "CVE-2026-14568.webp?v=1785137670", "takeaways": [], "ts": 1785136585, "exploited": 0, "has_score": 0, "created": 1785137492, "updated": 1785157443, "exploited_text": 0, "poc": 0, "score": 0.0, "kev": 0, "flags": []}, {"key": "CVE-2026-14289", "cve": "CVE-2026-14289", "lang": "en", "title": "CVE-2026-14289", "summary": "The FacturaONE para WooCommerce con VeriFactu WordPress plugin before 5.37 does not authenticate one of its request handlers, whose only protection is derived from a cryptographic key that is empty in the default, unconfigured state, allowing unauthenticated attackers to write an arbitrary file into a web-accessible directory and achieve remote code execution.", "product": "FacturaONE para WooCommerce con VeriFact", "category": "cve", "source": "NVD", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-14289", "card": "CVE-2026-14289.webp?v=1785137669", "takeaways": [], "ts": 1785136585, "exploited": 0, "has_score": 0, "created": 1785137492, "updated": 1785157443, "exploited_text": 0, "poc": 0, "score": 0.0, "kev": 0, "flags": []}, {"key": "CVE-2026-14236", "cve": "CVE-2026-14236", "lang": "en", "title": "CVE-2026-14236", "summary": "The Contact Form 7  WordPress plugin before 2.5 does not validate the host of a user-supplied return URL before using it as the success and cancel redirect targets of a Stripe checkout, allowing an unauthenticated attacker to redirect a victim, via a crafted link, to an arbitrary external site after the checkout flow.", "product": "Contact Form 7", "category": "cve", "source": "NVD", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-14236", "card": "CVE-2026-14236.webp?v=1785137669", "takeaways": [], "ts": 1785136585, "exploited": 0, "has_score": 0, "created": 1785137492, "updated": 1785157443, "exploited_text": 0, "poc": 0, "score": 0.0, "kev": 0, "flags": []}, {"key": "CVE-2026-14235", "cve": "CVE-2026-14235", "lang": "en", "title": "CVE-2026-14235", "summary": "The Download Manager WordPress plugin before 3.3.62 does not bind its temporary download token to the requesting session nor expire it promptly, making the token a long-lived, multi-use, portable bearer token, so that an attacker who obtains one leaked download key can repeatedly download a role- or password-protected package file without authorization.", "product": "Download Manager", "category": "cve", "source": "NVD", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-14235", "card": "CVE-2026-14235.webp?v=1785137669", "takeaways": [], "ts": 1785136585, "exploited": 0, "has_score": 0, "created": 1785137492, "updated": 1785157443, "exploited_text": 0, "poc": 0, "score": 0.0, "kev": 0, "flags": []}, {"key": "CVE-2026-14203", "cve": "CVE-2026-14203", "lang": "en", "title": "CVE-2026-14203", "summary": "The Smart Manager  WordPress plugin before 8.92.0 does not properly encode a post field before rendering it into an HTML attribute in its management grid, allowing users with the Contributor role or above to inject JavaScript that executes in the browser session of an administrator who views the grid.", "product": "Smart Manager", "category": "cve", "source": "NVD", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-14203", "card": "CVE-2026-14203.webp?v=1785137669", "takeaways": [], "ts": 1785136585, "exploited": 0, "has_score": 0, "created": 1785137492, "updated": 1785157443, "exploited_text": 0, "poc": 0, "score": 0.0, "kev": 0, "flags": []}, {"key": "CVE-2026-14190", "cve": "CVE-2026-14190", "lang": "en", "title": "CVE-2026-14190", "summary": "The Sina Extension for Elementor WordPress plugin before 3.10.2 does not escape a value reconstructed from request input in one of its unauthenticated AJAX handlers before reflecting it into the HTML response, allowing unauthenticated attackers to execute arbitrary JavaScript in the browser of anyone who triggers a crafted request.", "product": "Sina Extension for Elementor", "category": "cve", "source": "NVD", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-14190", "card": "CVE-2026-14190.webp?v=1785137669", "takeaways": [], "ts": 1785136585, "exploited": 0, "has_score": 0, "created": 1785137492, "updated": 1785157443, "exploited_text": 0, "poc": 0, "score": 0.0, "kev": 0, "flags": []}, {"key": "CVE-2026-14189", "cve": "CVE-2026-14189", "lang": "en", "title": "CVE-2026-14189", "summary": "The WPBot  WordPress plugin before 8.5.2 does not validate administrator-configured field identifiers before using them in a SQL query, allowing users with administrator access to perform SQL injection that executes when a visitor triggers a search.", "product": "WPBot", "category": "cve", "source": "NVD", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-14189", "card": "CVE-2026-14189.webp?v=1785137669", "takeaways": [], "ts": 1785136585, "exploited": 0, "has_score": 0, "created": 1785137492, "updated": 1785159442, "exploited_text": 0, "poc": 0, "score": 0.0, "kev": 0, "flags": []}, {"key": "CVE-2026-13726", "cve": "CVE-2026-13726", "lang": "en", "title": "CVE-2026-13726", "summary": "The MPG  WordPress plugin before 4.1.8 does not sanitise and escape a parameter before reflecting it back in the response, allowing unauthenticated attackers to perform Reflected Cross-Site Scripting against a victim who is induced to send a crafted request.", "product": "MPG", "category": "cve", "source": "NVD", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-13726", "card": "CVE-2026-13726.webp?v=1785137668", "takeaways": [], "ts": 1785136585, "exploited": 0, "has_score": 0, "created": 1785137492, "updated": 1785159442, "exploited_text": 0, "poc": 0, "score": 0.0, "kev": 0, "flags": []}, {"key": "CVE-2026-13714", "cve": "CVE-2026-13714", "lang": "en", "title": "CVE-2026-13714", "summary": "The Realtyna Organic IDX plugin + WPL Real Estate WordPress plugin before 5.3.0 does not validate the type of uploaded files, and its file upload functionality is gated only by an API that is enabled by default and authenticated with hardcoded credentials shipped identically across all installations. This makes it possible for unauthenticated attackers to upload arbitrary PHP files and achieve remote code execution.", "product": "Realtyna Organic IDX plugin + WPL Real E", "category": "cve", "source": "NVD", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-13714", "card": "CVE-2026-13714.webp?v=1785137668", "takeaways": [], "ts": 1785136585, "exploited": 0, "has_score": 0, "created": 1785137492, "updated": 1785159442, "exploited_text": 0, "poc": 0, "score": 0.0, "kev": 0, "flags": []}, {"key": "CVE-2026-13597", "cve": "CVE-2026-13597", "lang": "en", "title": "CVE-2026-13597", "summary": "The 微信二维码登陆 WordPress plugin through 1.3 does not properly validate WeChat webhook requests, as its signature check always passes, and it discloses the generated login code in the webhook response. This allows an unauthenticated attacker to forge a login event for any existing username, read the login code, and redeem it through an unauthenticated AJAX action to log in as that user, including an administrator, without a password.", "product": "微信二维码登陆", "category": "cve", "source": "NVD", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-13597", "card": "CVE-2026-13597.webp?v=1785137668", "takeaways": [], "ts": 1785136585, "exploited": 0, "has_score": 0, "created": 1785137492, "updated": 1785159442, "exploited_text": 0, "poc": 0, "score": 0.0, "kev": 0, "flags": []}, {"key": "CVE-2026-13400", "cve": "CVE-2026-13400", "lang": "en", "title": "CVE-2026-13400", "summary": "Simply Schedule Appointments is vulnerable to unauthenticated Stored Cross-Site Scripting in all versions up to and including 1.6.12.2. The root cause is a sanitization-ordering defect: the rendered notification content is decoded back into live HTML after it has already passed through the Simply Schedule Appointments WordPress plugin before 1.6.12.4's wp_kses_post() filter, so a double-encoded payload survives intake and is reintroduced as an executable element at render time.", "product": "Simply Schedule Appointments", "category": "cve", "source": "NVD", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-13400", "card": "CVE-2026-13400.webp?v=1785137668", "takeaways": [], "ts": 1785136585, "exploited": 0, "has_score": 0, "created": 1785137492, "updated": 1785159442, "exploited_text": 0, "poc": 0, "score": 0.0, "kev": 0, "flags": []}, {"key": "CVE-2026-13390", "cve": "CVE-2026-13390", "lang": "en", "title": "CVE-2026-13390", "summary": "The Events Calendar WordPress plugin before 6.16.5.1 does not perform an authorization check on one of its Event Aggregator import REST API routes and skips an integrity check for a particular status value, allowing unauthenticated attackers to mark existing import records as failed and to store arbitrary content in a hidden comment record.", "product": "The Events Calendar", "category": "cve", "source": "NVD", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-13390", "card": "CVE-2026-13390.webp?v=1785137671", "takeaways": [], "ts": 1785136584, "exploited": 0, "has_score": 0, "created": 1785137492, "updated": 1785153455, "exploited_text": 0, "poc": 0, "score": 0.0, "kev": 0, "flags": []}, {"key": "CVE-2026-13332", "cve": "CVE-2026-13332", "lang": "en", "title": "CVE-2026-13332", "summary": "The Masteriyo LMS  WordPress plugin before 2.3.1 does not correctly verify authorization on an unauthenticated AJAX action used to clear user sessions, allowing unauthenticated attackers to terminate the active sessions (force-logout) of any user on the site, including administrators.", "product": "Masteriyo LMS", "category": "cve", "source": "NVD", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-13332", "card": "CVE-2026-13332.webp?v=1785137671", "takeaways": [], "ts": 1785136584, "exploited": 0, "has_score": 0, "created": 1785137492, "updated": 1785153455, "exploited_text": 0, "poc": 0, "score": 0.0, "kev": 0, "flags": []}, {"key": "CVE-2026-13152", "cve": "CVE-2026-13152", "lang": "en", "title": "CVE-2026-13152", "summary": "The Custom Fields Account Registration For Woocommerce WordPress plugin before 1.4 does not prevent its custom registration fields from writing to the user capabilities meta key on sites that use a non-default database table prefix, so an unauthenticated user who registers an account can be granted the administrator role when a correspondingly named field has been configured.", "product": "Custom Fields Account Registration For W", "category": "cve", "source": "NVD", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-13152", "card": "CVE-2026-13152.webp?v=1785137671", "takeaways": [], "ts": 1785136584, "exploited": 0, "has_score": 0, "created": 1785137492, "updated": 1785153455, "exploited_text": 0, "poc": 0, "score": 0.0, "kev": 0, "flags": []}, {"key": "CVE-2026-12982", "cve": "CVE-2026-12982", "lang": "en", "title": "CVE-2026-12982", "summary": "The Document Gallery WordPress plugin before 5.1.1 does not properly sanitise and escape user input before reflecting it back in the response of an unauthenticated AJAX action, leading to a Reflected Cross-Site Scripting vulnerability which can be exploited against unauthenticated users.", "product": "Document Gallery", "category": "cve", "source": "NVD", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-12982", "card": "CVE-2026-12982.webp?v=1785137671", "takeaways": [], "ts": 1785136584, "exploited": 0, "has_score": 0, "created": 1785137492, "updated": 1785153455, "exploited_text": 0, "poc": 0, "score": 0.0, "kev": 0, "flags": []}, {"key": "CVE-2026-12493", "cve": "CVE-2026-12493", "lang": "en", "title": "CVE-2026-12493", "summary": "The Clover Payment Gateway by Zaytech for WooCommerce WordPress plugin before 1.3.6 does not verify that an approved external payment record actually belongs to the WooCommerce order being completed, nor that the paid amount matches the order total, allowing unauthenticated users to mark arbitrary orders as paid by replaying a single genuinely-approved payment reference (for example one obtained from their own minimal purchase).", "product": "Clover Payment Gateway by Zaytech for Wo", "category": "cve", "source": "NVD", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-12493", "card": "CVE-2026-12493.webp?v=1785137670", "takeaways": [], "ts": 1785136584, "exploited": 0, "has_score": 0, "created": 1785137492, "updated": 1785157443, "exploited_text": 0, "poc": 0, "score": 0.0, "kev": 0, "flags": []}, {"key": "CVE-2026-12394", "cve": "CVE-2026-12394", "lang": "en", "title": "CVE-2026-12394", "summary": "The MemberGlut  WordPress plugin before 1.1.5 does not validate the role chosen during front-end registration, allowing unauthenticated users to register an account with an arbitrary role, including administrator, leading to full site compromise.", "product": "MemberGlut", "category": "cve", "source": "NVD", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-12394", "card": "CVE-2026-12394.webp?v=1785137670", "takeaways": [], "ts": 1785136584, "exploited": 0, "has_score": 0, "created": 1785137492, "updated": 1785157443, "exploited_text": 0, "poc": 0, "score": 0.0, "kev": 0, "flags": []}, {"key": "CVE-2026-12255", "cve": "CVE-2026-12255", "lang": "en", "title": "CVE-2026-12255", "summary": "The MainWP Child  WordPress plugin before 6.1.2 does not verify the requester's identity in its site-registration request handler when password authentication has been disabled for the targeted account, allowing an unauthenticated attacker to obtain a valid authentication session as that account, including an administrator, by naming its login in a single registration request.", "product": "MainWP Child", "category": "cve", "source": "NVD", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-12255", "card": "CVE-2026-12255.webp?v=1785137670", "takeaways": [], "ts": 1785136584, "exploited": 0, "has_score": 0, "created": 1785137492, "updated": 1785155450, "exploited_text": 0, "poc": 0, "score": 0.0, "kev": 0, "flags": []}, {"key": "CVE-2026-10082", "cve": "CVE-2026-10082", "lang": "en", "title": "CVE-2026-10082", "summary": "The Advanced Ads  WordPress plugin before 2.0.23 does not sanitize and escape a shortcode parameter before outputting it in the page, allowing users with the Contributor role and above to inject arbitrary web scripts that execute when the affected content is viewed, including by higher-privileged users.", "product": "Advanced Ads", "category": "cve", "source": "NVD", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-10082", "card": "CVE-2026-10082.webp?v=1785137670", "takeaways": [], "ts": 1785136584, "exploited": 0, "has_score": 0, "created": 1785137492, "updated": 1785155450, "exploited_text": 0, "poc": 0, "score": 0.0, "kev": 0, "flags": []}, {"key": "CVE-2025-15662", "cve": "CVE-2025-15662", "lang": "en", "title": "CVE-2025-15662", "summary": "The Printcart Web to Print Product Designer for WooCommerce WordPress plugin before 2.5.3 does not restrict a user-supplied URL before fetching it server-side and does not enforce a valid authorization check, allowing unauthenticated attackers to read arbitrary local files (including configuration files containing database credentials and secret keys) and to make server-side requests to internal resources.", "product": "Printcart Web to Print Product Designer ", "category": "cve", "source": "NVD", "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-15662", "card": "CVE-2025-15662.webp?v=1785137671", "takeaways": [], "ts": 1785136583, "exploited": 0, "has_score": 0, "created": 1785137492, "updated": 1785153455, "exploited_text": 0, "poc": 0, "score": 0.0, "kev": 0, "flags": []}, {"key": "CVE-2026-15928", "cve": "CVE-2026-15928", "lang": "en", "title": "CVE-2026-15928", "summary": "XMLRPC-C Library versions 1.07 through 1.67.01 are vulnerable to a reflected cross-site scripting (XSS) vulnerability in the error page component.", "product": "XMLRPC-C", "category": "cve", "source": "NVD", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-15928", "card": "CVE-2026-15928.webp?v=1785123686", "takeaways": ["CVSS 4.0 : 8.2 HIGH", "Vector: AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N"], "ts": 1785122178, "exploited": 0, "has_score": 1, "created": 1785123577, "updated": 1785153455, "exploited_text": 0, "poc": 0, "score": 8.2, "kev": 0, "flags": []}, {"key": "CVE-2026-57990", "cve": "CVE-2026-57990", "lang": "en", "title": "CVE-2026-57990", "summary": "Files or directories accessible to external parties in Microsoft Edge (Chromium-based) allows an unauthorized attacker to disclose information over a network.", "product": "Microsoft Edge (Chromium-based)", "category": "cve", "source": "NVD", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-57990", "card": "CVE-2026-57990.webp?v=1785090314", "takeaways": ["CVSS 3.1 : 7.4 HIGH", "Vector: AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:N/A:N"], "ts": 1785089905, "exploited": 0, "has_score": 1, "created": 1785090213, "updated": 1785153455, "exploited_text": 0, "poc": 0, "score": 7.4, "kev": 0, "flags": []}, {"key": "CVE-2026-57989", "cve": "CVE-2026-57989", "lang": "en", "title": "CVE-2026-57989", "summary": "Origin validation error in Microsoft Edge (Chromium-based) allows an unauthorized attacker to disclose information over a network.", "product": "Microsoft Edge (Chromium-based)", "category": "cve", "source": "NVD", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-57989", "card": "CVE-2026-57989.webp?v=1785090313", "takeaways": ["CVSS 3.1 : 7.4 HIGH", "Vector: AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:N/A:N"], "ts": 1785089905, "exploited": 0, "has_score": 1, "created": 1785090213, "updated": 1785153455, "exploited_text": 0, "poc": 0, "score": 7.4, "kev": 0, "flags": []}, {"key": "CVE-2026-17497", "cve": "CVE-2026-17497", "lang": "en", "title": "CVE-2026-17497", "summary": "NoteGen before 0.32.0 grants the Tauri shell plugin shell:allow-execute capability for bash, python, and python3 with arbitrary arguments in the default desktop capabilities. JavaScript running in the application webview can therefore invoke plugin:shell|execute to run attacker-controlled operating system commands with the privileges of the NoteGen process. In combination with script execution in the webview (for example via chat XSS), this enables full remote code execution on the user's machine.", "product": "codexu NoteGen", "category": "cve", "source": "NVD", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-17497", "card": "CVE-2026-17497.webp?v=1785080480", "takeaways": ["CVSS 3.1 : 8.3 HIGH", "Vector: AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H"], "ts": 1785078987, "exploited": 0, "has_score": 1, "created": 1785080381, "updated": 1785153455, "exploited_text": 0, "poc": 0, "score": 8.3, "kev": 0, "flags": []}, {"key": "CVE-2026-17496", "cve": "CVE-2026-17496", "lang": "en", "title": "CVE-2026-17496", "summary": "NoteGen before 0.32.0 renders AI chat responses with markdown-it configured with html:true and injects the result into the DOM via dangerouslySetInnerHTML in chat-preview, without HTML sanitization and with CSP set to null. Attacker-controlled content that reaches the model prompt (for example a malicious skill REFERENCE.md that instructs the model to emit HTML) can cause the model response to include executable markup such as an img onerror handler. When the user views the chat response, that markup runs as JavaScript in the privileged Tauri webview, enabling arbitrary script execution in the application context (cross-site scripting).", "product": "codexu NoteGen", "category": "cve", "source": "NVD", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-17496", "card": "CVE-2026-17496.webp?v=1785080480", "takeaways": ["CVSS 3.1 : 8.1 HIGH", "Vector: AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N"], "ts": 1785078987, "exploited": 0, "has_score": 1, "created": 1785080381, "updated": 1785153455, "exploited_text": 0, "poc": 0, "score": 8.1, "kev": 0, "flags": []}, {"key": "CVE-2026-64530", "cve": "CVE-2026-64530", "lang": "en", "title": "CVE-2026-64530", "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet/sched: cls_api: Handle TC_ACT_CONSUMED in tcf_qevent_handle\n\ntcf_classify() can return TC_ACT_CONSUMED while the skb is held by the\ndefragmentation engine (e.g. act_ct on out-of-order fragments). When\nthat happens the skb is no longer owned by the caller and must not be\ntouched again.\n\ntcf_qevent_handle() did not handle TC_ACT_CONSUMED: it fell through the\nswitch and returned the skb to the caller as if classification had\npassed. The only qdisc that wires up qevents today is RED, via three call sites\n(qe_mark on RED_PROB_MARK/HARD_MARK, qe_early_drop on congestion_drop)\nred_enqueue() was continuing to operate on an skb it no longer owns  in this\ncase -- enqueueing it, dropping it, or updating statistics. Resulting in a UAF.\n\n  tc qdisc add dev eth0 root handle 1: red ... qevent early_drop block 10\n  tc filter add block 10 ... action ct\n\n  (with ct defrag enabled and traffic that produces out-of-order\n  fragments, e.g. a fragmented UDP stream)\n\nHandle TC_ACT_CONSUMED in tcf_qevent_handle() the same way the ingress\nand egress fast paths do: treat it as stolen and return NULL without\ntouching the skb. Unlike the ", "product": "Linux", "category": "cve", "source": "NVD", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-64530", "card": "CVE-2026-64530.webp?v=1785129632", "takeaways": ["CVSS 3.1 : 9.8 CRITICAL", "Vector: AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"], "ts": 1785050201, "exploited": 0, "has_score": 1, "created": 1785052282, "updated": 1785145485, "exploited_text": 0, "poc": 0, "score": 9.8, "kev": 0, "flags": []}, {"key": "CVE-2024-14040", "cve": "CVE-2024-14040", "lang": "en", "title": "CVE-2024-14040", "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet: nexthop: Increase weight to u16\n\nIn CLOS networks, as link failures occur at various points in the network,\nECMP weights of the involved nodes are adjusted to compensate. With high\nfan-out of the involved nodes, and overall high number of nodes,\na (non-)ECMP weight ratio that we would like to configure does not fit into\n8 bits. Instead of, say, 255:254, we might like to configure something like\n1000:999. For these deployments, the 8-bit weight may not be enough.\n\nTo that end, in this patch increase the next hop weight from u8 to u16.\n\nIncreasing the width of an integral type can be tricky, because while the\ncode still compiles, the types may not check out anymore, and numerical\nerrors come up. To prevent this, the conversion was done in two steps.\nFirst the type was changed from u8 to a single-member structure, which\ninvalidated all uses of the field. This allowed going through them one by\none and audit for type correctness. Then the structure was replaced with a\nvanilla u16 again. This should ensure that no place was missed.\n\nThe UAPI for configuring nexthop group members is that an attribute\nNHA_GROUP carri", "product": "Linux", "category": "cve", "source": "NVD", "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-14040", "card": "CVE-2024-14040.webp?v=1785052382", "takeaways": [], "ts": 1785050199, "exploited": 0, "has_score": 0, "created": 1785052282, "updated": 1785145485, "exploited_text": 0, "poc": 0, "score": 0.0, "kev": 0, "flags": []}, {"key": "CVE-2026-63720", "cve": "CVE-2026-63720", "lang": "en", "title": "CVE-2026-63720", "summary": "datamodel-code-generator prior to version 0.70.0 contains a code injection vulnerability that allows attackers who control input schemas to achieve remote code execution by supplying a malicious customBasePath value containing embedded newlines and a dot-free Python expression. The crafted value is emitted verbatim into a generated 'from ... import ...' statement without identifier validation, causing arbitrary Python code to execute when the generated module is imported.", "product": "koxudaxi datamodel-code-generator", "category": "cve", "source": "NVD", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-63720", "card": "CVE-2026-63720.webp?v=1785045293", "takeaways": ["CVSS 4.0 : 7.5 HIGH", "Vector: AV:N/AC:H/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N", "CVSS 3.1 : 7.5 HIGH"], "ts": 1785042983, "exploited": 0, "has_score": 1, "created": 1785045192, "updated": 1785139536, "exploited_text": 0, "poc": 0, "score": 7.5, "kev": 0, "flags": []}, {"key": "CVE-2026-15962", "cve": "CVE-2026-15962", "lang": "en", "title": "CVE-2026-15962", "summary": "The Fluent Forms Pro Add On Pack plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 6.2.6 via deserialization of untrusted input. This makes it possible for authenticated attackers, with Subscriber-level access and above, to inject a PHP Object. The additional presence of a POP chain allows attackers to change user passwords and potentially take over administrator accounts. Note: This can only be exploited if user update integration is enabled and a user meta field is mapped.", "product": "techjewel Fluent Forms Pro Add On Pack", "category": "cve", "source": "NVD", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-15962", "card": "CVE-2026-15962.webp?v=1785033445", "takeaways": ["CVSS 3.1 : 8.8 HIGH", "Vector: AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"], "ts": 1785032188, "exploited": 0, "has_score": 1, "created": 1785033347, "updated": 1785139536, "exploited_text": 0, "poc": 0, "score": 8.8, "kev": 0, "flags": []}, {"key": "CVE-2026-66013", "cve": "CVE-2026-66013", "lang": "en", "title": "CVE-2026-66013", "summary": "OpenRemote before 1.26.2 contains an authentication bypass vulnerability in the console registration API that allows unauthenticated attackers to update existing console assets by supplying a known asset identifier. Attackers can overwrite push notification tokens and console metadata without authentication or ownership validation, redirecting notifications or denying delivery to legitimate consoles.", "product": "openremote", "category": "cve", "source": "NVD", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-66013", "card": "CVE-2026-66013.webp?v=1784979047", "takeaways": ["CVSS 4.0 : 9.3 CRITICAL", "Vector: AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N"], "ts": 1784978239, "exploited": 0, "has_score": 1, "created": 1784978948, "updated": 1785139536, "exploited_text": 0, "poc": 0, "score": 9.3, "kev": 0, "flags": []}, {"key": "CVE-2026-66012", "cve": "CVE-2026-66012", "lang": "en", "title": "CVE-2026-66012", "summary": "SiYuan before v3.7.2 contains a missing authorization vulnerability in the POST /mcp kernel endpoint, which is gated only by a general auth check (model.CheckAuth) with no admin-role or read-only enforcement. This exposes 31 MCP tools, including a file tool with list/read/write/delete/rename/copy actions across the entire workspace. When the Publish server is enabled in anonymous mode (Conf.Publish.Enable=true and Conf.Publish.Auth.Enable=false), the Publish reverse proxy attaches an anonymous RoleReader JWT to proxied requests, allowing a remote unauthenticated attacker to reach /mcp. The attacker can read conf/conf.json to extract accessAuthCode, api.token, and cookieKey in plaintext, write arbitrary files in the workspace, and plant a plugin into data/plugins/ that executes with nodeIntegration:true and no contextIsolation on the next desktop launch, leading to administrator takeover.", "product": "siyuan-note siyuan", "category": "cve", "source": "NVD", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-66012", "card": "CVE-2026-66012.webp?v=1784979047", "takeaways": ["CVSS 4.0 : 10.0 CRITICAL", "Vector: AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H", "CVSS 3.1 : 10.0 CRITICAL"], "ts": 1784978239, "exploited": 0, "has_score": 1, "created": 1784978948, "updated": 1785139536, "exploited_text": 0, "poc": 0, "score": 10.0, "kev": 0, "flags": []}, {"key": "CVE-2026-64529", "cve": "CVE-2026-64529", "lang": "en", "title": "CVE-2026-64529", "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\ncrypto: qat - remove unused character device and IOCTLs\n\nThe QAT driver exposes a character device (qat_adf_ctl) with IOCTLs\nfor device configuration, start, stop, status query and enumeration.\nThese IOCTLs are not part of any public uAPI header and have no known\nin-tree or out-of-tree users. Device lifecycle is already managed via\nsysfs.\n\nThe ioctl interface also increases the attack surface and is the\nsubject of a number of bug reports.\n\nRemove the character device, the IOCTL definitions, and the related\ndata structures (adf_dev_status_info, adf_user_cfg_key_val,\nadf_user_cfg_section, adf_user_cfg_ctl_data). Drop the now-unused\nadf_cfg_user.h header and strip adf_ctl_drv.c down to the minimal\nmodule_init/module_exit hooks for workqueue, AER, and crypto/compression\nalgorithm registration.\n\nClean up leftover dead code that was only reachable from the removed\nIOCTL paths: adf_cfg_del_all(), adf_devmgr_verify_id(),\nadf_devmgr_get_num_dev(), adf_devmgr_get_dev_by_id(),\nadf_get_vf_real_id() and the unused ADF_CFG macros.\n\nAdditionally, drop the entry associated to QAT IOCTLs in\nioctl-number.rst.", "product": "Linux", "category": "cve", "source": "NVD", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-64529", "card": "CVE-2026-64529.webp?v=1785129632", "takeaways": ["CVSS 3.1 : 7.8 HIGH", "Vector: AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"], "ts": 1784974659, "exploited": 0, "has_score": 1, "created": 1784976482, "updated": 1785139536, "exploited_text": 0, "poc": 0, "score": 7.8, "kev": 0, "flags": []}, {"key": "CVE-2026-64528", "cve": "CVE-2026-64528", "lang": "en", "title": "CVE-2026-64528", "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\ntty: serial: samsung: Remove redundant port lock acquisition in rx helpers\n\nSashiko identified a deadlock when the console flow is engaged [1].\n\nWhen console flow control is enabled (UPF_CONS_FLOW),\ns3c24xx_serial_stop_tx() calls s3c24xx_serial_rx_enable() and\ns3c24xx_serial_start_tx() calls s3c24xx_serial_rx_disable().\n\nThe serial core framework invokes the .stop_tx() and .start_tx()\ncallbacks with the port->lock spinlock already held. Furthermore, all\ninternal driver paths that invoke stop_tx (such as the DMA TX\ncompletion handler s3c24xx_serial_tx_dma_complete() or the PIO TX IRQ\nhandler s3c24xx_serial_tx_irq()) also acquire port->lock prior to\ncalling it. (Note that s3c24xx_serial_start_tx() is only invoked by the\nserial core).\n\nHowever, s3c24xx_serial_rx_enable() and s3c24xx_serial_rx_disable()\nunconditionally attempt to acquire port->lock again using\nuart_port_lock_irqsave(). Since spinlocks are not recursive, this\ncauses a deadlock on the same CPU when console flow control is engaged.\n\nRemove the redundant lock acquisition from both rx helper functions.", "product": "Linux", "category": "cve", "source": "NVD", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-64528", "card": "CVE-2026-64528.webp?v=1784976683", "takeaways": [], "ts": 1784974659, "exploited": 0, "has_score": 0, "created": 1784976482, "updated": 1785139536, "exploited_text": 0, "poc": 0, "score": 0.0, "kev": 0, "flags": []}, {"key": "CVE-2026-64527", "cve": "CVE-2026-64527", "lang": "en", "title": "CVE-2026-64527", "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/hyperv: validate VMBus packet size in receive callback\n\nhyperv_receive_sub() reads msg->vid_hdr.type and dispatches into one\nof four message-type branches without knowing how many bytes the host\nwrote into hv->recv_buf. The completion path then runs\nmemcpy(hv->init_buf, msg, VMBUS_MAX_PACKET_SIZE), so the consumer that\nwakes on wait_for_completion_timeout() can read up to 16 KiB of\nresidue from a prior message as if it were the response payload.\n\nPass bytes_recvd into hyperv_receive_sub() and reject any packet that\ndoes not cover the pipe + synthvid header. A single switch on\nmsg->vid_hdr.type then computes the type-specific payload size: the\nthree completion-driving types (SYNTHVID_VERSION_RESPONSE,\nSYNTHVID_RESOLUTION_RESPONSE, SYNTHVID_VRAM_LOCATION_ACK) fall through\nto a shared exit that requires that size before memcpy/complete, while\nSYNTHVID_FEATURE_CHANGE validates its own payload and returns before\nreading is_dirt_needed. Unknown types are dropped.\n\nSYNTHVID_RESOLUTION_RESPONSE is variable length: the host fills\nresolution_count entries, not the full SYNTHVID_MAX_RESOLUTION_COUNT\narray. Validate the f", "product": "Linux", "category": "cve", "source": "NVD", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-64527", "card": "CVE-2026-64527.webp?v=1784976683", "takeaways": [], "ts": 1784974659, "exploited": 0, "has_score": 0, "created": 1784976482, "updated": 1785139536, "exploited_text": 0, "poc": 0, "score": 0.0, "kev": 0, "flags": []}, {"key": "CVE-2026-64526", "cve": "CVE-2026-64526", "lang": "en", "title": "CVE-2026-64526", "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\nethtool: tsconfig: fix missing ethnl_ops_complete()\n\ntsconfig_prepare_data() calls ethnl_ops_begin(), we need to call\nethnl_ops_complete() before returning the error.", "product": "Linux", "category": "cve", "source": "NVD", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-64526", "card": "CVE-2026-64526.webp?v=1784976685", "takeaways": [], "ts": 1784974658, "exploited": 0, "has_score": 0, "created": 1784976482, "updated": 1785135478, "exploited_text": 0, "poc": 0, "score": 0.0, "kev": 0, "flags": []}, {"key": "CVE-2026-64525", "cve": "CVE-2026-64525", "lang": "en", "title": "CVE-2026-64525", "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\nxfrm: move policy_bydst RCU sync from per-netns .exit to .pre_exit\n\nThe struct pernet_operations docstring in include/net/net_namespace.h\nexplicitly warns against blocking RCU primitives in .exit handlers:\n\n    Exit methods using blocking RCU primitives, such as\n    synchronize_rcu(), should be implemented via exit_batch.\n    [...]\n    Please, avoid synchronize_rcu() at all, where it's possible.\n\n    Note that a combination of pre_exit() and exit() can\n    be used, since a synchronize_rcu() is guaranteed between\n    the calls.\n\nxfrm_policy_fini() violates this: it calls synchronize_rcu() before\nfreeing the policy_bydst hash tables (so no RCU reader is mid-\ntraversal at free time), but runs from xfrm_net_ops.exit -- once per\nnamespace -- so a cleanup_net() of N namespaces pays N full RCU\ngrace periods serially.\n\nUse the documented pre_exit/exit split. Move the policy flush (and\nthe workqueue drains it depends on) into a new .pre_exit handler;\nxfrm_policy_fini() then runs in .exit and frees the hash tables\nafter the synchronize_rcu_expedited() that cleanup_net() guarantees\nbetween the two phases. Providing O(1) RCU ", "product": "Linux", "category": "cve", "source": "NVD", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-64525", "card": "CVE-2026-64525.webp?v=1784976685", "takeaways": [], "ts": 1784974658, "exploited": 0, "has_score": 0, "created": 1784976482, "updated": 1785135478, "exploited_text": 0, "poc": 0, "score": 0.0, "kev": 0, "flags": []}, {"key": "CVE-2026-64524", "cve": "CVE-2026-64524", "lang": "en", "title": "CVE-2026-64524", "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/hyperv: validate resolution_count and fix WIN8 fallback\n\nA SYNTHVID_RESOLUTION_RESPONSE with resolution_count > 64 walks past\nthe supported_resolution[SYNTHVID_MAX_RESOLUTION_COUNT] array in the\nparse loop. Bound resolution_count against the array size, folded\ninto the existing zero-check.\n\nWhen the WIN10 resolution probe fails, the caller in\nhyperv_connect_vsp() left hv->screen_*_max / preferred_* unpopulated,\nwhich sets mode_config.max_width / max_height to 0 and makes\ndrm_internal_framebuffer_create() reject every userspace framebuffer\nwith -EINVAL. The pre-WIN10 branch had the same gap for\npreferred_width / preferred_height. Use a single post-probe fallback\nguarded by screen_width_max == 0 so both paths converge on the WIN8\ndefaults.", "product": "Linux", "category": "cve", "source": "NVD", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-64524", "card": "CVE-2026-64524.webp?v=1785129633", "takeaways": ["CVSS 3.1 : 7.7 HIGH", "Vector: AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H"], "ts": 1784974658, "exploited": 0, "has_score": 1, "created": 1784976482, "updated": 1785135478, "exploited_text": 0, "poc": 0, "score": 7.7, "kev": 0, "flags": []}, {"key": "CVE-2026-64523", "cve": "CVE-2026-64523", "lang": "en", "title": "CVE-2026-64523", "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet/handshake: Take a long-lived file reference at submit\n\nhandshake_nl_accept_doit() needs the file pointer backing\nreq->hr_sk->sk_socket to survive the window between\nhandshake_req_next() and the subsequent FD_PREPARE() and get_file().\nThe submit-side sock_hold() does not provide that.  sk_refcnt keeps\nstruct sock alive, but struct socket is owned by sock->file: when\nthe consumer fputs the last file reference, sock_release() tears\nthe socket down regardless of any sock_hold.\n\nAdd an hr_file pointer to struct handshake_req and acquire an\nexplicit reference on sock->file during handshake_req_submit().\nhandshake_complete() and handshake_req_cancel() release the\nreference on the completion-bit-winning path.\n\nThe submit error path must also release the file reference, but\nafter rhashtable insertion a concurrent handshake_req_cancel() can\ndiscover the request and race the error path.  Gate the error-path\ncleanup -- sk_destruct restoration, fput, and request destruction\n-- with test_and_set_bit(HANDSHAKE_F_REQ_COMPLETED), the same\nserialization handshake_complete() and handshake_req_cancel()\nalready use.  When cancel h", "product": "Linux", "category": "cve", "source": "NVD", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-64523", "card": "CVE-2026-64523.webp?v=1785129633", "takeaways": ["CVSS 3.1 : 9.8 CRITICAL", "Vector: AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"], "ts": 1784974658, "exploited": 0, "has_score": 1, "created": 1784976482, "updated": 1785135478, "exploited_text": 0, "poc": 0, "score": 9.8, "kev": 0, "flags": []}, {"key": "CVE-2026-64522", "cve": "CVE-2026-64522", "lang": "en", "title": "CVE-2026-64522", "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet/mlx5e: Fix eswitch mode block underflow on IPsec acquire SA\n\nmlx5e_xfrm_add_state() handles acquire-flow temporary SAs by allocating\nsoftware state and skipping hardware offload setup.\n\nThat path jumps to the common success label before taking the eswitch mode\nblock. After tunnel-mode validation was moved earlier, the common success\nlabel unconditionally calls mlx5_eswitch_unblock_mode(). For acquire SAs,\nthis decrements esw->offloads.num_block_mode without a matching increment.\n\nReturn directly after installing the acquire SA offload handle, so only the\npaths that successfully called mlx5_eswitch_block_mode() call the matching\nunblock.", "product": "Linux", "category": "cve", "source": "NVD", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-64522", "card": "CVE-2026-64522.webp?v=1785129632", "takeaways": ["CVSS 3.1 : 8.8 HIGH", "Vector: AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"], "ts": 1784974658, "exploited": 0, "has_score": 1, "created": 1784976482, "updated": 1785135478, "exploited_text": 0, "poc": 0, "score": 8.8, "kev": 0, "flags": []}, {"key": "CVE-2026-64521", "cve": "CVE-2026-64521", "lang": "en", "title": "CVE-2026-64521", "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\npinctrl: meson: amlogic-a4: fix deadlock issue\n\nAccessing the pinconf-pins sysfs node may deadlock.\n\npinconf_pins_show() holds pctldev->mutex, and the platform driver\ncalls pinctrl_find_gpio_range_from_pin(), which tries to acquire\nthe same mutex again, leading to a deadlock.\n\nUse pinctrl_find_gpio_range_from_pin_nolock() to fix this issue.", "product": "Linux", "category": "cve", "source": "NVD", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-64521", "card": "CVE-2026-64521.webp?v=1784976684", "takeaways": [], "ts": 1784974658, "exploited": 0, "has_score": 0, "created": 1784976482, "updated": 1785139536, "exploited_text": 0, "poc": 0, "score": 0.0, "kev": 0, "flags": []}, {"key": "CVE-2026-64520", "cve": "CVE-2026-64520", "lang": "en", "title": "CVE-2026-64520", "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\nfirmware: arm_ffa: Bound PARTITION_INFO_GET_REGS copies\n\nThe register-based PARTITION_INFO_GET path trusted the firmware-provided\nindices when copying partition descriptors into the caller buffer.\nReject inconsistent counts or index progressions so the copy loop cannot\nwrite past the allocated array.\n\n(fixed cur_idx when exactly one descriptor in the first fragment)", "product": "Linux", "category": "cve", "source": "NVD", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-64520", "card": "CVE-2026-64520.webp?v=1785129632", "takeaways": ["CVSS 3.1 : 8.4 HIGH", "Vector: AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"], "ts": 1784974658, "exploited": 0, "has_score": 1, "created": 1784976482, "updated": 1785139536, "exploited_text": 0, "poc": 0, "score": 8.4, "kev": 0, "flags": []}, {"key": "CVE-2026-64519", "cve": "CVE-2026-64519", "lang": "en", "title": "CVE-2026-64519", "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\nNFSD: Fix infinite loop in layout state revocation\n\nfind_one_sb_stid() skips stids whose sc_status is non-zero, but the\nSC_TYPE_LAYOUT case in nfsd4_revoke_states() never sets sc_status\nbefore calling nfsd4_close_layout(). The retry loop therefore finds\nthe same layout stid on every iteration, hanging the revoker\nindefinitely.", "product": "Linux", "category": "cve", "source": "NVD", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-64519", "card": "CVE-2026-64519.webp?v=1784976683", "takeaways": [], "ts": 1784974658, "exploited": 0, "has_score": 0, "created": 1784976482, "updated": 1785137492, "exploited_text": 0, "poc": 0, "score": 0.0, "kev": 0, "flags": []}, {"key": "CVE-2026-64518", "cve": "CVE-2026-64518", "lang": "en", "title": "CVE-2026-64518", "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\ntcp: Fix out-of-bounds access for twsk in tcp_ao_established_key().\n\nlockdep_sock_is_held() was added in tcp_ao_established_key()\nby the cited commit.\n\nIt can be called from tcp_v[46]_timewait_ack() with twsk.\n\nSince it does not have sk->sk_lock, the lockdep annotation\nresults in out-of-bound access.\n\n  $ pahole -C tcp_timewait_sock vmlinux | grep size\n  \t/* size: 288, cachelines: 5, members: 8 */\n  $ pahole -C sock vmlinux | grep sk_lock\n  \tsocket_lock_t              sk_lock;              /*   440   192 */\n\nLet's not use lockdep_sock_is_held() for TCP_TIME_WAIT.", "product": "Linux", "category": "cve", "source": "NVD", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-64518", "card": "CVE-2026-64518.webp?v=1784976683", "takeaways": [], "ts": 1784974658, "exploited": 0, "has_score": 0, "created": 1784976482, "updated": 1785137492, "exploited_text": 0, "poc": 0, "score": 0.0, "kev": 0, "flags": []}, {"key": "CVE-2026-64517", "cve": "CVE-2026-64517", "lang": "en", "title": "CVE-2026-64517", "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/xe/gsc: Fix double-free of managed BO in error path\n\nThe error path in xe_gsc_init_post_hwconfig() explicitly frees a BO\nallocated with xe_managed_bo_create_pin_map() via\nxe_bo_unpin_map_no_vm(). Since the managed BO already has a devm\ncleanup action registered, this causes a double-free when devm\nunwinds during probe failure.\n\nRemove the explicit free and let devm handle it, consistent with\nall other xe_managed_bo_create_pin_map() callers.\n\n(cherry picked from commit 71d61e3e299a17139e47f980a4d6f425b2c59bf7)", "product": "Linux", "category": "cve", "source": "NVD", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-64517", "card": "CVE-2026-64517.webp?v=1784976687", "takeaways": [], "ts": 1784974657, "exploited": 0, "has_score": 0, "created": 1784976482, "updated": 1785135478, "exploited_text": 0, "poc": 0, "score": 0.0, "kev": 0, "flags": []}, {"key": "CVE-2026-64516", "cve": "CVE-2026-64516", "lang": "en", "title": "CVE-2026-64516", "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amdgpu/vce1: Fix VCE 1 firmware size and offsets\n\nThe VCPU BO contains the actual FW at an offset, but\nit was not calculated into the VCPU BO size.\nSubtract this from the FW size to make sure there is\nno out of bounds access.\n\nMake sure the stack and data offsets are aligned to\nthe 32K TLB size.\n\nCheck that the FW microcode actually fits in the\nspace that is reserved for it.\n\n(cherry picked from commit c16fe59f622a080fc457a57b3e8f14c780699449)", "product": "Linux", "category": "cve", "source": "NVD", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-64516", "card": "CVE-2026-64516.webp?v=1785129633", "takeaways": ["CVSS 3.1 : 8.8 HIGH", "Vector: AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H"], "ts": 1784974657, "exploited": 0, "has_score": 1, "created": 1784976482, "updated": 1785135478, "exploited_text": 0, "poc": 0, "score": 8.8, "kev": 0, "flags": []}, {"key": "CVE-2026-64515", "cve": "CVE-2026-64515", "lang": "en", "title": "CVE-2026-64515", "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: mac80211: fix MLE defragmentation\n\nIf either reconf or EPCS multi-link element (MLE) is contained in\na non-transmitted profile, the defragmentation routine is called\nwith a pointer to the defragmented copy, but the original elements.\n\nThis is incorrect for two reasons:\n - if the original defragmentation was needed, it will not find the\n   correct data\n - if the original frame is at a higher address, the parsing will\n   potentially overrun the heap data (though given the layout of\n   the buffers, only into the new defragmentation buffer, and then\n   it has to stop and fail once that's filled with copied data.\n\nFix it by tracking the container along with the pointer and in\ndoing so also unify the two almost identical defragmentation\nroutines.", "product": "Linux", "category": "cve", "source": "NVD", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-64515", "card": "CVE-2026-64515.webp?v=1785129633", "takeaways": ["CVSS 3.1 : 8.3 HIGH", "Vector: AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:H"], "ts": 1784974657, "exploited": 0, "has_score": 1, "created": 1784976482, "updated": 1785135478, "exploited_text": 0, "poc": 0, "score": 8.3, "kev": 0, "flags": []}, {"key": "CVE-2026-64514", "cve": "CVE-2026-64514", "lang": "en", "title": "CVE-2026-64514", "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\nuserfaultfd: gate must_wait writability check on pte_present()\n\nuserfaultfd_must_wait() and userfaultfd_huge_must_wait() read the PTE\nwithout taking the page table lock and then apply pte_write() /\nhuge_pte_write() to it.  Those accessors decode bits from the present\nencoding only; on a swap or migration entry they read the offset bits that\nhappen to share the same position and return an undefined result.\n\nThe intent of the check is \"is this fault still WP-blocked?\".  A\nnon-marker swap entry means the page is in transit -- the userfault\ncontext the original fault delivered against is no longer the same, and\nthe swap-in or migration completion path will re-deliver a fresh fault if\nuserspace still needs to handle it.  Worst case under the current code the\ngarbage write bit says \"wait\", and the thread stays asleep until a\nUFFDIO_WAKE that may never arrive.\n\nGate the writability check on pte_present() so the lockless re-check only\ninspects present-PTE bits when the entry is actually present.  The\nnon-present, non-marker case returns \"don't wait\" and lets the fault path\nretry.", "product": "Linux", "category": "cve", "source": "NVD", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-64514", "card": "CVE-2026-64514.webp?v=1784976686", "takeaways": [], "ts": 1784974657, "exploited": 0, "has_score": 0, "created": 1784976482, "updated": 1785135478, "exploited_text": 0, "poc": 0, "score": 0.0, "kev": 0, "flags": []}, {"key": "CVE-2026-64513", "cve": "CVE-2026-64513", "lang": "en", "title": "CVE-2026-64513", "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\nKVM: x86: Unconditionally recompute CR8 intercept on PPR update\n\nThe TPR_THRESHOLD field in the VMCS is used by VMX to induce VM exits\nwhen the guest's virtual TPR falls under the specified threshold,\nallowing KVM to inject previously masked interrupts.\n\nKVM handles these VM exits in handle_tpr_below_threshold().\nCommit eb90f3417a0c (\"KVM: vmx: speed up TPR below threshold vmexits\")\noptimized this function by calling apic_update_ppr() instead of raising\nKVM_REQ_EVENT. apic_update_ppr() then raises KVM_REQ_EVENT if there is\na pending, deliverable interrupt.\n\nHowever, if there are no new interrupts pending, apic_update_ppr() does\nnot issue the request. Thus, kvm_lapic_update_cr8_intercept() and\nvmx_update_cr8_intercept() are not called before VM entry, which results\nin a high, stale TPR_THRESHOLD. This is problematic due to the following\nsentence in 28.2.1.1 \"VM-Execution Control Fields\" in the SDM:\n\n  The following check is performed if the “use TPR shadow” VM-execution\n  control is 1 and the “virtualize APIC accesses” and “virtual-interrupt\n  delivery” VM-execution controls are both 0: the value of bits 3:0 of\n  t", "product": "Linux", "category": "cve", "source": "NVD", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-64513", "card": "CVE-2026-64513.webp?v=1784976686", "takeaways": [], "ts": 1784974657, "exploited": 0, "has_score": 0, "created": 1784976482, "updated": 1785135478, "exploited_text": 0, "poc": 0, "score": 0.0, "kev": 0, "flags": []}, {"key": "CVE-2026-64512", "cve": "CVE-2026-64512", "lang": "en", "title": "CVE-2026-64512", "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\nACPI: CPPC: Suppress UBSAN warning caused by field misuse\n\nThe definition of reg->access_width changes depending on the\nreg->space_id type.  Type ACPI_ADR_SPACE_PLATFORM_COMM uses\naccess_width to indicate the PCC region, which can result in a UBSAN\nif the value is greater than 4.\n\nFor example:\n\n UBSAN: shift-out-of-bounds in drivers/acpi/cppc_acpi.c:1090:9\n shift exponent 32 is too large for 32-bit type 'int'\n CPU: 61 UID: 0 PID: 1220 Comm: (udev-worker) Not tainted 7.0.10-201.fc44.aarch64 #1 PREEMPT(lazy)\n Hardware name: To be filled by O.E.M.\n Call trace:\n  ...(trimming)\n  ubsan_epilogue+0x10/0x48\n  __ubsan_handle_shift_out_of_bounds+0xdc/0x1e0\n  cpc_write+0x4d0/0x670\n  cppc_set_perf+0x18c/0x490\n  cppc_cpufreq_cpu_init+0x1c8/0x380 [cppc_cpufreq]\n  ... (trimming)\n\nLets fix this by validating the region type, as well as whether\naccess_width has a value. Then since we are returning bit_width\ndirectly for ACPI_ADR_SPACE_PLATFORM_COMM, drop the code correcting\nthe size.", "product": "Linux", "category": "cve", "source": "NVD", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-64512", "card": "CVE-2026-64512.webp?v=1784976686", "takeaways": [], "ts": 1784974657, "exploited": 0, "has_score": 0, "created": 1784976482, "updated": 1785135478, "exploited_text": 0, "poc": 0, "score": 0.0, "kev": 0, "flags": []}, {"key": "CVE-2026-64511", "cve": "CVE-2026-64511", "lang": "en", "title": "CVE-2026-64511", "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\nACPI: NFIT: core: Fix possible NULL pointer dereference\n\nAfter commit 9b311b7313d6 (\"ACPI: NFIT: Install Notify() handler before\ngetting NFIT table\"), acpi_nfit_probe() installs an ACPI notify handler\nfor the NFIT device before checking the presence of the NFIT table.  If\nthat table is not there, 0 is returned without allocating the acpi_desc\nobject and setting the driver data pointer of the NFIT device.  If the\nplatform firmware triggers an NFIT_NOTIFY_UC_MEMORY_ERROR notification\non the NFIT device at that point, acpi_nfit_uc_error_notify() will\ndereference a NULL pointer.\n\nPrevent that from occurring by adding an acpi_desc check against NULL\nto acpi_nfit_uc_error_notify().", "product": "Linux", "category": "cve", "source": "NVD", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-64511", "card": "CVE-2026-64511.webp?v=1784976686", "takeaways": [], "ts": 1784974657, "exploited": 0, "has_score": 0, "created": 1784976482, "updated": 1785135478, "exploited_text": 0, "poc": 0, "score": 0.0, "kev": 0, "flags": []}, {"key": "CVE-2026-64510", "cve": "CVE-2026-64510", "lang": "en", "title": "CVE-2026-64510", "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\nACPI: NFIT: core: Fix acpi_nfit_init() error cleanup\n\nIf acpi_nfit_init() fails after adding the acpi_desc object to the\nacpi_descs list, that object is never removed from that list because\nthe acpi_nfit_shutdown() devm action is not added for the NFIT device\nin that case.  Next, the acpi_nfit_init() failure causes\nacpi_nfit_probe() to fail, the acpi_desc object is freed, and a\ndangling pointer is left behind in the acpi_descs.  Any subsequent\nACPI Machine Check Exception will trigger nfit_handle_mce() which\niterates over acpi_descs and so a use-after-free will occur.\n\nMoreover, if acpi_nfit_probe() returns 0 after installing a notify\nhandler for the NFIT device and without allocating the acpi_desc\nobject and setting the NFIT device's driver data pointer, the\nacpi_desc object will be allocated by acpi_nfit_update_notify()\nand acpi_nfit_init() will be called to initialize it.  Regardless\nof whether or not acpi_nfit_init() fails in that case, the\nacpi_nfit_shutdown() devm action is not added for the NFIT device\nand acpi_desc is never removed from the acpi_descs list.  If the\nacpi_desc object is freed subsequently on", "product": "Linux", "category": "cve", "source": "NVD", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-64510", "card": "CVE-2026-64510.webp?v=1785129633", "takeaways": ["CVSS 3.1 : 7.0 HIGH", "Vector: AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H"], "ts": 1784974657, "exploited": 0, "has_score": 1, "created": 1784976482, "updated": 1785135478, "exploited_text": 0, "poc": 0, "score": 7.0, "kev": 0, "flags": []}, {"key": "CVE-2026-64509", "cve": "CVE-2026-64509", "lang": "en", "title": "CVE-2026-64509", "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\nrust: block: fix GenDisk cleanup paths\n\nGenDiskBuilder::build() still has fallible work after\n__blk_mq_alloc_disk(), but its error path only recovers the\nforeign queue data. That leaks the temporary gendisk and\nrequest_queue until later teardown. If the caller moved the last\nArc > into build(), the leaked queue can retain blk-mq\nstate after the tag set is dropped.\n\nFix the pre-registration failure path by dropping the temporary\ngendisk reference with put_disk() before recovering queue_data,\nso disk_release() can tear down the owned queue.\n\nAlso pair GenDisk::drop() with put_disk() after del_gendisk().\nOnce a Rust GenDisk has been added with device_add_disk(),\ndel_gendisk() only unregisters it; the final gendisk reference\nstill has to be dropped to complete the release path.", "product": "Linux", "category": "cve", "source": "NVD", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-64509", "card": "CVE-2026-64509.webp?v=1784976685", "takeaways": [], "ts": 1784974657, "exploited": 0, "has_score": 0, "created": 1784976482, "updated": 1785135478, "exploited_text": 0, "poc": 0, "score": 0.0, "kev": 0, "flags": []}, {"key": "CVE-2026-64508", "cve": "CVE-2026-64508", "lang": "en", "title": "CVE-2026-64508", "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\nbpf: Support for hardening against JIT spraying\n\nThe BPF JIT allocator packs many small programs into larger executable\nallocations and reuses space within those allocations as programs are\nloaded and freed. When fresh code is written into space that a previous\nprogram occupied, an indirect jump into the new program can reuse a branch\nprediction left behind by the old one.\n\nFlush the indirect branch predictors before reusing JIT memory so that\nindirect jumps into a newly written program don't reuse predictions from an\nold program that occupied the same space.\n\nIntroduce bpf_arch_pred_flush_enabled static key and bpf_arch_pred_flush\nstatic call for flushing the branch predictors on JIT memory reuse.\nArchitectures that need a flush, can update it to a predictor flush\nfunction. By default, its a NOP and does not emit any CALL.\n\nAllocations larger than a pack are not covered by this flush. That is safe\nbecause cBPF programs (the unprivileged attack surface) are bounded well\nbelow a pack size. Issue a warning if this assumption is ever violated\nwhile the flush is active.", "product": "Linux", "category": "cve", "source": "NVD", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-64508", "card": "CVE-2026-64508.webp?v=1784979048", "takeaways": [], "ts": 1784974656, "exploited": 0, "has_score": 0, "created": 1784978948, "updated": 1785135478, "exploited_text": 0, "poc": 0, "score": 0.0, "kev": 0, "flags": []}, {"key": "CVE-2026-64507", "cve": "CVE-2026-64507", "lang": "en", "title": "CVE-2026-64507", "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\nx86/bugs: Enable IBPB flush on BPF JIT allocation\n\nEnable hardening against JIT spraying when Spectre-v2 mitigations are in\nuse. Specifically, issue an IBPB flush on BPF JIT memory reuse. Skip\nenabling the IBPB flush if the BPF dispatcher is already using a retpoline\nsequence.\n\nThis hardening applies only when BPF-JIT is in use. Guard the enabling\nunder CONFIG_BPF_JIT so that bugs.c still builds with CONFIG_BPF_JIT=n.", "product": "Linux", "category": "cve", "source": "NVD", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-64507", "card": "CVE-2026-64507.webp?v=1784979048", "takeaways": [], "ts": 1784974656, "exploited": 0, "has_score": 0, "created": 1784978948, "updated": 1785135478, "exploited_text": 0, "poc": 0, "score": 0.0, "kev": 0, "flags": []}, {"key": "CVE-2026-64506", "cve": "CVE-2026-64506", "lang": "en", "title": "CVE-2026-64506", "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: rtw89: correct drop logic for malformed AMPDU frames\n\nThe previous commit aims to fix issue caused by malformed AMPDU frames.\nBut the drop logic fails to deal with the first AMPDU packet paired with\ncertain range of sequence number, and leads to unexpected packet drop.\nIt is more likely to encounter this failure when there are busy traffic\nduring rekey process and could lead to disconnection from the AP.\nFix this by adding a initial state judgement and only reset status\nduring pairwise rekey.", "product": "Linux", "category": "cve", "source": "NVD", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-64506", "card": "CVE-2026-64506.webp?v=1784979048", "takeaways": [], "ts": 1784974656, "exploited": 0, "has_score": 0, "created": 1784978948, "updated": 1785135478, "exploited_text": 0, "poc": 0, "score": 0.0, "kev": 0, "flags": []}, {"key": "CVE-2026-64505", "cve": "CVE-2026-64505", "lang": "en", "title": "CVE-2026-64505", "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\nusb: gadget: function: rndis: add length check for header\n\nAdd a length check for the rndis header in rndis_rm_hdr, to ensure that\nMessageType, MessageLength, DataOffset, and DataLength fields are\npresent before they are accessed.", "product": "Linux", "category": "cve", "source": "NVD", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-64505", "card": "CVE-2026-64505.webp?v=1784979047", "takeaways": [], "ts": 1784974656, "exploited": 0, "has_score": 0, "created": 1784978948, "updated": 1785135478, "exploited_text": 0, "poc": 0, "score": 0.0, "kev": 0, "flags": []}, {"key": "CVE-2026-64504", "cve": "CVE-2026-64504", "lang": "en", "title": "CVE-2026-64504", "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\niio: accel: bmc150: clamp the device-reported FIFO frame count\n\n__bmc150_accel_fifo_flush() copies the number of samples the device\nreports in its hardware FIFO into an on-stack buffer\n\n\tu16 buffer[BMC150_ACCEL_FIFO_LENGTH * 3];\n\nwhich is sized for at most BMC150_ACCEL_FIFO_LENGTH (32) samples. The\nframe count is read from the FIFO_STATUS register and only masked to its\n7 valid bits:\n\n\tcount = val & 0x7F;\n\nso it can be 0..127. The only other limit applied to it is the optional\ncaller-supplied sample budget:\n\n\tif (samples && count > samples)\n\t\tcount = samples;\n\nwhich does not constrain count on the flush-all path (samples == 0), and\nleaves it well above 32 whenever samples is larger. count samples are\nthen transferred into buffer[]:\n\n\tbmc150_accel_fifo_transfer(data, (u8 *)buffer, count);\n\nbmc150_accel_fifo_transfer() reads count * 6 bytes through regmap, so a\nmalfunctioning, malicious or counterfeit accelerometer (or an attacker\ntampering with the I2C/SPI bus) that reports up to 127 frames writes up\nto 762 bytes into the 192-byte buffer: a stack out-of-bounds write of up\nto 570 bytes that clobbers the stack canary", "product": "Linux", "category": "cve", "source": "NVD", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-64504", "card": "CVE-2026-64504.webp?v=1784976688", "takeaways": [], "ts": 1784974656, "exploited": 0, "has_score": 0, "created": 1784976482, "updated": 1785135478, "exploited_text": 0, "poc": 0, "score": 0.0, "kev": 0, "flags": []}, {"key": "CVE-2026-64503", "cve": "CVE-2026-64503", "lang": "en", "title": "CVE-2026-64503", "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\niio: accel: kxsd9: fix runtime PM imbalance on write_raw() error\n\nkxsd9_write_raw() takes a runtime PM reference with pm_runtime_get_sync()\nbut returns -EINVAL directly when a scale with a non-zero integer part is\nrequested, skipping the matching pm_runtime_put_autosuspend(). This leaks\na runtime PM usage-counter reference on every such write, after which the\ndevice can no longer autosuspend.\n\nSet the error code and fall through to the existing put instead of\nreturning early.", "product": "Linux", "category": "cve", "source": "NVD", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-64503", "card": "CVE-2026-64503.webp?v=1784976687", "takeaways": [], "ts": 1784974656, "exploited": 0, "has_score": 0, "created": 1784976482, "updated": 1785135478, "exploited_text": 0, "poc": 0, "score": 0.0, "kev": 0, "flags": []}, {"key": "CVE-2026-64502", "cve": "CVE-2026-64502", "lang": "en", "title": "CVE-2026-64502", "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\niio: adc: ad_sigma_delta: fix clear_pending_event for registerless devices\n\nad_sigma_delta_clear_pending_event() falls through to the status register\nread path for devices with has_registers = false and no rdy_gpiod. For\nsuch devices, ad_sd_read_reg() skips the address byte entirely and clocks\nraw MISO bytes with no address phase — making it byte-for-byte identical\nto reading conversion data. If a pending conversion result is present,\nthis partially consumes it and corrupts the data stream for the subsequent\nad_sd_read_reg() call in ad_sigma_delta_single_conversion().\n\nFurthermore, with num_resetclks = 0 on these devices, data_read_len\nevaluates to 0. If the clocked byte has bit 7 clear, pending_event is set\nand the code attempts memset(data + 2, 0xff, 0 - 1), overflowing to\nSIZE_MAX and corrupting the heap.\n\nFix by returning 0 immediately when neither rdy_gpiod nor has_registers\nis set. This is safe for all current registerless devices: ad7191 and\nad7780 (with powerdown GPIO) are reset between conversions by CS\ndeassertion, so there is no stale result to drain; ad7780 (without\npowerdown GPIO) and max11205 are con", "product": "Linux", "category": "cve", "source": "NVD", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-64502", "card": "CVE-2026-64502.webp?v=1785129634", "takeaways": ["CVSS 3.1 : 7.8 HIGH", "Vector: AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"], "ts": 1784974656, "exploited": 0, "has_score": 1, "created": 1784976482, "updated": 1785135478, "exploited_text": 0, "poc": 0, "score": 7.8, "kev": 0, "flags": []}, {"key": "CVE-2026-64501", "cve": "CVE-2026-64501", "lang": "en", "title": "CVE-2026-64501", "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\niio: adc: ad_sigma_delta: fix CS held asserted and state leaks\n\nIn ad_sigma_delta_single_conversion(), set_mode(AD_SD_MODE_IDLE) and\ndisable_one() were called from the out: block while keep_cs_asserted\nwas still true. This caused any SPI transfer issued by those callbacks\nto carry cs_change=1, leaving CS permanently asserted after the\nconversion. Fix by moving both calls into the out_unlock: block, after\nkeep_cs_asserted is cleared, matching the pattern already used in\nad_sd_calibrate().\n\nIn the error path of ad_sd_buffer_postenable(), if an operation fails\nafter set_mode(AD_SD_MODE_CONTINUOUS) has already succeeded (e.g.\nspi_offload_trigger_enable()), the device is left in continuous\nconversion mode with CS physically asserted. Additionally,\nbus_locked remaining true after spi_bus_unlock() causes subsequent\nSPI operations to call spi_sync_locked() without the bus lock actually\nheld, allowing concurrent SPI access.\n\nFix the error path by clearing keep_cs_asserted first, then calling\nset_mode(AD_SD_MODE_IDLE) to revert the device mode and deassert CS,\nthen clearing bus_locked before releasing the bus.\n\nFor devices ", "product": "Linux", "category": "cve", "source": "NVD", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-64501", "card": "CVE-2026-64501.webp?v=1785129634", "takeaways": ["CVSS 3.1 : 7.1 HIGH", "Vector: AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H"], "ts": 1784974656, "exploited": 0, "has_score": 1, "created": 1784976482, "updated": 1785135478, "exploited_text": 0, "poc": 0, "score": 7.1, "kev": 0, "flags": []}, {"key": "CVE-2026-64500", "cve": "CVE-2026-64500", "lang": "en", "title": "CVE-2026-64500", "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\niio: adc: lpc32xx: Initialize completion before requesting IRQ\n\nIn the report from Jaeyoung Chung:\n\n\"lpc32xx_adc_probe() in drivers/iio/adc/lpc32xx_adc.c registers its\ninterrupt handler with devm_request_irq() before it initializes\nst->completion with init_completion(). If an interrupt arrives after\ndevm_request_irq() and before init_completion(), the handler calls\ncomplete() on an uninitialized completion, causing a kernel panic.\n\nThe probe path, in lpc32xx_adc_probe():\n\n    iodev = devm_iio_device_alloc(&pdev->dev, sizeof(*st)); /* st kzalloc-zeroed */\n    ...\n    retval = devm_request_irq(&pdev->dev, irq, lpc32xx_adc_isr, 0,\n                              LPC32XXAD_NAME, st);           /* register handler */\n    ...\n    init_completion(&st->completion);                       /* initialize completion */\n\nlpc32xx_adc_isr() calls complete():\n\n    complete(&st->completion);\n\nIf the device raises an interrupt before init_completion() runs,\ncomplete() acquires the uninitialized wait.lock and walks the zeroed\ntask_list in swake_up_locked(). The zeroed task_list makes list_empty()\nreturn false, so swake_up_locked() dere", "product": "Linux", "category": "cve", "source": "NVD", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-64500", "card": "CVE-2026-64500.webp?v=1784979050", "takeaways": [], "ts": 1784974655, "exploited": 0, "has_score": 0, "created": 1784978948, "updated": 1785111822, "exploited_text": 0, "poc": 0, "score": 0.0, "kev": 0, "flags": []}, {"key": "CVE-2026-64499", "cve": "CVE-2026-64499", "lang": "en", "title": "CVE-2026-64499", "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\niio: adc: ti-ads1119: fix PM reference leak in buffer preenable\n\nads1119_triggered_buffer_preenable() resumes the device with\npm_runtime_resume_and_get() before starting a conversion.\n\nIf i2c_smbus_write_byte() fails, the function returns the error directly\nand leaves the runtime PM usage counter elevated. The matching\npostdisable callback is not called when preenable fails, so the reference\nis leaked and the device may remain runtime-active indefinitely.\n\nStore the I2C transfer result in ret and drop the runtime PM reference on\nfailure before returning the error.", "product": "Linux", "category": "cve", "source": "NVD", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-64499", "card": "CVE-2026-64499.webp?v=1784979050", "takeaways": [], "ts": 1784974655, "exploited": 0, "has_score": 0, "created": 1784978948, "updated": 1785105905, "exploited_text": 0, "poc": 0, "score": 0.0, "kev": 0, "flags": []}, {"key": "CVE-2026-64498", "cve": "CVE-2026-64498", "lang": "en", "title": "CVE-2026-64498", "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\niio: buffer: hw-consumer: free scan_mask on buffer release\n\nThe scan_mask lifetime changed in commit 9a2e1233d38c (\"iio: buffer:\nhw-consumer: remove redundant scan_mask flexible array\").\n\nBefore that change, the scan mask storage was embedded in struct\nhw_consumer_buffer, so iio_hw_buf_release() could free the whole\nallocation with a single kfree(hw_buf).\n\nThat commit moved the scan mask to a separate bitmap_zalloc() allocation\nstored in buffer.scan_mask, but left iio_hw_buf_release() unchanged.\n\nFree the scan mask in iio_hw_buf_release() before freeing the buffer\nwrapper.", "product": "Linux", "category": "cve", "source": "NVD", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-64498", "card": "CVE-2026-64498.webp?v=1784979049", "takeaways": [], "ts": 1784974655, "exploited": 0, "has_score": 0, "created": 1784978948, "updated": 1785117697, "exploited_text": 0, "poc": 0, "score": 0.0, "kev": 0, "flags": []}, {"key": "CVE-2026-64497", "cve": "CVE-2026-64497", "lang": "en", "title": "CVE-2026-64497", "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\niio: chemical: scd30: Cleanup initializations and fix sign-extension bug\n\nInclude linux/bitfield.h for FIELD_GET().\n\nCreate new macros for bit manipulation in combination with manual bit\nmanipulation being replaced with FIELD_GET().\n\nThe current variable declaration and initializations are barely readable\nand use comma separations across multiple lines. Refactor the\ninitializations so that mantissa and exp have separate declarations and\nsign gets initialized later.\n\nIn addition (and due to the nature of the cleanup), fix a sign-extension\nbug where, float32 would get bitwise anded with ~BIT(31)\n(which is 0xFFFFFFFF7FFFFFFF) which corrupted the exponent.", "product": "Linux", "category": "cve", "source": "NVD", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-64497", "card": "CVE-2026-64497.webp?v=1784979049", "takeaways": [], "ts": 1784974655, "exploited": 0, "has_score": 0, "created": 1784978948, "updated": 1785109865, "exploited_text": 0, "poc": 0, "score": 0.0, "kev": 0, "flags": []}, {"key": "CVE-2026-64496", "cve": "CVE-2026-64496", "lang": "en", "title": "CVE-2026-64496", "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\niio: event: Fix event FIFO reset race\n\n`iio_event_getfd()` creates the event file descriptor with\n`anon_inode_getfd()`, which allocates a new fd, creates the anonymous\nfile and installs it in the process fd table before returning to the\ncaller.\n\nThe IIO code resets the event FIFO after `anon_inode_getfd()` has returned,\nbut before `IIO_GET_EVENT_FD_IOCTL` has copied the fd number to userspace.\nBut since fd tables are shared between threads, another thread can guess\nthe newly allocated fd number and issue a `read()` on it as soon as the fd\nhas been installed.\n\nThis means the `kfifo_to_user()` in `iio_event_chrdev_read()` can run in\nparallel with the `kfifo_reset_out()` in `iio_event_getfd()`.\n\nThe kfifo documentation says that `kfifo_reset_out()` is only safe when it\nis called from the reader thread and there is only one concurrent reader.\nOtherwise it is dangerous and must be handled in the same way as\n`kfifo_reset()`.\n\nIf that happens, `kfifo_to_user()` can advance the FIFO `out` index based\non state from before the reset, after the reset has already moved the `out`\nindex to the current `in` index. That can leave", "product": "Linux", "category": "cve", "source": "NVD", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-64496", "card": "CVE-2026-64496.webp?v=1784979049", "takeaways": [], "ts": 1784974655, "exploited": 0, "has_score": 0, "created": 1784978948, "updated": 1785107907, "exploited_text": 0, "poc": 0, "score": 0.0, "kev": 0, "flags": []}, {"key": "CVE-2026-64495", "cve": "CVE-2026-64495", "lang": "en", "title": "CVE-2026-64495", "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\niio: gyro: bmg160: bail out when bandwidth/filter is not in table\n\nbmg160_get_filter() walks bmg160_samp_freq_table[] looking for the entry\nmatching the bw_bits value read from the chip:\n\n\tfor (i = 0; i < ARRAY_SIZE(bmg160_samp_freq_table); ++i) {\n\t\tif (bmg160_samp_freq_table[i].bw_bits == bw_bits)\n\t\t\tbreak;\n\t}\n\t*val = bmg160_samp_freq_table[i].filter;\n\nIf no entry matches, i ends up equal to the array size and the next line\nreads one slot past the end. bmg160_set_filter() has the same shape, driven\nby 'val' instead of bw_bits.\n\nsmatch flags both:\n\n  drivers/iio/gyro/bmg160_core.c:204 bmg160_get_filter() error:\n  buffer overflow 'bmg160_samp_freq_table' 7 <= 7\n  drivers/iio/gyro/bmg160_core.c:222 bmg160_set_filter() error:\n  buffer overflow 'bmg160_samp_freq_table' 7 <= 7\n\nReturn -EINVAL when no entry matches.\n\nThe set_filter() path is reachable from userspace via the sysfs\nin_anglvel_filter_low_pass_3db_frequency interface, so userspace can\ntrivially trigger the out-of-bounds read with a value that is not in\nbmg160_samp_freq_table[].filter.", "product": "Linux", "category": "cve", "source": "NVD", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-64495", "card": "CVE-2026-64495.webp?v=1784979049", "takeaways": [], "ts": 1784974655, "exploited": 0, "has_score": 0, "created": 1784978948, "updated": 1785121612, "exploited_text": 0, "poc": 0, "score": 0.0, "kev": 0, "flags": []}, {"key": "CVE-2026-64494", "cve": "CVE-2026-64494", "lang": "en", "title": "CVE-2026-64494", "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\niio: light: gp2ap002: fix runtime PM leak on read error\n\ngp2ap002_read_raw() calls pm_runtime_get_sync() before reading the\nlux value, but if gp2ap002_get_lux() fails, it returns directly. This\nskips the pm_runtime_put_autosuspend() call at the \"out\" label,\npermanently leaking a runtime PM reference and preventing the device\nfrom autosuspending.\n\nReplace the direct return with a \"goto out\" to ensure the reference\nis properly dropped on the error path.", "product": "Linux", "category": "cve", "source": "NVD", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-64494", "card": "CVE-2026-64494.webp?v=1784979049", "takeaways": [], "ts": 1784974655, "exploited": 0, "has_score": 0, "created": 1784978948, "updated": 1785115738, "exploited_text": 0, "poc": 0, "score": 0.0, "kev": 0, "flags": []}, {"key": "CVE-2026-64493", "cve": "CVE-2026-64493", "lang": "en", "title": "CVE-2026-64493", "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\niio: pressure: mpl115: fix runtime PM leak on read error\n\nmpl115_read_raw() takes a runtime PM reference with pm_runtime_get_sync()\nbefore reading the processed pressure or raw temperature, but on the read\nerror path it returns without calling pm_runtime_put_autosuspend(). Each\nfailed read therefore leaks a runtime PM reference and prevents the device\nfrom autosuspending.\n\nDrop the reference before checking the return value so both the success\nand error paths are balanced.", "product": "Linux", "category": "cve", "source": "NVD", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-64493", "card": "CVE-2026-64493.webp?v=1784979048", "takeaways": [], "ts": 1784974655, "exploited": 0, "has_score": 0, "created": 1784978948, "updated": 1785113780, "exploited_text": 0, "poc": 0, "score": 0.0, "kev": 0, "flags": []}, {"key": "CVE-2026-64492", "cve": "CVE-2026-64492", "lang": "en", "title": "CVE-2026-64492", "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\niio: temperature: tmp006: use devm_iio_trigger_register\n\ntmp006_probe() allocates the DRDY trigger with devm_iio_trigger_alloc()\nbut registers it with plain iio_trigger_register(). The driver has no\n.remove() callback, so on module unload the trigger stays in the global\ntrigger list while its memory is freed by devm, leaving a dangling\nentry.\n\nSwitch to devm_iio_trigger_register() so the registration is undone in\nthe same devm scope as the allocation.", "product": "Linux", "category": "cve", "source": "NVD", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-64492", "card": "CVE-2026-64492.webp?v=1784979048", "takeaways": [], "ts": 1784974655, "exploited": 0, "has_score": 0, "created": 1784978948, "updated": 1785119654, "exploited_text": 0, "poc": 0, "score": 0.0, "kev": 0, "flags": []}, {"key": "CVE-2026-64491", "cve": "CVE-2026-64491", "lang": "en", "title": "CVE-2026-64491", "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\nALSA: usx2y: us144mkii: fix work UAF on disconnect\n\ntascam_disconnect() cancels capture_work and midi_in_work before\nusb_kill_anchored_urbs() kills the capture/MIDI-in URBs.  Those URBs\nself-resubmit, and their completion handlers reschedule the work.\n\nA URB that completes in the small window between cancel_work_sync() and\nusb_kill_anchored_urbs() therefore re-arms the work after its only\ncancel.  Nothing cancels it again before snd_card_free() frees the\ncard-private tascam structure, so the work handler then runs on freed\nmemory.\n\nKill the anchored URBs before cancelling the work; once the work is\ncancelled no remaining URB can complete to re-arm it.", "product": "Linux", "category": "cve", "source": "NVD", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-64491", "card": "CVE-2026-64491.webp?v=1784979051", "takeaways": [], "ts": 1784974654, "exploited": 0, "has_score": 0, "created": 1784978948, "updated": 1784978948, "exploited_text": 0, "poc": 0, "score": 0.0, "kev": 0, "flags": []}, {"key": "CVE-2026-64490", "cve": "CVE-2026-64490", "lang": "en", "title": "CVE-2026-64490", "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\nALSA: virtio: Validate control metadata from the device\n\nvirtio-snd control handling trusts the device-provided control type and\nvalue count returned by the device.\n\nThat metadata is then used directly to index g_v2a_type_map[] in\nvirtsnd_kctl_info(), and to size loops and memcpy() operations in\nvirtsnd_kctl_get() and virtsnd_kctl_put() against fixed-size\nvirtio_snd_ctl_value and snd_ctl_elem_value arrays.\n\nA buggy or malicious device can therefore trigger out-of-bounds access by\nadvertising an invalid control type or an oversized value count.\n\nValidate control type and count once in virtsnd_kctl_parse_cfg(), before\nquerying enumerated items or exposing the control to ALSA.", "product": "Linux", "category": "cve", "source": "NVD", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-64490", "card": "CVE-2026-64490.webp?v=1784979051", "takeaways": [], "ts": 1784974654, "exploited": 0, "has_score": 0, "created": 1784978948, "updated": 1784978948, "exploited_text": 0, "poc": 0, "score": 0.0, "kev": 0, "flags": []}, {"key": "CVE-2026-64489", "cve": "CVE-2026-64489", "lang": "en", "title": "CVE-2026-64489", "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\nALSA: ymfpci: check snd_ctl_new1() return value\n\nsnd_ctl_new1() can return NULL when memory allocation fails.\nsnd_ymfpci_create_spdif_controls() does not check the return value\nbefore dereferencing kctl->id.device, which can lead to a NULL pointer\ndereference.\n\nAdd NULL checks after snd_ctl_new1() calls and return -ENOMEM if any\nfails.", "product": "Linux", "category": "cve", "source": "NVD", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-64489", "card": "CVE-2026-64489.webp?v=1784979051", "takeaways": [], "ts": 1784974654, "exploited": 0, "has_score": 0, "created": 1784978948, "updated": 1784978948, "exploited_text": 0, "poc": 0, "score": 0.0, "kev": 0, "flags": []}, {"key": "CVE-2026-64488", "cve": "CVE-2026-64488", "lang": "en", "title": "CVE-2026-64488", "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\nALSA: aoa: check snd_ctl_new1() return value\n\nsnd_ctl_new1() can return NULL when memory allocation fails. In\nlayout.c, the function does not check the return value before\ndereferencing ctl->id.name or passing to aoa_snd_ctl_add(), which can\nlead to a NULL pointer dereference.\n\nAdd NULL checks after snd_ctl_new1() calls and return early if any\nfails.", "product": "Linux", "category": "cve", "source": "NVD", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-64488", "card": "CVE-2026-64488.webp?v=1784979051", "takeaways": [], "ts": 1784974654, "exploited": 0, "has_score": 0, "created": 1784978948, "updated": 1784978948, "exploited_text": 0, "poc": 0, "score": 0.0, "kev": 0, "flags": []}, {"key": "CVE-2026-64487", "cve": "CVE-2026-64487", "lang": "en", "title": "CVE-2026-64487", "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\nALSA: caiaq: fix out-of-bounds read in the Traktor Kontrol S4 input parser\n\nsnd_usb_caiaq_tks4_dispatch() decodes the Traktor Kontrol S4 input\nstream in fixed 16-byte (TKS4_MSGBLOCK_SIZE) message blocks. On every\niteration it advances buf and subtracts the block size while looping on\n\"while (len)\".\n\nlen is urb->actual_length. That value is supplied by the device and is\nnot guaranteed to be a multiple of 16. When a final short block leaves\nlen between 1 and 15, the loop runs once more, reads up to buf[15], and\nthen does \"len -= TKS4_MSGBLOCK_SIZE\". As len is unsigned this underflows\nto a huge value. The loop then keeps iterating and walking buf far past\nthe end of the 512-byte ep4_in_buf, reading out of bounds until a bogus\nblock id happens to be hit.\n\nIterate only while a full message block is available. This stops the\nunsigned underflow and silently drops any trailing partial block, which\ncarries no complete control value anyway.\n\nThe sibling endpoint-4 parsers are not affected. The Traktor Kontrol X1\nand Maschine arms in snd_usb_caiaq_ep4_reply_dispatch() floor\nurb->actual_length before dispatching.", "product": "Linux", "category": "cve", "source": "NVD", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-64487", "card": "CVE-2026-64487.webp?v=1784979051", "takeaways": [], "ts": 1784974654, "exploited": 0, "has_score": 0, "created": 1784978948, "updated": 1784978948, "exploited_text": 0, "poc": 0, "score": 0.0, "kev": 0, "flags": []}, {"key": "CVE-2026-64486", "cve": "CVE-2026-64486", "lang": "en", "title": "CVE-2026-64486", "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\nALSA: cmipci: check snd_ctl_new1() return value\n\nsnd_ctl_new1() can return NULL when memory allocation fails.\nsnd_cmipci_spdif_controls() does not check the return value before\ndereferencing kctl->id.device, which can lead to a NULL pointer\ndereference.\n\nAdd NULL checks after snd_ctl_new1() calls and return -ENOMEM if any\nfails.", "product": "Linux", "category": "cve", "source": "NVD", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-64486", "card": "CVE-2026-64486.webp?v=1784979050", "takeaways": [], "ts": 1784974654, "exploited": 0, "has_score": 0, "created": 1784978948, "updated": 1784978948, "exploited_text": 0, "poc": 0, "score": 0.0, "kev": 0, "flags": []}, {"key": "CVE-2026-64485", "cve": "CVE-2026-64485", "lang": "en", "title": "CVE-2026-64485", "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\nALSA: compress: Fix task creation error unwind\n\nsnd_compr_task_new() allocates the driver task before validating the\nreturned DMA buffers and reserving file descriptors. When either of\nthose later steps fails, the core frees its task wrapper and DMA-buffer\nreferences without calling the driver's task_free() callback. Any\ndriver resources allocated by task_create() are therefore leaked.\n\nThe dual-fd allocation path also jumps to cleanup without storing the\nnegative get_unused_fd_flags() result in retval. Since retval still\ncontains the successful task_create() return value, TASK_CREATE can\nincorrectly report success although the task was discarded.\n\nPreserve the fd allocation errors and call task_free() when failure\noccurs after a successful task_create() callback.", "product": "Linux", "category": "cve", "source": "NVD", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-64485", "card": "CVE-2026-64485.webp?v=1784979050", "takeaways": [], "ts": 1784974654, "exploited": 0, "has_score": 0, "created": 1784978948, "updated": 1784978948, "exploited_text": 0, "poc": 0, "score": 0.0, "kev": 0, "flags": []}, {"key": "CVE-2026-64484", "cve": "CVE-2026-64484", "lang": "en", "title": "CVE-2026-64484", "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\nALSA: es1938: check snd_ctl_new1() return value\n\nsnd_ctl_new1() can return NULL when memory allocation fails.\nsnd_es1938_mixer() does not check the return value before dereferencing\nthe pointer, which can lead to a NULL pointer dereference.\n\nAdd a NULL check after snd_ctl_new1() and return -ENOMEM if it fails.", "product": "Linux", "category": "cve", "source": "NVD", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-64484", "card": "CVE-2026-64484.webp?v=1784979050", "takeaways": [], "ts": 1784974654, "exploited": 0, "has_score": 0, "created": 1784978948, "updated": 1784978948, "exploited_text": 0, "poc": 0, "score": 0.0, "kev": 0, "flags": []}, {"key": "CVE-2026-64483", "cve": "CVE-2026-64483", "lang": "en", "title": "CVE-2026-64483", "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\nALSA: firewire: isight: bound the sample count to the packet payload\n\nisight_packet() takes the frame count from the device iso packet and\nchecks it only against the device claimed iso length.\n\n\tcount = be32_to_cpu(payload->sample_count);\n\tif (likely(count  samples, count);\n\nlength is the iso header data_length. It can be up to 0xffff. So the\ngate allows a count up to about 16379. isight_samples() then copies\ncount frames out of payload->samples into the PCM DMA buffer.\n\npayload->samples holds only 2 * MAX_FRAMES_PER_PACKET values. The\ndevice multiplexes two samples per frame. A count past\nMAX_FRAMES_PER_PACKET reads past the payload. A count past the buffer\nsize writes past runtime->dma_area. The smallest PCM buffer is larger\nthan MAX_FRAMES_PER_PACKET. Bounding the count to MAX_FRAMES_PER_PACKET\nkeeps both the read and the write in range.\n\nA malicious or faulty Apple iSight on the FireWire bus reaches this\nduring a normal capture.\n\nAdd the MAX_FRAMES_PER_PACKET bound to the gate.", "product": "Linux", "category": "cve", "source": "NVD", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-64483", "card": "CVE-2026-64483.webp?v=1784981410", "takeaways": [], "ts": 1784974653, "exploited": 0, "has_score": 0, "created": 1784981311, "updated": 1784981311, "exploited_text": 0, "poc": 0, "score": 0.0, "kev": 0, "flags": []}, {"key": "CVE-2026-64482", "cve": "CVE-2026-64482", "lang": "en", "title": "CVE-2026-64482", "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\nALSA: gus: check snd_ctl_new1() return value\n\nsnd_ctl_new1() can return NULL when memory allocation fails.\nsnd_gf1_pcm_volume_control() does not check the return value before\ndereferencing kctl->id.index, which can lead to a NULL pointer\ndereference.\n\nAdd a NULL check after snd_ctl_new1() and return -ENOMEM if it fails.", "product": "Linux", "category": "cve", "source": "NVD", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-64482", "card": "CVE-2026-64482.webp?v=1784981410", "takeaways": [], "ts": 1784974653, "exploited": 0, "has_score": 0, "created": 1784981311, "updated": 1784981311, "exploited_text": 0, "poc": 0, "score": 0.0, "kev": 0, "flags": []}, {"key": "CVE-2026-64481", "cve": "CVE-2026-64481", "lang": "en", "title": "CVE-2026-64481", "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\nALSA: hda/cs35l41: Fix firmware load work teardown\n\ncs35l41_hda creates ALSA controls whose private data points at the\ncs35l41_hda object. The firmware load control can also queue\nfw_load_work.\n\nThose controls are not removed on component unbind, and device remove\nonly cancels fw_load_work through cs35l41_remove_dsp(). That helper is\nskipped when halo_initialized is false. With firmware_autostart\ndisabled, a firmware load can be requested before the DSP has been\ninitialized. If the component or device is removed before the queued\nwork runs, the worker can run after teardown and dereference driver\nstate that is no longer valid.\n\nTrack the created controls and remove them on unbind so no new control\ncallback can reach the driver data or queue more work. Then cancel\nfw_load_work to drain any request that was already queued. Also cancel\nthe work unconditionally during device remove before runtime PM teardown.", "product": "Linux", "category": "cve", "source": "NVD", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-64481", "card": "CVE-2026-64481.webp?v=1784981410", "takeaways": [], "ts": 1784974653, "exploited": 0, "has_score": 0, "created": 1784981311, "updated": 1784981311, "exploited_text": 0, "poc": 0, "score": 0.0, "kev": 0, "flags": []}, {"key": "CVE-2026-64480", "cve": "CVE-2026-64480", "lang": "en", "title": "CVE-2026-64480", "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\nALSA: ice1712: check snd_ctl_new1() return value\n\nsnd_ctl_new1() can return NULL when memory allocation fails. The\nice1712 driver calls snd_ctl_new1() without checking the return value\nbefore dereferencing the pointer in multiple places (ice1712.c,\nice1724.c, aureon.c), which can lead to NULL pointer dereferences.\n\nAdd NULL checks after snd_ctl_new1() calls and return -ENOMEM if any\nfails.", "product": "Linux", "category": "cve", "source": "NVD", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-64480", "card": "CVE-2026-64480.webp?v=1784981410", "takeaways": [], "ts": 1784974653, "exploited": 0, "has_score": 0, "created": 1784981311, "updated": 1784981311, "exploited_text": 0, "poc": 0, "score": 0.0, "kev": 0, "flags": []}, {"key": "CVE-2026-64479", "cve": "CVE-2026-64479", "lang": "en", "title": "CVE-2026-64479", "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\nALSA: seq: Fix uninitialised heap leak in snd_seq_event_dup()\n\nsnd_seq_event_dup() copies an incoming event into a pool cell and, in\nthe UMP-enabled build, clears the trailing cell->ump.raw.extra word that\nthe memcpy() did not cover.  The guard deciding whether to clear it\ncompares the copied size against sizeof(cell->event):\n\n\tmemcpy(&cell->ump, event, size);\n\tif (size  event))\n\t\tcell->ump.raw.extra = 0;\n\nFor a legacy (non-UMP) event, size == sizeof(struct snd_seq_event) ==\nsizeof(cell->event), so the condition is false and the extra word keeps\nstale data.  The cell pool is allocated with kvmalloc() (not zeroed) and\ncells are reused via a free list, so that word holds uninitialised heap\nor leftover event data.\n\nWhen such a cell is delivered to a UMP client (client->midi_version > 0)\nthat set SNDRV_SEQ_FILTER_NO_CONVERT -- so the legacy event reaches it\nunconverted -- snd_seq_read() reads it out as the larger struct\nsnd_seq_ump_event and copies the stale word to user space, a 4-byte\nkernel heap infoleak to an unprivileged /dev/snd/seq client.\n\nCompare against sizeof(cell->ump) instead, so the trailing word is zero", "product": "Linux", "category": "cve", "source": "NVD", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-64479", "card": "CVE-2026-64479.webp?v=1784981410", "takeaways": [], "ts": 1784974653, "exploited": 0, "has_score": 0, "created": 1784981311, "updated": 1784981311, "exploited_text": 0, "poc": 0, "score": 0.0, "kev": 0, "flags": []}, {"key": "CVE-2026-64478", "cve": "CVE-2026-64478", "lang": "en", "title": "CVE-2026-64478", "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\nALSA: usb-audio: avoid kobject path lookup in DualSense match\n\nThe DualSense jack-detection input handler verifies that a matching input\ndevice belongs to the same physical controller by building kobject path\nstrings for both the input device and the USB audio device, then comparing\nthe path prefix.\n\nThis was observed when a weak physical connection caused the controller\nto rapidly disconnect and reconnect. During that repeated hotplug,\nsnd_dualsense_ih_match() can run while the controller's USB device is\nbeing disconnected. kobject_get_path() walks ancestor kobjects and\ndereferences their names; if the USB device kobject name is no longer\nvalid, this can fault in strlen():\n\n  RIP: 0010:strlen+0x10/0x30\n  Call Trace:\n   kobject_get_path+0x34/0x150\n   snd_dualsense_ih_match+0x49/0xd0 [snd_usb_audio]\n   input_register_device+0x566/0x6a0\n   ps_probe+0xb89/0x1590 [hid_playstation]\n\nThe same ownership check can be done without building kobject path\nstrings. The input device is parented below the HID device, USB interface\nand USB device, so walking the input device parent chain and comparing\nagainst the mixer USB device", "product": "Linux", "category": "cve", "source": "NVD", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-64478", "card": "CVE-2026-64478.webp?v=1784981409", "takeaways": [], "ts": 1784974653, "exploited": 0, "has_score": 0, "created": 1784981311, "updated": 1784981311, "exploited_text": 0, "poc": 0, "score": 0.0, "kev": 0, "flags": []}, {"key": "CVE-2026-64477", "cve": "CVE-2026-64477", "lang": "en", "title": "CVE-2026-64477", "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\nx86,fs/resctrl: Prevent out-of-bounds access while offlining CPU when SNC enabled\n\nThe architecture updates the cpu_mask in a domain's header to track which\nonline CPUs are associated with the domain. When this mask becomes empty\nthe architecture initiates offline of the domain that includes calling\non resctrl fs to offline the domain. If it is a monitoring domain in\nwhich LLC occupancy is tracked resctrl fs forces the limbo handler to\nclear all busy RMID state associated with the domain.\n\nThe limbo handler always reads the current event value associated with a\nbusy RMID irrespective of it being checked as part of regular \"is it still\nbusy\" check or whether it will be forced released anyway. When reading an\nRMID on a system with SNC enabled the \"logical RMID\" is converted to the\n\"physical RMID\" and this conversion requires the NUMA node ID of the\nresctrl monitoring domain that is in turn determined by querying the NUMA\nnode ID of any CPU belonging to the monitoring domain.\n\nWhen the monitoring domain is going offline its cpu_mask is empty causing\nthe NUMA node ID query via cpu_to_node() to be done with \"nr_cpu_ids", "product": "Linux", "category": "cve", "source": "NVD", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-64477", "card": "CVE-2026-64477.webp?v=1784979052", "takeaways": [], "ts": 1784974653, "exploited": 0, "has_score": 0, "created": 1784978948, "updated": 1784978948, "exploited_text": 0, "poc": 0, "score": 0.0, "kev": 0, "flags": []}, {"key": "CVE-2026-64476", "cve": "CVE-2026-64476", "lang": "en", "title": "CVE-2026-64476", "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\nvfio/pci: Latch disable_idle_d3 per device\n\nWhen disable_idle_d3 was introduced in vfio-pci, it directly manipulated\nthe device power state with pci_set_power_state().  There were no\nrefcounts to maintain or balanced operations, we could unconditionally\nbring the device to D0 and conditionally move it to D3hot.  Therefore\nthe module parameter was made writable.\n\nLater, in commit c61302aa48f7 (\"vfio/pci: Move module parameters to\nvfio_pci.c\"), as part of the vfio-pci-core split, the writable aspect\nof the module parameter was nullified.  The parameter value could still\nbe changed through sysfs, but the vfio-pci driver latched the values\ninto vfio-pci-core globals at module init.  Loading the vfio-pci module,\nor unloading and reloading, with non-default or different values could\nchange the globals relative to existing devices bound to vfio-pci\nvariant drivers.\n\nRuntime PM was introduced in commit 7ab5e10eda02 (\"vfio/pci: Move the\nunused device into low power state with runtime PM\"), which marks the\npoint where power states became refcounted.  PM get and put operations\nneed to be balanced, but the same module operati", "product": "Linux", "category": "cve", "source": "NVD", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-64476", "card": "CVE-2026-64476.webp?v=1784979052", "takeaways": [], "ts": 1784974653, "exploited": 0, "has_score": 0, "created": 1784978948, "updated": 1784978948, "exploited_text": 0, "poc": 0, "score": 0.0, "kev": 0, "flags": []}, {"key": "CVE-2026-64475", "cve": "CVE-2026-64475", "lang": "en", "title": "CVE-2026-64475", "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\nvfio/pci: Release the VGA arbiter client on register_device() failure\n\nThe re-order in the Fixes commit below displaced vfio_pci_vga_init() as\nthe last failure point of what is now vfio_pci_core_register_device()\nwithout introducing an unwind for the VGA arbiter registration.\n\nIn current kernels this is mostly benign because vfio_pci_set_decode()\nonly uses pci_dev state, but the original failure path could leave a\ncallback with a freed vdev cookie.  The stale registration also becomes\nunsafe again once the callback follows drvdata to the vfio device.\n\nAdd the required VGA unwind callout.", "product": "Linux", "category": "cve", "source": "NVD", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-64475", "card": "CVE-2026-64475.webp?v=1784981412", "takeaways": [], "ts": 1784974652, "exploited": 0, "has_score": 0, "created": 1784981311, "updated": 1784981311, "exploited_text": 0, "poc": 0, "score": 0.0, "kev": 0, "flags": []}, {"key": "CVE-2026-64474", "cve": "CVE-2026-64474", "lang": "en", "title": "CVE-2026-64474", "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\nvfio: prevent infinite loop in vfio_mig_get_next_state() on blocked arc\n\nvfio_mig_get_next_state() walks vfio_from_fsm_table[] one step at a time,\nlooping to skip optional states the device does not support until\n*next_fsm is supported. A blocked transition is encoded as\nVFIO_DEVICE_STATE_ERROR, which the trailing return reports as -EINVAL.\n\nThe skip loop does not account for the ERROR sentinel.\nstate_flags_table[ERROR] is ~0U and vfio_from_fsm_table[ERROR][*] is\nERROR, so once *next_fsm becomes ERROR the loop condition stays true and\n*next_fsm never changes. The blocked arcs STOP_COPY -> PRE_COPY and\nSTOP_COPY -> PRE_COPY_P2P map to ERROR yet pass the support check on a\nprecopy-capable device, causing the loop to spin forever while holding\nthe driver state mutex. This can result in a soft lockup, and a panic\nwith softlockup_panic set.\n\nTerminate the skip loop on the ERROR sentinel so a blocked transition\nfalls through to the existing return and reports -EINVAL.", "product": "Linux", "category": "cve", "source": "NVD", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-64474", "card": "CVE-2026-64474.webp?v=1784981412", "takeaways": [], "ts": 1784974652, "exploited": 0, "has_score": 0, "created": 1784981311, "updated": 1784981311, "exploited_text": 0, "poc": 0, "score": 0.0, "kev": 0, "flags": []}, {"key": "CVE-2026-64473", "cve": "CVE-2026-64473", "lang": "en", "title": "CVE-2026-64473", "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\nvfio: Remove device debugfs before releasing devres\n\nVFIO device debugfs files created with debugfs_create_devm_seqfile()\nstore a devres allocated debugfs_devm_entry as inode private data.\nvfio_unregister_group_dev() currently calls vfio_device_del() before\nvfio_device_debugfs_exit(), but device_del() releases devres.  This can\nleave debugfs entries visible with stale inode private data while\nunregister waits for userspace references to drain.\n\nRemove the per-device debugfs tree before vfio_device_del().  The debugfs\nview is diagnostic only, so losing it at the start of unregister is\npreferable to preserving entries whose backing storage may already have\nbeen released.\n\nComplete the teardown by clearing the per-device debugfs root after\nremoval.  This matches the global debugfs root cleanup and prevents\nfuture users from mistaking a removed dentry for a live debugfs tree\nduring the remainder of unregister.", "product": "Linux", "category": "cve", "source": "NVD", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-64473", "card": "CVE-2026-64473.webp?v=1784981412", "takeaways": [], "ts": 1784974652, "exploited": 0, "has_score": 0, "created": 1784981311, "updated": 1784981311, "exploited_text": 0, "poc": 0, "score": 0.0, "kev": 0, "flags": []}, {"key": "CVE-2026-64472", "cve": "CVE-2026-64472", "lang": "en", "title": "CVE-2026-64472", "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\nvfio/mlx5: Fix racy bitfields and tighten struct layout\n\nBitfield operations are not atomic, they use a read-modify-write\npattern, therefore we should be careful not to pack bitfields that\ncan be concurrently updated into the same storage unit.\n\nThis split takes a binary approach: flags that are only modified\npre/post open/close remain bitfields, flags modified from user\naction, including actions that reach across to another device (ex.\nreset) use dedicated storage units.\n\nNote mlx5_vhca_page_tracker.status is relocated to fill the alignment\nhole this split exposes.\n\nBitfield justifications:\n\n  migrate_cap: written only in mlx5vf_cmd_set_migratable() at probe\n  chunk_mode: written only in mlx5vf_cmd_set_migratable() at probe\n  mig_state_cap: written only in mlx5vf_cmd_set_migratable() at probe\n\nDedicated storage units:\n\n  mdev_detach: written in the VF attach/detach event notifier\n               mlx5fv_vf_event() at runtime\n  log_active: written in mlx5vf_start_page_tracker()/\n              mlx5vf_stop_page_tracker() during runtime dirty tracking\n  deferred_reset: written in mlx5vf_state_mutex_unlock()/\n          ", "product": "Linux", "category": "cve", "source": "NVD", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-64472", "card": "CVE-2026-64472.webp?v=1784981412", "takeaways": [], "ts": 1784974652, "exploited": 0, "has_score": 0, "created": 1784981311, "updated": 1784981311, "exploited_text": 0, "poc": 0, "score": 0.0, "kev": 0, "flags": []}, {"key": "CVE-2026-64471", "cve": "CVE-2026-64471", "lang": "en", "title": "CVE-2026-64471", "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\nBluetooth: btusb: fix use-after-free on registration failure\n\nMake sure to release the sibling interfaces in case controller\nregistration fails to avoid use-after-free and double-free when they are\neventually disconnected.\n\nThis issue was reported by Sashiko while reviewing a fix for a wakeup\nsource leak in the btusb probe errors paths.", "product": "Linux", "category": "cve", "source": "NVD", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-64471", "card": "CVE-2026-64471.webp?v=1784981411", "takeaways": [], "ts": 1784974652, "exploited": 0, "has_score": 0, "created": 1784981311, "updated": 1784981311, "exploited_text": 0, "poc": 0, "score": 0.0, "kev": 0, "flags": []}, {"key": "CVE-2026-64470", "cve": "CVE-2026-64470", "lang": "en", "title": "CVE-2026-64470", "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\nBluetooth: btusb: fix use-after-free on marvell probe failure\n\nMake sure to stop any TX URBs submitted during Marvell OOB wakeup\nconfiguration on later probe failures to avoid use-after-free in the\ncompletion callback.\n\nThis issue was reported by Sashiko while reviewing a fix for a wakeup\nsource leak in the btusb probe errors paths.", "product": "Linux", "category": "cve", "source": "NVD", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-64470", "card": "CVE-2026-64470.webp?v=1784981411", "takeaways": [], "ts": 1784974652, "exploited": 0, "has_score": 0, "created": 1784981311, "updated": 1784981311, "exploited_text": 0, "poc": 0, "score": 0.0, "kev": 0, "flags": []}, {"key": "CVE-2026-64469", "cve": "CVE-2026-64469", "lang": "en", "title": "CVE-2026-64469", "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\nbinder: fix UAF in binder_thread_release()\n\nWhen a thread exits, binder_thread_release() walks its transaction stack\nto clear the t->from and t->to_proc that correspond with the exiting\nthread. However, a process dying in parallel might attempt to kfree some\nof these transactions. And if one of them has no associated t->to_proc,\nthe t->to_proc->inner_lock will not be acquired.\n\nThis means that transaction accesses in binder_thread_release() after\nt->to_proc has been cleared might race with binder_free_transaction()\nand cause a use-after-free error as reported by KASAN:\n\n  ==================================================================\n  BUG: KASAN: slab-use-after-free in binder_thread_release+0x5d0/0x798\n  Write of size 8 at addr ffff000016627500 by task X/715\n\n  CPU: 17 UID: 0 PID: 715 Comm: X Not tainted 7.1.0-rc5-00149-g8fde5d1d47f6 #30 PREEMPT\n  Hardware name: linux,dummy-virt (DT)\n  Call trace:\n   binder_thread_release+0x5d0/0x798\n   binder_ioctl+0x12c0/0x299c\n   [...]\n\n  Allocated by task 717 on cpu 18 at 67.267803s:\n   __kasan_kmalloc+0xa0/0xbc\n   __kmalloc_cache_noprof+0x174/0x444\n   binder_transaction+", "product": "Linux", "category": "cve", "source": "NVD", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-64469", "card": "CVE-2026-64469.webp?v=1784981411", "takeaways": [], "ts": 1784974652, "exploited": 0, "has_score": 0, "created": 1784981311, "updated": 1784981311, "exploited_text": 0, "poc": 0, "score": 0.0, "kev": 0, "flags": []}, {"key": "CVE-2026-64468", "cve": "CVE-2026-64468", "lang": "en", "title": "CVE-2026-64468", "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\nbinder: fix UAF in binder_free_transaction()\n\nIn binder_free_transaction(), the t->to_proc is read under the t->lock.\nHowever, once the t->lock is dropped, the to_proc can die in parallel.\nThis leads to a use-after-free error when we attempt to acquire its\ninner lock right afterwards:\n\n  ==================================================================\n  BUG: KASAN: slab-use-after-free in _raw_spin_lock+0xe4/0x1a0\n  Write of size 4 at addr ffff00001125da70 by task B/672\n\n  CPU: 20 UID: 0 PID: 672 Comm: B Not tainted 7.1.0-rc6-00284-g8e65320d91cd #4 PREEMPT\n  Hardware name: linux,dummy-virt (DT)\n  Call trace:\n   _raw_spin_lock+0xe4/0x1a0\n   binder_free_transaction+0x8c/0x320\n   binder_send_failed_reply+0x21c/0x2f8\n   binder_thread_release+0x488/0x7e0\n   binder_ioctl+0x12c0/0x29a0\n  [...]\n\n  Allocated by task 675:\n   __kmalloc_cache_noprof+0x174/0x444\n   binder_open+0x118/0xb70\n   do_dentry_open+0x374/0x1040\n   vfs_open+0x58/0x3bc\n  [...]\n\n  Freed by task 212:\n   __kasan_slab_free+0x58/0x80\n   kfree+0x1a0/0x4a4\n   binder_proc_dec_tmpref+0x32c/0x5e0\n   binder_deferred_func+0xc48/0x104c\n   process_one_work+0x53c/0xbc", "product": "Linux", "category": "cve", "source": "NVD", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-64468", "card": "CVE-2026-64468.webp?v=1784981411", "takeaways": [], "ts": 1784974652, "exploited": 0, "has_score": 0, "created": 1784981311, "updated": 1784981311, "exploited_text": 0, "poc": 0, "score": 0.0, "kev": 0, "flags": []}, {"key": "CVE-2026-64467", "cve": "CVE-2026-64467", "lang": "en", "title": "CVE-2026-64467", "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\nrust_binder: use a u64 stride when cleaning up the offsets array\n\nAllocation's Drop walks the offsets array (binder_size_t = u64 entries),\ncleaning up the objects, but it used usize instead of u64 for both the\nstride and the per-entry read.\n\nOn 64-bit kernels (usize == u64) this is harmless, but on 32-bit kernels\nit walks the 8-byte entries in 4-byte steps, iterating an N-entry array\n2N times, and reads the always-zero high word as offset 0, cleaning up\nthe object at offset 0 N extra times. As a result the referenced node or\nhandle ends up with a lower reference count than it actually has (a\nrefcount over-decrement), and binder's reference accounting is corrupted;\nfor example, the owner can be notified of a strong reference release\n(BR_RELEASE) even though references still remain.\n\nChange the stride to u64, and read each entry as a u64, narrowing it to\nusize with try_into().\n\nOn 32-bit ARM, when this over-decrement would drive a count below zero,\nthe driver's existing refcount guard refuses it and fires:\n\n  rust_binder: Failure: refcount underflow!", "product": "Linux", "category": "cve", "source": "NVD", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-64467", "card": "CVE-2026-64467.webp?v=1784981411", "takeaways": [], "ts": 1784974652, "exploited": 0, "has_score": 0, "created": 1784981311, "updated": 1784981311, "exploited_text": 0, "poc": 0, "score": 0.0, "kev": 0, "flags": []}, {"key": "CVE-2026-64466", "cve": "CVE-2026-64466", "lang": "en", "title": "CVE-2026-64466", "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\nrust_binder: clear freeze listener on node removal\n\nGenerally userspace is supposed to explicitly clear freeze listeners\nbefore they drop the refcount on the node ref to zero, but there's\nnothing forcing that. Currently, in this scenario the freeze listener\nremains in the freeze_listeners rbtree and in the remote node's freeze\nlistener list, even though the ref for which the listener is registered\nis gone. This could potentially lead to a memory leak due to a refcount\ncycle. Thus, remove the freeze listener in this scenario.", "product": "Linux", "category": "cve", "source": "NVD", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-64466", "card": "CVE-2026-64466.webp?v=1784981414", "takeaways": [], "ts": 1784974651, "exploited": 0, "has_score": 0, "created": 1784981311, "updated": 1784981311, "exploited_text": 0, "poc": 0, "score": 0.0, "kev": 0, "flags": []}, {"key": "CVE-2026-64465", "cve": "CVE-2026-64465", "lang": "en", "title": "CVE-2026-64465", "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\nusb: xhci: Fix sleep in atomic context in xhci_free_streams()\n\nWhen a USB device with active stream endpoints is disconnected,\nxhci_free_streams() is called from the hub_event workqueue to\nfree the stream resources.  It calls xhci_free_stream_info()\nwhile holding xhci->lock with irqs disabled.\n\nxhci_free_stream_info() invokes xhci_free_stream_ctx(), which\ncalls dma_free_coherent() for large stream context arrays.\n\ndma_free_coherent() can sleep (e.g. via vunmap), triggering\na BUG when called from atomic context.\n\nCall trace:\n dma_free_attrs+0x174/0x220\n xhci_free_stream_info+0xd0/0x11c\n xhci_free_streams+0x278/0x37c\n usb_free_streams+0x98/0xc0\n usb_unbind_interface+0x1b8/0x2f8\n device_release_driver_internal+0x1d4/0x2cc\n device_release_driver+0x18/0x28\n bus_remove_device+0x160/0x1a4\n device_del+0x1ec/0x350\n usb_disable_device+0x98/0x214\n usb_disconnect+0xf0/0x35c\n hub_event+0xab4/0x19ec\n process_one_work+0x278/0x63c\n\nFix this by saving the stream_info pointers and clearing the\nep references under the lock, then calling xhci_free_stream_info()\noutside the lock where sleeping is allowed.", "product": "Linux", "category": "cve", "source": "NVD", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-64465", "card": "CVE-2026-64465.webp?v=1784981414", "takeaways": [], "ts": 1784974651, "exploited": 0, "has_score": 0, "created": 1784981311, "updated": 1784981311, "exploited_text": 0, "poc": 0, "score": 0.0, "kev": 0, "flags": []}, {"key": "CVE-2026-64464", "cve": "CVE-2026-64464", "lang": "en", "title": "CVE-2026-64464", "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\nxhci: sideband: fix ring sg table pages leak\n\nxhci_ring_to_sgtable() allocates a temporary pages array and\nuses it to build the returned sg_table with\nsg_alloc_table_from_pages().\n\nThe error paths free the pages array, but the success path\nreturns the sg_table without freeing it. This leaks the temporary\narray every time a sideband client gets an endpoint or event ring\nbuffer.\n\nFree the pages array after sg_alloc_table_from_pages() succeeds.\nThe returned sg_table has its own scatterlist entries and does not\ndepend on the temporary array after construction.", "product": "Linux", "category": "cve", "source": "NVD", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-64464", "card": "CVE-2026-64464.webp?v=1784981414", "takeaways": [], "ts": 1784974651, "exploited": 0, "has_score": 0, "created": 1784981311, "updated": 1784981311, "exploited_text": 0, "poc": 0, "score": 0.0, "kev": 0, "flags": []}, {"key": "CVE-2026-64463", "cve": "CVE-2026-64463", "lang": "en", "title": "CVE-2026-64463", "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\nusb: typec: tcpci_rt1711h: unregister TCPCI port with devres\n\nrt1711h_probe() registers the TCPCI port before requesting the interrupt\nand enabling alert interrupts. If either of those later steps fails, the\nprobe function returns without unregistering the TCPCI port. The explicit\nunregister currently only happens from the remove callback.\n\nRegister a devres action immediately after tcpci_register_port() succeeds,\nso tcpci_unregister_port() runs on later probe failures and on driver\ndetach. Drop the remove callback to avoid unregistering the same port\ntwice.\n\nThis issue was identified during our ongoing static-analysis research while\nreviewing kernel code.", "product": "Linux", "category": "cve", "source": "NVD", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-64463", "card": "CVE-2026-64463.webp?v=1784981413", "takeaways": [], "ts": 1784974651, "exploited": 0, "has_score": 0, "created": 1784981311, "updated": 1784981311, "exploited_text": 0, "poc": 0, "score": 0.0, "kev": 0, "flags": []}, {"key": "CVE-2026-64462", "cve": "CVE-2026-64462", "lang": "en", "title": "CVE-2026-64462", "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\nPCI: altera: Fix resource leaks on probe failure\n\nThe chained IRQ handler is set during probe, but is only removed during the\ndriver remove(). If pci_host_probe() fails, the handler and INTx IRQ\ndomain remain set even though the devm-managed host bridge storage\ncontaining struct altera_pcie will be released, leaving the handler with\na stale data pointer.\n\nInterrupts are also enabled before pci_host_probe() is called. If probe\nfails after that point, the controller interrupt source should be disabled\nbefore the chained handler and INTx domain are removed.\n\nSo set the chained handler only after the INTx domain has been created.\nDisable controller interrupts during IRQ teardown, and tear the IRQ setup\ndown if pci_host_probe() fails.\n\n[mani: commit log]", "product": "Linux", "category": "cve", "source": "NVD", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-64462", "card": "CVE-2026-64462.webp?v=1784981413", "takeaways": [], "ts": 1784974651, "exploited": 0, "has_score": 0, "created": 1784981311, "updated": 1784981311, "exploited_text": 0, "poc": 0, "score": 0.0, "kev": 0, "flags": []}, {"key": "CVE-2026-64461", "cve": "CVE-2026-64461", "lang": "en", "title": "CVE-2026-64461", "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\nPCI: mediatek: Fix IRQ domain leak when port fails to enable\n\nWhen mtk_pcie_enable_port() fails, mtk_pcie_port_free() removes the port\nfrom pcie->ports and frees the port structure. However, the IRQ domains set\nup earlier by mtk_pcie_init_irq_domain() are never freed.\n\nFix this by refactoring mtk_pcie_irq_teardown() into a per-port helper,\nmtk_pcie_irq_teardown_port(), and calling it from mtk_pcie_setup() when\nmtk_pcie_enable_port() fails. Since the IRQ teardown must only happen in\nthe probe error path (during resume, child devices may have active MSI\nmappings and the NOIRQ context prohibits sleeping locks),\nmtk_pcie_enable_port() is changed to return an error code so callers can\ndistinguish the two paths and act accordingly.\n\nThis issue was reported by Sashiko while reviewing the EcoNet EN7528 SoC\nsupport series.", "product": "Linux", "category": "cve", "source": "NVD", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-64461", "card": "CVE-2026-64461.webp?v=1784981413", "takeaways": [], "ts": 1784974651, "exploited": 0, "has_score": 0, "created": 1784981311, "updated": 1784981311, "exploited_text": 0, "poc": 0, "score": 0.0, "kev": 0, "flags": []}, {"key": "CVE-2026-64460", "cve": "CVE-2026-64460", "lang": "en", "title": "CVE-2026-64460", "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\nPCI/IOV: Skip VF Resizable BAR restore on read error\n\nsriov_restore_vf_rebar_state() uses the VF Resizable BAR Control register\nto decide how many VF BARs to restore (nbars) and which VF BAR each\niteration addresses (bar_idx). bar_idx indexes into dev->sriov->barsz[],\nwhich has only PCI_SRIOV_NUM_BARS (6) entries.\n\nWhen a device does not respond, config reads typically return\nPCI_ERROR_RESPONSE (~0).  Both fields are 3 bits wide, so nbars and bar_idx\nboth evaluate to 7. The barsz[] access then goes out of bounds.  UBSAN\nreports this as:\n\n  UBSAN: array-index-out-of-bounds in drivers/pci/iov.c:948:51 index 7 is out of range for type 'resource_size_t [6]'\n\nObserved on an NVIDIA RTX PRO 1000 GPU (GB207GLM) that stopped responding\nduring a failed GC6 power state exit. The subsequent pci_restore_state()\ninvoked sriov_restore_vf_rebar_state() while config reads returned\n0xffffffff, triggering the splat.\n\nBail out if any VF Resizable BAR Control read returns PCI_ERROR_RESPONSE.\nNo further VF BARs are touched, which is safe because a config read that\nreturns PCI_ERROR_RESPONSE indicates the device is unreachable and\nresto", "product": "Linux", "category": "cve", "source": "NVD", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-64460", "card": "CVE-2026-64460.webp?v=1784981413", "takeaways": [], "ts": 1784974651, "exploited": 0, "has_score": 0, "created": 1784981311, "updated": 1784981311, "exploited_text": 0, "poc": 0, "score": 0.0, "kev": 0, "flags": []}, {"key": "CVE-2026-64459", "cve": "CVE-2026-64459", "lang": "en", "title": "CVE-2026-64459", "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\ntcp: restore RCU grace period in tcp_ao_destroy_sock\n\nCommit 51e547e8c89c (\"tcp: Free TCP-AO/TCP-MD5 info/keys without RCU\")\nremoved the call_rcu() callback from tcp_ao_destroy_sock(), arguing that\n\"the destruction of info/keys is delayed until the socket destructor\"\nand therefore \"no one can discover it anymore\".\n\nThat argument does not hold for the call site in tcp_connect()\n(net/ipv4/tcp_output.c:4327-4332). At that point the socket is in\nTCP_SYN_SENT, has already been inserted into the inet ehash by\ninet_hash_connect() in tcp_v4_connect(), and is therefore very much\ndiscoverable: any softirq running tcp_v4_rcv() on another CPU can take\nthe socket out of the ehash, walk into tcp_inbound_hash(), and load\ntp->ao_info via implicit RCU before bh_lock_sock_nested() is taken on\nthe destroying CPU.\n\nThe reader path then enters __tcp_ao_do_lookup() (net/ipv4/tcp_ao.c:208)\nwhich re-loads tp->ao_info via rcu_dereference_check(); the re-load can\nstill observe the (about-to-be-freed) pointer because there is no\nsynchronize_rcu() between rcu_assign_pointer(tp->ao_info, NULL) and\ntcp_ao_info_free() in tcp_ao_destroy_sock(). ", "product": "Linux", "category": "cve", "source": "NVD", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-64459", "card": "CVE-2026-64459.webp?v=1784981413", "takeaways": [], "ts": 1784974651, "exploited": 0, "has_score": 0, "created": 1784981311, "updated": 1784981311, "exploited_text": 0, "poc": 0, "score": 0.0, "kev": 0, "flags": []}, {"key": "CVE-2026-64458", "cve": "CVE-2026-64458", "lang": "en", "title": "CVE-2026-64458", "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\nmm/damon/ops-common: handle extreme intervals in damon_hot_score()\n\nFix three issues in damon_hot_score() that comes from wrong handling of\nextreme (zero or too high) monitoring intervals user setup.\n\nWhen the user sets sampling interval zero, damon_max_nr_accesses(), which\nis called from damon_hot_score(), causes a divide-by-zero.  Needless to\nsay, it is a problem.\n\nWhen the user sets the aggregation interval zero, the function returns\nzero.  It is wrong, since the real maximum nr_acceses in the setup should\nbe one.  Worse yet, it can cause another divide-by-zero from its caller,\ndamon_hot_score(), since it uses damon_max_nr_accesses() return value as a\ndenominator.\n\nWhen the user sets the aggregation interval very high, damon_hot_score()\ncould return a value out of [0, DAMOS_MAX_SCORE] range.  Since the return\nvalue is used as an index to the regions_score_histogram array, which is\nDAMOS_MAX_SCORE+1 size, it causes out of bounds array access.\n\nThe issues can be relatively easily reproduced like below.  The sysfs\nwrite permission is required, though.\n\n    # ./damo start --damos_action lru_prio --damos_quota_space", "product": "Linux", "category": "cve", "source": "NVD", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-64458", "card": "CVE-2026-64458.webp?v=1784983774", "takeaways": [], "ts": 1784974650, "exploited": 0, "has_score": 0, "created": 1784983674, "updated": 1784983674, "exploited_text": 0, "poc": 0, "score": 0.0, "kev": 0, "flags": []}, {"key": "CVE-2026-64457", "cve": "CVE-2026-64457", "lang": "en", "title": "CVE-2026-64457", "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\nvirtio_pci: fix vq info pointer lookup via wrong index\n\nUnbinding a virtio balloon device:\n\n    echo virtio0 > /sys/bus/virtio/drivers/virtio_balloon/unbind\n\ntriggers a NULL pointer dereference. The dmesg says:\n\n    BUG: kernel NULL pointer dereference, address: 0000000000000008\n    [...]\n    RIP: 0010:__list_del_entry_valid_or_report+0x5/0xf0\n    Call Trace:\n     \n    vp_del_vqs+0x121/0x230\n    remove_common+0x135/0x150\n    virtballoon_remove+0xee/0x100\n    virtio_dev_remove+0x3b/0x80\n    device_release_driver_internal+0x187/0x2c0\n    unbind_store+0xb9/0xe0\n    kernfs_fop_write_iter.llvm.11660790530567441834+0xf6/0x180\n    vfs_write+0x2a9/0x3b0\n    ksys_write+0x5c/0xd0\n    do_syscall_64+0x54/0x230\n    entry_SYSCALL_64_after_hwframe+0x29/0x31\n    [...]\n     \n\nThe virtio_balloon device registers 5 queues (inflate, deflate, stats,\nfree_page, reporting) but only the first two are unconditional. The\nstats, free_page and reporting queues are each conditional on their\nrespective feature bits. When any of these features are absent, the\ncorresponding vqs_info entry has name == NULL, creating holes in the\narray.\n\nThe root ", "product": "Linux", "category": "cve", "source": "NVD", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-64457", "card": "CVE-2026-64457.webp?v=1784983774", "takeaways": [], "ts": 1784974650, "exploited": 0, "has_score": 0, "created": 1784983674, "updated": 1784983674, "exploited_text": 0, "poc": 0, "score": 0.0, "kev": 0, "flags": []}, {"key": "CVE-2026-64456", "cve": "CVE-2026-64456", "lang": "en", "title": "CVE-2026-64456", "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\nhwrng: virtio: clamp device-reported used.len at copy_data()\n\nrandom_recv_done() stores the device-reported used.len directly into\nvi->data_avail.  copy_data() then indexes vi->data[] using\nvi->data_idx (advanced by previous copy_data() calls) and issues a\nmemcpy() without re-validating either value against the posted\nbuffer size sizeof(vi->data) (SMP_CACHE_BYTES bytes, typically 32\nor 64).\n\nA malicious or buggy virtio-rng backend can set used.len beyond\nsizeof(vi->data), steering the memcpy() past the end of the inline\narray into adjacent kmalloc-1k slab bytes.  hwrng_fillfn() mixes\nthose bytes into the guest RNG, and guest root can also observe\nthem directly via /dev/hwrng.\n\nConcrete impact is inside the guest:\n\n - Memory-safety / hardening: any virtio-rng backend that\n   over-reports used.len causes the driver to read past vi->data\n   into unrelated slab contents.  hwrng_fillfn() is a kernel thread\n   that runs as soon as the device is probed; no guest userspace\n   interaction is required to first-trigger the OOB.\n\n - Cross-boundary leak (confidential-compute threat model): a\n   malicious hypervisor cooperating", "product": "Linux", "category": "cve", "source": "NVD", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-64456", "card": "CVE-2026-64456.webp?v=1784983773", "takeaways": [], "ts": 1784974650, "exploited": 0, "has_score": 0, "created": 1784983674, "updated": 1784983674, "exploited_text": 0, "poc": 0, "score": 0.0, "kev": 0, "flags": []}, {"key": "CVE-2026-64455", "cve": "CVE-2026-64455", "lang": "en", "title": "CVE-2026-64455", "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\nUSB: chaoskey: Fix slab-use-after-free in chaoskey_release()\n\nThe chaoskey driver has a use-after-free bug in its release routine.\nIf the user closes the device file after the USB device has been\nunplugged, a debugging log statement will try to access the\nusb_interface structure after it has been deallocated:\n\n\tBUG: KASAN: slab-use-after-free in dev_driver_string (drivers/base/core.c:2406)\n\tRead of size 8 at addr ffff888168e8a0b8 by task chaoskey_raw_re/10106\n\n\tHardware name: QEMU Ubuntu 24.04 PC v2 (i440FX + PIIX, arch_caps fix, 1996), BIOS 1.16.3-debian-1.16.3-2 04/01/2014\n\tCall Trace:\n\t  \n\t dump_stack_lvl (lib/dump_stack.c:94 lib/dump_stack.c:120)\n\t print_report (mm/kasan/report.c:378 mm/kasan/report.c:482)\n\t kasan_report (mm/kasan/report.c:595)\n\t dev_driver_string (drivers/base/core.c:2406)\n\t __dynamic_dev_dbg (lib/dynamic_debug.c:906)\n\t chaoskey_release (drivers/usb/misc/chaoskey.c:323)\n\t __fput (fs/file_table.c:510)\n\t fput_close_sync (fs/file_table.c:615)\n\t __x64_sys_close (fs/open.c:1507 fs/open.c:1492 fs/open.c:1492)\n\t do_syscall_64 (arch/x86/entry/syscall_64.c:63 arch/x86/entry/syscall_64.c:94)\n\t entry_SY", "product": "Linux", "category": "cve", "source": "NVD", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-64455", "card": "CVE-2026-64455.webp?v=1784983773", "takeaways": [], "ts": 1784974650, "exploited": 0, "has_score": 0, "created": 1784983674, "updated": 1784983674, "exploited_text": 0, "poc": 0, "score": 0.0, "kev": 0, "flags": []}, {"key": "CVE-2026-64454", "cve": "CVE-2026-64454", "lang": "en", "title": "CVE-2026-64454", "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\nusb: dwc3: run gadget disconnect from sleepable suspend context\n\ndwc3_gadget_suspend() takes dwc->lock with IRQs disabled and then calls\ndwc3_disconnect_gadget().  For async callbacks that helper only uses\nplain spin_unlock()/spin_lock(), so the gadget ->disconnect() callback\nstill runs with IRQs disabled and any sleepable callback trips Lockdep.\n\nThis issue was found by our static analysis tool and then manually\nreviewed against the current tree.\n\nThe grounded PoC kept the dwc3_gadget_suspend() ->\ndwc3_disconnect_gadget() -> gadget_driver->disconnect() chain, and\nLockdep reported:\n\n  BUG: sleeping function called from invalid context\n  gadget_disconnect+0x21/0x39 [vuln_msv]\n  dwc3_gadget_suspend.constprop.0+0x2b/0x42 [vuln_msv]\n\nKeep the disconnect callback selection in one common helper, but add a\nsleepable suspend-side wrapper which snapshots the callback under\ndwc->lock and then runs it after spin_unlock_irqrestore().  The regular\nevent path still uses the existing spin_unlock()/spin_lock() window.", "product": "Linux", "category": "cve", "source": "NVD", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-64454", "card": "CVE-2026-64454.webp?v=1784983773", "takeaways": [], "ts": 1784974650, "exploited": 0, "has_score": 0, "created": 1784983674, "updated": 1784983674, "exploited_text": 0, "poc": 0, "score": 0.0, "kev": 0, "flags": []}, {"key": "CVE-2026-64453", "cve": "CVE-2026-64453", "lang": "en", "title": "CVE-2026-64453", "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\nusb: misc: usbio: fix disconnect UAF in client teardown\n\nusbio_disconnect() walks usbio->cli_list in reverse and uninitializes each\nauxiliary device. auxiliary_device_uninit() drops the device reference, and\nfor an unbound child that can run usbio_auxdev_release() and free the\ncontaining struct usbio_client.\n\nlist_for_each_entry_reverse() advances after the loop body by reading\nclient->link.prev. If the current client is freed by\nauxiliary_device_uninit(), the iterator dereferences freed memory.\n\nUse list_for_each_entry_safe_reverse() so the previous client is\ncached before the body can drop the final reference. This preserves\nreverse teardown order while keeping the next iterator cursor independent\nof the current client's lifetime.\n\nValidation reproduced this kernel report:\nBUG: KASAN: slab-use-after-free in usbio_disconnect+0x12e/0x150\n\nCall Trace:\n  \n dump_stack_lvl+0x66/0xa0\n print_report+0xce/0x630\n ? usbio_disconnect+0x12e/0x150\n ? srso_alias_return_thunk+0x5/0xfbef5\n ? __virt_addr_valid+0x188/0x320\n ? usbio_disconnect+0x12e/0x150\n kasan_report+0xe0/0x110\n ? usbio_disconnect+0x12e/0x150\n usbio_disconnect+0x1", "product": "Linux", "category": "cve", "source": "NVD", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-64453", "card": "CVE-2026-64453.webp?v=1784983773", "takeaways": [], "ts": 1784974650, "exploited": 0, "has_score": 0, "created": 1784983674, "updated": 1784983674, "exploited_text": 0, "poc": 0, "score": 0.0, "kev": 0, "flags": []}, {"key": "CVE-2026-64452", "cve": "CVE-2026-64452", "lang": "en", "title": "CVE-2026-64452", "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\n6lowpan: fix NHC entry use-after-free on error path\n\nlowpan_nhc_do_uncompression() looks up an NHC descriptor while holding\nlowpan_nhc_lock.  If the descriptor has no uncompress callback, the error\npath drops the lock before printing nhc->name.\n\nlowpan_nhc_del() removes descriptors under the same lock and then relies\non synchronize_net() before the owning module can be unloaded.  That only\nwaits for net RX RCU readers.  lowpan_header_decompress() is also exported\nand can be reached from callers that are not necessarily covered by the net\ncore RX critical section, for example the Bluetooth 6LoWPAN L2CAP receive\npath.\n\nThis leaves a race where one task drops lowpan_nhc_lock in the error path,\nanother task unregisters and frees the matching descriptor after\nsynchronize_net() returns, and the first task then dereferences nhc->name\nfor the warning.\n\nWith the post-unlock window widened, KASAN reports:\n\n  BUG: KASAN: slab-use-after-free in lowpan_nhc_do_uncompression+0x1f4/0x220\n  Read of size 8\n  lowpan_nhc_do_uncompression\n  lowpan_header_decompress\n\nFix this by printing the warning before dropping lowpan_nhc_lock, so ", "product": "Linux", "category": "cve", "source": "NVD", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-64452", "card": "CVE-2026-64452.webp?v=1784981414", "takeaways": [], "ts": 1784974650, "exploited": 0, "has_score": 0, "created": 1784981311, "updated": 1784981311, "exploited_text": 0, "poc": 0, "score": 0.0, "kev": 0, "flags": []}, {"key": "CVE-2026-64451", "cve": "CVE-2026-64451", "lang": "en", "title": "CVE-2026-64451", "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\ntracing: Fix NULL pointer dereference in func_set_flag()\n\nfunc_set_flag() dereferences tr->current_trace_flags before verifying\nthat the current tracer is actually the function tracer. When the active\ntracer has been switched away from \"function\" (e.g., to \"wakeup_rt\"),\ntr->current_trace_flags can be NULL, leading to a NULL pointer\ndereference and kernel crash.\n\nThe call chain that triggers this is:\n\n  trace_options_write()\n    -> __set_tracer_option()\n      -> trace->set_flag()          /* func_set_flag */\n\nIn func_set_flag(), the first operation is:\n\n  if (!!set == !!(tr->current_trace_flags->val & bit))\n\nThis dereferences tr->current_trace_flags unconditionally. The safety\ncheck that guards against a non-function tracer:\n\n  if (tr->current_trace != &function_trace)\n      return 0;\n\nis placed *after* the dereference, which is too late.\n\nThis was observed with the following crash dump:\n\n  BUG: unable to handle page fault at 0000000000000000\n  RIP: func_set_flag+0xd\n\n  Call Trace:\n   __set_tracer_option+0x27\n   trace_options_write+0x75\n   vfs_write+0x12a\n   ksys_write+0x66\n   do_syscall_64+0x5b\n\n  RIP: ffffffff914", "product": "Linux", "category": "cve", "source": "NVD", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-64451", "card": "CVE-2026-64451.webp?v=1784981414", "takeaways": [], "ts": 1784974650, "exploited": 0, "has_score": 0, "created": 1784981311, "updated": 1784981311, "exploited_text": 0, "poc": 0, "score": 0.0, "kev": 0, "flags": []}, {"key": "CVE-2026-64450", "cve": "CVE-2026-64450", "lang": "en", "title": "CVE-2026-64450", "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\ntipc: fix out-of-bounds read in broadcast Gap ACK blocks\n\nA broadcast PROTOCOL/STATE_MSG can carry a Gap ACK blocks record in its\ndata area. tipc_get_gap_ack_blks() only verifies that the record's len\nfield is self-consistent with its ugack_cnt/bgack_cnt counts\n(sz == struct_size(p, gacks, ugack_cnt + bgack_cnt)); it does not check\nthat the record actually fits in the message data area, msg_data_sz().\n\nThe unicast caller tipc_link_proto_rcv() bounds it (\"if (glen > dlen)\nbreak;\"), but the broadcast caller tipc_bcast_sync_rcv() discards the\nreturned size, so tipc_link_advance_transmq() copies the record off the\nreceive skb with an attacker-controlled count:\n\n\tthis_ga = kmemdup(ga, struct_size(ga, gacks, ga->bgack_cnt),\n\t\t\t  GFP_ATOMIC);\n\nA TIPC neighbour that negotiated TIPC_GAP_ACK_BLOCK triggers it with one\nordinary broadcast STATE_MSG (msg_bc_ack_invalid() clear), sized so its\ndata area is short, carrying a Gap ACK record with len = 0x400,\nbgack_cnt = 0xff and ugack_cnt = 0. len then equals\nstruct_size(p, gacks, 255), so the consistency check passes and ga is\nnon-NULL; kmemdup() reads struct_size(ga, gacks, 255)", "product": "Linux", "category": "cve", "source": "NVD", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-64450", "card": "CVE-2026-64450.webp?v=1784983775", "takeaways": [], "ts": 1784974649, "exploited": 0, "has_score": 0, "created": 1784983674, "updated": 1784983674, "exploited_text": 0, "poc": 0, "score": 0.0, "kev": 0, "flags": []}, {"key": "CVE-2026-64449", "cve": "CVE-2026-64449", "lang": "en", "title": "CVE-2026-64449", "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\nstaging: vme_user: bound slave read/write to the kern_buf size\n\nThe SLAVE-path helpers buffer_to_user() and buffer_from_user() copy\n'count' bytes into/out of the fixed-size kern_buf (size_buf ==\nPCI_BUF_SIZE == 0x20000, 128 KiB) using *ppos as the offset, without\nbounding *ppos + count against size_buf.\n\nvme_user_write()/vme_user_read() only clamp count to the VME window size\n(image_size = vme_get_size(resource)), which VME_SET_SLAVE sets from the\nuser-supplied slave.size -- validated against the VME address space (up\nto VME_A32_MAX = 4 GiB), not against PCI_BUF_SIZE.  When the window\nexceeds 128 KiB, a write()/read() copies past the kern_buf allocation.\n\nClamp count against size_buf in both helpers, with an early return when\n*ppos is already at/after the buffer end.  *ppos is >= 0 here (the caller\nrejects negative offsets), so size_buf - *ppos cannot wrap.  This mirrors\nthe existing clamp in the MASTER-path helpers resource_to_user() /\nresource_from_user(), and matches the read()/write() convention of a\nshort transfer at end-of-buffer.\n\nFound by static analysis (CodeQL taint tracking + CBMC bounded model\nchecking", "product": "Linux", "category": "cve", "source": "NVD", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-64449", "card": "CVE-2026-64449.webp?v=1784983775", "takeaways": [], "ts": 1784974649, "exploited": 0, "has_score": 0, "created": 1784983674, "updated": 1784983674, "exploited_text": 0, "poc": 0, "score": 0.0, "kev": 0, "flags": []}, {"key": "CVE-2026-64448", "cve": "CVE-2026-64448", "lang": "en", "title": "CVE-2026-64448", "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\nsmb: client: restrict implied bcc[0] exemption to responses without data area\n\nsmb2_check_message() has a long-standing quirk that accepts a response\nwhose calculated length is one byte larger than the bytes actually\nreceived (\"server can return one byte more due to implied bcc[0]\").\nThis was introduced to accommodate servers that omit the trailing bcc[0]\noverlap byte when no data area is present.\n\nHowever, the exemption is applied unconditionally, regardless of whether\nthe command actually carries a data area (has_smb2_data_area[]).  When a\nresponse with a data area is subject to the +1 exemption, the reported\ndata can extend one byte beyond the bytes actually received, yet\nsmb2_check_message() still accepts it.  The subsequent decoder then reads\npast the end of the receive buffer.  This is reachable during NEGOTIATE\nand SESSION_SETUP, before the session is established.\n\nThe resulting out-of-bounds reads are visible under KASAN when mounting\nagainst a non-conforming server; both the SPNEGO/negTokenInit and the\nNTLMSSP challenge decoders are affected:\n\n  BUG: KASAN: slab-out-of-bounds in asn1_ber_decoder+0x16a7/0x", "product": "Linux", "category": "cve", "source": "NVD", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-64448", "card": "CVE-2026-64448.webp?v=1784983775", "takeaways": [], "ts": 1784974649, "exploited": 0, "has_score": 0, "created": 1784983674, "updated": 1784983674, "exploited_text": 0, "poc": 0, "score": 0.0, "kev": 0, "flags": []}, {"key": "CVE-2026-64447", "cve": "CVE-2026-64447", "lang": "en", "title": "CVE-2026-64447", "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\nstaging: media: ipu7: fix double-free and use-after-free in error paths\n\nIn both ipu7_isys_init() and ipu7_psys_init(), pdata is allocated and\nthen passed to ipu7_bus_initialize_device(), which stores it in\nadev->pdata. The ipu7_bus_release() function frees adev->pdata when the\ndevice's reference count drops to zero.\n\nTwo error paths incorrectly call kfree(pdata) after the device teardown\nhas already freed it:\n\n1. When ipu7_mmu_init() fails: put_device() is called, which drops the\n   reference count to zero and triggers ipu7_bus_release() ->\n   kfree(pdata). The subsequent kfree(pdata) is a double-free.\n\n2. When ipu7_bus_add_device() fails: it calls auxiliary_device_uninit()\n   internally, which calls put_device() -> ipu7_bus_release() ->\n   kfree(pdata). The subsequent kfree(pdata) is again a double-free.\n\nNote that the kfree(pdata) when ipu7_bus_initialize_device() itself\nfails is correct, because in that case auxiliary_device_init() failed\nand the release function was never set up, so pdata must be freed\nmanually.\n\nAdditionally, the error code was not saved before calling put_device(),\ncausing ERR_CAST() to der", "product": "Linux", "category": "cve", "source": "NVD", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-64447", "card": "CVE-2026-64447.webp?v=1784983775", "takeaways": [], "ts": 1784974649, "exploited": 0, "has_score": 0, "created": 1784983674, "updated": 1784983674, "exploited_text": 0, "poc": 0, "score": 0.0, "kev": 0, "flags": []}, {"key": "CVE-2026-64446", "cve": "CVE-2026-64446", "lang": "en", "title": "CVE-2026-64446", "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\nstaging: rtl8723bs: fix heap buffer overflow in rtw_cfg80211_set_wpa_ie()\n\nsupplicant_ie is a 256-byte array in struct security_priv. The WPA and\nWPA2 IE copy paths use:\n\n    memcpy(padapter->securitypriv.supplicant_ie, &pwpa[0], wpa_ielen + 2);\n\nwhere wpa_ielen is the raw IE length field (u8, 0-255). When a local user\nsupplies a connect request via nl80211 with a crafted WPA IE of length 255,\nwpa_ielen + 2 equals 257, overflowing the 256-byte buffer by one byte into\nthe adjacent last_mic_err_time field.\n\nrtw_parse_wpa_ie() does not prevent this: its length consistency check\ncompares *(wpa_ie+1) against (u8)(wpa_ie_len-2), which is (u8)(255) == 255\nwhen wpa_ie_len = 257, so the check passes silently.\n\nAdd explicit bounds checks for both the WPA and WPA2 paths before the\nmemcpy, rejecting any IE whose total size (wpa_ielen + 2) exceeds the\nsupplicant_ie buffer.", "product": "Linux", "category": "cve", "source": "NVD", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-64446", "card": "CVE-2026-64446.webp?v=1784983774", "takeaways": [], "ts": 1784974649, "exploited": 0, "has_score": 0, "created": 1784983674, "updated": 1784983674, "exploited_text": 0, "poc": 0, "score": 0.0, "kev": 0, "flags": []}, {"key": "CVE-2026-64445", "cve": "CVE-2026-64445", "lang": "en", "title": "CVE-2026-64445", "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\nstaging: rtl8723bs: fix WEP length underflow and OOB read in OnAuth()\n\nOnAuth() has two bugs in the shared-key authentication path.\n\nWhen the Privacy bit is set, rtw_wep_decrypt() is called without\nverifying that the frame is long enough to contain a valid WEP IV and\nICV.  Inside rtw_wep_decrypt(), length is computed as:\n\n    length = len - WLAN_HDR_A3_LEN - iv_len\n\nand then passed as (length - 4) to crc32_le().  If len is less than\nWLAN_HDR_A3_LEN + iv_len + icv_len (32 bytes), length - 4 is negative\nand, after the implicit cast to size_t, causes crc32_le() to read far\nbeyond the frame buffer.  Add a minimum length check before accessing\nthe IV field and calling the decryption path.\n\nWhen processing a seq=3 response, rtw_get_ie() stores the Challenge\nText IE length in ie_len, but the subsequent memcmp() always reads 128\nbytes regardless of ie_len.  IEEE 802.11 mandates a challenge text of\nexactly 128 bytes; reject any IE whose length field differs, matching\nthe check already applied to OnAuthClient().", "product": "Linux", "category": "cve", "source": "NVD", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-64445", "card": "CVE-2026-64445.webp?v=1784983774", "takeaways": [], "ts": 1784974649, "exploited": 0, "has_score": 0, "created": 1784983674, "updated": 1784983674, "exploited_text": 0, "poc": 0, "score": 0.0, "kev": 0, "flags": []}, {"key": "CVE-2026-64444", "cve": "CVE-2026-64444", "lang": "en", "title": "CVE-2026-64444", "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\nstaging: rtl8723bs: fix OOB read in OnAssocRsp() IE loop\n\nThe IE parsing loop in OnAssocRsp() advances by (pIE->length + 2) each\niteration but only guards on i  length\nfrom pframe[pkt_len], which is one byte past the allocated receive buffer.\n\nAdditionally, even when the header bytes are in bounds, pIE->length\nitself can extend the data window beyond pkt_len, silently passing a\ntruncated IE to the handler functions.\n\nAdd two guards at the top of the loop body:\n  1. Break if fewer than sizeof(*pIE) bytes remain (can't read header).\n  2. Break if the IE's declared data extends past pkt_len.", "product": "Linux", "category": "cve", "source": "NVD", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-64444", "card": "CVE-2026-64444.webp?v=1784983774", "takeaways": [], "ts": 1784974649, "exploited": 0, "has_score": 0, "created": 1784983674, "updated": 1784983674, "exploited_text": 0, "poc": 0, "score": 0.0, "kev": 0, "flags": []}, {"key": "CVE-2026-64443", "cve": "CVE-2026-64443", "lang": "en", "title": "CVE-2026-64443", "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\nstaging: rtl8723bs: fix OOB read in update_beacon_info() IE loop\n\nThe IE parsing loop in update_beacon_info() advances by\n(pIE->length + 2) each iteration but only guards on i  length from one byte past the allocated receive buffer.\n\nAdditionally, even when the header bytes are in bounds, pIE->length\nitself can extend the data window beyond len, passing a truncated IE\nto the handler functions.\n\nAdd two guards at the top of the loop body:\n  1. Break if fewer than sizeof(*pIE) bytes remain (can't read header).\n  2. Break if the IE's declared data extends past len.\n\nAlso replace i += (pIE->length + 2) with i += sizeof(*pIE) + pIE->length\nfor consistency with the sizeof(*pIE) guards added above.", "product": "Linux", "category": "cve", "source": "NVD", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-64443", "card": "CVE-2026-64443.webp?v=1784983777", "takeaways": [], "ts": 1784974648, "exploited": 0, "has_score": 0, "created": 1784983674, "updated": 1784983674, "exploited_text": 0, "poc": 0, "score": 0.0, "kev": 0, "flags": []}, {"key": "CVE-2026-64442", "cve": "CVE-2026-64442", "lang": "en", "title": "CVE-2026-64442", "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\nstaging: rtl8723bs: fix OOB reads in IE loops in issue_assocreq() and join_cmd_hdl()\n\nTwo IE parsing loops are missing the header bounds checks before they\ndereference pIE->length:\n\n - issue_assocreq() walks pmlmeinfo->network.ies to build the\n   association request. If the stored IE data ends with only an\n   element_id byte and no length byte, pIE->length is read one byte\n   past the end of the buffer.\n\n - join_cmd_hdl() walks pnetwork->ies during station join and has\n   the same problem under the same conditions.\n\nBoth buffers are filled from AP beacon and probe-response frames, so a\nmalicious AP that sends a truncated final IE can trigger the issue.\n\nApply the two-guard pattern established in update_beacon_info():\n  1. Break if fewer than sizeof(*pIE) bytes remain.\n  2. Break if the IE's declared data extends past the buffer end.", "product": "Linux", "category": "cve", "source": "NVD", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-64442", "card": "CVE-2026-64442.webp?v=1784983777", "takeaways": [], "ts": 1784974648, "exploited": 0, "has_score": 0, "created": 1784983674, "updated": 1784983674, "exploited_text": 0, "poc": 0, "score": 0.0, "kev": 0, "flags": []}, {"key": "CVE-2026-64441", "cve": "CVE-2026-64441", "lang": "en", "title": "CVE-2026-64441", "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\nstaging: rtl8723bs: fix OOB reads in rtw_get_sec_ie(), rtw_get_wapi_ie(), and rtw_get_wps_attr()\n\nThree IE/attribute parsing functions have missing bounds checks.\n\nrtw_get_sec_ie() and rtw_get_wapi_ie() iterate over a raw IE buffer\nwithout verifying that the header bytes (tag + length) are within the\nremaining buffer before reading them.  Additionally, rtw_get_sec_ie()\ncompares the 4-byte WPA OUI at cnt+2 without checking that at least\n6 bytes remain, and rtw_get_wapi_ie() compares a 4-byte WAPI OUI at\ncnt+6 without checking that at least 10 bytes remain.\n\nrtw_get_wps_attr() reads wps_ie[0] and wps_ie+2 unconditionally at\nentry, before verifying that wps_ielen is large enough to contain\nthe 6-byte WPS IE header (element_id + length + 4-byte OUI).  Inside\nthe attribute loop, get_unaligned_be16() is called on attr_ptr and\nattr_ptr+2 without checking that 4 bytes remain in the buffer.\n\nAdd a cnt+2 bounds check before each loop body in rtw_get_sec_ie()\nand rtw_get_wapi_ie(), guard each multi-byte comparison with a minimum\nIE length requirement, add a wps_ielen < 6 early return in\nrtw_get_wps_attr(), and add a 4-byte b", "product": "Linux", "category": "cve", "source": "NVD", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-64441", "card": "CVE-2026-64441.webp?v=1784983777", "takeaways": [], "ts": 1784974648, "exploited": 0, "has_score": 0, "created": 1784983674, "updated": 1784983674, "exploited_text": 0, "poc": 0, "score": 0.0, "kev": 0, "flags": []}, {"key": "CVE-2026-64440", "cve": "CVE-2026-64440", "lang": "en", "title": "CVE-2026-64440", "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\nstaging: rtl8723bs: fix OOB write in HT_caps_handler()\n\nHT_caps_handler() iterates pIE->length bytes and writes into\nHT_caps.u.HT_cap[], which is a fixed 26-byte array (sizeof struct\nHT_caps_element). Because pIE->length is a raw u8 from an over-the-air\n802.11 AssocResponse frame and is never validated, a malicious AP can\nset it up to 255, causing up to 229 bytes of out-of-bounds writes into\nadjacent fields of struct mlme_ext_info.\n\nTruncate the iteration count to the size of HT_caps.u.HT_cap using\numin() so that data from a longer-than-expected IE is silently ignored\nrather than written out of bounds, preserving interoperability with APs\nthat pad the element. An early return on oversized IEs was considered\nbut rejected: it would bypass the pmlmeinfo->HT_caps_enable = 1\nassignment that precedes the loop, silently disabling HT mode for APs\nthat append extra bytes to the HT Capabilities IE.", "product": "Linux", "category": "cve", "source": "NVD", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-64440", "card": "CVE-2026-64440.webp?v=1784983776", "takeaways": [], "ts": 1784974648, "exploited": 0, "has_score": 0, "created": 1784983674, "updated": 1784983674, "exploited_text": 0, "poc": 0, "score": 0.0, "kev": 0, "flags": []}, {"key": "CVE-2026-64439", "cve": "CVE-2026-64439", "lang": "en", "title": "CVE-2026-64439", "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\ncrypto: krb5 - filter out async aead implementations at alloc\n\nkrb5_aead_encrypt(), krb5_aead_decrypt() in rfc3961_simplified.c and\nrfc8009_encrypt(), rfc8009_decrypt() in rfc8009_aes2.c set a NULL\ncompletion callback and treat any negative return from\ncrypto_aead_{encrypt,decrypt}() as terminal, falling through to\nkfree_sensitive(buffer).  When the encrypt_name resolves to an\nasync AEAD instance the request returns -EINPROGRESS, the buffer\nis freed while the backend's worker still holds a pointer, and the\nworker dereferences the freed slab on completion.\n\nKASAN report under UML+SLUB with a synthetic async aead backend\nbound to krb5->encrypt_name:\n\n  BUG: KASAN: slab-use-after-free in t5_stub_complete+0x7d/0xc7\n\nThe helpers were written synchronously, so filter the async\ninstances out at allocation time instead of plumbing\ncrypto_wait_req() through every call site.\n\nReachable via net/rxrpc/rxgk.c, fs/afs/cm_security.c and\nnet/ceph/crypto.c on systems with an async AEAD provider bound to\nthe krb5 enctype name.", "product": "Linux", "category": "cve", "source": "NVD", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-64439", "card": "CVE-2026-64439.webp?v=1784983776", "takeaways": [], "ts": 1784974648, "exploited": 0, "has_score": 0, "created": 1784983674, "updated": 1784983674, "exploited_text": 0, "poc": 0, "score": 0.0, "kev": 0, "flags": []}, {"key": "CVE-2026-64438", "cve": "CVE-2026-64438", "lang": "en", "title": "CVE-2026-64438", "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\ncrypto: qat - fix VF2PF work teardown race in adf_disable_sriov()\n\nThe VF2PF interrupt handler queues PF-side response work that stores a\nraw pointer to per-VF state (struct adf_accel_vf_info). Currently,\nadf_disable_sriov() destroys per-VF mutexes and frees vf_info without\nstopping new VF2PF work or waiting for in-flight workers to complete. A\nconcurrently scheduled or already queued worker can then dereference\nfreed memory.\n\nThis manifests as a use-after-free when KASAN is enabled:\n\n  BUG: KASAN: null-ptr-deref in mutex_lock+0x76/0xe0\n  Write of size 8 at addr 0000000000000260 by task kworker/24:2/...\n  Workqueue: qat_pf2vf_resp_wq adf_iov_send_resp [intel_qat]\n  Call Trace:\n    kasan_report+0x119/0x140\n    mutex_lock+0x76/0xe0\n    adf_gen4_pfvf_send+0xd4/0x1f0 [intel_qat]\n    adf_recv_and_handle_vf2pf_msg+0x290/0x360 [intel_qat]\n    adf_iov_send_resp+0x8c/0xe0 [intel_qat]\n    process_one_work+0x6ac/0xfd0\n    worker_thread+0x4dd/0xd30\n    kthread+0x326/0x410\n    ret_from_fork+0x33b/0x670\n\nAdd a PF-local flag, vf2pf_disabled, that gates work queueing, worker\nprocessing, and interrupt re-enabling during teardown. ", "product": "Linux", "category": "cve", "source": "NVD", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-64438", "card": "CVE-2026-64438.webp?v=1784983776", "takeaways": [], "ts": 1784974648, "exploited": 0, "has_score": 0, "created": 1784983674, "updated": 1784983674, "exploited_text": 0, "poc": 0, "score": 0.0, "kev": 0, "flags": []}, {"key": "CVE-2026-64437", "cve": "CVE-2026-64437", "lang": "en", "title": "CVE-2026-64437", "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\nksmbd: fix use-after-free of a deferred file_lock on SMB2_CLOSE then SMB2_CANCEL\n\nCommit f580d27e8928 (\"ksmbd: fix use-after-free of a deferred file_lock on\ndouble SMB2_CANCEL\") made smb2_cancel() skip a work whose state is\nKSMBD_WORK_CANCELLED, so its cancel_fn cannot be fired a second time. But\nKSMBD_WORK has three states (ACTIVE, CANCELLED, CLOSED), and the same\nfreeing producer path is reached for CLOSED too:\n\n  SMB2_CLOSE on the locking handle -> set_close_state_blocked_works() sets\n  the deferred work's state to KSMBD_WORK_CLOSED and wakes the smb2_lock()\n  worker. The worker takes the non-ACTIVE early-exit, locks_free_lock()s\n  the file_lock and, because the state is not KSMBD_WORK_CANCELLED, takes\n  the STATUS_RANGE_NOT_LOCKED branch with \"goto out2\" -- which, like the\n  cancelled branch, skips release_async_work(). The work stays on\n  conn->async_requests with a live cancel_fn = smb2_remove_blocked_lock\n  pointing at the freed file_lock.\n\nA subsequent SMB2_CANCEL for the same AsyncId then passes the\nKSMBD_WORK_CANCELLED-only guard (its state is KSMBD_WORK_CLOSED), so\nsmb2_cancel() fires cancel_fn again ov", "product": "Linux", "category": "cve", "source": "NVD", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-64437", "card": "CVE-2026-64437.webp?v=1784983776", "takeaways": [], "ts": 1784974648, "exploited": 0, "has_score": 0, "created": 1784983674, "updated": 1784983674, "exploited_text": 0, "poc": 0, "score": 0.0, "kev": 0, "flags": []}, {"key": "CVE-2026-64436", "cve": "CVE-2026-64436", "lang": "en", "title": "CVE-2026-64436", "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet: af_key: initialize alg_key_len for IPComp states\n\npfkey_msg2xfrm_state() handles the IPComp (SADB_X_SATYPE_IPCOMP) case by\nallocating x->calg and copying only the algorithm name:\n\n\tx->calg = kmalloc_obj(*x->calg);\n\tif (!x->calg) {\n\t\terr = -ENOMEM;\n\t\tgoto out;\n\t}\n\tstrcpy(x->calg->alg_name, a->name);\n\tx->props.calgo = sa->sadb_sa_encrypt;\n\nUnlike the authentication (x->aalg) and encryption (x->ealg) branches of\nthe same function, the compression branch never initializes\ncalg->alg_key_len.  IPComp carries no key and the allocation only\nreserves sizeof(struct xfrm_algo) (i.e. no room for a key), so the field\nis left containing uninitialized slab data.\n\ncalg->alg_key_len is later used as a length by xfrm_algo_clone() when an\nIPComp state is cloned during XFRM_MSG_MIGRATE:\n\n\txfrm_state_migrate()\n\t  xfrm_state_clone_and_setup()\n\t    x->calg = xfrm_algo_clone(orig->calg);\n\t      kmemdup(orig, xfrm_alg_len(orig));\n\nwhere xfrm_alg_len() returns sizeof(*alg) + (alg_key_len + 7) / 8.  With\na non-zero garbage alg_key_len, kmemdup() reads past the end of the\n68-byte calg object.  Adding an IPComp SA via PF_KEY and then mig", "product": "Linux", "category": "cve", "source": "NVD", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-64436", "card": "CVE-2026-64436.webp?v=1784983776", "takeaways": [], "ts": 1784974648, "exploited": 0, "has_score": 0, "created": 1784983674, "updated": 1784983674, "exploited_text": 0, "poc": 0, "score": 0.0, "kev": 0, "flags": []}, {"key": "CVE-2026-64435", "cve": "CVE-2026-64435", "lang": "en", "title": "CVE-2026-64435", "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\naudit: Fix data races of skb_queue_len() readers on audit_queue\n\nMultiple readers access audit_queue.qlen via skb_queue_len() without\nholding the queue lock or using READ_ONCE(), while kauditd writes to\nthis field via the skb_dequeue() → __skb_unlink() path with WRITE_ONCE()\nprotected by a spinlock. This constitutes data races.\n\nAll affected skb_queue_len(&audit_queue) call sites:\n  - kauditd_thread() wait_event_freezable() condition\n  - audit_receive_msg() AUDIT_GET handler (s.backlog assignment)\n  - audit_receive() backlog check\n  - audit_log_start() backlog check and pr_warn()\n\nKCSAN reports the following conflicting access pattern (one example):\n==================================================================\nBUG: KCSAN: data-race in audit_log_start / skb_dequeue\n\nwrite (marked) to 0xffffffff8512ee20 of 4 bytes by task 661 on cpu 57:\n skb_dequeue+0x70/0xf0\n kauditd_send_queue+0x71/0x220\n kauditd_thread+0x1cb/0x430\n kthread+0x1c2/0x210\n ret_from_fork+0x162/0x1a0\n ret_from_fork_asm+0x1a/0x30\n\nread to 0xffffffff8512ee20 of 4 bytes by task 36586 on cpu 1:\n audit_log_start+0x2a0/0x6b0\n audit_core_dumps+0x64/0xa0\n", "product": "Linux", "category": "cve", "source": "NVD", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-64435", "card": "CVE-2026-64435.webp?v=1784986138", "takeaways": [], "ts": 1784974647, "exploited": 0, "has_score": 0, "created": 1784986038, "updated": 1784986038, "exploited_text": 0, "poc": 0, "score": 0.0, "kev": 0, "flags": []}, {"key": "CVE-2026-64434", "cve": "CVE-2026-64434", "lang": "en", "title": "CVE-2026-64434", "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\nBluetooth: L2CAP: Fix UAF in channel timeout by holding conn ref\n\nl2cap_chan_timeout() runs asynchronously and accesses chan->conn. If\nthe connection is torn down while the timer is running or pending,\nchan->conn can be freed, leading to a use-after-free when the timer\nworker attempts to lock conn->lock:\n\n| BUG: KASAN: slab-use-after-free in instrument_atomic_read_write include/linux/instrumented.h:112 [inline]\n| BUG: KASAN: slab-use-after-free in atomic_long_try_cmpxchg_acquire include/linux/atomic/atomic-instrumented.h:4456 [inline]\n| BUG: KASAN: slab-use-after-free in __mutex_trylock_fast kernel/locking/mutex.c:161 [inline]\n| BUG: KASAN: slab-use-after-free in mutex_lock+0x4f/0xa0 kernel/locking/mutex.c:318\n| Write of size 8 at addr ffff8881298d9550 by task kworker/2:1/83\n|\n| CPU: 2 UID: 0 PID: 83 Comm: kworker/2:1 Not tainted 7.1.0-rc6-next-20260601-dirty #6 PREEMPT(full)\n| Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS 1.17.0-debian-1.17.0-1 04/01/2014\n| Workqueue: events l2cap_chan_timeout\n| Call Trace:\n|   \n|  instrument_atomic_read_write include/linux/instrumented.h:112 [inline]\n|  atomic_long", "product": "Linux", "category": "cve", "source": "NVD", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-64434", "card": "CVE-2026-64434.webp?v=1784986138", "takeaways": [], "ts": 1784974647, "exploited": 0, "has_score": 0, "created": 1784986038, "updated": 1784986038, "exploited_text": 0, "poc": 0, "score": 0.0, "kev": 0, "flags": []}, {"key": "CVE-2026-64433", "cve": "CVE-2026-64433", "lang": "en", "title": "CVE-2026-64433", "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\nBluetooth: MGMT: Fix UAF of hci_conn_params in add_device_complete\n\nadd_device_complete() runs from the hci_cmd_sync_work kworker, which\nholds only hci_req_sync_lock and *not* hci_dev_lock.  It calls\nhci_conn_params_lookup() and then dereferences the returned object\n(params->flags) without taking hci_dev_lock:\n\n\tparams = hci_conn_params_lookup(hdev, &cp->addr.bdaddr,\n\t\t\t\t\tle_addr_type(cp->addr.type));\n\t...\n\tdevice_flags_changed(NULL, hdev, &cp->addr.bdaddr,\n\t\t\t     cp->addr.type, hdev->conn_flags,\n\t\t\t     params ? params->flags : 0);\n\nhci_conn_params_lookup() walks hdev->le_conn_params and is documented to\nrequire hdev->lock.  A concurrent MGMT_OP_REMOVE_DEVICE\n(remove_device()), which does run under hci_dev_lock, can call\nhci_conn_params_free() to list_del() and kfree() the very object the\nlookup returned, so the subsequent params->flags read touches freed\nmemory [0].\n\nHold hci_dev_lock() across the hci_conn_params_lookup() and the read of\nparams->flags (and the matching event emission) so the lookup result\ncannot be freed by a concurrent remove_device() before it is used,\nhonouring the locking contract of hci_co", "product": "Linux", "category": "cve", "source": "NVD", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-64433", "card": "CVE-2026-64433.webp?v=1784986136", "takeaways": [], "ts": 1784974647, "exploited": 0, "has_score": 0, "created": 1784986038, "updated": 1784986038, "exploited_text": 0, "poc": 0, "score": 0.0, "kev": 0, "flags": []}, {"key": "CVE-2026-64432", "cve": "CVE-2026-64432", "lang": "en", "title": "CVE-2026-64432", "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\nfs/ntfs3: validate Dirty Page Table capacity in log_replay copy_lcns\n\nIn the analysis pass of $LogFile journal replay, log_replay() copies\nLCNs from each action log record into an existing Dirty Page Table\n(DPT) entry without bounding the destination index. A crafted NTFS\nimage with DPT entry lcns_follow=1 and an action log record with\nlcns_follow=2 produces a kernel slab out-of-bounds write at mount\ntime:\n\n  BUG: KASAN: slab-out-of-bounds in log_replay+0x654c/0xdb60\n  Write of size 8 at addr ffff8880095e1040 by task mount\n\nTwo attacker-controlled fields can drive j+i past the allocated\npage_lcns[] array:\n\n  1. dp->lcns_follow (capacity) can be smaller than lrh->lcns_follow.\n  2. lrh->target_vcn may be smaller than dp->vcn, making the u64\n     subtraction wrap to a huge size_t.\n\nValidate target VCN delta and per-record LCN count against the\nDPT entry capacity, bail via the existing out: cleanup label with\n-EINVAL.\n\nThis mirrors the bounds-check pattern added in commit b2bc7c44ed17\n(\"fs/ntfs3: Fix slab-out-of-bounds read in DeleteIndexEntryRoot\")\nand commit 0ca0485e4b2e (\"fs/ntfs3: validate rec->used in\njournal-rep", "product": "Linux", "category": "cve", "source": "NVD", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-64432", "card": "CVE-2026-64432.webp?v=1784983778", "takeaways": [], "ts": 1784974647, "exploited": 0, "has_score": 0, "created": 1784983674, "updated": 1784983674, "exploited_text": 0, "poc": 0, "score": 0.0, "kev": 0, "flags": []}, {"key": "CVE-2026-64431", "cve": "CVE-2026-64431", "lang": "en", "title": "CVE-2026-64431", "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\nntfs: avoid calling post_write_mst_fixup() for invalid index_block\n\nntfs_icx_ib_sync_write() calls post_write_mst_fixup() when ntfs_ib_write()\nreturns an error, intending to restore the buffer after a failed write.\n\nHowever, ntfs_ib_write() returns an error immediately if\npre_write_mst_fixup() validation fails. The caller,\nntfs_icx_ib_sync_write(), interprets any error as a write failure\nrequiring rollback. It does not differentiate between I/O errors and\nvalidation failures, and calls post_write_mst_fixup() anyway.\n\nSince post_write_mst_fixup() assumes that the index_block contents is\ncorrect, it doesn't perform the boundary checks, which results in\nout-of-bounds memory access.\n\nAn attacker can craft a malicious NTFS image with:\n  - large index_block.usa_ofs offset, pointing outside the ntfs_record\n  - index_block.usa_count = 0, causing integer underflow\n  - or index_block.usa_count larger than actual number of sectors in the\n    ntfs_record, causing out-of-bounds access\n\nKASAN reports describing the memory corruption:\n  ==================================================================\n  BUG: KASAN: slab-out-of-", "product": "Linux", "category": "cve", "source": "NVD", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-64431", "card": "CVE-2026-64431.webp?v=1784983778", "takeaways": [], "ts": 1784974647, "exploited": 0, "has_score": 0, "created": 1784983674, "updated": 1784983674, "exploited_text": 0, "poc": 0, "score": 0.0, "kev": 0, "flags": []}, {"key": "CVE-2026-64430", "cve": "CVE-2026-64430", "lang": "en", "title": "CVE-2026-64430", "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\nNTB: epf: Avoid calling pci_irq_vector() from hardirq context\n\nntb_epf_vec_isr() calls pci_irq_vector() in hardirq context to derive\nthe vector number. pci_irq_vector() calls msi_get_virq() that takes a\nmutex and can therefore trigger \"scheduling while atomic\" splats:\n\n  BUG: scheduling while atomic: kworker/u33:0/55/0x00010001\n  ...\n  Call trace:\n   ...\n   schedule+0x38/0x110\n   schedule_preempt_disabled+0x28/0x50\n   __mutex_lock.constprop.0+0x848/0x908\n   __mutex_lock_slowpath+0x18/0x30\n   mutex_lock+0x4c/0x60\n   msi_domain_get_virq+0xe8/0x138\n   pci_irq_vector+0x2c/0x60\n   ntb_epf_vec_isr+0x28/0x120 [ntb_hw_epf]\n   __handle_irq_event_percpu+0x70/0x3a8\n   handle_irq_event+0x48/0x100\n   handle_edge_irq+0x100/0x1c8\n   ...\n\nCache the Linux IRQ number for vector 0 when vectors are allocated and\nuse it as a base in the ISR. Running the ISR in a threaded IRQ handler\nwould also avoid the problem, but that would be unnecessary here.", "product": "Linux", "category": "cve", "source": "NVD", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-64430", "card": "CVE-2026-64430.webp?v=1784983777", "takeaways": [], "ts": 1784974647, "exploited": 0, "has_score": 0, "created": 1784983674, "updated": 1784983674, "exploited_text": 0, "poc": 0, "score": 0.0, "kev": 0, "flags": []}, {"key": "CVE-2026-64429", "cve": "CVE-2026-64429", "lang": "en", "title": "CVE-2026-64429", "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\ngpio: eic-sprd: use raw_spinlock_t in the irq startup path\n\nsprd_eic_irq_unmask() enables the GPIO IRQ and then updates controller\nstate through sprd_eic_update(), which takes sprd_eic->lock with\nspin_lock_irqsave().  The callback can be reached from irq_startup()\nwhile setting up a requested IRQ.  That path is not sleepable, but on\nPREEMPT_RT a regular spinlock_t becomes a sleeping lock.\n\nThis issue was found by our static analysis tool and then manually\nreviewed against the current tree.\n\nThe grounded PoC kept the request_threaded_irq() -> __setup_irq() ->\nirq_startup() -> sprd_eic_irq_unmask() -> sprd_eic_update() carrier and\nused the original spin_lock_irqsave(&sprd_eic->lock) edge.  Lockdep\n\n  BUG: sleeping function called from invalid context\n  hardirqs last disabled at ... __setup_irq.constprop.0 ... [vuln_msv]\n  sprd_rt_spin_lock_irqsave+0x1c/0x30 [vuln_msv]\n  sprd_eic_update.constprop.0+0x48/0x90 [vuln_msv]\n  sprd_eic_irq_unmask.constprop.0+0x35/0x50 [vuln_msv]\n  __setup_irq.constprop.0+0xd/0x30 [vuln_msv]\n\nConvert the Spreadtrum EIC controller lock to raw_spinlock_t.  The\nlocked section only serializes M", "product": "Linux", "category": "cve", "source": "NVD", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-64429", "card": "CVE-2026-64429.webp?v=1784983777", "takeaways": [], "ts": 1784974647, "exploited": 0, "has_score": 0, "created": 1784983674, "updated": 1784983674, "exploited_text": 0, "poc": 0, "score": 0.0, "kev": 0, "flags": []}, {"key": "CVE-2026-64428", "cve": "CVE-2026-64428", "lang": "en", "title": "CVE-2026-64428", "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\ngpio: sch: use raw_spinlock_t in the irq startup path\n\nsch_irq_unmask() enables the GPIO IRQ and then updates the controller\nstate through sch_irq_mask_unmask(), which takes sch->lock with\nspin_lock_irqsave().  The callback can be reached from irq_startup()\nwhile setting up a requested IRQ.  That path is not sleepable, but on\nPREEMPT_RT a regular spinlock_t becomes a sleeping lock.\n\nThis issue was found by our static analysis tool and then manually\nreviewed against the current tree.\n\nThe grounded PoC kept the request_threaded_irq() -> __setup_irq() ->\nirq_startup() -> sch_irq_unmask() -> sch_irq_mask_unmask() carrier and\nused the original spin_lock_irqsave(&sch->lock) edge.  Lockdep reported:\n\n  BUG: sleeping function called from invalid context\n  hardirqs last disabled at ... __setup_irq.constprop.0 ... [vuln_msv]\n  sch_rt_spin_lock_irqsave+0x1c/0x30 [vuln_msv]\n  sch_irq_mask_unmask.constprop.0+0x31/0x70 [vuln_msv]\n  __setup_irq.constprop.0+0xd/0x30 [vuln_msv]\n\nConvert the SCH controller lock to raw_spinlock_t.  The same lock is\nalso used by the GPIO direction and value callbacks, but those critical\nsections only", "product": "Linux", "category": "cve", "source": "NVD", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-64428", "card": "CVE-2026-64428.webp?v=1784986140", "takeaways": [], "ts": 1784974646, "exploited": 0, "has_score": 0, "created": 1784986038, "updated": 1784986038, "exploited_text": 0, "poc": 0, "score": 0.0, "kev": 0, "flags": []}, {"key": "CVE-2026-64427", "cve": "CVE-2026-64427", "lang": "en", "title": "CVE-2026-64427", "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\nHID: logitech-dj: Fix maxfield check in DJ short report validation\n\nCommit b6a57912854e (\"HID: logitech-dj: Prevent REPORT_ID_DJ_SHORT\nrelated user initiated OOB write\") added validation for the DJ short\noutput report, but the error path dereferences rep->field[0] even when\nrep->maxfield is zero.\n\nCommit 8b9a097eb2fc (\"HID: logitech-dj: fix wrong detection of bad\nDJ_SHORT output report\") made the check conditional on rep being present,\nbut a crafted descriptor can still create report ID 0x20 with only padding\noutput items. hid-core registers the report, ignores the padding field,\nand leaves rep->maxfield as zero.\n\nIn that case the validation enters the rep->maxfield  field[0]->report_count while printing the error message,\ncausing a NULL pointer dereference during probe. This is reproducible with\nuhid by emulating a Logitech receiver with a padding-only DJ short output\nreport:\n\n  BUG: KASAN: null-ptr-deref in logi_dj_probe+0xb1/0x754 [hid_logitech_dj]\n  Read of size 4 at addr 0000000000000028 by task kworker/4:1/129\n  ...\n  Call Trace:\n   logi_dj_probe+0xb1/0x754 [hid_logitech_dj]\n   hid_device_probe+0x329/0x3f0 [", "product": "Linux", "category": "cve", "source": "NVD", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-64427", "card": "CVE-2026-64427.webp?v=1784986139", "takeaways": [], "ts": 1784974646, "exploited": 0, "has_score": 0, "created": 1784986038, "updated": 1784986038, "exploited_text": 0, "poc": 0, "score": 0.0, "kev": 0, "flags": []}, {"key": "CVE-2026-64426", "cve": "CVE-2026-64426", "lang": "en", "title": "CVE-2026-64426", "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\nio_uring/nop: fix file reference leak with IOSQE_FIXED_FILE\n\nNOP file-acquisition support choses between a fixed (registered) file and\na normal fget()'d file based on its own IORING_NOP_FIXED_FILE flag in\nsqe->nop_flags. However, a request's REQ_F_FIXED_FILE is set\nindependently from the generic IOSQE_FIXED_FILE sqe flag during request\ninit, before the issue handler runs.\n\nIf a NOP is submitted with IOSQE_FIXED_FILE set (so REQ_F_FIXED_FILE is\nset) but without IORING_NOP_FIXED_FILE, io_nop() takes the normal path\nand grabs a real reference via io_file_get_normal(). On completion,\nio_put_file() only drops the reference when REQ_F_FIXED_FILE is clear,\nso the fget()'d file is never released and leaks:\n\n  BUG: memory leak\n  unreferenced object 0xffff88800f42c240 (size 176):\n    kmem_cache_alloc_noprof+0x358/0x440\n    alloc_empty_file+0x57/0x180\n    path_openat+0x44/0x1e50\n    do_file_open+0x121/0x200\n    do_sys_openat2+0xa7/0x150\n    __x64_sys_openat+0x82/0xf0\n\nDecide between fixed and normal file acquisition from REQ_F_FIXED_FILE,\nthe same way io_assign_file() does for every other opcode, and fold\nIORING_NOP_FIXED_FI", "product": "Linux", "category": "cve", "source": "NVD", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-64426", "card": "CVE-2026-64426.webp?v=1784986139", "takeaways": [], "ts": 1784974646, "exploited": 0, "has_score": 0, "created": 1784986038, "updated": 1784986038, "exploited_text": 0, "poc": 0, "score": 0.0, "kev": 0, "flags": []}, {"key": "CVE-2026-64425", "cve": "CVE-2026-64425", "lang": "en", "title": "CVE-2026-64425", "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\nio_uring/io-wq: re-check IO_WQ_BIT_EXIT for each linked work item\n\ncommit 10dc95939817 (\"io_uring/io-wq: check IO_WQ_BIT_EXIT inside work\nrun loop\") fixed the obvious case where io_worker_handle_work() took one\nexit-bit snapshot before draining pending work, but the fix stops one\nlevel too early.\n\nio_worker_handle_work() now re-checks IO_WQ_BIT_EXIT in its outer work\nrun loop, yet it still snapshots that bit once before processing a whole\ndependent linked-work chain. If io_wq_exit_start() sets IO_WQ_BIT_EXIT\nafter the first linked item has started, the remaining linked items can\nstill reuse stale do_kill = false, skip IO_WQ_WORK_CANCEL, and continue\nrunning after exit has begun.\n\nMove the check further inside, so it covers linked items too. Note: this\nis a syzbot special as it loves setting up tons of slow linked work on\nweird devices like msr that take forever to read, and immediately close\nthe ring. Exit then takes a long time.", "product": "Linux", "category": "cve", "source": "NVD", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-64425", "card": "CVE-2026-64425.webp?v=1784986139", "takeaways": [], "ts": 1784974646, "exploited": 0, "has_score": 0, "created": 1784986038, "updated": 1784986038, "exploited_text": 0, "poc": 0, "score": 0.0, "kev": 0, "flags": []}, {"key": "CVE-2026-64424", "cve": "CVE-2026-64424", "lang": "en", "title": "CVE-2026-64424", "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\nnetpoll: fix a use-after-free on shutdown path\n\nThere is a use-after-free error on netpoll, which is clearly detected by\nKASAN.\n\n      BUG: KASAN: slab-use-after-free in _raw_spin_lock_irqsave+0x3b/0x80\n      Read of size 1 at addr ... by task kworker/9:1\n      Workqueue: events queue_process\n      Call Trace:\n       skb_dequeue+0x1e/0xb0\n       queue_process+0x2c/0x600\n       process_scheduled_works+0x4b6/0x850\n       worker_thread+0x414/0x5a0\n      Allocated by task 242:\n       __netpoll_setup+0x201/0x4a0\n       netpoll_setup+0x249/0x550\n       enabled_store+0x32f/0x380\n      Freed by task 0:\n       kfree+0x1b7/0x540\n       rcu_core+0x3f8/0x7a0\n\nThe problem happens when there is a pending TX worker running in\nparallel with the cleanup path.\n\nThis is what happens on netpoll shutdown path:\n\n1) __netpoll_cleanup() is called\n2) set dev->npinfo to NULL\n3) call_rcu() with rcu_cleanup_netpoll_info()\n  3.1) rcu_cleanup_netpoll_info() tries to cancel all workers with\n       cancel_delayed_work(), but doesn't wait for the worker to finish\n4) and kfree(npinfo);\n\nBecause 3.1) doesn't really cancel the work, as the comment s", "product": "Linux", "category": "cve", "source": "NVD", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-64424", "card": "CVE-2026-64424.webp?v=1784986139", "takeaways": [], "ts": 1784974646, "exploited": 0, "has_score": 0, "created": 1784986038, "updated": 1784986038, "exploited_text": 0, "poc": 0, "score": 0.0, "kev": 0, "flags": []}, {"key": "CVE-2026-64423", "cve": "CVE-2026-64423", "lang": "en", "title": "CVE-2026-64423", "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\nipv4: igmp: remove multicast group from hash table on device destruction\n\nWhen a device is destroyed under RTNL, ip_mc_destroy_dev() iterates through\nthe multicast list and calls ip_ma_put() on each membership, scheduling\nthem for RCU reclamation. However, they are not unlinked from the device's\nmulticast hash table (mc_hash).\n\nSince the device remains published in dev->ip_ptr until after\nip_mc_destroy_dev() completes, concurrent RCU readers traversing mc_hash\ncan still locate and access the multicast group after its refcount is\ndecremented. If the RCU callback runs and frees the group while a reader is\naccessing it, a use-after-free occurs.\n\nFix this by unlinking the multicast group from mc_hash using\nip_mc_hash_remove() before scheduling it for reclamation.\n\nBUG: KASAN: slab-use-after-free in ip_check_mc_rcu+0x149/0x3f0\nRead of size 4 at addr ffff888009bf1408 by task mausezahn/2276\n\nCall Trace:\n  \n dump_stack_lvl+0x67/0x90\n print_report+0x175/0x7c0\n kasan_report+0x147/0x180\n ip_check_mc_rcu+0x149/0x3f0\n udp_v4_early_demux+0x36d/0x12d0\n ip_rcv_finish_core+0xb8b/0x1390\n ip_rcv_finish+0x54/0x120\n NF_HOOK+0x213/0x2b", "product": "Linux", "category": "cve", "source": "NVD", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-64423", "card": "CVE-2026-64423.webp?v=1784986138", "takeaways": [], "ts": 1784974646, "exploited": 0, "has_score": 0, "created": 1784986038, "updated": 1784986038, "exploited_text": 0, "poc": 0, "score": 0.0, "kev": 0, "flags": []}, {"key": "CVE-2026-64422", "cve": "CVE-2026-64422", "lang": "en", "title": "CVE-2026-64422", "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet: ipv4: bound TCP reordering sysctl writes and MTU probe sizes\n\nReject invalid `net.ipv4.tcp_reordering` values before they reach TCP\nsocket state. The sysctl is stored as an `int` but copied into the\n`u32` `tp->reordering` field for new sockets, so negative writes wrap\nto large values.\n\nWith `tcp_mtu_probing=2`, the wrapped value can overflow the\n`tcp_mtu_probe()` size calculation and drive the MTU probing path into\nan out-of-bounds read. Route `tcp_reordering` writes through\n`proc_dointvec_minmax()` and require it to be at least 1. Also require\n`tcp_max_reordering` to be at least 1 so the configured maximum cannot\nbecome negative either.\n\nWhen registering the table for a non-init network namespace, relocate\n`extra2` pointers that refer into `init_net.ipv4` so the\n`tcp_reordering` upper bound follows that namespace's\n`tcp_max_reordering`.\n\nHarden `tcp_mtu_probe()` itself by computing `size_needed` as `u64`.\nThis keeps the send queue and window checks from being bypassed through\nsigned integer overflow.", "product": "Linux", "category": "cve", "source": "NVD", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-64422", "card": "CVE-2026-64422.webp?v=1784986138", "takeaways": [], "ts": 1784974646, "exploited": 0, "has_score": 0, "created": 1784986038, "updated": 1784986038, "exploited_text": 0, "poc": 0, "score": 0.0, "kev": 0, "flags": []}, {"key": "CVE-2026-64421", "cve": "CVE-2026-64421", "lang": "en", "title": "CVE-2026-64421", "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\nmedia: nxp: imx8-isi: Fix use-after-free on remove\n\nKASAN reports a slab-use-after-free in __media_entity_remove_link()\nduring rmmod of imx8_isi:\n\n  BUG: KASAN: slab-use-after-free in __media_entity_remove_link+0x608/0x650\n  Read of size 2 at addr ffff0000d47cb02a by task rmmod/724\n\n  Call trace:\n   __media_entity_remove_link+0x608/0x650\n   __media_entity_remove_links+0x78/0x144\n   __media_device_unregister_entity+0x150/0x280\n   media_device_unregister_entity+0x48/0x68\n   v4l2_device_unregister_subdev+0x158/0x300\n   v4l2_async_unbind_subdev_one+0x22c/0x358\n   v4l2_async_nf_unbind_all_subdevs+0xfc/0x1c0\n   v4l2_async_nf_unregister+0x5c/0x14c\n   mxc_isi_remove+0x124/0x2a0 [imx8_isi]\n\n  Allocated by task 249:\n   __kmalloc_noprof+0x27c/0x690\n   mxc_isi_crossbar_init+0x22c/0x560 [imx8_isi]\n\n  Freed by task 724:\n   kfree+0x1e4/0x5b0\n   mxc_isi_crossbar_cleanup+0x34/0x80 [imx8_isi]\n   mxc_isi_remove+0x11c/0x2a0 [imx8_isi]\n\nThe problem is that mxc_isi_remove() calls mxc_isi_crossbar_cleanup()\nbefore mxc_isi_v4l2_cleanup(). The crossbar cleanup frees the media\nentity pads, but the subsequent v4l2 cleanup still tries to rem", "product": "Linux", "category": "cve", "source": "NVD", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-64421", "card": "CVE-2026-64421.webp?v=1784986138", "takeaways": [], "ts": 1784974646, "exploited": 0, "has_score": 0, "created": 1784986038, "updated": 1784986038, "exploited_text": 0, "poc": 0, "score": 0.0, "kev": 0, "flags": []}, {"key": "CVE-2026-64420", "cve": "CVE-2026-64420", "lang": "en", "title": "CVE-2026-64420", "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\nmfd: cros_ec: Delay dev_set_drvdata() until probe success\n\nIf ec_device_probe() fails, cros_ec_class_release releases memory for the\ncros_ec_dev structure. However, because the drvdata was already set,\nsub-drivers like cros_ec_typec can still retrieve the stale pointer via the\nplatform device. This leads to a use-after-free when cros_ec_typec attempts\nto access &typec->ec->ec->dev on a device that has already been released.\nMove dev_set_drvdata() to ensure that the pointer is only made available\nonce all initialization steps have succeeded.\n\n sysfs: cannot create duplicate filename '/class/chromeos/cros_ec'\n Call trace:\n  sysfs_do_create_link_sd+0x94/0xdc\n  sysfs_create_link+0x30/0x44\n  device_add_class_symlinks+0x90/0x13c\n  device_add+0xf0/0x50c\n  ec_device_probe+0x150/0x4f0\n  platform_probe+0xa0/0xe0\n ...\n BUG: KASAN: invalid-access in __memcpy+0x44/0x230\n Write at addr f5ffff809e2d33ac by task kworker/u32:5/125\n Pointer tag: [f5], memory tag: [fe]\n Tainted : [W]=WARN, [O]=OOT_MODULE\n Hardware name: Google Navi unprovisioned 0x7FFFFFFF/sku0 board/sku3\n Workqueue: events_unbound deferred_probe_work_func\n Call tra", "product": "Linux", "category": "cve", "source": "NVD", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-64420", "card": "CVE-2026-64420.webp?v=1784986141", "takeaways": [], "ts": 1784974645, "exploited": 0, "has_score": 0, "created": 1784986038, "updated": 1784986038, "exploited_text": 0, "poc": 0, "score": 0.0, "kev": 0, "flags": []}, {"key": "CVE-2026-64419", "cve": "CVE-2026-64419", "lang": "en", "title": "CVE-2026-64419", "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\nmm/shrinker: do not hold RCU lock in shrinker_debugfs_count_show()\n\nReading the debugfs \"count\" file of a memcg-aware shrinker can sleep\ninside an RCU read-side critical section:\n\n  BUG: sleeping function called from invalid context at kernel/cgroup/rstat.c:421\n  RCU nest depth: 1, expected: 0\n   css_rstat_flush\n   mem_cgroup_flush_stats\n   zswap_shrinker_count\n   shrinker_debugfs_count_show\n\nshrinker_debugfs_count_show() invokes the ->count_objects() callback under\nrcu_read_lock().  The zswap callback flushes memcg stats via\ncss_rstat_flush(), which may sleep, so it must not run under RCU.\n\nThe RCU lock is not needed here.  mem_cgroup_iter() takes RCU internally\nand returns a memcg holding a css reference (dropped on the next iteration\nor by mem_cgroup_iter_break()), so the memcg stays alive without it.  The\nshrinker is kept alive by the open debugfs file: shrinker_free() removes\nthe debugfs entries via debugfs_remove_recursive(), which waits for\nin-flight readers to drain, before call_rcu(..., shrinker_free_rcu_cb). \nThe sibling \"scan\" handler already invokes the sleeping ->scan_objects()\ncallback with no RCU se", "product": "Linux", "category": "cve", "source": "NVD", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-64419", "card": "CVE-2026-64419.webp?v=1784986141", "takeaways": [], "ts": 1784974645, "exploited": 0, "has_score": 0, "created": 1784986038, "updated": 1784986038, "exploited_text": 0, "poc": 0, "score": 0.0, "kev": 0, "flags": []}, {"key": "CVE-2026-64418", "cve": "CVE-2026-64418", "lang": "en", "title": "CVE-2026-64418", "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\nmm: shrinker: fix shrinker_info teardown race with expansion\n\nexpand_shrinker_info() iterates all visible memcgs under shrinker_mutex,\nincluding memcgs that have not finished ->css_online() yet.\n\nOnce pn->shrinker_info has been published, teardown must stay serialized\nwith expand_shrinker_info() until that memcg is either fully online or no\nlonger visible to iteration.  Today alloc_shrinker_info() breaks that rule\nby dropping shrinker_mutex before freeing a partially initialized\nshrinker_info array, which may cause the following race:\n\nCPU0                   CPU1\n====                   ====\n\ncss_create\n--> list_add_tail_rcu(&css->sibling, &parent_css->children);\n    online_css\n    --> mem_cgroup_css_online\n        --> alloc_shrinker_info\n            --> alloc node0 info\n                rcu_assign_pointer(C->node0->shrinker_info, old0)\n                alloc node1 info -> FAIL -> goto err\n                mutex_unlock(shrinker_mutex)\n\n                       shrinker_alloc()\n                       --> shrinker_memcg_alloc\n                           --> mutex_lock(shrinker_mutex)\n                               expand_s", "product": "Linux", "category": "cve", "source": "NVD", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-64418", "card": "CVE-2026-64418.webp?v=1784986141", "takeaways": [], "ts": 1784974645, "exploited": 0, "has_score": 0, "created": 1784986038, "updated": 1784986038, "exploited_text": 0, "poc": 0, "score": 0.0, "kev": 0, "flags": []}, {"key": "CVE-2026-64417", "cve": "CVE-2026-64417", "lang": "en", "title": "CVE-2026-64417", "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\nmm: shrinker: fix NULL pointer dereference in debugfs\n\nshrinker_debugfs_add() creates both \"count\" and \"scan\" debugfs files\nunconditionally.\n\nThat assumes every shrinker implements both count_objects() and\nscan_objects(), which is not guaranteed.  For example, the xen-backend\nshrinker sets count_objects() but leaves scan_objects() NULL, so writing\nto its scan file calls through a NULL function pointer and panics the\nkernel:\n\nBUG: kernel NULL pointer dereference, address: 0000000000000000\nRIP: 0010:0x0\nCode: Unable to access opcode bytes at 0xffffffffffffffd6.\nCall Trace:\n  \n shrinker_debugfs_scan_write+0x12e/0x270\n full_proxy_write+0x5f/0x90\n vfs_write+0xde/0x420\n ? filp_flush+0x75/0x90\n ? filp_close+0x1d/0x30\n ? do_dup2+0xb8/0x120\n ksys_write+0x68/0xf0\n ? filp_flush+0x75/0x90\n do_syscall_64+0xb3/0x5b0\n entry_SYSCALL_64_after_hwframe+0x76/0x7e\n\nThe count path has the same issue in principle if a shrinker omits\ncount_objects().\n\nTo fix it, only create \"count\" and \"scan\" debugfs files when the\ncorresponding callbacks are present.", "product": "Linux", "category": "cve", "source": "NVD", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-64417", "card": "CVE-2026-64417.webp?v=1784986141", "takeaways": [], "ts": 1784974645, "exploited": 0, "has_score": 0, "created": 1784986038, "updated": 1784986038, "exploited_text": 0, "poc": 0, "score": 0.0, "kev": 0, "flags": []}, {"key": "CVE-2026-64416", "cve": "CVE-2026-64416", "lang": "en", "title": "CVE-2026-64416", "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\nmm: swap_cgroup: fix NULL deref in lookup_swap_cgroup_id on swapless host\n\nlookup_swap_cgroup_id() passes swap_cgroup_ctrl[type].map to\n__swap_cgroup_id_lookup() without checking that the type was ever\nregistered via swap_cgroup_swapon().  On a swapless host every ctrl->map\nis NULL, so __swap_cgroup_id_lookup() dereferences NULL + a scaled\nswp_offset().\n\nSince commit bea67dcc5eea (\"mm: attempt to batch free swap entries for\nzap_pte_range()\"), zap_pte_range() -> swap_pte_batch() calls\nlookup_swap_cgroup_id() on any non-present, non-none PTE that decodes as a\nreal swap entry, without first validating it against swap_info[].  A\nsingle PTE corrupted into a type-0 swap entry takes the host down at\nprocess exit.\n\nWe hit this in production on a swapless 6.12.58 host: ~1s of\n\"get_swap_device: Bad swap file entry 3f800204222bb\" (do_swap_page() being\ncorrectly defensive about the same entry) followed by\n\n  BUG: unable to handle page fault for address: 000003f800204220\n  RIP: 0010:lookup_swap_cgroup_id+0x2b/0x60\n  Call Trace:\n   swap_pte_batch+0xbf/0x230\n   zap_pte_range+0x4c8/0x780\n   unmap_page_range+0x190/0x3e0\n   exit_mm", "product": "Linux", "category": "cve", "source": "NVD", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-64416", "card": "CVE-2026-64416.webp?v=1784986140", "takeaways": [], "ts": 1784974645, "exploited": 0, "has_score": 0, "created": 1784986038, "updated": 1784986038, "exploited_text": 0, "poc": 0, "score": 0.0, "kev": 0, "flags": []}, {"key": "CVE-2026-64415", "cve": "CVE-2026-64415", "lang": "en", "title": "CVE-2026-64415", "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\nmm/swap: add cond_resched() in swap_reclaim_full_clusters to prevent softlockup\n\nWe hit a real softlockup in an internal stress test environment.  The\nworkload was LTP memory/swap stress on a large arm64 machine, with 320\nCPUs, about 1TB memory and an 8.6GB swap device.  The system was under\nheavy load and the swap device had a large number of full clusters.  The\nsoftlockup was triggered during a stress test after about 3 days.\n\nSo, add periodic cond_resched() calls during large full_clusters\nreclaim operations to prevent softlockup issues.\n\nDetailed call trace as follow:\n\nPID: 3817773  TASK: ffff0883bb28b780  CPU: 48   COMMAND: \"kworker/48:7\"\n   #0 [ffff800080183d10] __crash_kexec at ffffa4c1361e5de4\n   #1 [ffff800080183d90] panic at ffffa4c1360d5e9c\n   #2 [ffff800080183e20] watchdog_timer_fn at ffffa4c136231fa8\n   ...\n  #16 [ffff8000c4ad3cb0] swap_cache_del_folio at ffffa4c1363e1614\n  #17 [ffff8000c4ad3ce0] __try_to_reclaim_swap at ffffa4c1363e4bfc\n  #18 [ffff8000c4ad3d40] swap_reclaim_full_clusters at ffffa4c1363e5474\n  #19 [ffff8000c4ad3da0] swap_reclaim_work at ffffa4c1363e550c\n  #20 [ffff8000c4ad3dc0] proces", "product": "Linux", "category": "cve", "source": "NVD", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-64415", "card": "CVE-2026-64415.webp?v=1784986140", "takeaways": [], "ts": 1784974645, "exploited": 0, "has_score": 0, "created": 1784986038, "updated": 1784986038, "exploited_text": 0, "poc": 0, "score": 0.0, "kev": 0, "flags": []}, {"key": "CVE-2026-64414", "cve": "CVE-2026-64414", "lang": "en", "title": "CVE-2026-64414", "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\nnetfilter: handle unreadable frags\n\nsashiko reports:\n When an skb with unreadable fragments (such as from devmem TCP, where\n skb_frags_readable(skb) returns false) is processed by the u32 module,\n skb_copy_bits() will safely return a negative error code [..]\n\nxt_u32: bail out with hotdrop in this case.\ngather_frags: return -1, just as if we had no fragment header.\nnfnetlink_queue: restrict to the linear part.\nnfnetlink_log: restrict to the linear part.\n\nv2:\n - skb_zerocopy helpers don't copy readable flag, i.e. nfnetlink_queue\n is broken too\n xt_u32 shouldn't return true if hotdrop was set.", "product": "Linux", "category": "cve", "source": "NVD", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-64414", "card": "CVE-2026-64414.webp?v=1784986140", "takeaways": [], "ts": 1784974645, "exploited": 0, "has_score": 0, "created": 1784986038, "updated": 1784986038, "exploited_text": 0, "poc": 0, "score": 0.0, "kev": 0, "flags": []}, {"key": "CVE-2026-64413", "cve": "CVE-2026-64413", "lang": "en", "title": "CVE-2026-64413", "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\nnetfilter: ebtables: zero chainstack array\n\nsashiko reports:\n looking at ebtables table\n translation, could a sparse cpu_possible_mask lead to an uninitialized pointer\n free?\n\n If cpu_possible_mask is sparse (for example, CPU 0 and CPU 2 are possible,\n but CPU 1 is not), the allocation loop skips CPU 1. If vmalloc_node() fails at\n CPU 2, the cleanup loop will blindly decrement and call vfree() on\n newinfo->chainstack[1].\n\nNot a real-world bug, such allocation isn't expected to fail\nin the first place.", "product": "Linux", "category": "cve", "source": "NVD", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-64413", "card": "CVE-2026-64413.webp?v=1784986140", "takeaways": [], "ts": 1784974645, "exploited": 0, "has_score": 0, "created": 1784986038, "updated": 1784986038, "exploited_text": 0, "poc": 0, "score": 0.0, "kev": 0, "flags": []}, {"key": "CVE-2026-64412", "cve": "CVE-2026-64412", "lang": "en", "title": "CVE-2026-64412", "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\nnetfilter: ebtables: module names must be null-terminated\n\nWe need to explicitly check the length, else we may pass non-null\nterminated string to request_module().", "product": "Linux", "category": "cve", "source": "NVD", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-64412", "card": "CVE-2026-64412.webp?v=1784988526", "takeaways": [], "ts": 1784974644, "exploited": 0, "has_score": 0, "created": 1784988405, "updated": 1784988405, "exploited_text": 0, "poc": 0, "score": 0.0, "kev": 0, "flags": []}, {"key": "CVE-2026-64411", "cve": "CVE-2026-64411", "lang": "en", "title": "CVE-2026-64411", "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\nnetfilter: ebtables: terminate table name before find_table_lock()\n\nupdate_counters() and compat_update_counters() forward a user-supplied\n32-byte table name to find_table_lock() without NUL-terminating it. On a\nlookup miss, find_inlist_lock() calls try_then_request_module(..., \"%s%s\",\n\"ebtable_\", name), and vsnprintf() reads past the name field and the\nstack object until it hits a zero byte.\n\n  BUG: KASAN: stack-out-of-bounds in string (lib/vsprintf.c:648 lib/vsprintf.c:730)\n  Read of size 1 at addr ffff8880119dfb20 by task exploit/147\n  Call Trace:\n  ...\n   string (lib/vsprintf.c:648 lib/vsprintf.c:730)\n   vsnprintf (lib/vsprintf.c:2945)\n   __request_module (kernel/module/kmod.c:150)\n   do_update_counters.isra.0 (net/bridge/netfilter/ebtables.c:371 net/bridge/netfilter/ebtables.c:380)\n   update_counters (net/bridge/netfilter/ebtables.c:1440)\n   do_ebt_set_ctl (net/bridge/netfilter/ebtables.c:2573)\n   nf_setsockopt (net/netfilter/nf_sockopt.c:101)\n   ip_setsockopt (net/ipv4/ip_sockglue.c:1424)\n   raw_setsockopt (net/ipv4/raw.c:847)\n   __sys_setsockopt (net/socket.c:2393)\n  ...\n\ncompat_do_replace() shares the same", "product": "Linux", "category": "cve", "source": "NVD", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-64411", "card": "CVE-2026-64411.webp?v=1784988526", "takeaways": [], "ts": 1784974644, "exploited": 0, "has_score": 0, "created": 1784988405, "updated": 1784988405, "exploited_text": 0, "poc": 0, "score": 0.0, "kev": 0, "flags": []}, {"key": "CVE-2026-64410", "cve": "CVE-2026-64410", "lang": "en", "title": "CVE-2026-64410", "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\nnetfilter: flowtable: IPIP tunnel hardware offload is not yet support\n\nNo driver supports for IPIP tunnels yet, give up early on setting up the\nhardware offload for this scenario.\n\nThis patch adds a stub that can be enhanced to add more configuration\nthat are currently not supported. As of now, the offload work is\nenqueued to the worker, then ignored if the hardware offload\nconfiguration is not supported.\n\nCheck the NF_FLOW_HW flag to know if this entry was already tried once\nto be offloaded so this is not retried on refresh when unsupported. Move\nNF_FLOW_HW flag check to nf_flow_offload_add(). If this NF_FLOW_HW flag\nis unset the _del and _stats variants are never called.\n\nThis can be updated later on to skip hardware offload work to be queued\nin case hardware offload does not support it.", "product": "Linux", "category": "cve", "source": "NVD", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-64410", "card": "CVE-2026-64410.webp?v=1784988525", "takeaways": [], "ts": 1784974644, "exploited": 0, "has_score": 0, "created": 1784988405, "updated": 1784988405, "exploited_text": 0, "poc": 0, "score": 0.0, "kev": 0, "flags": []}, {"key": "CVE-2026-64409", "cve": "CVE-2026-64409", "lang": "en", "title": "CVE-2026-64409", "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\nBluetooth: btmtksdio: fix infinite loop in btmtksdio_txrx_work()\n\nEvery once in a while we see a hung btmtksdio_flush() task:\n\n INFO: task kworker/u17:0:189 blocked for more than 122 seconds.\n __cancel_work_timer+0x3f4/0x460\n cancel_work_sync+0x1c/0x2c\n btmtksdio_flush+0x2c/0x40\n hci_dev_open_sync+0x10c4/0x2190\n [..]\n\nIt all boils down to incorrect time_is_before_jiffies() usage in\nbtmtksdio_txrx_work().  The btmtksdio_txrx_work() loop is expected\nto be terminated if running for longer than 5*HZ.  However the\ntimeout check is twisted:  time_is_before_jiffies(old_jiffies + 5*HZ)\nevaluates to true when old_jiffies + 5*HZ is in the past i.e. when a\ntimeout has occurred.  Using OR with time_is_before_jiffies(txrx_timeout)\nmeans that:\n- before the 5-second timeout: the condition is `int_status || false`,\n  so it loops as long as there are pending interrupts.\n- after the 5-second timeout: the condition becomes `int_status || true`,\n  which is always true.\n\nWhen the loop becomes infinite btmtksdio_txrx_work() loop never\nterminates and never releases the SDIO host.\n\nFix loop termination condition to actually enforce a 5*H", "product": "Linux", "category": "cve", "source": "NVD", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-64409", "card": "CVE-2026-64409.webp?v=1784986143", "takeaways": [], "ts": 1784974644, "exploited": 0, "has_score": 0, "created": 1784986038, "updated": 1784986038, "exploited_text": 0, "poc": 0, "score": 0.0, "kev": 0, "flags": []}, {"key": "CVE-2026-64408", "cve": "CVE-2026-64408", "lang": "en", "title": "CVE-2026-64408", "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\nBluetooth: bnep: pin L2CAP connection during netdev registration\n\nbnep_add_connection() reads the L2CAP connection without holding the\nchannel lock, then passes its HCI device to register_netdev(). Controller\nteardown can clear and release that connection concurrently, leaving the\nnetwork device registration path to dereference a freed parent device.\n\nTake a reference to the L2CAP connection while holding the channel lock.\nRetain it until register_netdev() has taken the parent device reference.", "product": "Linux", "category": "cve", "source": "NVD", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-64408", "card": "CVE-2026-64408.webp?v=1784986142", "takeaways": [], "ts": 1784974644, "exploited": 0, "has_score": 0, "created": 1784986038, "updated": 1784986038, "exploited_text": 0, "poc": 0, "score": 0.0, "kev": 0, "flags": []}, {"key": "CVE-2026-64407", "cve": "CVE-2026-64407", "lang": "en", "title": "CVE-2026-64407", "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\nBluetooth: btnxpuart: Fix out-of-bounds firmware read in nxp_recv_fw_req_v3()\n\nDuring the v3 firmware download the controller sends a v3_data_req with a\n32 bit offset and a 16 bit len. nxp_recv_fw_req_v3() checks only the lower\nbound of the offset and then sends firmware from that offset.\n\n  nxpdev->fw_dnld_v3_offset = offset - nxpdev->fw_v3_offset_correction;\n  serdev_device_write_buf(nxpdev->serdev, nxpdev->fw->data +\n                          nxpdev->fw_dnld_v3_offset, len);\n\nNothing checks that fw_dnld_v3_offset + len stays within nxpdev->fw->size,\nso a controller that asks for an offset or length past the firmware image\nmakes the driver read past the end of nxpdev->fw->data and send that\nmemory back over UART.\n\nnxp_recv_fw_req_v1() already bounds the same write. Add the equivalent\ncheck to the v3 path, reject the request when it falls outside the firmware\nimage, and zero len on the error path so the fw_v3_prev_sent bookkeeping at\nfree_skb stays consistent.", "product": "Linux", "category": "cve", "source": "NVD", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-64407", "card": "CVE-2026-64407.webp?v=1784986142", "takeaways": [], "ts": 1784974644, "exploited": 0, "has_score": 0, "created": 1784986038, "updated": 1784986038, "exploited_text": 0, "poc": 0, "score": 0.0, "kev": 0, "flags": []}, {"key": "CVE-2026-64406", "cve": "CVE-2026-64406", "lang": "en", "title": "CVE-2026-64406", "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\nBluetooth: fix UAF in bt_accept_dequeue()\n\nbt_accept_get() takes a temporary reference before dropping the accept\nqueue lock. bt_accept_dequeue() currently drops that reference before\nbt_accept_unlink(), leaving only the queue reference.\n\nbt_accept_unlink() drops the queue reference. The subsequent\nsock_hold() therefore accesses freed memory if it was the final\nreference, as observed by KASAN during listening L2CAP socket cleanup.\n\nRetain the temporary queue-walk reference through unlink and hand it to\nthe caller on success. Drop it explicitly on the closed and\nnot-yet-connected paths.", "product": "Linux", "category": "cve", "source": "NVD", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-64406", "card": "CVE-2026-64406.webp?v=1784986142", "takeaways": [], "ts": 1784974644, "exploited": 0, "has_score": 0, "created": 1784986038, "updated": 1784986038, "exploited_text": 0, "poc": 0, "score": 0.0, "kev": 0, "flags": []}, {"key": "CVE-2026-64405", "cve": "CVE-2026-64405", "lang": "en", "title": "CVE-2026-64405", "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\nBluetooth: hci_conn: Fix null ptr deref in hci_abort_conn()\n\nhci_abort_conn() read hci_skb_event(hdev->sent_cmd) when a connection\nwas pending, but hdev->sent_cmd can be NULL while req_status is still\nHCI_REQ_PEND, leading to a NULL pointer dereference and a general\nprotection fault from the hci_rx_work() receive path.\n\nInstead of inspecting hdev->sent_cmd, track the in-flight create\nconnection command with a new per-connection HCI_CONN_CREATE flag and\nroute all cancellation through hci_cancel_connect_sync(), which\ndispatches to a dedicated per-type cancel function. The create command\nis in exactly one of two states: still queued, or in flight. The cancel\nfunction holds cmd_sync_work_lock across the whole decision: the worker\ntakes this lock to dequeue every entry, so while it is held a queued\ncommand cannot start running and an in-flight command cannot complete\nand let the next command become pending. This keeps the flag test and\nhci_cmd_sync_cancel() atomic with respect to the worker, so a queued\ncommand is simply dequeued, and an in-flight command owned by this\nconnection is cancelled without the risk of cancel", "product": "Linux", "category": "cve", "source": "NVD", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-64405", "card": "CVE-2026-64405.webp?v=1784986142", "takeaways": [], "ts": 1784974644, "exploited": 0, "has_score": 0, "created": 1784986038, "updated": 1784986038, "exploited_text": 0, "poc": 0, "score": 0.0, "kev": 0, "flags": []}, {"key": "CVE-2026-64404", "cve": "CVE-2026-64404", "lang": "en", "title": "CVE-2026-64404", "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\nBluetooth: ISO: avoid NULL deref of conn in iso_conn_big_sync()\n\niso_conn_big_sync() drops the socket lock to call hci_get_route() and\nthen re-acquires it, but dereferences iso_pi(sk)->conn->hcon afterwards\nwithout re-checking that conn is still valid.\n\nWhile the lock is dropped, the connection can be torn down under the\nsame socket lock: iso_disconn_cfm() -> iso_conn_del() -> iso_chan_del()\nsets iso_pi(sk)->conn to NULL (and the broadcast teardown path can also\nclear conn->hcon on its own). When iso_conn_big_sync() re-acquires the\nlock and reads conn->hcon, conn may be NULL, causing a NULL pointer\ndereference (hcon is the first member of struct iso_conn).\n\nThis path is reached from iso_sock_recvmsg() for a PA-sync broadcast\nsink socket (BT_SK_DEFER_SETUP | BT_SK_PA_SYNC), so the dropped-lock\nwindow can race with connection teardown driven by controller events.\n\nRe-validate iso_pi(sk)->conn and its hcon after re-acquiring the socket\nlock and bail out if the connection went away, as already done in the\nsibling iso_sock_rebind_bc().", "product": "Linux", "category": "cve", "source": "NVD", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-64404", "card": "CVE-2026-64404.webp?v=1784986141", "takeaways": [], "ts": 1784974644, "exploited": 0, "has_score": 0, "created": 1784986038, "updated": 1784986038, "exploited_text": 0, "poc": 0, "score": 0.0, "kev": 0, "flags": []}, {"key": "CVE-2026-64403", "cve": "CVE-2026-64403", "lang": "en", "title": "CVE-2026-64403", "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\nBluetooth: L2CAP: validate option length before reading conf opt value\n\nl2cap_get_conf_opt() derives the option length from the\nattacker-controlled opt->len field and immediately dereferences\nopt->val (as u8, get_unaligned_le16() or get_unaligned_le32(), or a\nraw pointer for the default case) before any caller has confirmed\nthat opt->len bytes are present in the buffer. The callers\n(l2cap_parse_conf_req(), l2cap_parse_conf_rsp() and\nl2cap_conf_rfc_get()) only detect a malformed option afterwards, once\nthe running length has gone negative, by which point the\nout-of-bounds read has already executed.\n\nAn existing post-hoc length check keeps the garbage value from being\nconsumed, so this is not a data leak in the current control flow. It\nis still a validate-after-use ordering bug: up to 4 bytes are read\npast the end of the buffer before it is known to contain them, and it\nis fragile to future changes in the callers.\n\nFix it at the source. Pass the end of the buffer into\nl2cap_get_conf_opt() and refuse to touch opt->val unless the full\noption (header + value) fits. Each caller computes an end pointer\nonce before the lo", "product": "Linux", "category": "cve", "source": "NVD", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-64403", "card": "CVE-2026-64403.webp?v=1784988527", "takeaways": [], "ts": 1784974643, "exploited": 0, "has_score": 0, "created": 1784988405, "updated": 1784988405, "exploited_text": 0, "poc": 0, "score": 0.0, "kev": 0, "flags": []}, {"key": "CVE-2026-64402", "cve": "CVE-2026-64402", "lang": "en", "title": "CVE-2026-64402", "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\ncoresight: ultrasoc-smb: Fix OOB write in smb_sync_perf_buffer()\n\nWhen the SMB sink is used as a perf AUX sink, smb_update_buffer() calls\nsmb_sync_perf_buffer() to copy hardware trace data into the perf AUX ring\nbuffer pages. It derives pg_idx = head >> PAGE_SHIFT from @head, which is\nhandle->head, and indexes dst_pages[pg_idx]. The pg_idx %= nr_pages\nnormalization is only applied after the first loop iteration.\n\nThis leaves the initial page index underived from the buffer size, which\ncan result in an out-of-bounds write past dst_pages[] when head exceeds\nthe AUX buffer size.\n\nNormalize head modulo the AUX buffer size before deriving the page index\nand offset, mirroring tmc_etr_sync_perf_buffer().", "product": "Linux", "category": "cve", "source": "NVD", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-64402", "card": "CVE-2026-64402.webp?v=1784988527", "takeaways": [], "ts": 1784974643, "exploited": 0, "has_score": 0, "created": 1784988405, "updated": 1784988405, "exploited_text": 0, "poc": 0, "score": 0.0, "kev": 0, "flags": []}, {"key": "CVE-2026-64401", "cve": "CVE-2026-64401", "lang": "en", "title": "CVE-2026-64401", "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\nsmb: client: resolve SWN tcon from live registrations\n\ncifs_swn_notify() looks up a witness registration by id under\ncifs_swnreg_idr_mutex, drops the mutex, and then uses the registration's\ncached tcon pointer.  That pointer is not a lifetime reference, and it is\nnot a stable representative once cifs_get_swn_reg() lets multiple tcons\nfor the same net/share name share one registration id.\n\nA same-share second mount can keep the cifs_swn_reg alive after the first\ntcon unregisters and is freed.  The registration then still points at the\nfreed first tcon, so taking tc_lock or incrementing tc_count through\nswnreg->tcon only moves the use-after-free earlier.  Taking tc_lock while\nholding cifs_swnreg_idr_mutex also violates the documented CIFS lock\norder.\n\nFix this by making the registration store only the stable witness\nidentity: id, net name, share name, and notify flags.  When a notify\narrives, copy that identity under cifs_swnreg_idr_mutex, drop the mutex,\nthen find and pin a live witness tcon that currently matches the net/share\npair under the normal cifs_tcp_ses_lock -> tc_lock order.  The notification\npath uses th", "product": "Linux", "category": "cve", "source": "NVD", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-64401", "card": "CVE-2026-64401.webp?v=1784988527", "takeaways": [], "ts": 1784974643, "exploited": 0, "has_score": 0, "created": 1784988405, "updated": 1784988405, "exploited_text": 0, "poc": 0, "score": 0.0, "kev": 0, "flags": []}, {"key": "CVE-2026-64400", "cve": "CVE-2026-64400", "lang": "en", "title": "CVE-2026-64400", "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\nksmbd: prevent path traversal bypass by restricting caseless retry\n\nksmbd_vfs_path_lookup() enforces LOOKUP_BENEATH to restrict path\nresolution within the share root. When a crafted path attempts to\nescape the share boundary using parent-directory components ('..'),\nvfs_path_parent_lookup() detects this and immediately fails,\nreturning -EXDEV.\n\nHowever, a bug exists in __ksmbd_vfs_kern_path() under caseless mode.\nThe function fails to intercept the -EXDEV error and erroneously\nfalls through to the caseless retry logic, which is intended only\nfor genuinely missing files. During this retry process, the path\nis reconstructed, leading to an unintended LOOKUP_BENEATH bypass\nthat allows write-capable users to create zero-length files or\ndirectories outside the exported share.\n\nFix this by ensuring that the execution only proceeds to the caseless\nlookup retry when the error is specifically -ENOENT. Any other errors,\nsuch as -EXDEV from a path traversal attempt, must be returned immediately.", "product": "Linux", "category": "cve", "source": "NVD", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-64400", "card": "CVE-2026-64400.webp?v=1784988527", "takeaways": [], "ts": 1784974643, "exploited": 0, "has_score": 0, "created": 1784988405, "updated": 1784988405, "exploited_text": 0, "poc": 0, "score": 0.0, "kev": 0, "flags": []}, {"key": "CVE-2026-64399", "cve": "CVE-2026-64399", "lang": "en", "title": "CVE-2026-64399", "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\nksmbd: add permission checks for FSCTL_DUPLICATE_EXTENTS_TO_FILE\n\nThe FSCTL_DUPLICATE_EXTENTS_TO_FILE arm of smb2_ioctl() overwrites the\ndestination file's data via vfs_clone_file_range() with neither the\nshare-level KSMBD_TREE_CONN_FLAG_WRITABLE check nor a per-handle\nfp->daccess check that the other write-bearing arms carry. A client can\noverwrite destination data on a read-only share, or from a handle opened\nwith only FILE_WRITE_ATTRIBUTES (which still yields an FMODE_WRITE filp).\nFILE_WRITE_ATTRIBUTES-only destination handle overwrote the file's data via\nthe clone. Add both checks, matching the FSCTL_SET_SPARSE permission fix;\nrequire FILE_WRITE_DATA since this writes data.", "product": "Linux", "category": "cve", "source": "NVD", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-64399", "card": "CVE-2026-64399.webp?v=1784988527", "takeaways": [], "ts": 1784974643, "exploited": 0, "has_score": 0, "created": 1784988405, "updated": 1784988405, "exploited_text": 0, "poc": 0, "score": 0.0, "kev": 0, "flags": []}, {"key": "CVE-2026-64398", "cve": "CVE-2026-64398", "lang": "en", "title": "CVE-2026-64398", "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\nksmbd: add a permission check for FSCTL_SET_ZERO_DATA\n\nFSCTL_SET_ZERO_DATA in smb2_ioctl() destroys file data via\nksmbd_vfs_zero_data() -> vfs_fallocate(PUNCH_HOLE/ZERO_RANGE) after\nchecking only the share-level KSMBD_TREE_CONN_FLAG_WRITABLE, with no\nper-handle access check. A handle opened with only FILE_WRITE_ATTRIBUTES\nstill yields an FMODE_WRITE filp (FILE_WRITE_ATTRIBUTES is part of\nFILE_WRITE_DESIRE_ACCESS_LE, so smb2_create_open_flags() opens it\nO_WRONLY), so the vfs_fallocate FMODE_WRITE check does not stop it; only\nthe missing fp->daccess gate would. Reproduced on mainline 7.1-rc7 with\nKASAN by an authenticated SMB client: a FILE_WRITE_ATTRIBUTES-only handle\nzeroed 4096 bytes of file data it had no FILE_WRITE_DATA right to\n(6/6; a FILE_READ_DATA-only handle was correctly denied).\n\nThis is the unfixed sibling of commit cc57232cae23 (\"ksmbd: fix FSCTL\npermission bypass by adding a permission check for FSCTL_SET_SPARSE\").\nBecause SET_ZERO_DATA writes data (not an attribute), require\nFILE_WRITE_DATA.", "product": "Linux", "category": "cve", "source": "NVD", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-64398", "card": "CVE-2026-64398.webp?v=1784988526", "takeaways": [], "ts": 1784974643, "exploited": 0, "has_score": 0, "created": 1784988405, "updated": 1784988405, "exploited_text": 0, "poc": 0, "score": 0.0, "kev": 0, "flags": []}, {"key": "CVE-2026-64397", "cve": "CVE-2026-64397", "lang": "en", "title": "CVE-2026-64397", "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\nksmbd: serialize QUERY_DIRECTORY requests per file\n\nsmb2_query_dir() stores a pointer to its stack-allocated private data in\nthe ksmbd_file readdir_data. Concurrent QUERY_DIRECTORY requests using the\nsame file handle can overwrite this pointer while an iterate_dir() callback\nis still using it, resulting in a stack use-after-free.\n\nAdd a per-file mutex and hold it while accessing the shared directory\nenumeration state. The lock covers scan restart, dot entry state,\nreaddir_data setup and iteration, and response construction. This prevents\nanother request from replacing readdir_data.private before the current\nrequest has finished using it and also serializes the shared file position.", "product": "Linux", "category": "cve", "source": "NVD", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-64397", "card": "CVE-2026-64397.webp?v=1784988526", "takeaways": [], "ts": 1784974643, "exploited": 0, "has_score": 0, "created": 1784988405, "updated": 1784988405, "exploited_text": 0, "poc": 0, "score": 0.0, "kev": 0, "flags": []}, {"key": "CVE-2026-64396", "cve": "CVE-2026-64396", "lang": "en", "title": "CVE-2026-64396", "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\nksmbd: fix UAF of struct file_lock in SMB2_LOCK deferred-lock cancellation\n\nWhen a blocking byte-range lock request is deferred in the\nFILE_LOCK_DEFERRED path, ksmbd registers the asynchronous work into\nthe connection's async_requests list via setup_async_work(). The cancel\ncallback smb2_remove_blocked_lock() holds a reference to the flock.\n\nIf the lock waiter is subsequently woken up but the work state is no\nlonger KSMBD_WORK_ACTIVE (e.g., due to a concurrent cancellation), the\ncleanup path calls locks_free_lock(flock) without dequeuing the work from\nthe async_requests list. Concurrently, smb2_cancel() walks the list\nunder conn->request_lock and invokes the cancel callback, which then\ndereferences the already freed 'flock'. This leads to a slab-use-after-free\ninside __wake_up_common.\n\nFix this by restructuring the cleanup logic after the worker returns\nfrom ksmbd_vfs_posix_lock_wait(). Move list_del(&smb_lock->llist) and\nrelease_async_work(work) to the top of the cleanup block. This guarantees\nthat the async work is completely dequeued and serialized under\nconn->request_lock before locks_free_lock(flock) is calle", "product": "Linux", "category": "cve", "source": "NVD", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-64396", "card": "CVE-2026-64396.webp?v=1784988526", "takeaways": [], "ts": 1784974643, "exploited": 0, "has_score": 0, "created": 1784988405, "updated": 1784988405, "exploited_text": 0, "poc": 0, "score": 0.0, "kev": 0, "flags": []}, {"key": "CVE-2026-64395", "cve": "CVE-2026-64395", "lang": "en", "title": "CVE-2026-64395", "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\nksmbd: require source read access for duplicate extents\n\nFSCTL_DUPLICATE_EXTENTS_TO_FILE passes the source file directly to\nvfs_clone_file_range() or vfs_copy_file_range() without checking the SMB\naccess mask granted to the source handle. A handle opened with attribute\naccess can consequently be used to copy file contents into an\nattacker-readable destination.\n\nRequire FILE_READ_DATA on the source handle before either VFS operation,\nmatching other ksmbd data-copy paths.", "product": "Linux", "category": "cve", "source": "NVD", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-64395", "card": "CVE-2026-64395.webp?v=1784988529", "takeaways": [], "ts": 1784974642, "exploited": 0, "has_score": 0, "created": 1784988405, "updated": 1784988405, "exploited_text": 0, "poc": 0, "score": 0.0, "kev": 0, "flags": []}, {"key": "CVE-2026-64394", "cve": "CVE-2026-64394", "lang": "en", "title": "CVE-2026-64394", "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\nksmbd: add a WRITE_DAC/WRITE_OWNER check to SMB2 SET_INFO SECURITY\n\ncommit cc57232cae23 (\"ksmbd: fix FSCTL permission bypass by adding a\npermission check for FSCTL_SET_SPARSE\") added a fp->daccess gate to\nfsctl_set_sparse and noted that \"similar handle-level checks exist in other\nfunctions but are missing here.\" The SMB2 SET_INFO SECURITY arm is one of\nthe missing ones, and the most security-relevant: smb2_set_info_sec() calls\nset_info_sec() with no per-handle access check.\n\nset_info_sec() (fs/smb/server/smbacl.c) re-permissions the file: it\nrewrites owner/group/mode via notify_change(), rewrites the POSIX ACL via\nset_posix_acl(), and on KSMBD_SHARE_FLAG_ACL_XATTR shares removes and\nrewrites the Windows security descriptor via ksmbd_vfs_set_sd_xattr().\nEvery other persistent-mutation arm of the sibling handler\nsmb2_set_info_file() checks fp->daccess first (FILE_WRITE_DATA /\nFILE_DELETE / FILE_WRITE_EA / FILE_WRITE_ATTRIBUTES); the SECURITY arm —\nwhich mutates the access control itself — is the only one with no gate.\n\nA client can therefore open a handle with FILE_WRITE_ATTRIBUTES only (no\nFILE_WRITE_DAC / FILE_WRI", "product": "Linux", "category": "cve", "source": "NVD", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-64394", "card": "CVE-2026-64394.webp?v=1784988529", "takeaways": [], "ts": 1784974642, "exploited": 0, "has_score": 0, "created": 1784988405, "updated": 1784988405, "exploited_text": 0, "poc": 0, "score": 0.0, "kev": 0, "flags": []}, {"key": "CVE-2026-64393", "cve": "CVE-2026-64393", "lang": "en", "title": "CVE-2026-64393", "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\nksmbd: run set info with opener credentials\n\nSMB2 SET_INFO handlers call path-based VFS helpers after checking the\naccess mask granted to the SMB handle. Those helpers perform their owner,\ninode permission and LSM checks using the current ksmbd worker credentials.\n\nRun the complete SET_INFO dispatch with the credentials captured when the\nhandle was opened. This also removes the separate security information\ncredential setup and keeps all SET_INFO classes under one credential scope.\n\nDirect override_creds() is used because it can nest with the request\ncredential overrides already used by rename and link helpers.", "product": "Linux", "category": "cve", "source": "NVD", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-64393", "card": "CVE-2026-64393.webp?v=1784988529", "takeaways": [], "ts": 1784974642, "exploited": 0, "has_score": 0, "created": 1784988405, "updated": 1784988405, "exploited_text": 0, "poc": 0, "score": 0.0, "kev": 0, "flags": []}, {"key": "CVE-2026-64392", "cve": "CVE-2026-64392", "lang": "en", "title": "CVE-2026-64392", "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\nksmbd: use opener credentials for delete-on-close\n\nDelete-on-close can be completed by deferred or durable handle teardown,\nwhere no request work is available. Both the base-file unlink and the ADS\nxattr removal consequently run with the ksmbd worker credentials and can\nbypass filesystem permission checks.\n\nRun both operations with the credentials captured in struct file when the\nhandle was opened. This preserves the authenticated user's fsuid, fsgid,\nsupplementary groups and capability restrictions at final close.", "product": "Linux", "category": "cve", "source": "NVD", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-64392", "card": "CVE-2026-64392.webp?v=1784988529", "takeaways": [], "ts": 1784974642, "exploited": 0, "has_score": 0, "created": 1784988405, "updated": 1784988405, "exploited_text": 0, "poc": 0, "score": 0.0, "kev": 0, "flags": []}, {"key": "CVE-2026-64391", "cve": "CVE-2026-64391", "lang": "en", "title": "CVE-2026-64391", "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\nksmbd: use opener credentials for ADS I/O\n\nAlternate data streams are stored as xattrs. Unlike regular file I/O,\ntheir read and write paths therefore call VFS xattr helpers which recheck\ninode permissions and LSM policy using the current task credentials.\n\nRun ADS I/O with the credentials captured when the SMB handle was opened.", "product": "Linux", "category": "cve", "source": "NVD", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-64391", "card": "CVE-2026-64391.webp?v=1784988528", "takeaways": [], "ts": 1784974642, "exploited": 0, "has_score": 0, "created": 1784988405, "updated": 1784988405, "exploited_text": 0, "poc": 0, "score": 0.0, "kev": 0, "flags": []}, {"key": "CVE-2026-64390", "cve": "CVE-2026-64390", "lang": "en", "title": "CVE-2026-64390", "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\nksmbd: track the connection owning a byte-range lock\n\nSMB2_LOCK adds each granted byte-range lock to both the file lock list\nand the lock list of the connection which handled the request.  The\nfinal close and durable handle paths, however, remove the connection\nlist entry while holding fp->conn->llist_lock.\n\nWith SMB3 multichannel, the connection handling the LOCK request can be\ndifferent from the connection which opened the file.  The entry can\ntherefore be removed under a different spinlock from the one protecting\nthe list it belongs to.  A concurrent traversal can then access freed\nstruct ksmbd_lock and struct file_lock objects.\n\nRecord the connection owning each lock's clist entry and hold a\nreference to it while the entry is linked.  Use that connection and its\nllist_lock for unlock, rollback, close, and durable preserve.  Durable\nreconnect assigns the new connection as the owner when publishing the\nlocks again.", "product": "Linux", "category": "cve", "source": "NVD", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-64390", "card": "CVE-2026-64390.webp?v=1784988528", "takeaways": [], "ts": 1784974642, "exploited": 0, "has_score": 0, "created": 1784988405, "updated": 1784988405, "exploited_text": 0, "poc": 0, "score": 0.0, "kev": 0, "flags": []}, {"key": "CVE-2026-64389", "cve": "CVE-2026-64389", "lang": "en", "title": "CVE-2026-64389", "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\nksmbd: validate NTLMv2 response before updating session key\n\nksmbd_auth_ntlmv2() derives the NTLMv2 session key into\nsess->sess_key before it verifies the NTLMv2 response.\nksmbd_decode_ntlmssp_auth_blob() then continues into KEY_XCH even\nwhen ksmbd_auth_ntlmv2() failed.\n\nWith SMB3 multichannel binding, the failed authentication operates on\nan existing session and the session setup error path does not expire\nbinding sessions. A client can send a binding session setup with a\nbad NT proof and KEY_XCH and still modify sess->sess_key before\nSTATUS_LOGON_FAILURE is returned.\n\nRelevant path:\n\n  smb2_sess_setup()\n    -> conn->binding = true\n    -> ntlm_authenticate()\n       -> session_user()\n       -> ksmbd_decode_ntlmssp_auth_blob()\n          -> ksmbd_auth_ntlmv2()\n             -> calc_ntlmv2_hash()\n             -> hmac_md5_usingrawkey(..., sess->sess_key)\n             -> crypto_memneq() returns mismatch\n          -> KEY_XCH arc4_crypt(..., sess->sess_key, ...)\n    -> out_err without expiring the binding session\n\nDerive the base session key into a local buffer and copy it to\nsess->sess_key only after the proof matches. R", "product": "Linux", "category": "cve", "source": "NVD", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-64389", "card": "CVE-2026-64389.webp?v=1784988528", "takeaways": [], "ts": 1784974642, "exploited": 0, "has_score": 0, "created": 1784988405, "updated": 1784988405, "exploited_text": 0, "poc": 0, "score": 0.0, "kev": 0, "flags": []}, {"key": "CVE-2026-64388", "cve": "CVE-2026-64388", "lang": "en", "title": "CVE-2026-64388", "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\nsmb/client: fix chown/chgrp with SMB3 POSIX Extensions\n\nOwnership (chown) and group (chgrp) modifications were being ignored when\nmounting with SMB3 POSIX Extensions unless CIFS_MOUNT_CIFS_ACL or\nCIFS_MOUNT_MODE_FROM_SID were also explicitly set.\n\nFix this by checking for posix_extensions in cifs_setattr_nounix() when\nupdating UID and GID, ensuring that id_mode_to_cifs_acl() is called to map\nand set the ownership/group information on the server.", "product": "Linux", "category": "cve", "source": "NVD", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-64388", "card": "CVE-2026-64388.webp?v=1784988528", "takeaways": [], "ts": 1784974642, "exploited": 0, "has_score": 0, "created": 1784988405, "updated": 1784988405, "exploited_text": 0, "poc": 0, "score": 0.0, "kev": 0, "flags": []}, {"key": "CVE-2026-64387", "cve": "CVE-2026-64387", "lang": "en", "title": "CVE-2026-64387", "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\nsmb: client: fix query directory replay double-free\n\nA response-bearing attempt can return a replayable error and free its\nresponse buffer. If SMB2_query_directory_init() fails before the next send,\ncleanup retains the previous buffer type and frees that response again.\n\nReset response bookkeeping before each attempt to prevent the stale free.", "product": "Linux", "category": "cve", "source": "NVD", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-64387", "card": "CVE-2026-64387.webp?v=1784988528", "takeaways": [], "ts": 1784974642, "exploited": 0, "has_score": 0, "created": 1784988405, "updated": 1784988405, "exploited_text": 0, "poc": 0, "score": 0.0, "kev": 0, "flags": []}, {"key": "CVE-2026-64386", "cve": "CVE-2026-64386", "lang": "en", "title": "CVE-2026-64386", "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\nsmb: client: fix query_info() replay double-free\n\nA response-bearing attempt can return a replayable error and free its\nresponse buffer. If SMB2_query_info_init() fails before the next send,\ncleanup retains the previous buffer type and frees that response again.\n\nReset response bookkeeping before each attempt to prevent the stale free.", "product": "Linux", "category": "cve", "source": "NVD", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-64386", "card": "CVE-2026-64386.webp?v=1784990892", "takeaways": [], "ts": 1784974641, "exploited": 0, "has_score": 0, "created": 1784990793, "updated": 1784990793, "exploited_text": 0, "poc": 0, "score": 0.0, "kev": 0, "flags": []}, {"key": "CVE-2026-64385", "cve": "CVE-2026-64385", "lang": "en", "title": "CVE-2026-64385", "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\nsmb: client: fix double-free in SMB2_ioctl() replay\n\nA response-bearing attempt can return a replayable error and free its\nresponse buffer. If SMB2_ioctl_init() fails before the next send, cleanup\nretains the previous buffer type and frees that response again.\n\nReset response bookkeeping before each attempt to prevent the stale free.", "product": "Linux", "category": "cve", "source": "NVD", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-64385", "card": "CVE-2026-64385.webp?v=1784990892", "takeaways": [], "ts": 1784974641, "exploited": 0, "has_score": 0, "created": 1784990793, "updated": 1784990793, "exploited_text": 0, "poc": 0, "score": 0.0, "kev": 0, "flags": []}, {"key": "CVE-2026-64384", "cve": "CVE-2026-64384", "lang": "en", "title": "CVE-2026-64384", "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\nsmb: client: fix change notify replay double-free\n\nA response-bearing attempt can return a replayable error and free its\nresponse buffer. If SMB2_notify_init() fails before the next send, cleanup\nretains the previous buffer type and frees that response again.\n\nReset response bookkeeping before each attempt to prevent the stale free.", "product": "Linux", "category": "cve", "source": "NVD", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-64384", "card": "CVE-2026-64384.webp?v=1784990892", "takeaways": [], "ts": 1784974641, "exploited": 0, "has_score": 0, "created": 1784990793, "updated": 1784990793, "exploited_text": 0, "poc": 0, "score": 0.0, "kev": 0, "flags": []}, {"key": "CVE-2026-64383", "cve": "CVE-2026-64383", "lang": "en", "title": "CVE-2026-64383", "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\nsmb: client: fix double-free in SMB2_flush() replay\n\nSMB2_flush() keeps its response buffer bookkeeping across replay\nattempts. If a replayable flush response is received and the retry then\nfails before cifs_send_recv() stores a replacement response, flush_exit\nwill free the stale response pointer a second time.\n\nReinitialize resp_buftype and rsp_iov at the top of the replay loop so\ncleanup only acts on response state produced by the current attempt.\nThis fixes a double-free without changing replay handling for successful\nrequests.", "product": "Linux", "category": "cve", "source": "NVD", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-64383", "card": "CVE-2026-64383.webp?v=1784988530", "takeaways": [], "ts": 1784974641, "exploited": 0, "has_score": 0, "created": 1784988405, "updated": 1784988405, "exploited_text": 0, "poc": 0, "score": 0.0, "kev": 0, "flags": []}, {"key": "CVE-2026-64382", "cve": "CVE-2026-64382", "lang": "en", "title": "CVE-2026-64382", "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\nsmb: client: fix double-free in SMB2_open() replay\n\nA response-bearing attempt can return a replayable error and free its\nresponse buffer. If SMB2_open_init() fails before the next send, cleanup\nretains the previous buffer type and frees that response again.\n\nReset response bookkeeping before each attempt to prevent the stale free.", "product": "Linux", "category": "cve", "source": "NVD", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-64382", "card": "CVE-2026-64382.webp?v=1784988530", "takeaways": [], "ts": 1784974641, "exploited": 0, "has_score": 0, "created": 1784988405, "updated": 1784988405, "exploited_text": 0, "poc": 0, "score": 0.0, "kev": 0, "flags": []}, {"key": "CVE-2026-64381", "cve": "CVE-2026-64381", "lang": "en", "title": "CVE-2026-64381", "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\nsmb: client: Fix next buffer leak in receive_encrypted_standard()\n\nreceive_encrypted_standard() allocates next_buffer before checking\nwhether the number of compound PDUs already reached MAX_COMPOUND. If\nthe limit check fails, the function returns immediately and the newly\nallocated next_buffer is not assigned to server->smallbuf/server->bigbuf,\nmaking it leaked.\n\nMove the MAX_COMPOUND check before allocating next_buffer.", "product": "Linux", "category": "cve", "source": "NVD", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-64381", "card": "CVE-2026-64381.webp?v=1784988530", "takeaways": [], "ts": 1784974641, "exploited": 0, "has_score": 0, "created": 1784988405, "updated": 1784988405, "exploited_text": 0, "poc": 0, "score": 0.0, "kev": 0, "flags": []}, {"key": "CVE-2026-64380", "cve": "CVE-2026-64380", "lang": "en", "title": "CVE-2026-64380", "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\nsmb: client: harden POSIX SID length parsing\n\nposix_info_sid_size() reads sid[1] to obtain the subauthority count,\nbut its existing boundary check still accepts buffers with only one\nremaining byte. Require two bytes before reading sid[1] so all client\npaths that reuse the helper reject truncated POSIX SIDs safely.", "product": "Linux", "category": "cve", "source": "NVD", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-64380", "card": "CVE-2026-64380.webp?v=1784988530", "takeaways": [], "ts": 1784974641, "exploited": 0, "has_score": 0, "created": 1784988405, "updated": 1784988405, "exploited_text": 0, "poc": 0, "score": 0.0, "kev": 0, "flags": []}, {"key": "CVE-2026-64379", "cve": "CVE-2026-64379", "lang": "en", "title": "CVE-2026-64379", "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\nsmb: client: mask server-provided mode to 07777 in modefromsid\n\nWhen modefromsid is active, parse_dacl() applies the server-provided\nsub_auth[2] value from the NFS mode SID to cf_mode without masking to\n07777. Apply the correct masking, same as in the read path.", "product": "Linux", "category": "cve", "source": "NVD", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-64379", "card": "CVE-2026-64379.webp?v=1784988529", "takeaways": [], "ts": 1784974641, "exploited": 0, "has_score": 0, "created": 1784988405, "updated": 1784988405, "exploited_text": 0, "poc": 0, "score": 0.0, "kev": 0, "flags": []}, {"key": "CVE-2026-64378", "cve": "CVE-2026-64378", "lang": "en", "title": "CVE-2026-64378", "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\nwriteback: fix race between cgroup_writeback_umount() and inode_switch_wbs()\n\nWhen a container exits, the following BUG_ON() is occasionally triggered:\n\n==================================================================\n VFS: Busy inodes after unmount of sdb (ext4)\n ------------[ cut here ]------------\n kernel BUG at fs/super.c:695!\n CPU: 3 PID: 6 Comm: containerd-shim Tainted: G OE K 6.6 #1\n pstate: 63400009 (nZCv daif +PAN -UAO +TCO +DIT -SSBS BTYPE=--)\n pc : generic_shutdown_super+0xf0/0x100\n lr : generic_shutdown_super+0xf0/0x100\n Call trace:\n  generic_shutdown_super+0xf0/0x100\n  kill_block_super+0x20/0x48\n  ext4_kill_sb+0x28/0x60\n  deactivate_locked_super+0x54/0x130\n  deactivate_super+0x84/0xa0\n  cleanup_mnt+0xa4/0x140\n  __cleanup_mnt+0x18/0x28\n  task_work_run+0x78/0xe0\n  do_notify_resume+0x204/0x240\n==================================================================\n\nThe root cause is a race between cgroup_writeback_umount() and\ninode_switch_wbs()/cleanup_offline_cgwb(). There is a window between\ninode_prepare_wbs_switch() returning true and the subsequent\nwb_queue_isw() call. Following is the process that tr", "product": "Linux", "category": "cve", "source": "NVD", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-64378", "card": "CVE-2026-64378.webp?v=1784990894", "takeaways": [], "ts": 1784974640, "exploited": 0, "has_score": 0, "created": 1784990793, "updated": 1784990793, "exploited_text": 0, "poc": 0, "score": 0.0, "kev": 0, "flags": []}, {"key": "CVE-2026-64377", "cve": "CVE-2026-64377", "lang": "en", "title": "CVE-2026-64377", "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\ncpufreq: qcom-cpufreq-hw: Fix possible double free\n\nqcom_cpufreq.data is allocated with devm_kzalloc() in probe() as an\narray of per-domain data. qcom_cpufreq_hw_cpu_init() stores a pointer to\none element of this array in policy->driver_data.\n\nqcom_cpufreq_hw_cpu_exit() currently calls kfree() on policy->driver_data.\nThis is not valid because the memory is devm-managed. For the first\ndomain, this can free the devm-managed allocation while the devres entry\nis still active, leading to a possible double free when the platform\ndevice is later detached. For other domains, the pointer may refer to an\nelement inside the array rather than the allocation base.\n\nRemove the kfree(data) call and let devres release qcom_cpufreq.data.\n\nThis issue was found by a static analysis tool I am developing.", "product": "Linux", "category": "cve", "source": "NVD", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-64377", "card": "CVE-2026-64377.webp?v=1784990894", "takeaways": [], "ts": 1784974640, "exploited": 0, "has_score": 0, "created": 1784990793, "updated": 1784990793, "exploited_text": 0, "poc": 0, "score": 0.0, "kev": 0, "flags": []}, {"key": "CVE-2026-64376", "cve": "CVE-2026-64376", "lang": "en", "title": "CVE-2026-64376", "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\nfirmware_loader: fix device reference leak in firmware_upload_register()\n\nfirmware_upload_register()\n  -> fw_create_instance()\n     -> device_initialize()\n\nAfter fw_create_instance() succeeds, the lifetime of the embedded struct\ndevice is expected to be managed through the device core reference\ncounting, since fw_create_instance() has already called\ndevice_initialize().\n\nIn firmware_upload_register(), if alloc_lookup_fw_priv() fails after\nfw_create_instance() succeeds, the code reaches free_fw_sysfs and frees\nfw_sysfs directly instead of releasing the device reference with\nput_device(). This may leave the reference count of the embedded struct\ndevice unbalanced, resulting in a refcount leak.\n\nThe issue was identified by a static analysis tool I developed and\nconfirmed by manual review. Fix this by using put_device(fw_dev) in the\nfailure path and letting fw_dev_release() handle the final cleanup,\ninstead of freeing the instance directly from the error path.", "product": "Linux", "category": "cve", "source": "NVD", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-64376", "card": "CVE-2026-64376.webp?v=1784990894", "takeaways": [], "ts": 1784974640, "exploited": 0, "has_score": 0, "created": 1784990793, "updated": 1784990793, "exploited_text": 0, "poc": 0, "score": 0.0, "kev": 0, "flags": []}, {"key": "CVE-2026-64375", "cve": "CVE-2026-64375", "lang": "en", "title": "CVE-2026-64375", "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\nproc: protect ptrace_may_access() with exec_update_lock (FD links)\n\nproc_pid_get_link() and proc_pid_readlink() currently look up the task from\nthe pid once, then do the ptrace access check on that task, then look up\nthe task from the pid a second time to do the actual access.\nThat's racy in several ways.\n\nTo fix it, pass the task to the ->proc_get_link() handler, and instead of\nproc_fd_access_allowed(), introduce a new helper call_proc_get_link() that\nlooks up and locks the task, does the access check, and calls\n->proc_get_link().", "product": "Linux", "category": "cve", "source": "NVD", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-64375", "card": "CVE-2026-64375.webp?v=1784990893", "takeaways": [], "ts": 1784974640, "exploited": 0, "has_score": 0, "created": 1784990793, "updated": 1784990793, "exploited_text": 0, "poc": 0, "score": 0.0, "kev": 0, "flags": []}, {"key": "CVE-2026-64374", "cve": "CVE-2026-64374", "lang": "en", "title": "CVE-2026-64374", "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\nsched/rt: Have RT_PUSH_IPI be default off for non PREEMPT_RT\n\nRT migration is done aggressively. When a CPU schedules out a high\npriority RT task for a lower priority task, it will look to see if there's\nany RT tasks that are waiting to run on another CPU that is of higher\npriority than the task this CPU is about to run. If it finds one, it will\npull that task over to the CPU and allow it to run there instead.\n\nNormally, this pulling is done by looking at the RT overloaded mask (rto)\nwhich contains all the CPUs in the scheduler domain with RT tasks that are\nwaiting to run due to a higher priority RT task currently running on their\nCPU. The CPU that is about to schedule a lower priority task will grab the\nrq lock of the overloaded CPU and move the RT task from that CPU's runqueue\nto the local one and schedule the higher priority RT task.\n\nThis caused issues when a lot of CPUs would schedule a lower priority task\nat the same time. They would all try to grab the same runqueue lock of\nthe CPU with the overloaded RT tasks. Only the first CPU that got in will\nget that task. All the others would wait until they got the r", "product": "Linux", "category": "cve", "source": "NVD", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-64374", "card": "CVE-2026-64374.webp?v=1784990893", "takeaways": [], "ts": 1784974640, "exploited": 0, "has_score": 0, "created": 1784990793, "updated": 1784990793, "exploited_text": 0, "poc": 0, "score": 0.0, "kev": 0, "flags": []}, {"key": "CVE-2026-64373", "cve": "CVE-2026-64373", "lang": "en", "title": "CVE-2026-64373", "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\ncpufreq: Fix hotplug-suspend race during reboot\n\nDuring system reboot, cpufreq_suspend() is called via the\nkernel_restart() -> device_shutdown() path. Unlike the normal system\nsuspend path, the reboot path does not call freeze_processes(), so\nuserspace processes and kernel threads remain active.\n\nThis allows CPU hotplug operations to run concurrently with\ncpufreq_suspend(). The original code has no synchronization with CPU\nhotplug, leading to a race condition where governor_data can be freed\nby the hotplug path while cpufreq_suspend() is still accessing it,\nresulting in a null pointer dereference:\n\n  Unable to handle kernel NULL pointer dereference\n  Call Trace:\n   do_kernel_fault+0x28/0x3c\n   cpufreq_suspend+0xdc/0x160\n   device_shutdown+0x18/0x200\n   kernel_restart+0x40/0x80\n   arm64_sys_reboot+0x1b0/0x200\n\nFix this by adding cpus_read_lock()/cpus_read_unlock() to\ncpufreq_suspend() to block CPU hotplug operations while suspend is in\nprogress.\n\n[ rjw: Changelog edits ]", "product": "Linux", "category": "cve", "source": "NVD", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-64373", "card": "CVE-2026-64373.webp?v=1784990893", "takeaways": [], "ts": 1784974640, "exploited": 0, "has_score": 0, "created": 1784990793, "updated": 1784990793, "exploited_text": 0, "poc": 0, "score": 0.0, "kev": 0, "flags": []}, {"key": "CVE-2026-64372", "cve": "CVE-2026-64372", "lang": "en", "title": "CVE-2026-64372", "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\ncpufreq: pcc: fix use-after-free and double free in _OSC evaluation\n\npcc_cpufreq_do_osc() calls acpi_evaluate_object() twice for the\ntwo-phase _OSC negotiation. Between the two calls it freed\noutput.pointer but left output.length unchanged. Since\nacpi_evaluate_object() treats a non-zero length with a non-NULL\npointer as an existing buffer to write into, the second call wrote\ninto freed memory (use-after-free). The subsequent kfree(output.pointer)\nat out_free then freed the same pointer a second time (double free).\n\nReset output.pointer to NULL and output.length to ACPI_ALLOCATE_BUFFER\nafter freeing the first result, so ACPICA allocates a fresh buffer for\neach phase independently.", "product": "Linux", "category": "cve", "source": "NVD", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-64372", "card": "CVE-2026-64372.webp?v=1784990893", "takeaways": [], "ts": 1784974640, "exploited": 0, "has_score": 0, "created": 1784990793, "updated": 1784990793, "exploited_text": 0, "poc": 0, "score": 0.0, "kev": 0, "flags": []}, {"key": "CVE-2026-64371", "cve": "CVE-2026-64371", "lang": "en", "title": "CVE-2026-64371", "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\nproc: protect ptrace_may_access() with exec_update_lock (part 1)\n\nFix the easy cases where procfs currently calls ptrace_may_access() without\nexec_update_lock protection, where the fix is to simply add the extra lock\nor use mm_access():\n\n - do_task_stat(): grab exec_update_lock\n - proc_pid_wchan(): grab exec_update_lock\n - proc_map_files_lookup(): use mm_access() instead of get_task_mm()\n - proc_map_files_readdir(): use mm_access() instead of get_task_mm()\n - proc_ns_get_link(): grab exec_update_lock\n - proc_ns_readlink(): grab exec_update_lock", "product": "Linux", "category": "cve", "source": "NVD", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-64371", "card": "CVE-2026-64371.webp?v=1784990893", "takeaways": [], "ts": 1784974640, "exploited": 0, "has_score": 0, "created": 1784990793, "updated": 1784990793, "exploited_text": 0, "poc": 0, "score": 0.0, "kev": 0, "flags": []}, {"key": "CVE-2026-64370", "cve": "CVE-2026-64370", "lang": "en", "title": "CVE-2026-64370", "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\nposix-cpu-timers: Fix pid refcount leak in do_cpu_nanosleep() error path\n\nIn do_cpu_nanosleep(), posix_cpu_timer_create() takes a pid reference\nvia get_pid() and stores it in timer.it.cpu.pid. If the subsequent\nposix_cpu_timer_set() call fails, the function returns immediately\nwithout calling posix_cpu_timer_del() to release the pid reference,\ncausing a leak.\n\nFix it by calling posix_cpu_timer_del() before the unlock-and-return\non the error path, consistent with the other exit paths in the same\nfunction.", "product": "Linux", "category": "cve", "source": "NVD", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-64370", "card": "CVE-2026-64370.webp?v=1784990896", "takeaways": [], "ts": 1784974639, "exploited": 0, "has_score": 0, "created": 1784990793, "updated": 1784990793, "exploited_text": 0, "poc": 0, "score": 0.0, "kev": 0, "flags": []}, {"key": "CVE-2026-64369", "cve": "CVE-2026-64369", "lang": "en", "title": "CVE-2026-64369", "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\ns390: Revert support for DCACHE_WORD_ACCESS\n\nload_unaligned_zeropad() reads eight bytes from unaligned addresses and may\ncross page boundaries. It handles exceptions which may happen if reading\nfrom the second page results in an exception.\n\nFor pages which are donated to the Ultravisor for secure execution purposes\nthe do_secure_storage_access() exception handler however does not handle\nsuch exceptions correctly. Such an exception may result in an endless\nexception loop which will never be resolved.\n\nAn attempt to fix this [1] turned out to be not sufficient. For now revert\nload_unaligned_zeropad() until this problem has been resolved in a proper\nway.\n\nNote that the implementation of load_unaligned_zeropad() itself is\ncorrect. The revert is just a temporary workaround until there is complete\nfix for secure storage access exceptions.\n\n[1] commit b00be77302d7 (\"s390/mm: Add missing secure storage access fixups for donated memory\")", "product": "Linux", "category": "cve", "source": "NVD", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-64369", "card": "CVE-2026-64369.webp?v=1784990895", "takeaways": [], "ts": 1784974639, "exploited": 0, "has_score": 0, "created": 1784990793, "updated": 1784990793, "exploited_text": 0, "poc": 0, "score": 0.0, "kev": 0, "flags": []}, {"key": "CVE-2026-64368", "cve": "CVE-2026-64368", "lang": "en", "title": "CVE-2026-64368", "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\nmm/slab: do not limit zeroing to orig_size when only red zoning is enabled\n\nWhen init (zeroing) on allocation is requested, for kmalloc() we\ngenerally have to zero the full object size even if a smaller size is\nrequested, in order to provide krealloc()'s __GFP_ZERO guarantees.\n\nBut if we track the requested size, krealloc() uses that information to\ndo the right thing, so we can zero only the requested size. With red\nzoning also enabled, any extra size became part of the red zone, so it\nmust not be zeroed and thus we must zero only the requested size.\n\nHowever the current check is imprecise, and will trigger also when only\nSLAB_RED_ZONE is enabled without SLAB_STORE_USER (which enables tracking\nthe requested size). This means enabling red zoning alone can compromise\nkrealloc()'s __GFP_ZERO contract.\n\nFix this by using slub_debug_orig_size() instead, which is the exact\ncheck for whether the requested size is tracked. We don't need to care\nif red zoning is also enabled or not. Also update and expand the\ncomment accordingly.", "product": "Linux", "category": "cve", "source": "NVD", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-64368", "card": "CVE-2026-64368.webp?v=1784990895", "takeaways": [], "ts": 1784974639, "exploited": 0, "has_score": 0, "created": 1784990793, "updated": 1784990793, "exploited_text": 0, "poc": 0, "score": 0.0, "kev": 0, "flags": []}, {"key": "CVE-2026-64367", "cve": "CVE-2026-64367", "lang": "en", "title": "CVE-2026-64367", "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\nHID: hid-goodix-spi: validate report size to prevent stack buffer overflow\n\ngoodix_hid_set_raw_report() builds a protocol frame in a 128-byte stack\nbuffer (tmp_buf), writing an 11-12 byte header followed by the\ncaller-supplied report data.  The HID core caps report size at\nHID_MAX_BUFFER_SIZE (16384) by default, while the driver does not set\nhid_ll_driver.max_buffer_size and performs no bounds checking before\ncopying the payload:\n\n    memcpy(tmp_buf + tx_len, buf, len);\n\nA hidraw SET_REPORT ioctl with a report larger than ~116 bytes\noverflows the stack buffer.\n\nAdd a size check after constructing the header, rejecting reports that\nwould exceed the buffer capacity.\n\nDiscovered by Atuin - Automated Vulnerability Discovery Engine.", "product": "Linux", "category": "cve", "source": "NVD", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-64367", "card": "CVE-2026-64367.webp?v=1784990895", "takeaways": [], "ts": 1784974639, "exploited": 0, "has_score": 0, "created": 1784990793, "updated": 1784990793, "exploited_text": 0, "poc": 0, "score": 0.0, "kev": 0, "flags": []}, {"key": "CVE-2026-64366", "cve": "CVE-2026-64366", "lang": "en", "title": "CVE-2026-64366", "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\nHID: wacom: fix slab-out-of-bounds write in wacom_wac_queue_insert\n\nwacom_wac_queue_insert() calls kfifo_skip() in a loop when the kfifo\ndoesn't have enough space for the incoming report. If the kfifo is\nempty, kfifo_skip() reads stale data left in the kmalloc'd buffer\nvia __kfifo_peek_n() and interprets it as a record length, advancing\nfifo->out by that garbage value. This corrupts the internal kfifo\nstate, causing kfifo_unused() to return a value much larger than the\nactual buffer size, which bypasses __kfifo_in_r()'s guard:\n\n  if (len + recsize > kfifo_unused(fifo))\n      return 0;\n\nkfifo_copy_in() then performs an out-of-bounds memcpy, writing up to\n3842 bytes past the 256-byte buffer.\n\nAdd a !kfifo_is_empty() condition to the while loop so kfifo_skip()\nis never called on an empty fifo, and check the return value of\nkfifo_in() to reject reports that are too large for the fifo.", "product": "Linux", "category": "cve", "source": "NVD", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-64366", "card": "CVE-2026-64366.webp?v=1784990895", "takeaways": [], "ts": 1784974639, "exploited": 0, "has_score": 0, "created": 1784990793, "updated": 1784990793, "exploited_text": 0, "poc": 0, "score": 0.0, "kev": 0, "flags": []}, {"key": "CVE-2026-64365", "cve": "CVE-2026-64365", "lang": "en", "title": "CVE-2026-64365", "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\nHID: letsketch: fix UAF on inrange_timer at driver unbind\n\nletsketch_driver does not provide a .remove callback, but\nletsketch_probe() arms a per-device timer:\n\n    timer_setup(&data->inrange_timer, letsketch_inrange_timeout, 0);\n\nThe timer is re-armed from letsketch_raw_event() with a 100 ms\ntimeout on every pen-in-range report, and its callback dereferences\ndata->input_tablet to deliver a synthetic BTN_TOOL_PEN release.\n\nletsketch_data is allocated with devm_kzalloc(), and its input_dev\nfields are devm-allocated via letsketch_setup_input_tablet().  On\ndevice unbind (USB unplug or rmmod), the HID core runs its default\nteardown and devm cleanup frees both letsketch_data and the input\ndevices.  Because no .remove callback exists, nothing drains the\ntimer first: if raw_event armed it within ~100 ms of the unbind,\nthe pending timer fires on freed memory.  This is a UAF read of\ndata and of data->input_tablet, followed by input_report_key() /\ninput_sync() into the freed input_dev.\n\nThe same problem can occur on the probe error path: if\nhid_hw_start() enabled I/O on an always-poll-quirk device and then\nfailed, raw_event", "product": "Linux", "category": "cve", "source": "NVD", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-64365", "card": "CVE-2026-64365.webp?v=1784990894", "takeaways": [], "ts": 1784974639, "exploited": 0, "has_score": 0, "created": 1784990793, "updated": 1784990793, "exploited_text": 0, "poc": 0, "score": 0.0, "kev": 0, "flags": []}, {"key": "CVE-2026-64364", "cve": "CVE-2026-64364", "lang": "en", "title": "CVE-2026-64364", "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\nHID: multitouch: fix out-of-bounds bit access on mt_io_flags\n\nmt_io_flags is a single unsigned long, but mt_process_slot(),\nmt_release_pending_palms() and mt_release_contacts() use it as a\nper-slot bitmap indexed by the slot number. That slot number is only\nbounded by td->maxcontacts, which is taken from the device's\nContactCountMaximum feature report and can be up to 255, not by\nBITS_PER_LONG.\n\nAs a result, a multitouch device that advertises a large contact count\nmakes set_bit()/clear_bit() operate past the mt_io_flags word and\ncorrupt the adjacent members of struct mt_device. The sticky-fingers\nrelease timer is the easiest way to reach this. mt_release_contacts()\nruns\n\n\tfor (i = 0; i  num_slots; i++)\n\t\tclear_bit(i, &td->mt_io_flags);\n\nwith num_slots == maxcontacts. For maxcontacts around 250 the loop\nclears the bits that overlap td->applications.next, zeroing that list\nhead, and the list_for_each_entry() that immediately follows then\ndereferences NULL. The kernel panics from timer (softirq) context. On a\nKASAN build this shows up as a general protection fault in\nmt_release_contacts() with a null-ptr-deref at of", "product": "Linux", "category": "cve", "source": "NVD", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-64364", "card": "CVE-2026-64364.webp?v=1784990894", "takeaways": [], "ts": 1784974639, "exploited": 0, "has_score": 0, "created": 1784990793, "updated": 1784990793, "exploited_text": 0, "poc": 0, "score": 0.0, "kev": 0, "flags": []}, {"key": "CVE-2026-64363", "cve": "CVE-2026-64363", "lang": "en", "title": "CVE-2026-64363", "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\nHID: appleir: fix UAF on pending key_up_timer in remove()\n\nappleir_remove() runs hid_hw_stop() before timer_delete_sync().\nhid_hw_stop() synchronously unregisters the HID input device via\nhid_disconnect() -> hidinput_disconnect() -> input_unregister_device(),\nwhich drops the last reference and frees the underlying input_dev when\nno userspace handle holds it open.\n\nkey_up_tick() reads appleir->input_dev and calls input_report_key() /\ninput_sync() on it.  The timer is armed from appleir_raw_event() with\na HZ/8 (~125 ms) timeout on every keydown and key-repeat report.  If a\nkey was pressed shortly before the device is disconnected, the timer\ncan fire after hid_hw_stop() has freed input_dev but before the\nteardown drains it.\n\nA simple reorder is not sufficient.  Putting the timer drain first\nstill leaves a window where a USB URB completion (raw_event) running\nduring hid_hw_stop() can call mod_timer() and re-arm the timer, which\nthen fires after hidinput_disconnect() has freed input_dev.  The same\nURB-completion window also lets raw_event() reach key_up(), key_down()\nand battery_flat() directly, all of which dereferenc", "product": "Linux", "category": "cve", "source": "NVD", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-64363", "card": "CVE-2026-64363.webp?v=1784993255", "takeaways": [], "ts": 1784974638, "exploited": 0, "has_score": 0, "created": 1784993157, "updated": 1784993157, "exploited_text": 0, "poc": 0, "score": 0.0, "kev": 0, "flags": []}, {"key": "CVE-2026-64362", "cve": "CVE-2026-64362", "lang": "en", "title": "CVE-2026-64362", "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\nHID: lg-g15: cancel pending work on remove to fix a use-after-free\n\nlg_g15_data is allocated with devm and holds a work item. The report\nhandlers schedule that work straight from device input.\nlg_g15_event() and lg_g15_v2_event() do it on the backlight cycle key,\nand lg_g510_leds_event() does it too. The worker dereferences the\nlg_g15_data back through container_of.\n\nThe driver had no remove callback and never cancelled the work. So if a\nreport scheduled the work and the keyboard was then unplugged, devres\nfreed lg_g15_data while the work was still pending or running, and the\nworker touched freed memory. This is a use-after-free. It is reachable\nas a race on device unplug.\n\nAdd a remove callback that cancels the work before devres frees the\nstate. g15->work is only initialized for the models that schedule it\n(G15, G15 v2, G510). The G13 and Z-10 leave it zeroed, so guard the\ncancel on g15->work.func to avoid cancelling a work that was never set\nup. The g15 NULL test mirrors the one already in lg_g15_raw_event().", "product": "Linux", "category": "cve", "source": "NVD", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-64362", "card": "CVE-2026-64362.webp?v=1784990897", "takeaways": [], "ts": 1784974638, "exploited": 0, "has_score": 0, "created": 1784990793, "updated": 1784990793, "exploited_text": 0, "poc": 0, "score": 0.0, "kev": 0, "flags": []}, {"key": "CVE-2026-64361", "cve": "CVE-2026-64361", "lang": "en", "title": "CVE-2026-64361", "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\nhfs/hfsplus: fix u32 overflow in check_and_correct_requested_length\n\ncheck_and_correct_requested_length() compares (off + len) against\nnode_size using u32 arithmetic.  When the caller passes a large len\nvalue (e.g. from an underflowed subtraction in hfs_brec_remove()),\noff + len can wrap past 2^32 and produce a small result, causing the\nbounds check to pass when it should fail.\n\nFor example, with off=14 and len=0xFFFFFFF2 (underflowed from\ndata_off - keyoffset - size in hfs_brec_remove), off + len wraps to 6,\nwhich is less than a typical node_size of 512, so the check passes and\nthe subsequent memmove reads ~4GB past the node buffer.\n\nFix this by widening the addition to u64 before comparing against\nnode_size.  This prevents the u32 wrap while keeping the logic\nstraightforward.", "product": "Linux", "category": "cve", "source": "NVD", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-64361", "card": "CVE-2026-64361.webp?v=1784990897", "takeaways": [], "ts": 1784974638, "exploited": 0, "has_score": 0, "created": 1784990793, "updated": 1784990793, "exploited_text": 0, "poc": 0, "score": 0.0, "kev": 0, "flags": []}, {"key": "CVE-2026-64360", "cve": "CVE-2026-64360", "lang": "en", "title": "CVE-2026-64360", "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\nhfs/hfsplus: zero-initialize buffer in hfs_bnode_read\n\nhfs_bnode_read() can return early without writing to the output buffer\nwhen is_bnode_offset_valid() fails or when check_and_correct_requested_\nlength() corrects the length to zero.  Callers such as hfs_bnode_read_\nu16() and hfs_bnode_read_u8() pass stack-allocated buffers and use the\nresult unconditionally, leading to KMSAN uninit-value reports.\n\nRather than initializing at each individual call site, zero the buffer\nat the start of hfs_bnode_read() before any validation checks.  This\nensures all callers in both hfs and hfsplus get a deterministic zero\nvalue regardless of which early-return path is taken.", "product": "Linux", "category": "cve", "source": "NVD", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-64360", "card": "CVE-2026-64360.webp?v=1784990897", "takeaways": [], "ts": 1784974638, "exploited": 0, "has_score": 0, "created": 1784990793, "updated": 1784990793, "exploited_text": 0, "poc": 0, "score": 0.0, "kev": 0, "flags": []}, {"key": "CVE-2026-64359", "cve": "CVE-2026-64359", "lang": "en", "title": "CVE-2026-64359", "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\nnilfs2: reject CLEAN_SEGMENTS ioctl with out-of-range segment numbers\n\nSyzbot reported a hung task in nilfs_transaction_begin() where multiple\ntasks performing chmod() on a nilfs2 mount blocked for over 143 seconds\nwaiting to acquire ns_segctor_sem for read:\n\n  INFO: task syz.0.17:5918 blocked for more than 143 seconds.\n  Call Trace:\n   schedule+0x164/0x360\n   rwsem_down_read_slowpath+0x6d9/0x940\n   down_read+0x99/0x2e0\n   nilfs_transaction_begin+0x364/0x710 fs/nilfs2/segment.c:221\n   nilfs_setattr+0x124/0x2c0 fs/nilfs2/inode.c:921\n   notify_change+0xc1a/0xf40\n   chmod_common+0x273/0x4a0\n   do_fchmodat+0x12d/0x230\n\nThe writer holding ns_segctor_sem was a concurrent\nNILFS_IOCTL_CLEAN_SEGMENTS caller, stuck inside printk while emitting\nper-element warnings from nilfs_sufile_updatev():\n\n   __nilfs_msg+0x373/0x450 fs/nilfs2/super.c:78\n   nilfs_sufile_updatev+0x21c/0x6d0 fs/nilfs2/sufile.c:186\n   nilfs_sufile_freev fs/nilfs2/sufile.h:93 [inline]\n   nilfs_free_segments fs/nilfs2/segment.c:1140 [inline]\n   nilfs_segctor_collect_blocks fs/nilfs2/segment.c:1261 [inline]\n   nilfs_segctor_do_construct+0x1f55/0x76c0\n   nilfs_", "product": "Linux", "category": "cve", "source": "NVD", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-64359", "card": "CVE-2026-64359.webp?v=1784990896", "takeaways": [], "ts": 1784974638, "exploited": 0, "has_score": 0, "created": 1784990793, "updated": 1784990793, "exploited_text": 0, "poc": 0, "score": 0.0, "kev": 0, "flags": []}, {"key": "CVE-2026-64358", "cve": "CVE-2026-64358", "lang": "en", "title": "CVE-2026-64358", "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\nmedia: mtk-jpeg: cancel workqueue on release for supported platforms only\n\nSince a recent fix the mtk_jpeg_release function cancels any pending\nor running work present in the driver workqueue using\ncancel_work_sync function.\nCurrently, only the multicore based variants use this workqueue and they\nhave the jpeg_worker platform data field initialized with a workqueue\ncallback function. For the others, this field value remain NULL by\ndefault.\nThe cancel_work_sync function is unconditionally called in\nmtk_jpeg_release function, even for the variants that do not use the\nworkqueue. This call generates a WARN_ON print in __flush_work because\nthe workqueue callback function presence check fails in __flush_work\nfunction (used by cancel_work_sync).\n\nSo, to avoid these warnings, call cancel_work_sync only if a workqueue\ncallback is defined in platform data.", "product": "Linux", "category": "cve", "source": "NVD", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-64358", "card": "CVE-2026-64358.webp?v=1784990896", "takeaways": [], "ts": 1784974638, "exploited": 0, "has_score": 0, "created": 1784990793, "updated": 1784990793, "exploited_text": 0, "poc": 0, "score": 0.0, "kev": 0, "flags": []}, {"key": "CVE-2026-64357", "cve": "CVE-2026-64357", "lang": "en", "title": "CVE-2026-64357", "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\nxfs: fix exchmaps reservation limit check\n\nxfs_exchmaps_estimate_overhead() adds the bmbt and rmapbt\noverhead to a local resblks variable, but the final UINT_MAX\ncheck still tests req->resblks.  That is the reservation value\nfrom before the overhead was added.\n\nThe computed value is stored back in req->resblks and later passed\nto xfs_trans_alloc(), whose block reservation argument is unsigned\nint.  Check the computed reservation so the existing limit applies\nto the value that will be used.", "product": "Linux", "category": "cve", "source": "NVD", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-64357", "card": "CVE-2026-64357.webp?v=1784990896", "takeaways": [], "ts": 1784974638, "exploited": 0, "has_score": 0, "created": 1784990793, "updated": 1784990793, "exploited_text": 0, "poc": 0, "score": 0.0, "kev": 0, "flags": []}, {"key": "CVE-2026-64356", "cve": "CVE-2026-64356", "lang": "en", "title": "CVE-2026-64356", "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\nxfs: fix memory leak in xfs_dqinode_metadir_create()\n\nIf xfs_metadir_create() fails in xfs_dqinode_metadir_create(), the current\ncode returns directly, leaking the allocated update and transaction state.\nIf the subsequent commit fails, the caller-owned inode reference is left\nbehind.\n\nFix this memory leak by routing the create failure path through\nxfs_metadir_cancel().  For both create and commit failures, finish and\nrelease any inode returned to the caller, mirroring the unwind pattern in\nxfs_metadir_mkdir().\n\nThe bug was first flagged by an experimental analysis tool we are\ndeveloping for kernel memory-management bugs while analyzing\nv6.13-rc1. The tool is still under development and is not yet publicly\navailable. Manual inspection confirms that the bug is still\npresent in v7.1.1.\n\nAn x86_64 allyesconfig build showed no new warnings. Runtime validation\nused kprobe fault injection during `mount -o uquota` on a metadir XFS\nimage. Injecting xfs_metadir_create() reproduced the old active-update path\nthat left mount stuck later in mount setup; after this change, the same\ninjection reported cancel_hits=1 and irele_hit", "product": "Linux", "category": "cve", "source": "NVD", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-64356", "card": "CVE-2026-64356.webp?v=1784990896", "takeaways": [], "ts": 1784974638, "exploited": 0, "has_score": 0, "created": 1784990793, "updated": 1784990793, "exploited_text": 0, "poc": 0, "score": 0.0, "kev": 0, "flags": []}, {"key": "CVE-2026-64355", "cve": "CVE-2026-64355", "lang": "en", "title": "CVE-2026-64355", "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\nbpf: Reject fragmented frames in devmap\n\nDevmap broadcast redirects clone the packet for all but the last\ndestination.\n\nFor native XDP, that clone path copies only the linear xdp_frame data,\nwhile fragmented frames keep skb_shared_info in tailroom outside the\nlinear area. Cloning such a frame leaves XDP_FLAGS_HAS_FRAGS set but\nwithout valid frag metadata, and the later free path can interpret\nuninitialized tail data as skb_shared_info, leading to an out-of-bounds\naccess during frame return.\n\nReject fragmented native XDP frames in dev_map_enqueue_clone().\n\nAdd the same restriction to the generic XDP clone path in\ndev_map_redirect_clone(). Generic XDP represents fragmented packets as\nnonlinear skbs, and rejecting them here keeps clone-based broadcast\nsupport aligned between native and generic XDP.", "product": "Linux", "category": "cve", "source": "NVD", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-64355", "card": "CVE-2026-64355.webp?v=1784993256", "takeaways": [], "ts": 1784974637, "exploited": 0, "has_score": 0, "created": 1784993157, "updated": 1784993157, "exploited_text": 0, "poc": 0, "score": 0.0, "kev": 0, "flags": []}, {"key": "CVE-2026-64354", "cve": "CVE-2026-64354", "lang": "en", "title": "CVE-2026-64354", "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\nbpf: Validate BTF repeated field counts before expansion\n\nbtf_parse_struct_metas() walks user-supplied BTF during BPF_BTF_LOAD,\nand btf_repeat_fields() expands repeatable fields from array elements\ninto the fixed BTF_FIELDS_MAX scratch array used by btf_parse_fields().\n\nThe remaining-capacity check performs the expanded field count calculation\nin u32. A malformed BTF can wrap that calculation, causing the check to\npass even when the expanded field count exceeds the scratch array\ncapacity. The following memcpy() can then write past the end of the\narray.\n\nUse checked addition and multiplication before copying repeated fields\nand reject impossible counts.", "product": "Linux", "category": "cve", "source": "NVD", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-64354", "card": "CVE-2026-64354.webp?v=1784993256", "takeaways": [], "ts": 1784974637, "exploited": 0, "has_score": 0, "created": 1784993157, "updated": 1784993157, "exploited_text": 0, "poc": 0, "score": 0.0, "kev": 0, "flags": []}, {"key": "CVE-2026-64353", "cve": "CVE-2026-64353", "lang": "en", "title": "CVE-2026-64353", "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\nbpf: Keep dynamic inner array lookups nullable\n\nAn ARRAY_OF_MAPS can use an array created with BPF_F_INNER_MAP as its\ninner map template. A concrete inner array with a different max_entries\nvalue can then replace the template.\n\nAfter a successful outer map lookup, the verifier represents the\nresulting map pointer using the inner map template. Const-key lookup\nnullness elision consequently uses the template max_entries even though\nthe runtime helper uses the concrete inner map max_entries.\n\nDo not elide lookup result nullness for maps marked with BPF_F_INNER_MAP,\nbecause the template max_entries does not prove that the key is in bounds\nfor the concrete runtime map.", "product": "Linux", "category": "cve", "source": "NVD", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-64353", "card": "CVE-2026-64353.webp?v=1784993256", "takeaways": [], "ts": 1784974637, "exploited": 0, "has_score": 0, "created": 1784993157, "updated": 1784993157, "exploited_text": 0, "poc": 0, "score": 0.0, "kev": 0, "flags": []}, {"key": "CVE-2026-64352", "cve": "CVE-2026-64352", "lang": "en", "title": "CVE-2026-64352", "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\nbpf: Allow LPM map access from sleepable BPF programs\n\ntrie_lookup_elem() annotates its rcu_dereference_check() walks with\nonly rcu_read_lock_bh_held().  Because rcu_dereference_check(p, c)\nresolves to \"c || rcu_read_lock_held()\", this passes for XDP/NAPI and\nclassic RCU readers but fails for sleepable BPF programs, which enter\nvia __bpf_prog_enter_sleepable() and hold only rcu_read_lock_trace().\n\ntrie_update_elem() and trie_delete_elem() have the same problem in a\ndifferent form: they walk the trie with plain rcu_dereference(), which\nasserts rcu_read_lock_held() unconditionally.  Both are reachable from\nsleepable BPF programs via the bpf_map_update_elem / bpf_map_delete_elem\nhelpers, and from the syscall path under classic rcu_read_lock().  In\nthe writer paths the trie is actually protected by trie->lock (an\nrqspinlock taken across the walk); we never relied on the RCU read-side\nlock to keep nodes alive there.\n\nA sleepable LSM hook that ends up touching an LPM trie therefore\ntriggers lockdep on debug kernels:\n\n  =============================\n  WARNING: suspicious RCU usage\n  7.1.0-... Tainted: G            E\n  --", "product": "Linux", "category": "cve", "source": "NVD", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-64352", "card": "CVE-2026-64352.webp?v=1784993256", "takeaways": [], "ts": 1784974637, "exploited": 0, "has_score": 0, "created": 1784993157, "updated": 1784993157, "exploited_text": 0, "poc": 0, "score": 0.0, "kev": 0, "flags": []}, {"key": "CVE-2026-64351", "cve": "CVE-2026-64351", "lang": "en", "title": "CVE-2026-64351", "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet: usb: kalmia: bound RX frame length in kalmia_rx_fixup()\n\nkalmia_rx_fixup() computes usb_packet_length = skb->len - (2 *\nKALMIA_HEADER_LENGTH) as a u16, guarded only by a pre-loop check that\nskb->len is at least KALMIA_HEADER_LENGTH, which is 6. A device can\ndeliver a short bulk-IN frame with skb->len in the 6 to 11 range, or\nleave a short trailing remainder on a later loop iteration. Either case\nunderflows usb_packet_length to about 65530.\n\nThat bypasses the usb_packet_length < ether_packet_length truncation path.\nThe device-supplied ether_packet_length, a le16 up to 65535 read from\nheader_start[2], then drives a memcmp() and the following skb_trim() and\nskb_pull() past the end of the rx buffer. The rx buffer is hard_mtu * 10,\nwhich is 14000 bytes. That is an out of bounds read.\n\nRequire both the start and end framing headers to be present before\nsubtracting them, on every loop iteration.", "product": "Linux", "category": "cve", "source": "NVD", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-64351", "card": "CVE-2026-64351.webp?v=1784993256", "takeaways": [], "ts": 1784974637, "exploited": 0, "has_score": 0, "created": 1784993157, "updated": 1784993157, "exploited_text": 0, "poc": 0, "score": 0.0, "kev": 0, "flags": []}, {"key": "CVE-2026-64350", "cve": "CVE-2026-64350", "lang": "en", "title": "CVE-2026-64350", "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\nusb: cdnsp: fix stream context array leak in cdnsp_alloc_stream_info()\n\ncdnsp_alloc_stream_info() allocates stream_info->stream_ctx_array with\ncdnsp_alloc_stream_ctx(). If a later stream ring allocation or stream\nmapping update fails, the error path frees the allocated stream rings\nand stream_rings array, but leaves stream_ctx_array allocated.\n\nFree the stream context array before falling through to the stream_rings\ncleanup path.", "product": "Linux", "category": "cve", "source": "NVD", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-64350", "card": "CVE-2026-64350.webp?v=1784993255", "takeaways": [], "ts": 1784974637, "exploited": 0, "has_score": 0, "created": 1784993157, "updated": 1784993157, "exploited_text": 0, "poc": 0, "score": 0.0, "kev": 0, "flags": []}, {"key": "CVE-2026-64349", "cve": "CVE-2026-64349", "lang": "en", "title": "CVE-2026-64349", "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\nusb: dwc3: fix dwc3_readl() and dwc3_writel() calls in dwc3_ulpi_setup()\n\nThe dwc3_ulpi_setup() calls the register read and write calls with\ndwc3->regs when both these calls take the dwc3 structure directly.\n\nChnage these two calls to fix the following sparse warning, and\npossibly a nasty bug in the dwc3_ulpi_setup() code:\n\ndrivers/usb/dwc3/core.c:796:45: warning: incorrect type in argument 1 (different address spaces)\ndrivers/usb/dwc3/core.c:796:45:    expected struct dwc3 *dwc\ndrivers/usb/dwc3/core.c:796:45:    got void [noderef] __iomem *regs\ndrivers/usb/dwc3/core.c:798:40: warning: incorrect type in argument 1 (different address spaces)\ndrivers/usb/dwc3/core.c:798:40:    expected struct dwc3 *dwc\ndrivers/usb/dwc3/core.c:798:40:    got void [noderef] __iomem *regs", "product": "Linux", "category": "cve", "source": "NVD", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-64349", "card": "CVE-2026-64349.webp?v=1784993255", "takeaways": [], "ts": 1784974637, "exploited": 0, "has_score": 0, "created": 1784993157, "updated": 1784993157, "exploited_text": 0, "poc": 0, "score": 0.0, "kev": 0, "flags": []}, {"key": "CVE-2026-64348", "cve": "CVE-2026-64348", "lang": "en", "title": "CVE-2026-64348", "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\nusb: free iso schedules on failed submit\n\nEHCI and FOTG210 isochronous submits build an ehci_iso_sched before\nlinking the URB to the endpoint queue, and keep the staged schedule in\nurb->hcpriv until iso_stream_schedule() and the link helpers consume it.\nIf the controller is no longer accessible, or usb_hcd_link_urb_to_ep()\nfails, submit jumps to done_not_linked before that handoff happens and\nleaks the staged schedule still attached to urb->hcpriv.\n\nFree the staged schedule from done_not_linked when submit fails before\nthe URB is linked and clear urb->hcpriv after the free.\n\nThe bug was first flagged by an experimental analysis tool we are\ndeveloping for kernel memory-management bugs while analyzing\nv6.13-rc1. The tool is still under development and is not yet publicly\navailable. Manual inspection confirms that the bug is still\npresent in v7.1.1.\n\nAn x86_64 allyesconfig build showed no new warnings. As we do not have an\nEHCI host controller with a USB isochronous device to test with, no\nruntime testing was able to be performed.", "product": "Linux", "category": "cve", "source": "NVD", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-64348", "card": "CVE-2026-64348.webp?v=1784993255", "takeaways": [], "ts": 1784974637, "exploited": 0, "has_score": 0, "created": 1784993157, "updated": 1784993157, "exploited_text": 0, "poc": 0, "score": 0.0, "kev": 0, "flags": []}, {"key": "CVE-2026-64347", "cve": "CVE-2026-64347", "lang": "en", "title": "CVE-2026-64347", "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\nusb: gadget: composite: fix dead empty check in the USB_DT_OTG handler\n\nThe OTG branch of composite_setup() falls back to the first\nconfiguration when none is selected:\n\n\tif (cdev->config)\n\t\tconfig = cdev->config;\n\telse\n\t\tconfig = list_first_entry(&cdev->configs,\n\t\t\t\t\t  struct usb_configuration, list);\n\tif (!config)\n\t\tgoto done;\n\t...\n\tmemcpy(req->buf, config->descriptors[0], value);\n\nlist_first_entry() never returns NULL. On an empty list it returns\ncontainer_of() of the list head. So the \"if (!config)\" check is dead.\n\nWhen cdev->configs is empty, config points at the head inside struct\nusb_composite_dev. config->descriptors[0] reads whatever sits at that\noffset. The memcpy copies up to w_length bytes of it into the response\nbuffer.\n\ncdev->configs can be empty in two cases. One is a teardown race on\ngadget unbind with a control transfer in flight. The other is a driver\nthat sets is_otg before it adds a config. A reproducer that holds\ncdev->configs empty triggers a KASAN fault in this branch.\n\nUse list_first_entry_or_null() so the existing check does its job.", "product": "Linux", "category": "cve", "source": "NVD", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-64347", "card": "CVE-2026-64347.webp?v=1784993258", "takeaways": [], "ts": 1784974636, "exploited": 0, "has_score": 0, "created": 1784993157, "updated": 1784993157, "exploited_text": 0, "poc": 0, "score": 0.0, "kev": 0, "flags": []}, {"key": "CVE-2026-64346", "cve": "CVE-2026-64346", "lang": "en", "title": "CVE-2026-64346", "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\nusb: gadget: udc: Fix use-after-free in gadget_match_driver\n\nThe udc structure acts as the management structure for the gadget,\nbut their lifecycles are decoupled. A race condition exists where\nusb_del_gadget() frees the udc memory (e.g., via mode-switch work)\nwhile gadget_match_driver() concurrently accesses the freed udc memory\n(e.g., via configfs), causing a Use-After-Free (UAF) that triggers a\nNULL pointer dereference when the freed memory is zeroed:\n\n[39430.908615][ T1171] Unable to handle kernel NULL pointer dereference at virtual address 0000000000000000\n[39430.911397][ T1171] pc : __pi_strcmp+0x20/0x140\n[39430.911441][ T1171] lr : gadget_match_driver+0x34/0x60\n...\n[39430.911890][ T1171]  usb_gadget_register_driver_owner+0x50/0xf8\n[39430.911910][ T1171]  gadget_dev_desc_UDC_store+0xf4/0x140\n[39430.931308][ T1171]  configfs_write_iter+0xec/0x134\n\n[39430.957058][ T1171] Workqueue: events_freezable __dwc3_set_mode\n[39430.957287][ T1171]  dwc3_gadget_exit+0x34/0x8c\n[39430.957304][ T1171]  __dwc3_set_mode+0xc0/0x664\n\nFix this by ensuring the udc structure remains allocated until the\ngadget is released. To achiev", "product": "Linux", "category": "cve", "source": "NVD", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-64346", "card": "CVE-2026-64346.webp?v=1784993258", "takeaways": [], "ts": 1784974636, "exploited": 0, "has_score": 0, "created": 1784993157, "updated": 1784993157, "exploited_text": 0, "poc": 0, "score": 0.0, "kev": 0, "flags": []}, {"key": "CVE-2026-64345", "cve": "CVE-2026-64345", "lang": "en", "title": "CVE-2026-64345", "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\nusb: gadget: f_printer: take kref only for successful open\n\nprinter_open() returns -EBUSY when the character device is already\nopen, but it increments dev->kref regardless of the return value. VFS\ndoes not call ->release() for a failed open, so every rejected second\nopen permanently leaks one reference.\n\nMove kref_get() into the successful-open branch.", "product": "Linux", "category": "cve", "source": "NVD", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-64345", "card": "CVE-2026-64345.webp?v=1784993257", "takeaways": [], "ts": 1784974636, "exploited": 0, "has_score": 0, "created": 1784993157, "updated": 1784993157, "exploited_text": 0, "poc": 0, "score": 0.0, "kev": 0, "flags": []}, {"key": "CVE-2026-64344", "cve": "CVE-2026-64344", "lang": "en", "title": "CVE-2026-64344", "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\nUSB: idmouse: fix use-after-free on disconnect race\n\nmutex_unlock() may access the mutex structure after releasing the lock\nand therefore cannot be used to manage lifetime of objects directly\n(unlike spinlocks and refcounts). [1][2]\n\nUse a kref to release the driver data to avoid use-after-free in\nmutex_unlock() when release() races with disconnect().\n\n[1] a51749ab34d9 (\"locking/mutex: Document that mutex_unlock() is\n                   non-atomic\")\n[2] 2b9d9e0a9ba0 (\"locking/mutex: Clarify that mutex_unlock(), and most\n                   other sleeping locks, can still use the lock object\n                   after it's unlocked\")", "product": "Linux", "category": "cve", "source": "NVD", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-64344", "card": "CVE-2026-64344.webp?v=1784993257", "takeaways": [], "ts": 1784974636, "exploited": 0, "has_score": 0, "created": 1784993157, "updated": 1784993157, "exploited_text": 0, "poc": 0, "score": 0.0, "kev": 0, "flags": []}, {"key": "CVE-2026-64343", "cve": "CVE-2026-64343", "lang": "en", "title": "CVE-2026-64343", "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\nUSB: ldusb: fix use-after-free on disconnect race\n\nmutex_unlock() may access the mutex structure after releasing the lock\nand therefore cannot be used to manage lifetime of objects directly\n(unlike spinlocks and refcounts). [1][2]\n\nUse a kref to release the driver data to avoid use-after-free in\nmutex_unlock() when release() races with disconnect().\n\n[1] a51749ab34d9 (\"locking/mutex: Document that mutex_unlock() is\n                   non-atomic\")\n[2] 2b9d9e0a9ba0 (\"locking/mutex: Clarify that mutex_unlock(), and most\n                   other sleeping locks, can still use the lock object\n                   after it's unlocked\")", "product": "Linux", "category": "cve", "source": "NVD", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-64343", "card": "CVE-2026-64343.webp?v=1784993257", "takeaways": [], "ts": 1784974636, "exploited": 0, "has_score": 0, "created": 1784993157, "updated": 1784993157, "exploited_text": 0, "poc": 0, "score": 0.0, "kev": 0, "flags": []}, {"key": "CVE-2026-64342", "cve": "CVE-2026-64342", "lang": "en", "title": "CVE-2026-64342", "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\nUSB: iowarrior: fix use-after-free on disconnect\n\nSubmitted write URBs are not stopped on close() and therefore need to be\nstopped unconditionally on disconnect() to avoid use-after-free in the\ncompletion handler.", "product": "Linux", "category": "cve", "source": "NVD", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-64342", "card": "CVE-2026-64342.webp?v=1784993257", "takeaways": [], "ts": 1784974636, "exploited": 0, "has_score": 0, "created": 1784993157, "updated": 1784993157, "exploited_text": 0, "poc": 0, "score": 0.0, "kev": 0, "flags": []}, {"key": "CVE-2026-64341", "cve": "CVE-2026-64341", "lang": "en", "title": "CVE-2026-64341", "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\nUSB: iowarrior: fix use-after-free on disconnect race\n\nmutex_unlock() may access the mutex structure after releasing the lock\nand therefore cannot be used to manage lifetime of objects directly\n(unlike spinlocks and refcounts). [1][2]\n\nUse a kref to release the driver data to avoid use-after-free in\nmutex_unlock() when release() races with disconnect().\n\n[1] a51749ab34d9 (\"locking/mutex: Document that mutex_unlock() is non-atomic\")\n[2] 2b9d9e0a9ba0 (\"locking/mutex: Clarify that mutex_unlock(), and most\n                   other sleeping locks, can still use the lock object\n                   after it's unlocked\")", "product": "Linux", "category": "cve", "source": "NVD", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-64341", "card": "CVE-2026-64341.webp?v=1784993257", "takeaways": [], "ts": 1784974636, "exploited": 0, "has_score": 0, "created": 1784993157, "updated": 1784993157, "exploited_text": 0, "poc": 0, "score": 0.0, "kev": 0, "flags": []}, {"key": "CVE-2026-64340", "cve": "CVE-2026-64340", "lang": "en", "title": "CVE-2026-64340", "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\nUSB: legousbtower: fix use-after-free on disconnect race\n\nmutex_unlock() may access the mutex structure after releasing the lock\nand therefore cannot be used to manage lifetime of objects directly\n(unlike spinlocks and refcounts). [1][2]\n\nUse a kref to release the driver data to avoid use-after-free in\nmutex_unlock() when release() races with disconnect().\n\n[1] a51749ab34d9 (\"locking/mutex: Document that mutex_unlock() is\n                   non-atomic\")\n[2] 2b9d9e0a9ba0 (\"locking/mutex: Clarify that mutex_unlock(), and most\n                   other sleeping locks, can still use the lock object\n                   after it's unlocked\")", "product": "Linux", "category": "cve", "source": "NVD", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-64340", "card": "CVE-2026-64340.webp?v=1784993260", "takeaways": [], "ts": 1784974635, "exploited": 0, "has_score": 0, "created": 1784993157, "updated": 1784993157, "exploited_text": 0, "poc": 0, "score": 0.0, "kev": 0, "flags": []}, {"key": "CVE-2026-64339", "cve": "CVE-2026-64339", "lang": "en", "title": "CVE-2026-64339", "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\nusb: misc: usbio: bound bulk IN response length to the received transfer\n\nusbio_bulk_msg() copies bpkt_len = le16_to_cpu(bpkt->len) bytes out of\nthe bulk IN buffer (usbio->rxbuf, allocated with size usbio->rxbuf_len)\ninto the caller's buffer.  bpkt_len is fully controlled by the device\nand is only checked against ibuf_len; ibuf_len in turn is checked\nagainst usbio->txbuf_len, not against rxbuf_len:\n\n\tif ((obuf_len > (usbio->txbuf_len - sizeof(*bpkt))) ||\n\t    (ibuf_len > (usbio->txbuf_len - sizeof(*bpkt))))\n\t\treturn -EMSGSIZE;\n\ntxbuf_len and rxbuf_len are taken independently from the bulk OUT and\nbulk IN endpoint wMaxPacketSize in usbio_probe().  A malicious or\nmalfunctioning device that advertises a large bulk OUT endpoint and a\nsmall bulk IN endpoint (e.g. by claiming one of the quirk-free IDs such\nas the Lattice NX33U, 0x2ac1:0x20cb) therefore makes ibuf_len, and\nhence the device-supplied bpkt_len, exceed rxbuf_len.  memcpy() then\nreads up to txbuf_len - rxbuf_len bytes past the end of the rxbuf slab\nobject.  The over-read bytes are handed back to the i2c layer and on to\nuser space through i2c-dev, disclosing a", "product": "Linux", "category": "cve", "source": "NVD", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-64339", "card": "CVE-2026-64339.webp?v=1784993259", "takeaways": [], "ts": 1784974635, "exploited": 0, "has_score": 0, "created": 1784993157, "updated": 1784993157, "exploited_text": 0, "poc": 0, "score": 0.0, "kev": 0, "flags": []}, {"key": "CVE-2026-64338", "cve": "CVE-2026-64338", "lang": "en", "title": "CVE-2026-64338", "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\nUSB: misc: uss720: unregister parport on probe failure\n\nuss720_probe() registers a parport before reading the 1284 register used\nto detect unsupported Belkin F5U002 adapters. If get_1284_register()\nfails, the error path drops the driver private data and the USB device\nreference, but leaves the parport device registered.\n\nLeaving the port registered is more than a private allocation leak:\nparport_register_port() has already reserved a parport number and\nregistered the parport bus device, while pp->private_data still points at\nthe private data that the common error path is about to release.\n\nUndo the pre-announce registration in the get_1284_register() failure\nbranch before jumping to the common private-data cleanup path. Clear\npriv->pp first, matching the disconnect path and avoiding a stale pointer\nin the private data.\n\nThis issue was identified during our ongoing static-analysis research while\nreviewing kernel code.", "product": "Linux", "category": "cve", "source": "NVD", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-64338", "card": "CVE-2026-64338.webp?v=1784993259", "takeaways": [], "ts": 1784974635, "exploited": 0, "has_score": 0, "created": 1784993157, "updated": 1784993157, "exploited_text": 0, "poc": 0, "score": 0.0, "kev": 0, "flags": []}, {"key": "CVE-2026-64337", "cve": "CVE-2026-64337", "lang": "en", "title": "CVE-2026-64337", "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\nusb: mtu3: unmap request DMA on queue failure\n\nmtu3_gadget_queue() maps the request before checking whether\nthe QMU GPD ring can accept another transfer. the request is\nreturned with -EAGAIN before it is linked on the endpoint\nrequest list if mtu3_prepare_transfer() fails.\n\nNormal completion and dequeue paths unmap requests from\nmtu3_req_complete(), but this error path never reaches that\nhelper, so the DMA mapping is left active. Unmap the request\nbefore returning from the failed queue path.", "product": "Linux", "category": "cve", "source": "NVD", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-64337", "card": "CVE-2026-64337.webp?v=1784993259", "takeaways": [], "ts": 1784974635, "exploited": 0, "has_score": 0, "created": 1784993157, "updated": 1784993157, "exploited_text": 0, "poc": 0, "score": 0.0, "kev": 0, "flags": []}, {"key": "CVE-2026-64336", "cve": "CVE-2026-64336", "lang": "en", "title": "CVE-2026-64336", "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\nUSB: serial: keyspan_pda: fix information leak\n\nThe write() callback is supposed to return the number of characters\naccepted or a negative errno. Since the addition of write fifo support\nthe keyspan_pda implementation will however return the number characters\nsubmitted to the device if the write urb is not already in use. If this\nnumber is larger than the number of characters passed to write(), the\nline discipline continues writing data from beyond the tty write buffer.\n\nFix the information leak by making sure that keyspan_pda_write_start()\nreturns zero on success as intended.", "product": "Linux", "category": "cve", "source": "NVD", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-64336", "card": "CVE-2026-64336.webp?v=1784993259", "takeaways": [], "ts": 1784974635, "exploited": 0, "has_score": 0, "created": 1784993157, "updated": 1784993157, "exploited_text": 0, "poc": 0, "score": 0.0, "kev": 0, "flags": []}, {"key": "CVE-2026-64335", "cve": "CVE-2026-64335", "lang": "en", "title": "CVE-2026-64335", "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\nUSB: serial: digi_acceleport: fix broken rx after throttle\n\nIf the port is closed while throttled, the read urb is never resubmitted\nand the port will not receive any further data until the device is\nreconnected (or the driver is rebound).\n\nClear the throttle flags and submit the urb if needed when opening the\nport.", "product": "Linux", "category": "cve", "source": "NVD", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-64335", "card": "CVE-2026-64335.webp?v=1784993258", "takeaways": [], "ts": 1784974635, "exploited": 0, "has_score": 0, "created": 1784993157, "updated": 1784993157, "exploited_text": 0, "poc": 0, "score": 0.0, "kev": 0, "flags": []}, {"key": "CVE-2026-64334", "cve": "CVE-2026-64334", "lang": "en", "title": "CVE-2026-64334", "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\nUSB: serial: digi_acceleport: fix hard lockup on disconnect\n\nIf submitting the OOB write urb fails persistently (e.g if the device is\nbeing disconnected) the driver would loop indefinitely with interrupts\ndisabled.\n\nCheck for urb submission errors when sending OOB commands to avoid\nhanging if, for example, open(), set_termios() or close() races with a\nphysical disconnect.\n\nThis is issue was flagged by Sashiko when reviewing an unrelated change\nto the driver.", "product": "Linux", "category": "cve", "source": "NVD", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-64334", "card": "CVE-2026-64334.webp?v=1784993258", "takeaways": [], "ts": 1784974635, "exploited": 0, "has_score": 0, "created": 1784993157, "updated": 1784993157, "exploited_text": 0, "poc": 0, "score": 0.0, "kev": 0, "flags": []}, {"key": "CVE-2026-64333", "cve": "CVE-2026-64333", "lang": "en", "title": "CVE-2026-64333", "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\nUSB: serial: digi_acceleport: fix write buffer corruption\n\nThe digi_write_inb_command() is supposed to wait for the write urb to\nbecome available or return an error, but instead it updates the transfer\nbuffer and tries to resubmit the urb on timeout.\n\nTo make things worse, for commands like break control where no timeout\nis used, the driver would corrupt the urb immediately due to a broken\njiffies comparison (on 32-bit machines this takes five minutes of uptime\nto trigger due to INITIAL_JIFFIES).\n\nFix this by adding the missing return on timeout and waiting\nindefinitely when no timeout has been specified as intended.\n\nThis issue was (sort of) flagged by Sashiko when reviewing an unrelated\nchange to the driver.", "product": "Linux", "category": "cve", "source": "NVD", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-64333", "card": "CVE-2026-64333.webp?v=1784993258", "takeaways": [], "ts": 1784974635, "exploited": 0, "has_score": 0, "created": 1784993157, "updated": 1784993157, "exploited_text": 0, "poc": 0, "score": 0.0, "kev": 0, "flags": []}, {"key": "CVE-2026-64332", "cve": "CVE-2026-64332", "lang": "en", "title": "CVE-2026-64332", "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\nUSB: ulpi: fix memory leak on registration failure\n\nThe allocated device name is never freed on early ULPI device\nregistration failures.\n\nFix this by initialising the device structure earlier and releasing the\ninitial reference whenever registration fails.", "product": "Linux", "category": "cve", "source": "NVD", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-64332", "card": "CVE-2026-64332.webp?v=1784995621", "takeaways": [], "ts": 1784974634, "exploited": 0, "has_score": 0, "created": 1784995520, "updated": 1784995520, "exploited_text": 0, "poc": 0, "score": 0.0, "kev": 0, "flags": []}, {"key": "CVE-2026-64331", "cve": "CVE-2026-64331", "lang": "en", "title": "CVE-2026-64331", "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\nusbip: vudc: fix NULL deref in vep_dequeue()\n\nvep_alloc_request() wasn't initializing vrequest->udc, so cancellations\non the FunctionFS AIO path were arriving in vep_dequeue without a valid\nUDC reference.\n\nSince vrequest->udc is never actually properly used anywhere, we opt to\nremove it, and update vep_dequeue to obtain a reference to the udc with\nep_to_vudc(), consistent with the other vep_ ops.\n\nAFAICT this bug has existed for ~10 years. Seems that nobody has really\nstressed the FunctionFS AIO path on usbip's vudc.\n\nI tested this fix in a QEMU aarch64 guest driving FunctionFS endpoints\nvia AIO. Before the fix, running `usbip attach` from the host would\ncause the guest to oops with the following backtrace:\n\nCall trace:\n vep_dequeue+0x1c/0xe4 (P)\n usb_ep_dequeue+0x14/0x20\n ffs_aio_cancel+0x24/0x34\n __arm64_sys_io_cancel+0xb0/0x124\n do_el0_svc+0x68/0x100\n el0_svc+0x18/0x5c\n el0t_64_sync_handler+0x98/0xdc\n el0t_64_sync+0x154/0x158", "product": "Linux", "category": "cve", "source": "NVD", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-64331", "card": "CVE-2026-64331.webp?v=1784995621", "takeaways": [], "ts": 1784974634, "exploited": 0, "has_score": 0, "created": 1784995520, "updated": 1784995520, "exploited_text": 0, "poc": 0, "score": 0.0, "kev": 0, "flags": []}, {"key": "CVE-2026-64330", "cve": "CVE-2026-64330", "lang": "en", "title": "CVE-2026-64330", "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\nusb: typec: tcpm: Validate SVID index in svdm_consume_modes()\n\nIn svdm_consume_modes(), the SVID value is read from pmdata->svids using\npmdata->svid_index as an array index without bounds validation:\n\n    paltmode->svid = pmdata->svids[pmdata->svid_index];\n\nIf pmdata->svid_index is driven beyond SVID_DISCOVERY_MAX (16), it results\nin an out-of-bounds read of the pmdata->svids array. Because pd_mode_data\nis embedded inside struct tcpm_port, indexing past svids reads into\nadjacent fields. In particular:\n- At index 16, it reads the altmodes count.\n- At index 18 and beyond, it reads into altmode_desc[], which contains\n  partner-supplied SVDM Discovery Modes VDOs.\n\nBy injecting a chosen SVID into altmode_desc[0].vdo and driving svid_index\nto 20, the partner can force paltmode->svid to be loaded with an arbitrary,\npartner- chosen SVID, which is then registered via\ntypec_partner_register_altmode().\n\nFix this by validating that pmdata->svid_index is non-negative and strictly\nless than pmdata->nsvids before accessing the pmdata->svids array inside\nsvdm_consume_modes().", "product": "Linux", "category": "cve", "source": "NVD", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-64330", "card": "CVE-2026-64330.webp?v=1784995621", "takeaways": [], "ts": 1784974634, "exploited": 0, "has_score": 0, "created": 1784995520, "updated": 1784995520, "exploited_text": 0, "poc": 0, "score": 0.0, "kev": 0, "flags": []}, {"key": "CVE-2026-64329", "cve": "CVE-2026-64329", "lang": "en", "title": "CVE-2026-64329", "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\nusb: typec: ucsi: ccg: Fix use-after-free of ucsi on remove\n\nThe threaded IRQ handler ccg_irq_handler() calls ucsi_notify_common(),\nwhich on a connector-change event calls ucsi_connector_change() and\nschedules connector work.  In ucsi_ccg_remove(), ucsi_destroy() frees\nuc->ucsi (kfree) before free_irq() is called, so a handler invocation\nalready in flight may access the freed object after ucsi_destroy().\n\n  CPU 0 (remove)            | CPU 1 (threaded IRQ)\n    ucsi_destroy(uc->ucsi)  |   ccg_irq_handler()\n      kfree(ucsi) // FREE   |     ucsi_notify_common(uc->ucsi) // USE\n\nMove free_irq() before ucsi_destroy() in the remove path.  It is kept\nafter ucsi_unregister(): ucsi_unregister() cancels connector work whose\nhandler issues GET_CONNECTOR_STATUS through ucsi_send_command_common(),\nwhich waits for a completion that is signalled from the IRQ handler, so\nthe IRQ must stay active until that work has been cancelled.\n\nThe probe error path already orders free_irq() before ucsi_destroy().\n\nThis bug was found by static analysis.", "product": "Linux", "category": "cve", "source": "NVD", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-64329", "card": "CVE-2026-64329.webp?v=1784995620", "takeaways": [], "ts": 1784974634, "exploited": 0, "has_score": 0, "created": 1784995520, "updated": 1784995520, "exploited_text": 0, "poc": 0, "score": 0.0, "kev": 0, "flags": []}, {"key": "CVE-2026-64328", "cve": "CVE-2026-64328", "lang": "en", "title": "CVE-2026-64328", "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\nusb: gadget: f_fs: Fix DMA fence leak\n\nIn ffs_dmabuf_transfer(), a ffs_dma_fence object is kmalloc'd, with the\nunderlying dma_fence later initialized by dma_fence_init(), which sets\nits kref counter to 1. Then, dma_resv_add_fence() gets a second\nreference, and a pointer to the ffs_dma_fence is passed as the\nusb_request's \"context\" field.\n\nThe dma-resv mechanism will manage the second reference, but the first\nreference is never properly released; the ffs_dmabuf_cleanup() function\ndecreases the reference count, but only to balance with the reference\ngrab in ffs_dmabuf_signal_done().\n\nThe code will then slowly leak memory as more ffs_dma_fence objects are\ncreated without being ever freed.\n\nAddress this issue by transferring ownership of the fence to the DMA\nreservation object, by calling dma_fence_put() right after\ndma_resv_add_fence(). The ffs_dma_fence then gets properly discarded\nafter being signalled.", "product": "Linux", "category": "cve", "source": "NVD", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-64328", "card": "CVE-2026-64328.webp?v=1784995620", "takeaways": [], "ts": 1784974634, "exploited": 0, "has_score": 0, "created": 1784995520, "updated": 1784995520, "exploited_text": 0, "poc": 0, "score": 0.0, "kev": 0, "flags": []}, {"key": "CVE-2026-64327", "cve": "CVE-2026-64327", "lang": "en", "title": "CVE-2026-64327", "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\nusb: gadget: f_fs: Initialize epfile->in early to fix endpoint direction checks\n\nWhen parsing endpoint descriptors, ffs_data_got_descs() generates the\neps_addrmap which contains the endpoint direction. However, epfile->in\nwas previously only populated in ffs_func_eps_enable() which executes\nupon USB host connection. As a result, early userspace ioctls like\nFUNCTIONFS_DMABUF_ATTACH that run before the host connects would see\nepfile->in as 0, leading to incorrect DMA directions.\n\nBy moving the initialization to ffs_epfiles_create(), epfile->in is\naccurate before userspace opens the endpoint files.", "product": "Linux", "category": "cve", "source": "NVD", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-64327", "card": "CVE-2026-64327.webp?v=1784995620", "takeaways": [], "ts": 1784974634, "exploited": 0, "has_score": 0, "created": 1784995520, "updated": 1784995520, "exploited_text": 0, "poc": 0, "score": 0.0, "kev": 0, "flags": []}, {"key": "CVE-2026-64326", "cve": "CVE-2026-64326", "lang": "en", "title": "CVE-2026-64326", "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\nblock: skip sync_blockdev() on surprise removal in bdev_mark_dead()\n\nbdev_mark_dead()'s @surprise == true means the device is already gone.\nThe filesystem callback fs_bdev_mark_dead() honours this and skips\nsync_filesystem(), but the bare block device path (no ->mark_dead op)\nlost its !surprise guard when the holder ->mark_dead callback was wired\nup (see Fixes), and now calls sync_blockdev() unconditionally, which can\nhang forever waiting on writeback that can no longer complete.\n\nsyzkaller hit this via nvme_reset_work()'s \"I/O queues lost\" path:\nnvme_mark_namespaces_dead() -> blk_mark_disk_dead() ->\nbdev_mark_dead(bdev, true) -> sync_blockdev() blocks in\nfolio_wait_writeback(), wedging the reset worker and every task waiting\non it.\n\nSkip the sync on surprise removal, matching fs_bdev_mark_dead();\ninvalidate_bdev() still runs. Orderly removal (surprise == false) is\nunchanged.\n\nFound by FuzzNvme(Syzkaller with FEMU fuzzing framework).", "product": "Linux", "category": "cve", "source": "NVD", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-64326", "card": "CVE-2026-64326.webp?v=1784995619", "takeaways": [], "ts": 1784974634, "exploited": 0, "has_score": 0, "created": 1784995520, "updated": 1784995520, "exploited_text": 0, "poc": 0, "score": 0.0, "kev": 0, "flags": []}, {"key": "CVE-2026-64325", "cve": "CVE-2026-64325", "lang": "en", "title": "CVE-2026-64325", "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: mt76: mt7921/mt7925: fix NULL dereference in CSA beacon\n\nThis patch is based on a BUG as reported by Bongani Hlope at\nhttps://lore.kernel.org/all/20260502125824.425d7159@bongani-mini.home.org.za/\n\nWhen a channel-switch announcement (CSA) beacon is received,\ncfg80211 queues a wiphy work item that eventually calls\nmt7921_channel_switch_rx_beacon(). If the station disconnects\n(or the channel context is otherwise torn down) between the\ntime the work is queued and the time it runs, the driver's\ndev->new_ctx pointer can already have been cleared to NULL.\nmt7921_channel_switch_rx_beacon() then dereferences new_ctx\nunconditionally, triggering a NULL pointer dereference at\naddress 0x0:\n\n  BUG: kernel NULL pointer dereference, address: 0000000000000000\n  RIP: 0010:mt7921_channel_switch_rx_beacon+0x1f/0x100 [mt7921_common]\n\nThe same missing guard exists in mt7925_channel_switch_rx_beacon(),\nwhich shares the same code pattern introduced by the same commit.\n\nAdd an early-return NULL check for dev->new_ctx in both\nmt7921_channel_switch_rx_beacon() and\nmt7925_channel_switch_rx_beacon(). When new_ctx is NULL there is\nno pen", "product": "Linux", "category": "cve", "source": "NVD", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-64325", "card": "CVE-2026-64325.webp?v=1784993260", "takeaways": [], "ts": 1784974634, "exploited": 0, "has_score": 0, "created": 1784993157, "updated": 1784993157, "exploited_text": 0, "poc": 0, "score": 0.0, "kev": 0, "flags": []}, {"key": "CVE-2026-64324", "cve": "CVE-2026-64324", "lang": "en", "title": "CVE-2026-64324", "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\nudf: validate free block extents against the partition length\n\nudf_free_blocks() checks the logical block number and count against the\npartition length, but drops the extent offset from that final bound.  A\ncrafted extent can pass the guard while logicalBlockNum + offset + count\npoints past the partition, which later indexes past the space bitmap\narray.\n\nA single ftruncate(2) on a file backed by such an extent reliably\npanics the kernel.  This is a local availability issue.  On desktop\nsystems where UDisks/polkit allows the active user to mount removable\nUDF media without CAP_SYS_ADMIN, an unprivileged local user can supply\nthe crafted filesystem and trigger the panic by truncating a writable\nfile on it.  Systems that require root or CAP_SYS_ADMIN to mount the\nimage have a higher prerequisite.\n\nNo confidentiality or integrity impact is claimed: the reproduced\nprimitive is an out-of-bounds read of a bitmap pointer slot followed by\na kernel panic.\n\nUse the already computed logicalBlockNum + offset + count value for the\npartition length check.  Also make load_block_bitmap() reject an\nout-of-range block group before i", "product": "Linux", "category": "cve", "source": "NVD", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-64324", "card": "CVE-2026-64324.webp?v=1784995623", "takeaways": [], "ts": 1784974633, "exploited": 0, "has_score": 0, "created": 1784995520, "updated": 1784995520, "exploited_text": 0, "poc": 0, "score": 0.0, "kev": 0, "flags": []}, {"key": "CVE-2026-64323", "cve": "CVE-2026-64323", "lang": "en", "title": "CVE-2026-64323", "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\nudf: validate VAT header length against the VAT inode size\n\nudf_load_vat() takes the virtual partition's start offset straight from\nthe on-disk VAT 2.0 header without checking it against the VAT inode\nsize:\n\n\tmap->s_type_specific.s_virtual.s_start_offset =\n\t\tle16_to_cpu(vat20->lengthHeader);\n\tmap->s_type_specific.s_virtual.s_num_entries =\n\t\t(sbi->s_vat_inode->i_size -\n\t\t\tmap->s_type_specific.s_virtual.s_start_offset) >> 2;\n\nlengthHeader is a fully attacker-controlled 16-bit value.  If it exceeds\nthe VAT inode size, the s_num_entries subtraction underflows to a huge\ncount, which defeats the \"block > s_num_entries\" bound in\nudf_get_pblock_virt15(); and on the ICB-inline path that function reads\n\n\t((__le32 *)(iinfo->i_data + s_start_offset))[block]\n\nso a large s_start_offset indexes past the inode's in-ICB data.  Mounting\na crafted UDF image with a virtual (VAT) partition then triggers an\nout-of-bounds read.\n\nReject a VAT whose header length does not leave room for at least one\nentry within the VAT inode.", "product": "Linux", "category": "cve", "source": "NVD", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-64323", "card": "CVE-2026-64323.webp?v=1784995623", "takeaways": [], "ts": 1784974633, "exploited": 0, "has_score": 0, "created": 1784995520, "updated": 1784995520, "exploited_text": 0, "poc": 0, "score": 0.0, "kev": 0, "flags": []}, {"key": "CVE-2026-64322", "cve": "CVE-2026-64322", "lang": "en", "title": "CVE-2026-64322", "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\nudf: validate sparing table length as an entry count, not a byte count\n\nudf_load_sparable_map() accepts a sparing table when\n\n\tsizeof(*st) + le16_to_cpu(st->reallocationTableLen) > sb->s_blocksize\n\nis false, i.e. it treats reallocationTableLen as a number of BYTES that\nmust fit in the block.  But the table is walked as an array of 8-byte\nsparingEntry elements:\n\n\tfor (i = 0; i  reallocationTableLen); i++) {\n\t\tstruct sparingEntry *entry = &st->mapEntry[i];\n\t\t... entry->origLocation ...\n\t}\n\nin udf_get_pblock_spar15() and udf_relocate_blocks().  A\nreallocationTableLen of N therefore passes the check whenever\nsizeof(*st) + N  mapEntry[] is an out-of-bounds\nwrite.\n\nValidate reallocationTableLen as the entry count it is, with\nstruct_size().", "product": "Linux", "category": "cve", "source": "NVD", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-64322", "card": "CVE-2026-64322.webp?v=1784995622", "takeaways": [], "ts": 1784974633, "exploited": 0, "has_score": 0, "created": 1784995520, "updated": 1784995520, "exploited_text": 0, "poc": 0, "score": 0.0, "kev": 0, "flags": []}, {"key": "CVE-2026-64321", "cve": "CVE-2026-64321", "lang": "en", "title": "CVE-2026-64321", "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\nnvme: target: rdma: fix ndev refcount leak on queue connect\n\nnvmet_rdma_queue_connect() calls nvmet_rdma_find_get_device() which\nacquires a reference on the returned ndev via kref_get(). On the path\nwhere the host queue backlog is exceeded and the function returns\nNVME_SC_CONNECT_CTRL_BUSY, reference of ndev is not released, leaking\nthe kref.\n\nFix this by adding a goto to the existing put_device label before the\nearly return.", "product": "Linux", "category": "cve", "source": "NVD", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-64321", "card": "CVE-2026-64321.webp?v=1784995622", "takeaways": [], "ts": 1784974633, "exploited": 0, "has_score": 0, "created": 1784995520, "updated": 1784995520, "exploited_text": 0, "poc": 0, "score": 0.0, "kev": 0, "flags": []}, {"key": "CVE-2026-64320", "cve": "CVE-2026-64320", "lang": "en", "title": "CVE-2026-64320", "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\nnvmet: fix pre-auth out-of-bounds heap read in Discovery Get Log Page\n\nnvmet_execute_disc_get_log_page() validates only the dword alignment\nof the host-supplied Log Page Offset (lpo).  The 64-bit offset is then\nadded to a small kzalloc'd buffer that holds the discovery log page\nand the result is passed straight to nvmet_copy_to_sgl(), which\nmemcpy()s data_len bytes out to the host with no source-side bound\ncheck:\n\n    u64 offset      = nvmet_get_log_page_offset(req->cmd);  /* 64-bit host */\n    size_t data_len = nvmet_get_log_page_len(req->cmd);     /* 32-bit host */\n    ...\n    if (offset & 0x3) { ... }                               /* only check */\n    ...\n    alloc_len = sizeof(*hdr) + entry_size * discovery_log_entries(req);\n    buffer = kzalloc(alloc_len, GFP_KERNEL);\n    ...\n    status = nvmet_copy_to_sgl(req, 0, buffer + offset, data_len);\n\nThe Discovery controller is unauthenticated -- nvmet_host_allowed()\nreturns true unconditionally for the discovery subsystem -- so the call\nis reachable pre-authentication by any TCP/RDMA/FC peer that can reach\nthe nvmet target.  With a discovery log page of ~1 KiB, an a", "product": "Linux", "category": "cve", "source": "NVD", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-64320", "card": "CVE-2026-64320.webp?v=1784995622", "takeaways": [], "ts": 1784974633, "exploited": 0, "has_score": 0, "created": 1784995520, "updated": 1784995520, "exploited_text": 0, "poc": 0, "score": 0.0, "kev": 0, "flags": []}, {"key": "CVE-2026-64319", "cve": "CVE-2026-64319", "lang": "en", "title": "CVE-2026-64319", "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\nnvmet-auth: validate reply message payload bounds against transfer length\n\nnvmet_auth_reply() accesses the variable-length rval[] array using\nattacker-controlled hl (hash length) and dhvlen (DH value length) fields\nwithout verifying they fit within the allocated buffer of tl bytes.\n\nA malicious NVMe-oF initiator can craft a DHCHAP_REPLY message with a\nsmall transfer length but large hl/dhvlen values, causing out-of-bounds\nheap reads when the target processes the DH public key (rval + 2*hl) or\nperforms the host response memcmp.\n\nWith DH authentication configured, the OOB pointer is passed directly to\nsg_init_one() and read by crypto_kpp_compute_shared_secret(), reaching\nup to 526 bytes past the buffer. This is exploitable pre-authentication.\n\nAdd bounds validation ensuring sizeof(*data) + 2*hl + dhvlen <= tl before\nany access to the variable-length fields.\n\nDiscovered by Atuin - Automated Vulnerability Discovery Engine.", "product": "Linux", "category": "cve", "source": "NVD", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-64319", "card": "CVE-2026-64319.webp?v=1784995622", "takeaways": [], "ts": 1784974633, "exploited": 0, "has_score": 0, "created": 1784995520, "updated": 1784995520, "exploited_text": 0, "poc": 0, "score": 0.0, "kev": 0, "flags": []}, {"key": "CVE-2026-64318", "cve": "CVE-2026-64318", "lang": "en", "title": "CVE-2026-64318", "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\npartitions: aix: bound the pp_count scan to the ppe array\n\naix_partition() reads the physical volume descriptor into a fixed-size\nstruct pvd and then scans its physical-partition-extent array:\n\n\tint numpps = be16_to_cpu(pvd->pp_count);\n\t...\n\tfor (i = 0; i  ppe + i;\n\t\t...\n\t\tlp_ix = be16_to_cpu(p->lp_ix);\n\npvd points at a single kmalloc()'d struct pvd whose ppe[] member holds a\nfixed ARRAY_SIZE(pvd->ppe) (1016) entries, but the loop runs up to the\non-disk pp_count.  pp_count is an unvalidated __be16 read straight from\nthe descriptor, so a crafted AIX image with pp_count larger than 1016\ndrives the loop to read pvd->ppe[i] past the end of the allocation (up\nto 65535 entries, ~2 MB out of bounds).\n\nThe partition scan runs without mounting anything, when a block device\nwith a crafted AIX/IBM partition table appears (an attacker-supplied\nimage attached with losetup -P, or a device auto-scanned by udev), via\nmsdos_partition() -> aix_partition().\n\nClamp the scan to the number of entries the ppe[] array can hold.", "product": "Linux", "category": "cve", "source": "NVD", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-64318", "card": "CVE-2026-64318.webp?v=1784995621", "takeaways": [], "ts": 1784974633, "exploited": 0, "has_score": 0, "created": 1784995520, "updated": 1784995520, "exploited_text": 0, "poc": 0, "score": 0.0, "kev": 0, "flags": []}, {"key": "CVE-2026-64317", "cve": "CVE-2026-64317", "lang": "en", "title": "CVE-2026-64317", "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\nisofs: bound Rock Ridge symlink components to the SL record\n\nget_symlink_chunk() and the SL handling in\nparse_rock_ridge_inode_internal() walk the variable-length components of\na Rock Ridge \"SL\" (symbolic link) record.  Each component is a two-byte\nheader (flags, len) followed by len bytes of text, so it occupies\nslp->len + 2 bytes.  Both loops read slp->len and advance to the next\ncomponent, and get_symlink_chunk() additionally does\nmemcpy(rpnt, slp->text, slp->len), but neither checks that the component\nlies within the SL record before dereferencing it.\n\nA crafted SL record whose component declares a len that runs past the\nrecord (rr->len) therefore triggers an out-of-bounds read of up to 255\nbytes.  When the record sits at the tail of its backing buffer - for\nexample a small kmalloc()ed continuation block reached through a CE\nrecord - the read crosses the allocation; get_symlink_chunk() then\ncopies the out-of-bounds bytes into the symlink body returned to user\nspace by readlink(), disclosing adjacent kernel memory.\n\nISO 9660 images are routinely mounted from untrusted removable media -\ndesktop environments auto", "product": "Linux", "category": "cve", "source": "NVD", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-64317", "card": "CVE-2026-64317.webp?v=1784995621", "takeaways": [], "ts": 1784974633, "exploited": 0, "has_score": 0, "created": 1784995520, "updated": 1784995520, "exploited_text": 0, "poc": 0, "score": 0.0, "kev": 0, "flags": []}, {"key": "CVE-2026-64316", "cve": "CVE-2026-64316", "lang": "en", "title": "CVE-2026-64316", "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\ncrypto: caam - use print_hex_dump_devel to guard key hex dumps\n\nUse print_hex_dump_devel() for dumping sensitive key material in\n*_setkey() and gen_split_key() to avoid leaking secrets at runtime when\nCONFIG_DYNAMIC_DEBUG is enabled.", "product": "Linux", "category": "cve", "source": "NVD", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-64316", "card": "CVE-2026-64316.webp?v=1784995624", "takeaways": [], "ts": 1784974632, "exploited": 0, "has_score": 0, "created": 1784995520, "updated": 1784995520, "exploited_text": 0, "poc": 0, "score": 0.0, "kev": 0, "flags": []}, {"key": "CVE-2026-64315", "cve": "CVE-2026-64315", "lang": "en", "title": "CVE-2026-64315", "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\ncrypto: caam - use print_hex_dump_devel to guard key hex dumps\n\nUse print_hex_dump_devel() for dumping sensitive key material in\n*_setkey() to avoid leaking secrets at runtime when CONFIG_DYNAMIC_DEBUG\nis enabled.", "product": "Linux", "category": "cve", "source": "NVD", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-64315", "card": "CVE-2026-64315.webp?v=1784995624", "takeaways": [], "ts": 1784974632, "exploited": 0, "has_score": 0, "created": 1784995520, "updated": 1784995520, "exploited_text": 0, "poc": 0, "score": 0.0, "kev": 0, "flags": []}, {"key": "CVE-2026-64314", "cve": "CVE-2026-64314", "lang": "en", "title": "CVE-2026-64314", "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\ncrypto: chacha20poly1305 - validate poly1305 template argument\n\nchachapoly_create() still accepts the compatibility poly1305 parameter\nin the template name, but it assumes the second template argument is\nalways present and immediately passes it to strcmp().\n\nWhen the argument is missing, crypto_attr_alg_name() returns an error\npointer. Check for that before comparing the name so malformed template\ninstantiations fail with an error instead of dereferencing the error\npointer in strcmp().\n\nThis matches the surrounding Crypto API template pattern where\ncrypto_attr_alg_name() results are validated before string-specific use.", "product": "Linux", "category": "cve", "source": "NVD", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-64314", "card": "CVE-2026-64314.webp?v=1784995624", "takeaways": [], "ts": 1784974632, "exploited": 0, "has_score": 0, "created": 1784995520, "updated": 1784995520, "exploited_text": 0, "poc": 0, "score": 0.0, "kev": 0, "flags": []}, {"key": "CVE-2026-64313", "cve": "CVE-2026-64313", "lang": "en", "title": "CVE-2026-64313", "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\ncrypto: ecc - Fix carry overflow in vli multiplication\n\nThe carry flag calculation fails when r01.m_high is saturated\n(0xFFFFFFFFFFFFFFFF) and addition of lower bits overflows.\n\nThe condition (r01.m_high < product.m_high) doesn't handle the case\nwhere r01.m_high == product.m_high and an additional carry exists\nfrom lower-bit overflow.\n\nWhen commit 3c4b23901a0c (\"crypto: ecdh - Add ECDH software support\")\nintroduced crypto/ecc.c, it split the muladd() function in the\nmicro-ecc library into separate mul_64_64() and add_128_128() helpers.\nIt seems the check got lost in translation.\n\nAdd proper handling for this boundary by accounting for the carry\nfrom the lower addition.", "product": "Linux", "category": "cve", "source": "NVD", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-64313", "card": "CVE-2026-64313.webp?v=1784995624", "takeaways": [], "ts": 1784974632, "exploited": 0, "has_score": 0, "created": 1784995520, "updated": 1784995520, "exploited_text": 0, "poc": 0, "score": 0.0, "kev": 0, "flags": []}, {"key": "CVE-2026-64312", "cve": "CVE-2026-64312", "lang": "en", "title": "CVE-2026-64312", "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\ncrypto: pcrypt - restore callback for non-parallel fallback\n\npcrypt installs pcrypt_aead_done() on the child AEAD request before\ntrying to submit it through padata.  If padata_do_parallel() returns\n-EBUSY, pcrypt falls back to calling the child AEAD directly.\n\nThat fallback must not keep the padata completion callback.  Otherwise\nan asynchronous completion runs pcrypt_aead_done() even though the\nrequest was never enrolled in padata.\n\nRestore the original request callback and callback data before calling\nthe child AEAD directly.  This keeps the fallback path aligned with a\ndirect AEAD request while leaving the parallel path unchanged.", "product": "Linux", "category": "cve", "source": "NVD", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-64312", "card": "CVE-2026-64312.webp?v=1784995624", "takeaways": [], "ts": 1784974632, "exploited": 0, "has_score": 0, "created": 1784995520, "updated": 1784995520, "exploited_text": 0, "poc": 0, "score": 0.0, "kev": 0, "flags": []}, {"key": "CVE-2026-64311", "cve": "CVE-2026-64311", "lang": "en", "title": "CVE-2026-64311", "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\ncrypto: loongson - Remove broken and unused loongson-rng\n\nThe loongson-rng rng_alg has several vulnerabilities, including not\nproviding forward security, and a use-after-free bug due to the use of\nwait_for_completion_interruptible().\n\nMeanwhile, the rng_alg framework doesn't really have any purpose in the\nfirst place other than to access the software algorithms crypto/drbg.c\nand crypto/jitterentropy.c.  Hardware-specific rng_algs have no\nin-kernel user, and unlike hwrng there's no feed into the actual Linux\nRNG.  As such, there's really no point to this code.  There are of\ncourse other rng_alg drivers that are similarly unused, but they're\nsimilarly in the process of being phased out, e.g.\nhttps://lore.kernel.org/r/20260529193648.18172-1-ebiggers@kernel.org and\nhttps://lore.kernel.org/r/20260529220430.34135-1-ebiggers@kernel.org\n\nGiven that, there's no point in fixing forward these vulnerabilities,\nand it makes much more sense to simply roll back the addition of this\ndriver.  If this platform provides TRNG (not PRNG) functionality, it\ncould make sense to add a hwrng driver, but it would be quite different.", "product": "Linux", "category": "cve", "source": "NVD", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-64311", "card": "CVE-2026-64311.webp?v=1784995623", "takeaways": [], "ts": 1784974632, "exploited": 0, "has_score": 0, "created": 1784995520, "updated": 1784995520, "exploited_text": 0, "poc": 0, "score": 0.0, "kev": 0, "flags": []}, {"key": "CVE-2026-64310", "cve": "CVE-2026-64310", "lang": "en", "title": "CVE-2026-64310", "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\ncrypto: ccp - Do not initialize SNP for SEV ioctls\n\nSashiko notes:\n\n> if SEV initialization fails and KVM is actively running normal VMs, could a\n> userspace process trigger this code path via /dev/sev ioctls (e.g.,\n> SEV_PDH_GEN) and zero out MSR_VM_HSAVE_PA globally? Would the next VMRUN\n> execution for an active VM trigger a general protection fault and crash the\n> host?\n\nsev_move_to_init_state() is called for ioctls requiring only SEV firmware:\nSEV_PEK_GEN, SEV_PDH_GEN, SEV_PEK_CSR, SEV_PEK_CERT_IMPORT, and\nSEV_PDH_CERT_EXPORT. After the firmware command, it does SEV_SHUTDOWN on\nthe SEV firmware. Since these commands do not require SNP to be\ninitialized, skip it by calling __sev_platform_init_locked() which only\ninitializes the SEV firmware. This way SNP is not Initialized at all, and\nHSAVE_PA is not cleared.\n\nThe previous code saved any SEV initialization firmware error to\ninit_args.error and then threw it away and hardcoded the return value of\nINVALID_PLATFORM_STATE regardless of the real firmware error. This patch\nchanges it to surface the underlying error, which is hopefully both more\nuseful and doesn't ca", "product": "Linux", "category": "cve", "source": "NVD", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-64310", "card": "CVE-2026-64310.webp?v=1784995623", "takeaways": [], "ts": 1784974632, "exploited": 0, "has_score": 0, "created": 1784995520, "updated": 1784995520, "exploited_text": 0, "poc": 0, "score": 0.0, "kev": 0, "flags": []}, {"key": "CVE-2026-64309", "cve": "CVE-2026-64309", "lang": "en", "title": "CVE-2026-64309", "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\ncrypto: ccp - Do not initialize SNP for ioctl(SNP_COMMIT)\n\nSashiko notes:\n\n> if SEV initialization fails and KVM is actively running normal VMs, could a\n> userspace process trigger this code path via /dev/sev ioctls (e.g.,\n> SEV_PDH_GEN) and zero out MSR_VM_HSAVE_PA globally? Would the next VMRUN\n> execution for an active VM trigger a general protection fault and crash the\n> host?\n\nThe SNP_COMMIT command does not require the firmware to be in any\nparticular state. Skip initializing it if it was previously uninitialized.\n\nThe SEV-SNP firmware specification doc 56860 does not mention SNP_COMMIT in\nTable 5 as a command that is allowed in the UNINIT state, but it is in fact\nallowed and a future documentation update will reflect that.", "product": "Linux", "category": "cve", "source": "NVD", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-64309", "card": "CVE-2026-64309.webp?v=1784995623", "takeaways": [], "ts": 1784974632, "exploited": 0, "has_score": 0, "created": 1784995520, "updated": 1784995520, "exploited_text": 0, "poc": 0, "score": 0.0, "kev": 0, "flags": []}, {"key": "CVE-2026-64308", "cve": "CVE-2026-64308", "lang": "en", "title": "CVE-2026-64308", "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\ncrypto: ccp - Do not initialize SNP for ioctl(SNP_VLEK_LOAD)\n\nSashiko notes:\n\n> if SEV initialization fails and KVM is actively running normal VMs, could a\n> userspace process trigger this code path via /dev/sev ioctls (e.g.,\n> SEV_PDH_GEN) and zero out MSR_VM_HSAVE_PA globally? Would the next VMRUN\n> execution for an active VM trigger a general protection fault and crash the\n> host?\n\nThe SEV firmware docs for SNP_VLEK_LOAD note:\n\n> On SNP_SHUTDOWN, the VLEK is deleted.\n\nThat is, the initialization/shutdown wrapper here is pointless, because the\nfirmware immediately throws away the key anyway. Instead, refuse to do\nanything if SNP has not been previously initialized.\n\nThis is an ABI break: before, this was a no-op and almost certainly a\nmistake by userspace, and now it returns -ENODEV. ABI compatibility could be\nmaintained here by simply returning 0 in the check instead.", "product": "Linux", "category": "cve", "source": "NVD", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-64308", "card": "CVE-2026-64308.webp?v=1784997987", "takeaways": [], "ts": 1784974631, "exploited": 0, "has_score": 0, "created": 1784997888, "updated": 1784997888, "exploited_text": 0, "poc": 0, "score": 0.0, "kev": 0, "flags": []}, {"key": "CVE-2026-64307", "cve": "CVE-2026-64307", "lang": "en", "title": "CVE-2026-64307", "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\ncrypto: ccp - Do not initialize SNP for ioctl(SNP_CONFIG)\n\nSashiko notes:\n\n> if SEV initialization fails and KVM is actively running normal VMs, could a\n> userspace process trigger this code path via /dev/sev ioctls (e.g.,\n> SEV_PDH_GEN) and zero out MSR_VM_HSAVE_PA globally? Would the next VMRUN\n> execution for an active VM trigger a general protection fault and crash the\n> host?\n\nRefuse to re-try initialization if SNP is not already initialized for\nSNP_CONFIG.\n\nThis is technically an ABI break: before if SNP initialization failed it\ncould be transparently retriggered by this ioctl, and if no VMs were\nrunning, everything worked fine. Hopefully this is enough of a corner case\nthat nobody will notice, but someone does, there are a few options:\n\n* do something like symbol_get() for kvm and refuse to initialize if KVM is\n  loaded\n* check each cpu's HSAVE_PA for non-zero data before re-initializing\n* once initialization has failed, continue to refuse to initialize until\n  the ccp module is unloaded", "product": "Linux", "category": "cve", "source": "NVD", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-64307", "card": "CVE-2026-64307.webp?v=1784997987", "takeaways": [], "ts": 1784974631, "exploited": 0, "has_score": 0, "created": 1784997888, "updated": 1784997888, "exploited_text": 0, "poc": 0, "score": 0.0, "kev": 0, "flags": []}, {"key": "CVE-2026-64306", "cve": "CVE-2026-64306", "lang": "en", "title": "CVE-2026-64306", "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\ncrypto: drbg - Fix returning success on failure in CTR_DRBG\n\ndrbg_ctr_generate() sometimes returns success when it fails, leaving the\noutput buffer uninitialized.  Fix it.", "product": "Linux", "category": "cve", "source": "NVD", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-64306", "card": "CVE-2026-64306.webp?v=1784997986", "takeaways": [], "ts": 1784974631, "exploited": 0, "has_score": 0, "created": 1784997888, "updated": 1784997888, "exploited_text": 0, "poc": 0, "score": 0.0, "kev": 0, "flags": []}, {"key": "CVE-2026-64305", "cve": "CVE-2026-64305", "lang": "en", "title": "CVE-2026-64305", "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\ncrypto: qat - protect service table iterations with service_lock\n\nThe service_table list is protected by service_lock when entries are\nadded or removed (in adf_service_add() and adf_service_remove()), but\nseveral functions iterate over the list without holding this lock.\n\nA concurrent adf_service_register() or adf_service_unregister() call\ncould modify the list during traversal, leading to list corruption or\na use-after-free.\n\nFix this by holding service_lock across all list_for_each_entry()\niterations of service_table in adf_dev_init(), adf_dev_start(),\nadf_dev_stop(), adf_dev_shutdown(), adf_dev_restarting_notify(),\nadf_dev_restarted_notify(), and adf_error_notifier().\n\nThe lock ordering is safe: callers of the static helpers (adf_dev_up()\nand adf_dev_down()) acquire state_lock before service_lock, and no\nevent_hld callback or service_lock holder ever acquires state_lock in\nthe reverse order.", "product": "Linux", "category": "cve", "source": "NVD", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-64305", "card": "CVE-2026-64305.webp?v=1784997986", "takeaways": [], "ts": 1784974631, "exploited": 0, "has_score": 0, "created": 1784997888, "updated": 1784997888, "exploited_text": 0, "poc": 0, "score": 0.0, "kev": 0, "flags": []}, {"key": "CVE-2026-64304", "cve": "CVE-2026-64304", "lang": "en", "title": "CVE-2026-64304", "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\ncrypto: qat - validate RSA CRT component lengths\n\nThe generic RSA key parser (rsa_helper.c) bounds each CRT component (p,\nq, dp, dq, qinv) by the modulus size n_sz, but qat_rsa_setkey_crt()\nallocates half-size DMA buffers (key_sz / 2) and right-aligns each\ncomponent with:\n\n    memcpy(dst + half_key_sz - len, src, len)\n\nWhen a CRT component is larger than half_key_sz the subtraction\nunderflows and memcpy writes past the DMA buffer, causing memory\ncorruption.\n\nAdd a len > half_key_sz check next to the existing !len check for each\nof the five CRT components so the driver falls back to the non-CRT path\ninstead of writing out of bounds.", "product": "Linux", "category": "cve", "source": "NVD", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-64304", "card": "CVE-2026-64304.webp?v=1784997986", "takeaways": [], "ts": 1784974631, "exploited": 0, "has_score": 0, "created": 1784997888, "updated": 1784997888, "exploited_text": 0, "poc": 0, "score": 0.0, "kev": 0, "flags": []}, {"key": "CVE-2026-64303", "cve": "CVE-2026-64303", "lang": "en", "title": "CVE-2026-64303", "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\nspi: fsl-lpspi: terminate the RX channel on TX prepare failure path\n\nWhen dmaengine_prep_slave_sg() fails for the TX channel, the error path\nterminates the TX DMA channel but leaves the RX channel running. Since\nthe RX channel was already submitted and issued prior to preparing\nthe TX descriptor, returning -EINVAL causes the SPI core to unmap the\nDMA buffers while the RX DMA engine continues writing to them, leading\nto potential memory corruption or use-after-free.\n\nTerminate the RX channel before returning on the TX prepare failure path.", "product": "Linux", "category": "cve", "source": "NVD", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-64303", "card": "CVE-2026-64303.webp?v=1784997986", "takeaways": [], "ts": 1784974631, "exploited": 0, "has_score": 0, "created": 1784997888, "updated": 1784997888, "exploited_text": 0, "poc": 0, "score": 0.0, "kev": 0, "flags": []}, {"key": "CVE-2026-64302", "cve": "CVE-2026-64302", "lang": "en", "title": "CVE-2026-64302", "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\nx86/mm: Fix freeing of PMD-sized vmemmap pages\n\nCommit bf9e4e30f353 (\"x86/mm: use pagetable_free()\"), switched from\nfreeing non-boot page tables through __free_pages() to\npagetable_free().\n\nHowever, the function is also called to free vmemmap pages.\n\nGiven that vmemmap pages are not page tables, already the page_ptdesc(page)\nis wrong. But worse, pagetable_free() calls:\n\n\t__free_pages(page, compound_order(page));\n\nSince vmemmap pages are not compound pages (see vmemmap_alloc_block())\n-- except for HVO, which doesn't apply here -- only first page of a\nPMD-sized vmemmap page is freed, leaking the other ones.\n\nFix it by properly decoupling pagetable and vmemmap freeing.\nfree_pagetable() no longer has to mess with SECTION_INFO, as only the\nvmemmap is marked like that in register_page_bootmem_memmap().\n\nThe indentation in remove_pmd_table() is messed up. Fix that while\ntouching it.\n\nBootmem info handling will soon be fixed up. For now, handle it\nsimilar to free_pagetable(), just avoiding the ifdef.\n\n[ dhansen: changelog munging. More imperative voice ]", "product": "Linux", "category": "cve", "source": "NVD", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-64302", "card": "CVE-2026-64302.webp?v=1784995625", "takeaways": [], "ts": 1784974631, "exploited": 0, "has_score": 0, "created": 1784995520, "updated": 1784995520, "exploited_text": 0, "poc": 0, "score": 0.0, "kev": 0, "flags": []}, {"key": "CVE-2026-64301", "cve": "CVE-2026-64301", "lang": "en", "title": "CVE-2026-64301", "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\nregulator: scmi: fix of_node refcount leak in scmi_regulator_probe()\n\nscmi_regulator_probe() calls of_find_node_by_name() which takes a\nreference on the returned device node. On the error path where\nprocess_scmi_regulator_of_node() fails, the function returns without\ncalling of_node_put() on the child node, leaking the reference.\n\nAdd of_node_put(np) on the error path to properly release the\nreference.", "product": "Linux", "category": "cve", "source": "NVD", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-64301", "card": "CVE-2026-64301.webp?v=1784995625", "takeaways": [], "ts": 1784974631, "exploited": 0, "has_score": 0, "created": 1784995520, "updated": 1784995520, "exploited_text": 0, "poc": 0, "score": 0.0, "kev": 0, "flags": []}, {"key": "CVE-2026-64300", "cve": "CVE-2026-64300", "lang": "en", "title": "CVE-2026-64300", "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\nperf/aux: Fix page UAF in map_range()\n\nmap_range() reads rb->aux_pages[], rb->aux_nr_pages and rb->aux_pgoff via\nperf_mmap_to_page() while holding only event->mmap_mutex. Those fields are\nserialized by rb->aux_mutex, and mmap_mutex is per event.\n\nThus, two events sharing one rb via PERF_EVENT_IOC_SET_OUTPUT can race\nrb_alloc_aux() with map_range(), leading to a page-UAF scenario as follows:\n\n  CPU 0                           CPU 1\n  =====                           =====\n  rb_alloc_aux()                  map_range()\n  [1]: allocate rb->aux_pages[0]\n  [2]: rb->aux_nr_pages++\n                                  [3]: perf_mmap_to_page()\n                                         returns rb->aux_pages[0]\n                                  [4]: map it as VM_PFNMAP\n  [5]: rb->aux_pgoff = 1\n\n  munmap the page\n  [6]: free rb->aux_pages[0]\n\nPages mapped as VM_PFNMAP have no refcount protection, so CPU 1 holds a\nmapping to a freed physical frame.\n\nFix this by taking rb->aux_mutex across the page walk in map_range().", "product": "Linux", "category": "cve", "source": "NVD", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-64300", "card": "CVE-2026-64300.webp?v=1784997989", "takeaways": [], "ts": 1784974630, "exploited": 0, "has_score": 0, "created": 1784997888, "updated": 1784997888, "exploited_text": 0, "poc": 0, "score": 0.0, "kev": 0, "flags": []}, {"key": "CVE-2026-64299", "cve": "CVE-2026-64299", "lang": "en", "title": "CVE-2026-64299", "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\ntracing: Prevent out-of-bounds read in glob matching\n\nString event fields are not necessarily NUL-terminated, so the filter\npredicate functions (filter_pred_string(), filter_pred_strloc() and\nfilter_pred_strrelloc()) pass the field length to the regex match\ncallbacks, and the length-aware matchers honour it.\n\nregex_match_glob() was the exception: it ignored the length and called\nglob_match(), which scans the string until it hits a NUL byte. Some\nstring fields are not NUL-terminated. One example is the dynamic char\narray of the xfs_* namespace tracepoints, which is copied without a\ntrailing NUL. For such a field, glob matching reads past the end of\nthe event field, causing a KASAN slab-out-of-bounds read in\nglob_match(), reached via regex_match_glob() and filter_match_preds()\nfrom the xfs_lookup tracepoint.\n\nAdd a length-bounded glob_match_len() and use it from regex_match_glob()\nso glob matching always stops at the field boundary. The matching loop\nis factored into a shared helper so glob_match() keeps its behaviour.", "product": "Linux", "category": "cve", "source": "NVD", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-64299", "card": "CVE-2026-64299.webp?v=1784997988", "takeaways": [], "ts": 1784974630, "exploited": 0, "has_score": 0, "created": 1784997888, "updated": 1784997888, "exploited_text": 0, "poc": 0, "score": 0.0, "kev": 0, "flags": []}, {"key": "CVE-2026-64298", "cve": "CVE-2026-64298", "lang": "en", "title": "CVE-2026-64298", "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\nNFSv4: include MAY_WRITE in open permission mask for O_TRUNC\n\nPOSIX requires write permission to truncate a file, so an open() that\nspecifies O_TRUNC must be authorized for write access regardless of the\nO_ACCMODE access mode.\n\nnfs_open_permission_mask() builds the access mask passed to\nnfs_may_open(), which is the local authorization gate for OPENs the\nclient serves itself from a cached write delegation via the\ncan_open_delegated() path in nfs4_try_open_cached().  The mask is\nderived from O_ACCMODE alone, so an open(O_RDONLY | O_TRUNC) against a\nfile the caller cannot write requests only MAY_READ and passes the\nlocal check.  The OPEN is then satisfied locally and the truncation is\nissued to the server as a SETATTR(size=0) over the delegation stateid,\nwhich the server accepts under standard write-delegation semantics.\nPOSIX requires that this open fail with EACCES.\n\nInclude MAY_WRITE in the mask whenever O_TRUNC is set so the local\ncheck matches the access the server would have enforced.", "product": "Linux", "category": "cve", "source": "NVD", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-64298", "card": "CVE-2026-64298.webp?v=1784997988", "takeaways": [], "ts": 1784974630, "exploited": 0, "has_score": 0, "created": 1784997888, "updated": 1784997888, "exploited_text": 0, "poc": 0, "score": 0.0, "kev": 0, "flags": []}, {"key": "CVE-2026-64297", "cve": "CVE-2026-64297", "lang": "en", "title": "CVE-2026-64297", "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\nmodule: decompress: check return value of module_extend_max_pages()\n\nmodule_extend_max_pages() calls kvrealloc() internally and returns\n-ENOMEM on allocation failure. The return value is never checked.\n\nIf the initial allocation fails, info->pages remains NULL and\ninfo->max_pages remains 0. Subsequent calls to module_get_next_page()\nwill attempt to dynamically grow the array by calling\nmodule_extend_max_pages(info, 0) since info->used_pages is 0. This\nresults in kvrealloc(NULL, 0) returning ZERO_SIZE_PTR, which is treated\nas a success, leading to a dereference of ZERO_SIZE_PTR and a kernel\noops.\n\nFix: add the missing error check after module_extend_max_pages() and\nreturn immediately on failure. This matches the pattern used by every\nother kvrealloc() caller in the module loading path.\n\n[Sami: Corrected the analysis in the commit message.]", "product": "Linux", "category": "cve", "source": "NVD", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-64297", "card": "CVE-2026-64297.webp?v=1784997988", "takeaways": [], "ts": 1784974630, "exploited": 0, "has_score": 0, "created": 1784997888, "updated": 1784997888, "exploited_text": 0, "poc": 0, "score": 0.0, "kev": 0, "flags": []}, {"key": "CVE-2026-64296", "cve": "CVE-2026-64296", "lang": "en", "title": "CVE-2026-64296", "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\nexfat: bound uniname advance in exfat_find_dir_entry()\n\nIn exfat_find_dir_entry(), each TYPE_EXTEND (file name) entry advances the\noutput pointer by a fixed amount while the loop guard only tracks the\naccumulated name length:\n\n\tif (++order == 2)\n\t\tuniname = p_uniname->name;\n\telse\n\t\tuniname += EXFAT_FILE_NAME_LEN;\n\tlen = exfat_extract_uni_name(ep, entry_uniname);\n\tname_len += len;\n\tunichar = *(uniname+len);\n\t*(uniname+len) = 0x0;\n\nuniname grows by EXFAT_FILE_NAME_LEN (15) per name entry, but name_len\ngrows only by the actual extracted length, which is shorter when a name\nfragment contains an early NUL.  The only guard is\n`name_len >= MAX_NAME_LENGTH`, so a crafted directory with many short\nname fragments lets uniname run far past the\np_uniname->name[MAX_NAME_LENGTH + 3] buffer while name_len stays small,\ncausing an out-of-bounds read and write at *(uniname+len).\n\nThe sibling extractor exfat_get_uniname_from_ext_entry() already stops\non a short fragment (the lockstep `len != EXFAT_FILE_NAME_LEN` guard\nadded in commit d42334578eba (\"exfat: check if filename entries exceeds\nmax filename length\")); exfat_find_dir_entry", "product": "Linux", "category": "cve", "source": "NVD", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-64296", "card": "CVE-2026-64296.webp?v=1784997988", "takeaways": [], "ts": 1784974630, "exploited": 0, "has_score": 0, "created": 1784997888, "updated": 1784997888, "exploited_text": 0, "poc": 0, "score": 0.0, "kev": 0, "flags": []}, {"key": "CVE-2026-64295", "cve": "CVE-2026-64295", "lang": "en", "title": "CVE-2026-64295", "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\nmm: page_ext: add count limit to page_ext_iter_next to prevent invalid PFN access\n\nThe page_ext iteration API does not validate if the PFN still belongs to a\nvalid section while advancing the iterator.  When dynamically adding\nmemory in the hotplug path, it can lead to a NULL pointer dereference\nduring page_ext_lookup at the boundary of the last valid section when\niterator count equals __pgcount.\n\nThe for_each_page_ext() macro calls page_ext_iter_next() as its loop\nincrement.  for_each_page_ext() does a \"__page_ext =\npage_ext_iter_next(&__iter)\" at the end.  This causes page_ext_iter_next()\nto increment iter->index past __pgcount and call page_ext_lookup(start_pfn\n+ __pgcount).  During memory hotplug (online), the PFN at start_pfn +\n__pgcount may belong to a section that has not yet been initialized,\ncausing page_ext_lookup() to trigger a NULL pointer dereference.\n\n[   14.555124][  T846] Call trace:\n[   14.555125][  T846]  lookup_page_ext+0x6c/0x108 (P)\n[   14.555127][  T846]  page_ext_lookup+0x30/0x3c\n[   14.555129][  T846]  __reset_page_owner+0x11c/0x260\n[   14.571201][  T846]  __free_pages_ok+0x5e8/0x8e0\n[   14", "product": "Linux", "category": "cve", "source": "NVD", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-64295", "card": "CVE-2026-64295.webp?v=1784997987", "takeaways": [], "ts": 1784974630, "exploited": 0, "has_score": 0, "created": 1784997888, "updated": 1784997888, "exploited_text": 0, "poc": 0, "score": 0.0, "kev": 0, "flags": []}, {"key": "CVE-2026-64294", "cve": "CVE-2026-64294", "lang": "en", "title": "CVE-2026-64294", "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\nmm: do file ownership checks with the proper mount idmap\n\nEver since idmapped mounts were introduced, inode ownership checks (for\nside-channel protection) in mincore() and madvise(MADV_PAGEOUT) were done\nagainst the nop_mnt_idmap, which completely ignores the file's mount's\nidmap.  This results in odd edgecases like:\n\n1) mount/bind-mount with an idmap userA:userB:1\n2) userB runs an owner_or_capable() check on file that is owned by userA\non-disk/in-memory, but owned by userB after idmap translation\n3) owner_or_capable() mysteriously fails as the correct idmap wasn't supplied\n\nIn the case of mincore/madvise MADV_PAGEOUT, this is usually benign,\nbecause file_permission(file, MAY_WRITE) will probably succeed, as it uses\nthe proper idmap internally, but it does not need to be the case on e.g a\n0444 file where even the owner itself doesn't have permissions to write to\nit.\n\nSince this is clearly not trivial to get right, introduce a\nfile_owner_or_capable() that can carry the correct semantics, and switch\nthe various users in mm to it.\n\nThe issue was found by manual code inspection & an off-list discussion\nwith Jan Kara.", "product": "Linux", "category": "cve", "source": "NVD", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-64294", "card": "CVE-2026-64294.webp?v=1784997987", "takeaways": [], "ts": 1784974630, "exploited": 0, "has_score": 0, "created": 1784997888, "updated": 1784997888, "exploited_text": 0, "poc": 0, "score": 0.0, "kev": 0, "flags": []}, {"key": "CVE-2026-64293", "cve": "CVE-2026-64293", "lang": "en", "title": "CVE-2026-64293", "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\niommufd: Use sizeof(*hdr) instead of sizeof(hdr) in veventq read\n\nThe bound-check in iommufd_veventq_fops_read() for the normal vEVENT\npath uses sizeof(hdr) where the surrounding code uses sizeof(*hdr):\n\n\tif (!vevent_for_lost_events_header(cur) &&\n\t    sizeof(hdr) + cur->data_len > count - done) {\n\nhdr is declared as struct iommufd_vevent_header *, so sizeof(hdr)\nevaluates to the size of the pointer.  Surrounding code uses\nsizeof(*hdr) consistently:\n\n\tif (done >= count || sizeof(*hdr) > count - done) {\n\t...\n\tif (copy_to_user(buf + done, hdr, sizeof(*hdr))) {\n\t...\n\tdone += sizeof(*hdr);\n\nstruct iommufd_vevent_header is currently 8 bytes (two __u32 fields,\nflags and sequence), so on 64-bit (sizeof(void *) == 8) the two\nexpressions happen to be equal and the check works as intended.\n\nOn 32-bit (sizeof(void *) == 4) the check under-counts the header by\n4 bytes: a vEVENT whose data_len causes 8 + cur->data_len to exceed\ncount - done while 4 + cur->data_len does not will pass the check,\nthen the loop will copy_to_user 8 bytes of header followed by data_len\nbytes of payload, writing past the user-supplied buffer.\n\nIt is ", "product": "Linux", "category": "cve", "source": "NVD", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-64293", "card": "CVE-2026-64293.webp?v=1784997987", "takeaways": [], "ts": 1784974630, "exploited": 0, "has_score": 0, "created": 1784997888, "updated": 1784997888, "exploited_text": 0, "poc": 0, "score": 0.0, "kev": 0, "flags": []}, {"key": "CVE-2026-64292", "cve": "CVE-2026-64292", "lang": "en", "title": "CVE-2026-64292", "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\niommufd: Move vevent memory allocation outside spinlock\n\nThe veventq memory allocation happens inside the spinlock. Given its depth\nis decided by the user space, this leaves a vulnerability, where userspace\ncan allocate large queues to exhaust atomic memory reserves.\n\nMove the allocation outside the spinlock and use GFP_NOWAIT, which can fail\nfast under memory pressure without dipping into the GFP_ATOMIC reserves or\ndirect-reclaiming from the threaded IRQ handler. On allocation failure,\nqueue the lost_events_header (so userspace learns of the drop) and return\n-ENOMEM so the caller learns of the kernel-side memory pressure.\n\nThis is intentionally distinct from the queue-overflow path, which also\nqueues the lost_events_header but returns 0: a full queue is an expected\nuserspace-pacing condition rather than a kernel error.\n\nA subsequent change will cap the upper bound of the veventq_depth.", "product": "Linux", "category": "cve", "source": "NVD", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-64292", "card": "CVE-2026-64292.webp?v=1784997990", "takeaways": [], "ts": 1784974629, "exploited": 0, "has_score": 0, "created": 1784997888, "updated": 1784997888, "exploited_text": 0, "poc": 0, "score": 0.0, "kev": 0, "flags": []}, {"key": "CVE-2026-64291", "cve": "CVE-2026-64291", "lang": "en", "title": "CVE-2026-64291", "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\niommufd: Set veventq_depth upper bound\n\niommufd_veventq_alloc() accepts any !0 veventq_depth from userspace, with\nan upper bound at U32_MAX.\n\nThis leaves a vulnerability where userspace can allocate excessively large\nqueues to exhaust kernel memory reserves.\n\nCap the veventq_depth (maximum number of entries) to 1 << 19, matching the\nmaximum number of entries in the SMMUv3 EVTQ (the largest use case today).", "product": "Linux", "category": "cve", "source": "NVD", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-64291", "card": "CVE-2026-64291.webp?v=1784997990", "takeaways": [], "ts": 1784974629, "exploited": 0, "has_score": 0, "created": 1784997888, "updated": 1784997888, "exploited_text": 0, "poc": 0, "score": 0.0, "kev": 0, "flags": []}, {"key": "CVE-2026-64290", "cve": "CVE-2026-64290", "lang": "en", "title": "CVE-2026-64290", "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\niommufd: Break the loop on failure in iommufd_fault_fops_read()\n\nOn a copy_to_user() failure inside the inner list_for_each_entry, only the\ninner loop breaks; the outer while re-fetches the just-restored fault group\nand retries the failing copy_to_user() forever, spinning the reader at 100%\nCPU with fault->mutex held.\n\nCheck rc after the inner loop and break the outer while as well.", "product": "Linux", "category": "cve", "source": "NVD", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-64290", "card": "CVE-2026-64290.webp?v=1784997990", "takeaways": [], "ts": 1784974629, "exploited": 0, "has_score": 0, "created": 1784997888, "updated": 1784997888, "exploited_text": 0, "poc": 0, "score": 0.0, "kev": 0, "flags": []}, {"key": "CVE-2026-64289", "cve": "CVE-2026-64289", "lang": "en", "title": "CVE-2026-64289", "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\niommufd: Set upper bounds on cache invalidation entry_num and entry_len\n\niommufd_hwpt_invalidate() takes a user-controlled entry_num and entry_len,\neach bounded only by U32_MAX. An entry_len beyond the kernel's struct size\nmakes the copy helper verify the extra bytes are zero, scanning that excess\nin one uninterruptible pass; a multi-gigabyte value over zeroed user memory\ntrips the soft-lockup watchdog.\n\nA large entry_num is the other half, driving the backend invalidation loop\nwith no reschedule. The VT-d nested handler, for one, copies each entry and\nflushes caches per iteration, pinning the CPU on a non-preemptible kernel.\n\nCap both in the ioctl. entry_len is held under PAGE_SIZE, above any request\nstruct, and entry_num under 1 << 19, the order of a hardware invalidation\nqueue and well beyond any real batch, bounding the per-call loop length.", "product": "Linux", "category": "cve", "source": "NVD", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-64289", "card": "CVE-2026-64289.webp?v=1784997990", "takeaways": [], "ts": 1784974629, "exploited": 0, "has_score": 0, "created": 1784997888, "updated": 1784997888, "exploited_text": 0, "poc": 0, "score": 0.0, "kev": 0, "flags": []}, {"key": "CVE-2026-64288", "cve": "CVE-2026-64288", "lang": "en", "title": "CVE-2026-64288", "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\nKVM: arm64: nv: Avoid dereferencing NULL VNCR pseudo-TLB\n\nVNCR TLB invalidation occurs from MMU notifiers or TLBI instructions,\nand either can race against a vcpu not being onlined yet (no pseudo-TLB\nallocated). Similarly, the TLB might be invalid, and the invalidation\nshould be skipped in this case.\n\nBoth kvm_invalidate_vncr_ipa() and kvm_invalidate_vncr_va() are\nexpected to perform the same checks, except that the latter doesn't\ncheck for the allocation and blindly dereferences the pointer.\n\nSolve this by introducing a new iterator built on top of the usual\nkvm_for_each_vcpu() that checks for both of the above conditions,\nand convert the two users to it.", "product": "Linux", "category": "cve", "source": "NVD", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-64288", "card": "CVE-2026-64288.webp?v=1784997990", "takeaways": [], "ts": 1784974629, "exploited": 0, "has_score": 0, "created": 1784997888, "updated": 1784997888, "exploited_text": 0, "poc": 0, "score": 0.0, "kev": 0, "flags": []}, {"key": "CVE-2026-64287", "cve": "CVE-2026-64287", "lang": "en", "title": "CVE-2026-64287", "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\nKVM: arm64: Bound used_lrs when flushing the pKVM hyp vCPU\n\nflush_hyp_vcpu() copies the host vGIC state into the hyp's private vCPU\non every run. The vGIC list register save and restore use used_lrs as\ntheir loop bound and expect it to stay within the number of implemented\nlist registers. While this is generally the case, flush_hyp_vcpu()\ncopies vgic_v3 verbatim and does not enforce this, so a value provided\nby the host is used at EL2 to index vgic_lr[] and access ICH_LR _EL2\n(host -> EL2).\n\nFix by clamping used_lrs to the number of implemented list registers\nafter the copy, as the trusted path already does in\nvgic_flush_lr_state(). The number of implemented list registers is\nconstant after init, so it is replicated once from\nkvm_vgic_global_state.nr_lr into hyp_gicv3_nr_lr rather than read on\nevery entry.", "product": "Linux", "category": "cve", "source": "NVD", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-64287", "card": "CVE-2026-64287.webp?v=1784997989", "takeaways": [], "ts": 1784974629, "exploited": 0, "has_score": 0, "created": 1784997888, "updated": 1784997888, "exploited_text": 0, "poc": 0, "score": 0.0, "kev": 0, "flags": []}, {"key": "CVE-2026-64286", "cve": "CVE-2026-64286", "lang": "en", "title": "CVE-2026-64286", "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\nKVM: arm64: Clear __hyp_running_vcpu when flushing the pKVM hyp vCPU\n\nflush_hyp_vcpu() copies the host vCPU context into the hyp's private\nvCPU on every run. ctxt_to_vcpu() expects a guest context to have a\nNULL __hyp_running_vcpu, which is only ever set on the host context, so\nthat it resolves the vCPU via container_of(). While this is generally\nthe case, flush_hyp_vcpu() copies the context verbatim and does not\nenforce this, so a value provided by the host is dereferenced at EL2\n(host -> EL2).\n\nFix by clearing __hyp_running_vcpu after the copy.", "product": "Linux", "category": "cve", "source": "NVD", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-64286", "card": "CVE-2026-64286.webp?v=1784997989", "takeaways": [], "ts": 1784974629, "exploited": 0, "has_score": 0, "created": 1784997888, "updated": 1784997888, "exploited_text": 0, "poc": 0, "score": 0.0, "kev": 0, "flags": []}, {"key": "CVE-2026-64285", "cve": "CVE-2026-64285", "lang": "en", "title": "CVE-2026-64285", "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\nKVM: SEV: Pin source page for write when adding CPUID data for SNP guest\n\nWhen populating a guest_memfd instance with the initial CPUID data for an\nSNP guest, acquire a writable pin on the source page as KVM will write back\nthe \"correct\" CPUID information if the userspace provided data is rejected\nby trusted firmware.  Because KVM writes to the source page using a kernel\nmapping, pinning for read could result in KVM clobbering read-only memory.\n\nNote, well-behaved VMMs are unlikely to be affected, as CPUID information\nis almost always dynamically generated by userspace, i.e. it's unlikely for\nthe CPUID information to be backed by a read-only mapping.\n\n[sean: rewrite shortlog and changelog, tag for stable@]", "product": "Linux", "category": "cve", "source": "NVD", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-64285", "card": "CVE-2026-64285.webp?v=1784997989", "takeaways": [], "ts": 1784974629, "exploited": 0, "has_score": 0, "created": 1784997888, "updated": 1784997888, "exploited_text": 0, "poc": 0, "score": 0.0, "kev": 0, "flags": []}, {"key": "CVE-2026-64284", "cve": "CVE-2026-64284", "lang": "en", "title": "CVE-2026-64284", "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\nKVM: x86: Ensure vendor's exit handler runs before fastpath userspace exits\n\nMove the handling of fastpath userspace exits into vendor code to ensure\nKVM runs vendor specific operations that need to run before userspace gains\ncontrol of the vCPU.  E.g. for VMX (and soon to be for SVM as well), KVM\nneeds to flush the PML buffer prior to exiting to userspace, otherwise any\nmemory written by the final KVM_RUN might never be flagged as dirty.\n\nNote, waiting to snapshot CR0 and CR3 until svm_handle_exit() is flawed in\ngeneral, as that risks consuming stale state in a fastpath handler.  That\nwill be addressed in a future change.", "product": "Linux", "category": "cve", "source": "NVD", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-64284", "card": "CVE-2026-64284.webp?v=1784997989", "takeaways": [], "ts": 1784974629, "exploited": 0, "has_score": 0, "created": 1784997888, "updated": 1784997888, "exploited_text": 0, "poc": 0, "score": 0.0, "kev": 0, "flags": []}, {"key": "CVE-2026-64283", "cve": "CVE-2026-64283", "lang": "en", "title": "CVE-2026-64283", "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\nKVM: guest_memfd: Treat memslot binding offset+size as unsigned values\n\nWhen binding a memslot to a guest_memfd file, treat the offset and size as\nunsigned values to fix a bug where the sum of the two can result in a false\nnegative when checking for overflow against the size of the file.  Passing\nunsigned values also avoids relying on somewhat obscure checks in other\nflows for safety, and tracks the offset and size as they are intended to be\ntracked, as unsigned values.\n\nOn 64-bit kernels, the number of pages a memslot contains and thus the size\n(and offset) of its guest_memfd binding are unsigned 64-bit values.  Taking\nthe offset+size as an loff_t instead of a uoff_t inadvertently converts\nthe unsigned value to a signed value if the offset and/or size is massive.\n\nLocally storing the offset and size as signed values is benign in and of\nitself (though even that is *extremely* difficult to discern), but\noperating on their sum is not.\n\nFor the offset, KVM explicitly checks against a negative value, which might\nseem like a bug as KVM could incorrectly reject a legitimate binding, but\nthat's not actually the case as K", "product": "Linux", "category": "cve", "source": "NVD", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-64283", "card": "CVE-2026-64283.webp?v=1785000352", "takeaways": [], "ts": 1784974628, "exploited": 0, "has_score": 0, "created": 1785000251, "updated": 1785000251, "exploited_text": 0, "poc": 0, "score": 0.0, "kev": 0, "flags": []}, {"key": "CVE-2026-64282", "cve": "CVE-2026-64282", "lang": "en", "title": "CVE-2026-64282", "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\nKVM: arm64: Don't leak PFN when kvm_translate_vncr() races MMU notifier\n\nIn the case that kvm_translate_vncr() races with an MMU notifier the\nearly return does not release a reference on the faulted in PFN. Add\nthe necessary call to kvm_release_faultin_page() for the unused PFN.", "product": "Linux", "category": "cve", "source": "NVD", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-64282", "card": "CVE-2026-64282.webp?v=1785000352", "takeaways": [], "ts": 1784974628, "exploited": 0, "has_score": 0, "created": 1785000251, "updated": 1785000251, "exploited_text": 0, "poc": 0, "score": 0.0, "kev": 0, "flags": []}, {"key": "CVE-2026-64281", "cve": "CVE-2026-64281", "lang": "en", "title": "CVE-2026-64281", "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\nsvcrdma: wake sq waiters when the transport closes\n\nThreads parked in svc_rdma_sq_wait() on sc_sq_ticket_wait or\nsc_send_wait can hang indefinitely in TASK_UNINTERRUPTIBLE state\nacross transport teardown, pinning svc_xprt references and\nblocking svc_rdma_free().\n\nThe close path sets XPT_CLOSE before invoking xpo_detach and both\nwait_event predicates include an XPT_CLOSE term, but the\npredicates are re-evaluated only on wakeup. sc_sq_ticket_wait has\nno completion-driven wake path; it is advanced solely by the\nchained ticket handoff inside svc_rdma_sq_wait() itself. Without\nan explicit wake at close, parked threads never observe\nXPT_CLOSE, hold their svc_xprt_get reference forever, and\nsvc_rdma_free() blocks on xpt_ref dropping to zero.\n\nTwo close entry points reach this transport. Local teardown runs\nsvc_rdma_detach() from svc_handle_xprt() -> svc_delete_xprt() ->\nxpo_detach() on a worker thread. A remote disconnect arrives at\nsvc_rdma_cma_handler(), which calls svc_xprt_deferred_close():\nthat sets XPT_CLOSE and enqueues the transport but does not\naccess either RDMA waitqueue, so a worker already parked in\nsvc_rdma", "product": "Linux", "category": "cve", "source": "NVD", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-64281", "card": "CVE-2026-64281.webp?v=1785000352", "takeaways": [], "ts": 1784974628, "exploited": 0, "has_score": 0, "created": 1785000251, "updated": 1785000251, "exploited_text": 0, "poc": 0, "score": 0.0, "kev": 0, "flags": []}, {"key": "CVE-2026-64280", "cve": "CVE-2026-64280", "lang": "en", "title": "CVE-2026-64280", "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\nfpga: dfl-afu: validate DMA mapping length in afu_dma_map_region()\n\nafu_ioctl_dma_map() accepts a 64-bit length from userspace via\nDFL_FPGA_PORT_DMA_MAP ioctl without an upper bound check. The value\nis passed to afu_dma_pin_pages() where npages is derived as\nlength >> PAGE_SHIFT and passed to pin_user_pages_fast() which takes\nint nr_pages, causing implicit truncation if length is very large.\n\nValidate map.length at the ioctl entry point before calling\nafu_dma_map_region(), rejecting values whose page count exceeds\nINT_MAX.", "product": "Linux", "category": "cve", "source": "NVD", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-64280", "card": "CVE-2026-64280.webp?v=1785000352", "takeaways": [], "ts": 1784974628, "exploited": 0, "has_score": 0, "created": 1785000251, "updated": 1785000251, "exploited_text": 0, "poc": 0, "score": 0.0, "kev": 0, "flags": []}, {"key": "CVE-2026-64279", "cve": "CVE-2026-64279", "lang": "en", "title": "CVE-2026-64279", "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\ni2c: core: fix adapter deregistration race\n\nAdapters can be looked up by their id using i2c_get_adapter() which\ntakes a reference to the embedded struct device.\n\nRemove the adapter from the IDR before tearing it down during\nderegistration (and on registration failure) to make sure its resources\nare not accessed after having been freed (e.g. the device name).", "product": "Linux", "category": "cve", "source": "NVD", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-64279", "card": "CVE-2026-64279.webp?v=1785000351", "takeaways": [], "ts": 1784974628, "exploited": 0, "has_score": 0, "created": 1785000251, "updated": 1785000251, "exploited_text": 0, "poc": 0, "score": 0.0, "kev": 0, "flags": []}, {"key": "CVE-2026-64278", "cve": "CVE-2026-64278", "lang": "en", "title": "CVE-2026-64278", "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\ni2c: imx-lpi2c: mark I2C adapter when hardware is powered down\n\nOn some i.MX platforms, certain I2C client drivers keep a periodic\nworkqueue which continues to trigger I2C transfers.\n\nDuring system suspend/resume, there exists a time window between:\n  - suspend_noirq and the system entering suspend\n  - the system starting to resume and resume_noirq\n\nIn this window, the I2C controller resources such as clock and pinctrl\nmay already be disabled or not yet restored.\n\nIf a workqueue triggers an I2C transfer in this period, the driver\nattempts to access I2C registers while the hardware resources are\nunavailable, which may lead to system hang.\n\nMark the I2C adapter as suspended during noirq suspend and block new\ntransfers until resume, ensuring that I2C transfers are only issued\nwhen hardware resources are available.", "product": "Linux", "category": "cve", "source": "NVD", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-64278", "card": "CVE-2026-64278.webp?v=1785000351", "takeaways": [], "ts": 1784974628, "exploited": 0, "has_score": 0, "created": 1785000251, "updated": 1785000251, "exploited_text": 0, "poc": 0, "score": 0.0, "kev": 0, "flags": []}, {"key": "CVE-2026-64277", "cve": "CVE-2026-64277", "lang": "en", "title": "CVE-2026-64277", "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\nInput: synaptics-rmi4 - bound the F3A keymap to the GPIO count\n\nrmi_f3a_initialize() takes the GPIO count from the device query register\n(f3a->gpio_count = buf & RMI_F3A_GPIO_COUNT, range 0..127).\nrmi_f3a_map_gpios() then allocates gpio_key_map with\nmin(gpio_count, TRACKSTICK_RANGE_END) == at most 6 entries, but\nrmi_f3a_attention() iterates the full gpio_count and dereferences\ngpio_key_map[i], and input->keycodemax is set to the full gpio_count\nwhile input->keycode points at the 6-entry allocation.\n\nA device that reports gpio_count > 6 therefore causes an out-of-bounds\nread of gpio_key_map[] on every attention interrupt, and out-of-bounds\naccesses through the input core's default keymap ioctls: EVIOCGKEYCODE\nreads past the buffer (leaking adjacent slab memory to user space) and\nEVIOCSKEYCODE writes a caller-controlled value past it, for any process\nable to open the evdev node, since input_default_getkeycode() and\ninput_default_setkeycode() only bound the index against keycodemax.\n\nSize the keymap for the full gpio_count. The mapping loop is unchanged:\nit still assigns only the first min(gpio_count, TRACKSTICK_RANG", "product": "Linux", "category": "cve", "source": "NVD", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-64277", "card": "CVE-2026-64277.webp?v=1784997991", "takeaways": [], "ts": 1784974628, "exploited": 0, "has_score": 0, "created": 1784997888, "updated": 1784997888, "exploited_text": 0, "poc": 0, "score": 0.0, "kev": 0, "flags": []}, {"key": "CVE-2026-64276", "cve": "CVE-2026-64276", "lang": "en", "title": "CVE-2026-64276", "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\nInput: synaptics-rmi4 - bound the F30 keymap to the GPIO/LED count\n\nrmi_f30_map_gpios() allocates gpioled_key_map with\nmin(gpioled_count, TRACKSTICK_RANGE_END) == at most 6 entries, but\nrmi_f30_attention() iterates the full f30->gpioled_count (device query\nregister, range 0..31) and dereferences gpioled_key_map[i], and\ninput->keycodemax is set to the full gpioled_count while input->keycode\npoints at the 6-entry allocation.\n\nA device that reports gpioled_count > 6 with GPIO support enabled\ntherefore causes an out-of-bounds read on the attention interrupt and\nout-of-bounds read/write through the EVIOCGKEYCODE/EVIOCSKEYCODE ioctls,\nwhich bound the index only against keycodemax. This is the same defect\nas the F3A handler, which was copied from F30.\n\nSize the keymap for the full gpioled_count; the mapping loop still\nassigns only the first min(gpioled_count, TRACKSTICK_RANGE_END) entries.", "product": "Linux", "category": "cve", "source": "NVD", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-64276", "card": "CVE-2026-64276.webp?v=1784997991", "takeaways": [], "ts": 1784974628, "exploited": 0, "has_score": 0, "created": 1784997888, "updated": 1784997888, "exploited_text": 0, "poc": 0, "score": 0.0, "kev": 0, "flags": []}, {"key": "CVE-2026-64275", "cve": "CVE-2026-64275", "lang": "en", "title": "CVE-2026-64275", "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\nInput: elan_i2c - prevent division by zero and arithmetic underflow\n\nThe Elan I2C touchpad driver queries the device for its physical\ndimensions and trace counts to calculate the device resolution and width.\nHowever, if the device firmware or device tree provides invalid zero\nvalues for x_traces or y_traces, it results in a fatal division-by-zero\nexception leading to a kernel panic during device probe.\n\nAdd checks to ensure these parameters are non-zero before performing\nthe division. If invalid trace values are detected, fall back to a safe\ndefault of 1.\n\nAdditionally, prevent an arithmetic underflow in the touch reporting\nlogic. Previously, if the calculated or fallback width was smaller than\nETP_FWIDTH_REDUCE (90), the subtraction would underflow, resulting in a\nmassive unsigned integer being reported to userspace. Clamp the adjusted\nwidth to a minimum of 0 to safely handle small physical dimensions and\nfallback scenarios.\n\nCompleting the probe with safe fallback values ensures the sysfs nodes\nare created, keeping the firmware update path intact so a recovery\nfirmware can be flashed to the device.", "product": "Linux", "category": "cve", "source": "NVD", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-64275", "card": "CVE-2026-64275.webp?v=1785000354", "takeaways": [], "ts": 1784974627, "exploited": 0, "has_score": 0, "created": 1785000251, "updated": 1785000251, "exploited_text": 0, "poc": 0, "score": 0.0, "kev": 0, "flags": []}, {"key": "CVE-2026-64274", "cve": "CVE-2026-64274", "lang": "en", "title": "CVE-2026-64274", "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\nInput: goodix - clamp the device-reported contact count\n\ngoodix_ts_read_input_report() copies the number of touch points reported\nby the device into an on-stack buffer\n\n\tu8 point_data[2 + GOODIX_MAX_CONTACT_SIZE * GOODIX_MAX_CONTACTS];\n\nwhich is sized for at most GOODIX_MAX_CONTACTS (10) contacts. The only\nruntime check bounds the per-interrupt count against ts->max_touch_num,\nbut that value is taken verbatim from a 4-bit field of the device\nconfiguration block and is never clamped:\n\n\tts->max_touch_num = ts->config[MAX_CONTACTS_LOC] & 0x0f;\n\nThe nibble can be 0..15, so a malfunctioning, malicious or counterfeit\ncontroller (or an attacker tampering with the I2C bus) can advertise up\nto 15 contacts. goodix_ts_read_input_report() then accepts a touch_num\nof up to 15 and the second goodix_i2c_read() writes\nts->contact_size * (touch_num - 1) bytes past the one-contact header into\npoint_data - up to 30 bytes (45 with the 9-byte report format) beyond the\n92-byte buffer: a stack out-of-bounds write.\n\nClamp max_touch_num to GOODIX_MAX_CONTACTS, the number of contacts\npoint_data[] is sized for, when reading it from the conf", "product": "Linux", "category": "cve", "source": "NVD", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-64274", "card": "CVE-2026-64274.webp?v=1785000354", "takeaways": [], "ts": 1784974627, "exploited": 0, "has_score": 0, "created": 1785000251, "updated": 1785000251, "exploited_text": 0, "poc": 0, "score": 0.0, "kev": 0, "flags": []}, {"key": "CVE-2026-64273", "cve": "CVE-2026-64273", "lang": "en", "title": "CVE-2026-64273", "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\nInput: iforce - bound the device-reported force-feedback effect index\n\niforce_process_packet() handles a status report (packet id 0x02) by\ntaking a force-feedback effect index straight from the device wire and\nusing it to address the per-effect state array:\n\n\ti = data[1] & 0x7f;\n\tif (data[1] & 0x80) {\n\t\tif (!test_and_set_bit(FF_CORE_IS_PLAYED,\n\t\t\t\t      iforce->core_effects[i].flags))\n\t\t\t...\n\t} else if (test_and_clear_bit(FF_CORE_IS_PLAYED,\n\t\t\t\t      iforce->core_effects[i].flags)) {\n\t\t...\n\t}\n\nThe index is masked only with 0x7f, so it ranges 0..127, but\ncore_effects[] holds only IFORCE_EFFECTS_MAX (32) entries.  For an index\nof 32..127 the test_and_set_bit()/test_and_clear_bit() is an\nout-of-bounds single-bit read-modify-write past the array.  core_effects[]\nis the second-to-last member of struct iforce, so the write lands in the\ntrailing members and beyond the embedding kzalloc()'d iforce_serio /\niforce_usb object.\n\ndata[1] is unvalidated device payload on both transports (the USB\ninterrupt endpoint and serio), and the status path is not gated on force\nfeedback being present, so a malicious or counterfeit device ", "product": "Linux", "category": "cve", "source": "NVD", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-64273", "card": "CVE-2026-64273.webp?v=1785000354", "takeaways": [], "ts": 1784974627, "exploited": 0, "has_score": 0, "created": 1785000251, "updated": 1785000251, "exploited_text": 0, "poc": 0, "score": 0.0, "kev": 0, "flags": []}, {"key": "CVE-2026-64272", "cve": "CVE-2026-64272", "lang": "en", "title": "CVE-2026-64272", "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\nInput: mms114 - fix touch indexing for MMS134S and MMS136\n\nThe MMS134S and MMS136 touch controllers have an event size of 6 bytes\nrather than 8 bytes. When __mms114_read_reg() reads the touch data\npacket from the device into the touch buffer, the events are packed\ntightly at 6-byte intervals. However, the driver iterates through the\nevents using standard C array indexing (touch[index]), where each\nelement is sizeof(struct mms114_touch) (8 bytes) apart. As a result, any\ntouch events beyond the first one are read from incorrect offsets and\nparsed improperly.\n\nFix this by explicitly calculating the byte offset for each touch event\nbased on the device's specific event size.", "product": "Linux", "category": "cve", "source": "NVD", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-64272", "card": "CVE-2026-64272.webp?v=1785000353", "takeaways": [], "ts": 1784974627, "exploited": 0, "has_score": 0, "created": 1785000251, "updated": 1785000251, "exploited_text": 0, "poc": 0, "score": 0.0, "kev": 0, "flags": []}, {"key": "CVE-2026-64271", "cve": "CVE-2026-64271", "lang": "en", "title": "CVE-2026-64271", "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\nInput: touchwin - reset the packet index on every complete packet\n\ntw_interrupt() accumulates each non-zero serial byte into a fixed\nthree-byte buffer with a running index that is only reset once a full\npacket has been received *and* the device's two Y bytes agree:\n\n\ttw->data[tw->idx++] = data;\n\tif (tw->idx == TW_LENGTH && tw->data[1] == tw->data[2]) {\n\t\t...\n\t\ttw->idx = 0;\n\t}\n\nThe reset is gated on tw->data[1] == tw->data[2], a value the device\ncontrols.  A malicious, malfunctioning or counterfeit Touchwindow\nperipheral can stream non-zero bytes whose 2nd and 3rd bytes differ: the\nindex reaches TW_LENGTH without the equality holding, is never reset, and\nkeeps growing, so tw->data[tw->idx++] walks off the end of the three-byte\narray and the rest of the heap-allocated struct tw, one attacker-chosen\nbyte at a time -- an unbounded, device-driven heap out-of-bounds write.\n\nReset the index on every completed packet and report an event only when\nthe two Y bytes match, like the other serio touchscreen drivers do.", "product": "Linux", "category": "cve", "source": "NVD", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-64271", "card": "CVE-2026-64271.webp?v=1785000353", "takeaways": [], "ts": 1784974627, "exploited": 0, "has_score": 0, "created": 1785000251, "updated": 1785000251, "exploited_text": 0, "poc": 0, "score": 0.0, "kev": 0, "flags": []}, {"key": "CVE-2026-64270", "cve": "CVE-2026-64270", "lang": "en", "title": "CVE-2026-64270", "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\nInput: mms114 - reject an oversized device packet size\n\nmms114_interrupt() reads a packet of touch data from the device into a\nfixed-size on-stack buffer\n\n\tstruct mms114_touch touch[MMS114_MAX_TOUCH];\n\nwhich holds MMS114_MAX_TOUCH (10) events of MMS114_EVENT_SIZE (8) bytes,\ni.e. 80 bytes. The length of the I2C read into it is taken verbatim from\nthe device:\n\n\tpacket_size = mms114_read_reg(data, MMS114_PACKET_SIZE);\n\tif (packet_size <= 0)\n\t\tgoto out;\n\t...\n\terror = __mms114_read_reg(data, MMS114_INFORMATION, packet_size,\n\t\t\t(u8 *)touch);\n\npacket_size is a single device register byte (0x0F) and the only check\nis the lower bound packet_size <= 0; it is never bounded against the\nsize of touch[]. A malfunctioning, malicious or counterfeit controller\n(or an attacker tampering with the I2C bus) can report a packet_size of\nup to 255, so __mms114_read_reg() writes up to 175 bytes past the end of\ntouch[] on the IRQ-thread stack: a stack out-of-bounds write that can\noverwrite the stack canary, saved registers and the return address.\n\nA well-formed device never reports more than the buffer holds, so reject\nan oversized packet ", "product": "Linux", "category": "cve", "source": "NVD", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-64270", "card": "CVE-2026-64270.webp?v=1785000353", "takeaways": [], "ts": 1784974627, "exploited": 0, "has_score": 0, "created": 1785000251, "updated": 1785000251, "exploited_text": 0, "poc": 0, "score": 0.0, "kev": 0, "flags": []}, {"key": "CVE-2026-64269", "cve": "CVE-2026-64269", "lang": "en", "title": "CVE-2026-64269", "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\nRDMA/rtrs-srv: Bound RDMA-Write length to chunk size in rdma_write_sg\n\nWhen the server answers an RTRS READ, rdma_write_sg() builds the source\nscatter/gather entry for the IB_WR_RDMA_WRITE that returns data to the\npeer. Its length is taken directly from the wire descriptor:\n\n  plist->length = le32_to_cpu(id->rd_msg->desc[0].len);\n\nrd_msg points into the chunk buffer that the remote peer filled via\nRDMA-WRITE-WITH-IMM (rtrs_srv_rdma_done() -> process_io_req() ->\nprocess_read()), so desc[0].len is attacker-controlled and, before this\nchange, was only rejected when zero. The source address is the fixed\nchunk start (dma_addr[msg_id]) and the source lkey is the PD-wide\nlocal_dma_lkey, which is not tied to the chunk's MR mapping, so the verbs\nlayer does not constrain the transfer length to max_chunk_size. msg_id\nand off are bounded against queue_depth and max_chunk_size in\nrtrs_srv_rdma_done(), but desc[0].len is a separate field that was not\nchecked against the chunk size.\n\nA peer that advertises desc[0].len larger than max_chunk_size can make\nthe posted RDMA write read past the chunk's mapped region. The resulting\nbeh", "product": "Linux", "category": "cve", "source": "NVD", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-64269", "card": "CVE-2026-64269.webp?v=1785000353", "takeaways": [], "ts": 1784974627, "exploited": 0, "has_score": 0, "created": 1785000251, "updated": 1785000251, "exploited_text": 0, "poc": 0, "score": 0.0, "kev": 0, "flags": []}, {"key": "CVE-2026-64268", "cve": "CVE-2026-64268", "lang": "en", "title": "CVE-2026-64268", "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\nRDMA/siw: bound Read Response placement to the RREAD length\n\nIn drivers/infiniband/sw/siw/siw_qp_rx.c, siw_proc_rresp() places each\ninbound Read Response DDP segment at sge->laddr + wqe->processed and then\naccumulates wqe->processed, but it never checks the running total against\nthe sink buffer length on continuation segments. siw_check_sge() resolves\nand validates the sink memory only on the first fragment (the if (!*mem)\nbranch), and siw_rresp_check_ntoh() compares the cumulative length against\nwqe->bytes only on the final segment (the !frx->more_ddp_segs guard).\n\nA connected siw peer that answers an outstanding RREAD with Read Response\nsegments that keep the DDP Last flag clear, carrying more total payload\nthan the RREAD requested, drives wqe->processed past the validated sink\nbuffer; the next siw_rx_data() call writes out of bounds at\nsge->laddr + wqe->processed. siw runs iWARP over ordinary routable TCP,\nso the peer is the remote end of an established RDMA connection and needs\nno local privilege.\n\nBound every segment before placement, exactly as siw_proc_send() and\nsiw_proc_write() already do for their tagged", "product": "Linux", "category": "cve", "source": "NVD", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-64268", "card": "CVE-2026-64268.webp?v=1785000352", "takeaways": [], "ts": 1784974627, "exploited": 0, "has_score": 0, "created": 1785000251, "updated": 1785000251, "exploited_text": 0, "poc": 0, "score": 0.0, "kev": 0, "flags": []}, {"key": "CVE-2026-64267", "cve": "CVE-2026-64267", "lang": "en", "title": "CVE-2026-64267", "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\nfuse: avoid 32-bit prune notification count wrap\n\nFUSE_NOTIFY_PRUNE validates the nodeid payload length with:\n\n    size - sizeof(outarg) != outarg.count * sizeof(u64)\n\nOn 32-bit kernels, size_t is also 32 bits, so the daemon-controlled\ncount multiplication can wrap.  A prune notification with count\n0x20000000 and no nodeid payload passes the check, enters the copy\nloop, and asks the device copy path to read nodeids that are not\npresent in the userspace write buffer.  In QEMU this reaches the\nfuse_copy_fill() BUG_ON(!err) path.\n\nValidate the payload length with array_size() instead.  That accepts\nexactly the same valid messages, but avoids wrapping arithmetic before\nthe copy loop consumes the count.", "product": "Linux", "category": "cve", "source": "NVD", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-64267", "card": "CVE-2026-64267.webp?v=1785000356", "takeaways": [], "ts": 1784974626, "exploited": 0, "has_score": 0, "created": 1785000251, "updated": 1785000251, "exploited_text": 0, "poc": 0, "score": 0.0, "kev": 0, "flags": []}, {"key": "CVE-2026-64266", "cve": "CVE-2026-64266", "lang": "en", "title": "CVE-2026-64266", "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\nfuse: re-lock request before returning from fuse_ref_folio()\n\nfuse_ref_folio() unlocks the request but does not re-lock it before\nreturning. fuse_chan_abort() can end the request and the async end\ncallback (eg fuse_writepage_free()) can free the args while the\nsubsequent copy chain logic after fuse_ref_folio() accesses them,\nleading to use-after-free issues.\n\nFix this by locking the request in fuse_ref_folio() before returning.", "product": "Linux", "category": "cve", "source": "NVD", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-64266", "card": "CVE-2026-64266.webp?v=1785000356", "takeaways": [], "ts": 1784974626, "exploited": 0, "has_score": 0, "created": 1785000251, "updated": 1785000251, "exploited_text": 0, "poc": 0, "score": 0.0, "kev": 0, "flags": []}, {"key": "CVE-2026-64265", "cve": "CVE-2026-64265", "lang": "en", "title": "CVE-2026-64265", "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\nfuse: clear intr_entry in fuse_resend and fuse_remove_pending_req\n\nWhen fuse_resend() moves a request from fpq->processing back to\nfiq->pending, it sets FR_PENDING and clears FR_SENT but does not\nremove the requests intr_entry from fiq->interrupts.  If the\nrequest had FR_INTERRUPTED set from a prior signal, intr_entry\nremains dangling on fiq->interrupts.  When the requesting task\nthen receives a fatal signal, fuse_remove_pending_req() sees\nFR_PENDING=1, removes the request from fiq->pending and frees it\nvia the refcount path, also without cleaning intr_entry.  The\nstale intr_entry causes use-after-free when fuse_read_interrupt()\niterates fiq->interrupts:\n  - list_del_init(&req->intr_entry) -> UAF write on freed slab\n  - req->in.h.unique -> UAF read, data leaked to userspace\n\nRemove intr_entry from fiq->interrupts in fuse_resend() for\ninterrupted requests before they are placed back on fiq->pending.\n\nAdd a WARN_ON if the intr_entry is not empty on request destruction.", "product": "Linux", "category": "cve", "source": "NVD", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-64265", "card": "CVE-2026-64265.webp?v=1785000355", "takeaways": [], "ts": 1784974626, "exploited": 0, "has_score": 0, "created": 1785000251, "updated": 1785000251, "exploited_text": 0, "poc": 0, "score": 0.0, "kev": 0, "flags": []}, {"key": "CVE-2026-64264", "cve": "CVE-2026-64264", "lang": "en", "title": "CVE-2026-64264", "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\nfuse-uring: fix EFAULT clobber in fuse_uring_commit\n\ncopy_from_user() returns the number of bytes not copied as an unsigned\nresidual on failure (1..sizeof(struct fuse_out_header)). fuse_uring_commit\nstores that residual in ssize_t err, sets req->out.h.error to -EFAULT,\nthen jumps to out: with err still holding the positive residual.\n\n    err = copy_from_user(&req->out.h, &ent->headers->in_out,\n                         sizeof(req->out.h));\n    if (err) {\n        req->out.h.error = -EFAULT;\n        goto out;          /* err is the positive residual */\n    }\n    ...\n    out:\n        fuse_uring_req_end(ent, req, err);\n\nfuse_uring_req_end() then runs\n\n    if (error)\n        req->out.h.error = error;\n\nwhich overwrites the just-assigned -EFAULT with the positive residual.\nFUSE callers such as fuse_simple_request() test err  out.args.\n\nFix by assigning err = -EFAULT in the failure branch before jumping\nto out, so fuse_uring_req_end() receives a negative errno and sets\nreq->out.h.error to -EFAULT.", "product": "Linux", "category": "cve", "source": "NVD", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-64264", "card": "CVE-2026-64264.webp?v=1785000355", "takeaways": [], "ts": 1784974626, "exploited": 0, "has_score": 0, "created": 1785000251, "updated": 1785000251, "exploited_text": 0, "poc": 0, "score": 0.0, "kev": 0, "flags": []}, {"key": "CVE-2026-64263", "cve": "CVE-2026-64263", "lang": "en", "title": "CVE-2026-64263", "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\nfuse-uring: fix moving cancelled entry to ent_in_userspace list\n\nfuse_uring_cancel() moves entries that are available (these have no reqs\nattached) to the ent_in_userspace list. ent_list_request_expired()\nchecks the first entry on ent_in_userspace and dereferences\nent->fuse_req unconditionally, which will crash on a cancelled entry\nthat was moved to this list.\n\nFix this by freeing the entry and dropping queue_refs directly in\nfuse_uring_cancel(). This is safe because cancel is the cancel handler\nitself - after io_uring_cmd_done(), no more cancels will be dispatched\nfor this command, and teardown serializes with cancel via queue->lock.\n\nSince cancel now decrements queue_refs, fuse_uring_abort() must no\nlonger gate fuse_uring_abort_end_requests() on queue_refs > 0, as\ncancelled entries may have already dropped queue_refs while requests are\nstill queued. Remove the gate so abort always flushes requests and stops\nqueues.", "product": "Linux", "category": "cve", "source": "NVD", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-64263", "card": "CVE-2026-64263.webp?v=1785000355", "takeaways": [], "ts": 1784974626, "exploited": 0, "has_score": 0, "created": 1785000251, "updated": 1785000251, "exploited_text": 0, "poc": 0, "score": 0.0, "kev": 0, "flags": []}, {"key": "CVE-2026-64262", "cve": "CVE-2026-64262", "lang": "en", "title": "CVE-2026-64262", "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\nfuse-uring: end fuse_req on io-uring cancel task work\n\nWhen io_uring delivers task work with tw.cancel set (PF_EXITING,\nPF_KTHREAD fallback, or percpu_ref_is_dying on the ring context),\nfuse_uring_send_in_task() takes the cancel branch, assigns\n-ECANCELED, and falls through to fuse_uring_send(). That path only\nflips the entry to FRRS_USERSPACE and completes the io_uring cmd;\nit never discharges the ring entry's owning reference to the\nfuse_req that fuse_uring_add_req_to_ring_ent() handed it at\ndispatch time.\n\n    fuse_uring_send_in_task()\n      tw.cancel == true\n        err = -ECANCELED\n      fuse_uring_send(ent, cmd, err, issue_flags)\n        ent->state = FRRS_USERSPACE\n        list_move(&ent->list, &queue->ent_in_userspace)\n        ent->cmd = NULL\n        io_uring_cmd_done(-ECANCELED)\n        /* ent->fuse_req still set, req still hashed */\n\nThe fuse_req stays linked on fpq->processing[hash] and\nfuse_request_end() is never invoked. The originating syscall\nthread blocks in D-state in request_wait_answer() until\nfuse_abort_conn() runs, which can be the entire connection\nlifetime. For FR_BACKGROUND requests fc->num_", "product": "Linux", "category": "cve", "source": "NVD", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-64262", "card": "CVE-2026-64262.webp?v=1785000355", "takeaways": [], "ts": 1784974626, "exploited": 0, "has_score": 0, "created": 1785000251, "updated": 1785000251, "exploited_text": 0, "poc": 0, "score": 0.0, "kev": 0, "flags": []}, {"key": "CVE-2026-64261", "cve": "CVE-2026-64261", "lang": "en", "title": "CVE-2026-64261", "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\nfuse-uring: Avoid use-after-free in fuse_uring_async_stop_queues\n\nfuse_uring_async_stop_queues() might run when the last reference\non ring->queue_refs was already dropped.\n\nIn order to avoid an early destruction a reference on struct fuse_conn\nis now taken before starting fuse_uring_async_stop_queues() and that\nreference is only released when that delayed work queue terminates.", "product": "Linux", "category": "cve", "source": "NVD", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-64261", "card": "CVE-2026-64261.webp?v=1785000355", "takeaways": [], "ts": 1784974626, "exploited": 0, "has_score": 0, "created": 1785000251, "updated": 1785000251, "exploited_text": 0, "poc": 0, "score": 0.0, "kev": 0, "flags": []}, {"key": "CVE-2026-64260", "cve": "CVE-2026-64260", "lang": "en", "title": "CVE-2026-64260", "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\nfuse-uring: Avoid queue->stopped races and set/read that value under lock\n\nThere are several readers of queue->stopped that check the value\nunder lock, but fuse_uring_commit_fetch() did not and actually\nthe value was not set under the lock in fuse_uring_abort_end_requests()\neither. Especially in fuse_uring_commit_fetch it is important\nto check under a lock, because due to races 'struct fuse_req'\nmight be freed with fuse_request_end, but another thread/cpu\nmight already do teardown work.", "product": "Linux", "category": "cve", "source": "NVD", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-64260", "card": "CVE-2026-64260.webp?v=1785000354", "takeaways": [], "ts": 1784974626, "exploited": 0, "has_score": 0, "created": 1785000251, "updated": 1785000251, "exploited_text": 0, "poc": 0, "score": 0.0, "kev": 0, "flags": []}, {"key": "CVE-2026-64259", "cve": "CVE-2026-64259", "lang": "en", "title": "CVE-2026-64259", "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\nfuse-uring: make a fuse_req on SQE commit only findable after memcpy\n\nBad userspace might try to trick us and send commit SQEs request\nunique / commit-id of requests that are not even send to\nfuse-server (io_uring_cmd_done() not called) yet.\n\nfuse_uring_commit_fetch() ends the fuse request when the ring entry\nhas a wrong state, but that could have caused a use-after-free\nwith the memcpy operations in fuse_uring_send_in_task().\nIn order to avoid such races the call of fuse_uring_add_to_pq()\nis moved after the copy operations and just before completing\nthe io-uring request - malicious userspace cannot find the request\nanymore until all prepration work in fuse-client/kernel is completed.\n\nThis also moves fuse_uring_add_to_pq() a bit up in the code to\navoid a forward declaration. Also not with a preparation commit,\nto make it easier to back port to older kernels.", "product": "Linux", "category": "cve", "source": "NVD", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-64259", "card": "CVE-2026-64259.webp?v=1785000354", "takeaways": [], "ts": 1784974626, "exploited": 0, "has_score": 0, "created": 1785000251, "updated": 1785000251, "exploited_text": 0, "poc": 0, "score": 0.0, "kev": 0, "flags": []}, {"key": "CVE-2026-64258", "cve": "CVE-2026-64258", "lang": "en", "title": "CVE-2026-64258", "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\nfuse-uring: remove request-less entries from ent_w_req_queue to fix NULL deref\n\nIf a copy into the userspace ring buffer fails, a request will be\nterminated and fuse_uring_req_end() will set ent->fuse_req to NULL but\nit will leave the entry on ent_w_req_queue in FRRS_FUSE_REQ state. This\ncan lead to a NULL deref if the request expiration logic scans\nent_w_req_queue in the window before the entry is moved off it.\n\nFix this by taking the entry off ent_w_req_queue and changing its state\nfrom FRRS_FUSE_REQ to FRRS_INVALID before terminating the request.", "product": "Linux", "category": "cve", "source": "NVD", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-64258", "card": "CVE-2026-64258.webp?v=1785000356", "takeaways": [], "ts": 1784974625, "exploited": 0, "has_score": 0, "created": 1785000251, "updated": 1785000251, "exploited_text": 0, "poc": 0, "score": 0.0, "kev": 0, "flags": []}, {"key": "CVE-2026-64257", "cve": "CVE-2026-64257", "lang": "en", "title": "CVE-2026-64257", "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\nsmb: client: reject overlapping data areas in SMB2 responses\n\nCommit 53b7c271f06b (\"smb: client: restrict implied bcc[0] exemption to\nresponses without data area\") restricted the implied bcc[0] length\nexception to responses without a data area. However, the overlap\nhandling in __smb2_calc_size() clears data_length, which can make an\ninvalid response appear to have no data area and so qualify for the\nexception.\n\nTrack data area overlap separately and reject such responses before\napplying the length compatibility exceptions.", "product": "Linux", "category": "cve", "source": "NVD", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-64257", "card": "CVE-2026-64257.webp?v=1785000356", "takeaways": [], "ts": 1784974625, "exploited": 0, "has_score": 0, "created": 1785000251, "updated": 1785000251, "exploited_text": 0, "poc": 0, "score": 0.0, "kev": 0, "flags": []}, {"key": "CVE-2026-64256", "cve": "CVE-2026-64256", "lang": "en", "title": "CVE-2026-64256", "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\nxfs: don't wrap around quota ids in dqiterate\n\nLOLLM noticed that q_id is an unsigned 32-bit variable.  If it happens\nto be set to XFS_DQ_ID_MAX due to a filesystem that actually has a dquot\nfor ID_MAX, then this addition will truncate to zero and the iteration\nstarts over.  Fix this by casting to u64.", "product": "Linux", "category": "cve", "source": "NVD", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-64256", "card": "CVE-2026-64256.webp?v=1785002713", "takeaways": [], "ts": 1784974624, "exploited": 0, "has_score": 0, "created": 1785002614, "updated": 1785002614, "exploited_text": 0, "poc": 0, "score": 0.0, "kev": 0, "flags": []}, {"key": "CVE-2026-16766", "cve": "CVE-2026-16766", "lang": "en", "title": "CVE-2026-16766", "summary": "Catalyst::View::Wkhtmltopdf versions before 0.6.1 for Perl allow shell command injection (RCE) via PDF render options.\n\nOptions are passed directly to the wkhtmltopdf command without sanitization.\n\nAny web application that passes user-controlled options such as the page_size, orientation or margins without validation allows shell command injection.\n\nVersion 0.6.0 was released with an incomplete fix for this issue.\n\nNote that the wkhtmltopdf project is no longer being developed, and users of this package should migrate to alternative solutions.", "product": "RRWO Catalyst::View::Wkhtmltopdf", "category": "cve", "source": "NVD", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-16766", "card": "CVE-2026-16766.webp?v=1784971857", "takeaways": [], "ts": 1784970992, "exploited": 0, "has_score": 0, "created": 1784971759, "updated": 1784976482, "exploited_text": 0, "poc": 0, "score": 0.0, "kev": 0, "flags": []}, {"key": "CVE-2026-10818", "cve": "CVE-2026-10818", "lang": "en", "title": "CVE-2026-10818", "summary": "The WPForms Pro plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 1.10.1.1 via the ajax_chunk_upload_finalize function. This is due to the file type validation occurring after chunk metadata and file contents have already been written to disk, and the assembled file not being deleted upon validation failure. This makes it possible for unauthenticated attackers to upload files that may be executable, which makes remote code execution possible.", "product": "WPForms Pro", "category": "cve", "source": "NVD", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-10818", "card": "CVE-2026-10818.webp?v=1784964772", "takeaways": ["CVSS 3.1 : 8.1 HIGH", "Vector: AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H"], "ts": 1784963828, "exploited": 0, "has_score": 1, "created": 1784964649, "updated": 1784976482, "exploited_text": 0, "poc": 0, "score": 8.1, "kev": 0, "flags": []}, {"key": "CVE-2026-66374", "cve": "CVE-2026-66374", "lang": "en", "title": "CVE-2026-66374", "summary": "Knot Resolver before 6.4.1 allows remote code execution via a heap-based buffer overflow in the DoQ (DNS-over-QUIC) receive path.", "product": "nic Knot Resolver", "category": "cve", "source": "NVD", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-66374", "card": "CVE-2026-66374.webp?v=1784944213", "takeaways": ["CVSS 3.1 : 8.1 HIGH", "Vector: AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:H/A:L"], "ts": 1784942186, "exploited": 0, "has_score": 1, "created": 1784944093, "updated": 1784976482, "exploited_text": 0, "poc": 0, "score": 8.1, "kev": 0, "flags": []}, {"key": "CVE-2026-66373", "cve": "CVE-2026-66373", "lang": "en", "title": "CVE-2026-66373", "summary": "Redis before 8.8.0, in the unusual case where an authenticated attacker can execute RESTORE, allows remote code execution via a RESTORE payload where the same NACK (pending entry) is referenced by more than one consumer, because deleting both consumers via XGROUP DELCONSUMER leads to a double free. NOTE: this issue exists because of an incomplete fix for CVE-2026-25243.", "product": "Redis", "category": "cve", "source": "NVD", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-66373", "card": "CVE-2026-66373.webp?v=1784944213", "takeaways": ["CVSS 3.1 : 7.5 HIGH", "Vector: AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H"], "ts": 1784942186, "exploited": 0, "has_score": 1, "created": 1784944093, "updated": 1784976482, "exploited_text": 0, "poc": 0, "score": 7.5, "kev": 0, "flags": []}, {"key": "CVE-2026-61892", "cve": "CVE-2026-61892", "lang": "en", "title": "CVE-2026-61892", "summary": "Weintek cMT3092X HMI allows a non-privileged user to modify tokens to escalate privileges.", "product": "Weintek cMT3092X firmware", "category": "cve", "source": "NVD", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-61892", "card": "CVE-2026-61892.webp?v=1784936287", "takeaways": ["CVSS 4.0 : 8.7 HIGH", "Vector: AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N", "CVSS 3.1 : 8.8 HIGH"], "ts": 1784935011, "exploited": 0, "has_score": 1, "created": 1784936183, "updated": 1784976482, "exploited_text": 0, "poc": 0, "score": 8.7, "kev": 0, "flags": []}, {"key": "CVE-2026-61886", "cve": "CVE-2026-61886", "lang": "en", "title": "CVE-2026-61886", "summary": "Weintek cMT3092X HMI stores user account passwords in plaintext.", "product": "Weintek cMT3092X firmware", "category": "cve", "source": "NVD", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-61886", "card": "CVE-2026-61886.webp?v=1784936286", "takeaways": ["CVSS 4.0 : 7.1 HIGH", "Vector: AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N", "CVSS 3.1 : 6.5 MEDIUM"], "ts": 1784935011, "exploited": 0, "has_score": 1, "created": 1784936183, "updated": 1784976482, "exploited_text": 0, "poc": 0, "score": 7.1, "kev": 0, "flags": []}, {"key": "CVE-2026-60135", "cve": "CVE-2026-60135", "lang": "en", "title": "CVE-2026-60135", "summary": "An attacker can modify data that should be restricted to read‑only access.", "product": "Weintek cMT3092X firmware", "category": "cve", "source": "NVD", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-60135", "card": "CVE-2026-60135.webp?v=1784936286", "takeaways": ["CVSS 4.0 : 7.1 HIGH", "Vector: AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N", "CVSS 3.1 : 6.5 MEDIUM"], "ts": 1784935011, "exploited": 0, "has_score": 1, "created": 1784936183, "updated": 1784976482, "exploited_text": 0, "poc": 0, "score": 7.1, "kev": 0, "flags": []}, {"key": "CVE-2026-60134", "cve": "CVE-2026-60134", "lang": "en", "title": "CVE-2026-60134", "summary": "Weintek cMT3092X HMI allows a non-privileged user to modify cookies to gain elevated privileges.", "product": "Weintek cMT3092X firmware", "category": "cve", "source": "NVD", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-60134", "card": "CVE-2026-60134.webp?v=1784936287", "takeaways": ["CVSS 4.0 : 8.7 HIGH", "Vector: AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N", "CVSS 3.1 : 8.8 HIGH"], "ts": 1784935010, "exploited": 0, "has_score": 1, "created": 1784936183, "updated": 1784976482, "exploited_text": 0, "poc": 0, "score": 8.7, "kev": 0, "flags": []}, {"key": "CVE-2026-16280", "cve": "CVE-2026-16280", "lang": "en", "title": "CVE-2026-16280", "summary": "An integer overflow when calculating physical offsets for sparse PMRs may result in 32-bit truncation of address computations for PMRs larger than 4 GB. This can lead to incorrect GPU MMU mappings and may allow a non-privileged user to trigger access to unintended physical memory, resulting in memory corruption or information disclosure.", "product": "Imagination Technologies Graphics DDK", "category": "cve", "source": "NVD", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-16280", "card": "CVE-2026-16280.webp?v=1784936287", "takeaways": [], "ts": 1784935010, "exploited": 0, "has_score": 0, "created": 1784936183, "updated": 1784976482, "exploited_text": 0, "poc": 0, "score": 0.0, "kev": 0, "flags": []}, {"key": "CVE-2026-61884", "cve": "CVE-2026-61884", "lang": "en", "title": "CVE-2026-61884", "summary": "The web management interface of Tycon Systems TPDIN-Monitor-WEB2\n\n does not perform server-side validation of credentials during the login process. By submitting empty values for both credential fields, an unauthenticated remote attacker can bypass the authentication check and establish a valid administrative session. This grants full access to device controls including power relay management, device reboot, remote access service configuration, and network settings, which could allow an attacker to disrupt connected infrastructure or cause physical damage to equipment.", "product": "Tycon Systems TPDIN-Monitor-WEB2", "category": "cve", "source": "NVD", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-61884", "card": "CVE-2026-61884.webp?v=1784932363", "takeaways": ["CVSS 4.0 : 9.3 CRITICAL", "Vector: AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N", "CVSS 3.1 : 9.8 CRITICAL"], "ts": 1784931410, "exploited": 0, "has_score": 1, "created": 1784932251, "updated": 1784976482, "exploited_text": 0, "poc": 0, "score": 9.3, "kev": 0, "flags": []}, {"key": "CVE-2025-71408", "cve": "CVE-2025-71408", "lang": "en", "title": "CVE-2025-71408", "summary": "NLTK (Natural Language Toolkit) before version 3.9.3 contains an eval injection vulnerability in the nltk.collocations module that allows an attacker who controls command-line arguments to execute arbitrary Python code. When collocations.py is invoked directly, the __main__ block passes command-line arguments directly to eval() as suffixes of BigramAssocMeasures without allowlist validation or sanitization, enabling an attacker to supply a Python expression that escapes the intended attribute lookup and executes arbitrary code including OS commands via the os module.", "product": "ntlk", "category": "cve", "source": "NVD", "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-71408", "card": "CVE-2025-71408.webp?v=1784932361", "takeaways": ["CVSS 4.0 : 8.5 HIGH", "Vector: AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N", "CVSS 3.1 : 7.8 HIGH"], "ts": 1784931410, "exploited": 0, "has_score": 1, "created": 1784932251, "updated": 1784976482, "exploited_text": 0, "poc": 0, "score": 8.5, "kev": 0, "flags": []}, {"key": "CVE-2026-66041", "cve": "CVE-2026-66041", "lang": "en", "title": "CVE-2026-66041", "summary": "FFmpeg 7.0 through 8.1.2, fixed in commit 4da9812, contains a heap out-of-bounds write vulnerability in the vf_quirc filter that allows an attacker to corrupt heap memory by supplying a crafted PGS/SUP subtitle file with mismatched frame dimensions. Attackers can provide a subtitle file whose second presentation has larger dimensions than its first, causing av_image_copy_plane() to copy data exceeding the initial allocation size into the undersized libquirc grayscale image buffer, resulting in heap corruption and process crash with potential for code execution.", "product": "FFmpeg", "category": "cve", "source": "NVD", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-66041", "card": "CVE-2026-66041.webp?v=1784924503", "takeaways": ["CVSS 4.0 : 7.7 HIGH", "Vector: AV:N/AC:L/AT:P/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N", "CVSS 3.1 : 8.8 HIGH"], "ts": 1784924301, "exploited": 0, "has_score": 1, "created": 1784924397, "updated": 1784976482, "exploited_text": 0, "poc": 0, "score": 7.7, "kev": 0, "flags": []}, {"key": "CVE-2026-66040", "cve": "CVE-2026-66040", "lang": "en", "title": "CVE-2026-66040", "summary": "FFmpeg through 8.1.2, fixed in commit b506faf, contains a heap out-of-bounds write vulnerability in the native PNG and APNG encoders that allows remote attackers to corrupt heap memory by supplying a crafted PNG image with a malicious eXIf chunk. Attackers can craft an eXIf chunk where multiple IFD entries reference the same large value payload, causing canonical serialization to expand the output far beyond the undersized allocation estimated by add_exif_profile_size(), resulting in png_write_chunk() writing tens of thousands of bytes past the buffer boundary, leading to deterministic heap corruption, process crash, and potentially arbitrary code execution.", "product": "FFmpeg", "category": "cve", "source": "NVD", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-66040", "card": "CVE-2026-66040.webp?v=1784924503", "takeaways": ["CVSS 4.0 : 8.7 HIGH", "Vector: AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N", "CVSS 3.1 : 8.8 HIGH"], "ts": 1784924301, "exploited": 0, "has_score": 1, "created": 1784924397, "updated": 1784976482, "exploited_text": 0, "poc": 0, "score": 8.7, "kev": 0, "flags": []}, {"key": "CVE-2026-66039", "cve": "CVE-2026-66039", "lang": "en", "title": "CVE-2026-66039", "summary": "FFmpeg through 8.1.2, fixed in commit aafb5c6, contains a signed integer overflow vulnerability in the MACE6 audio decoder that allows attackers to corrupt heap memory by supplying a crafted CAF file with a malicious bytes_per_packet value. Attackers can craft a CAF file with oversized bytes_per_packet and frames_per_packet values in the desc chunk to trigger an integer overflow in mace_decode_frame() during output sample count computation, resulting in an undersized buffer allocation and heap out-of-bounds write that could enable code execution.", "product": "FFmpeg", "category": "cve", "source": "NVD", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-66039", "card": "CVE-2026-66039.webp?v=1784924504", "takeaways": ["CVSS 4.0 : 8.7 HIGH", "Vector: AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N", "CVSS 3.1 : 8.8 HIGH"], "ts": 1784924300, "exploited": 0, "has_score": 1, "created": 1784924397, "updated": 1784974118, "exploited_text": 0, "poc": 0, "score": 8.7, "kev": 0, "flags": []}, {"key": "CVE-2026-66038", "cve": "CVE-2026-66038", "lang": "en", "title": "CVE-2026-66038", "summary": "FFmpeg through 8.1.2, fixed in commit 8670835, contains an information disclosure vulnerability in the LCL/ZLIB video decoder that allows attackers to expose uninitialized heap memory by supplying a valid zlib stream that inflates to fewer bytes than the expected frame size. The zlib_decomp() function in lcldec.c treats short decompression as non-fatal and continues to the RGB24 conversion path, which copies a full frame's worth of rows from the allocation buffer using original frame dimensions, causing uninitialized heap contents including pointer-derived allocator bytes to be copied into the attacker-observable AVFrame output and potentially defeating ASLR in long-lived media processing services.", "product": "FFmpeg", "category": "cve", "source": "NVD", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-66038", "card": "CVE-2026-66038.webp?v=1784924504", "takeaways": ["CVSS 4.0 : 7.1 HIGH", "Vector: AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N", "CVSS 3.1 : 6.5 MEDIUM"], "ts": 1784924300, "exploited": 0, "has_score": 1, "created": 1784924397, "updated": 1784974118, "exploited_text": 0, "poc": 0, "score": 7.1, "kev": 0, "flags": []}, {"key": "CVE-2026-66037", "cve": "CVE-2026-66037", "lang": "en", "title": "CVE-2026-66037", "summary": "FFmpeg through 8.1.2, fixed in commit 5d7112c, contains an uncontrolled resource consumption vulnerability in the IAMF demuxer that allows an unauthenticated attacker to cause multi-gigabyte memory allocation from a 17-byte input file by supplying a crafted count_label field. The mix_presentation_obu() function in libavformat/iamf_parse.c calls av_calloc(count_label, sizeof(*language_label)) with an attacker-controlled value before validating available OBU data, enabling an allocation amplification of approximately 126 million bytes per input byte that exhausts process memory or triggers an OOM-kill during format probing.", "product": "FFmpeg", "category": "cve", "source": "NVD", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-66037", "card": "CVE-2026-66037.webp?v=1784924503", "takeaways": ["CVSS 4.0 : 7.1 HIGH", "Vector: AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N", "CVSS 3.1 : 6.5 MEDIUM"], "ts": 1784924300, "exploited": 0, "has_score": 1, "created": 1784924397, "updated": 1784976482, "exploited_text": 0, "poc": 0, "score": 7.1, "kev": 0, "flags": []}, {"key": "CVE-2026-66036", "cve": "CVE-2026-66036", "lang": "en", "title": "CVE-2026-66036", "summary": "FFmpeg through 8.1.2, fixed in commit 5d7112c, contains a heap out-of-bounds write vulnerability in the vf_hqdn3d filter that allows attackers to corrupt heap memory by supplying a crafted video whose frame resolution increases between frames when filtergraph reinitialization is disabled via the -reinit_filter 0 option. Attackers can provide a malicious video input where vf_hqdn3d.config_input() allocates undersized per-plane line-history buffers based on the initial frame width, and subsequent larger frames cause denoise_spatial() to write beyond the allocation boundary, resulting in heap memory corruption.", "product": "FFmpeg", "category": "cve", "source": "NVD", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-66036", "card": "CVE-2026-66036.webp?v=1784924503", "takeaways": ["CVSS 4.0 : 7.7 HIGH", "Vector: AV:N/AC:L/AT:P/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N", "CVSS 3.1 : 8.8 HIGH"], "ts": 1784924300, "exploited": 0, "has_score": 1, "created": 1784924397, "updated": 1784976482, "exploited_text": 0, "poc": 0, "score": 7.7, "kev": 0, "flags": []}, {"key": "CVE-2026-62835", "cve": "CVE-2026-62835", "lang": "en", "title": "CVE-2026-62835", "summary": "Improper authorization in Azure Portal allows an unauthorized attacker to disclose information over a network.", "product": "Microsoft Azure Portal", "category": "cve", "source": "NVD", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-62835", "card": "CVE-2026-62835.webp?v=1784924504", "takeaways": ["CVSS 3.1 : 9.3 CRITICAL", "Vector: AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:L"], "ts": 1784924299, "exploited": 0, "has_score": 1, "created": 1784924397, "updated": 1784974118, "exploited_text": 0, "poc": 0, "score": 9.3, "kev": 0, "flags": []}, {"key": "CVE-2026-54342", "cve": "CVE-2026-54342", "lang": "en", "title": "CVE-2026-54342", "summary": "In epa4all, prior to version 2026-05-20, an attacker on the network path between epa4all and any backend (ePA Aktensystem, Konnektor, IDP, TSS) can present a self-signed TLS certificate and intercept the connection. For non-VAU connections (Konnektor, IDP), this allows direct read and modification of the inner traffic, including smartcard operations and OIDC authentication exchanges. For the ePA backend, the disabled TLS verification is the transport-level enabler for the VAU MITM described in GHSA-vvh7-x6c7-46gh. This issue has been patched in version 2026-05-20.", "product": "med-united epa4all", "category": "cve", "source": "NVD", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-54342", "card": "CVE-2026-54342.webp?v=1784922536", "takeaways": ["CVSS 3.1 : 8.1 HIGH", "Vector: AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N"], "ts": 1784920619, "exploited": 0, "has_score": 1, "created": 1784922434, "updated": 1784974118, "exploited_text": 0, "poc": 0, "score": 8.1, "kev": 0, "flags": []}, {"key": "CVE-2026-48036", "cve": "CVE-2026-48036", "lang": "en", "title": "CVE-2026-48036", "summary": "Hulumi is an open-source toolkit that ships secure-by-default cloud and platform infrastructure components for Pulumi. Prior to version 1.4.0, consumers running drift detection in CI / cron could see transient adapter failures silently cached as \"all clear\" — masking real attacks for up to six hours — or see ordinary provider-version churn falsely promoted to incident severity. Either way, the verdict source was unreliable for downstream incident workflows that gate on it. This issue has been patched in version 1.4.0.", "product": "kerberosmansour hulumi", "category": "cve", "source": "NVD", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-48036", "card": "CVE-2026-48036.webp?v=1784922537", "takeaways": ["CVSS 4.0 : 8.4 HIGH", "Vector: AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:H/VA:L/SC:N/SI:H/SA:L"], "ts": 1784920618, "exploited": 0, "has_score": 1, "created": 1784922434, "updated": 1784974118, "exploited_text": 0, "poc": 0, "score": 8.4, "kev": 0, "flags": []}, {"key": "CVE-2026-48035", "cve": "CVE-2026-48035", "lang": "en", "title": "CVE-2026-48035", "summary": "Hulumi is an open-source toolkit that ships secure-by-default cloud and platform infrastructure components for Pulumi. Prior to version 1.4.0, consumers using AccountFoundation could ship an AWS account whose CloudTrail / Config audit logs were deletable by any S3-delete-capable principal — while believing the startup-hardened tier guaranteed tamper-resistance. Sandbox-tier deployments had no audit immutability at all (defects 1 and 3 compounded). This issue has been patched in version 1.4.0.", "product": "kerberosmansour hulumi", "category": "cve", "source": "NVD", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-48035", "card": "CVE-2026-48035.webp?v=1784922537", "takeaways": ["CVSS 4.0 : 7.1 HIGH", "Vector: AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N"], "ts": 1784920618, "exploited": 0, "has_score": 1, "created": 1784922434, "updated": 1784974118, "exploited_text": 0, "poc": 0, "score": 7.1, "kev": 0, "flags": []}, {"key": "CVE-2026-48034", "cve": "CVE-2026-48034", "lang": "en", "title": "CVE-2026-48034", "summary": "Hulumi is an open-source toolkit that ships secure-by-default cloud and platform infrastructure components for Pulumi. Prior to version 1.4.0, there is a bypass via decoy sibling resources targeting a different bucket. This issue has been patched in version 1.4.0.", "product": "kerberosmansour hulumi", "category": "cve", "source": "NVD", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-48034", "card": "CVE-2026-48034.webp?v=1784922537", "takeaways": ["CVSS 4.0 : 8.5 HIGH", "Vector: AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:H/SI:H/SA:L"], "ts": 1784920618, "exploited": 0, "has_score": 1, "created": 1784922434, "updated": 1784974118, "exploited_text": 0, "poc": 0, "score": 8.5, "kev": 0, "flags": []}, {"key": "CVE-2026-48033", "cve": "CVE-2026-48033", "lang": "en", "title": "CVE-2026-48033", "summary": "Hulumi is an open-source toolkit that ships secure-by-default cloud and platform infrastructure components for Pulumi. Prior to version 1.4.0, policy packs can be bypassed by a forged Pulumi-URN logical name. This issue has been patched in version 1.4.0.", "product": "kerberosmansour hulumi", "category": "cve", "source": "NVD", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-48033", "card": "CVE-2026-48033.webp?v=1784922537", "takeaways": ["CVSS 4.0 : 8.4 HIGH", "Vector: AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:H/SI:H/SA:N"], "ts": 1784920618, "exploited": 0, "has_score": 1, "created": 1784922434, "updated": 1784974118, "exploited_text": 0, "poc": 0, "score": 8.4, "kev": 0, "flags": []}, {"key": "CVE-2026-48032", "cve": "CVE-2026-48032", "lang": "en", "title": "CVE-2026-48032", "summary": "Hulumi is an open-source toolkit that ships secure-by-default cloud and platform infrastructure components for Pulumi. Prior to version 1.4.0, IAM-role policy checks can be bypassed when the role trusts multiple OIDC providers. This issue has been patched in version 1.4.0.", "product": "kerberosmansour hulumi", "category": "cve", "source": "NVD", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-48032", "card": "CVE-2026-48032.webp?v=1784922537", "takeaways": ["CVSS 4.0 : 8.3 HIGH", "Vector: AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:L/SC:N/SI:N/SA:N"], "ts": 1784920618, "exploited": 0, "has_score": 1, "created": 1784922434, "updated": 1784974118, "exploited_text": 0, "poc": 0, "score": 8.3, "kev": 0, "flags": []}, {"key": "CVE-2026-48021", "cve": "CVE-2026-48021", "lang": "en", "title": "CVE-2026-48021", "summary": "In epa4all, prior to version 2026-05-20, an attacker who can intercept the TLS connection between epa4all and the ePA backend can complete the VAU handshake with attacker-controlled keys and obtain the session encryption keys. All inner HTTP traffic (patient consent decisions, medication data, document operations, authorization tokens, and entitlement queries) becomes readable and modifiable. The attacker can also inject arbitrary requests through the hijacked channel. This issue has been patched in version 2026-05-20.", "product": "med-united epa4all", "category": "cve", "source": "NVD", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-48021", "card": "CVE-2026-48021.webp?v=1784922536", "takeaways": ["CVSS 3.1 : 9.1 CRITICAL", "Vector: AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N"], "ts": 1784920618, "exploited": 0, "has_score": 1, "created": 1784922434, "updated": 1784974118, "exploited_text": 0, "poc": 0, "score": 9.1, "kev": 0, "flags": []}, {"key": "CVE-2026-17107", "cve": "CVE-2026-17107", "lang": "en", "title": "CVE-2026-17107", "summary": "A flaw was found in the cluster-proxy service-proxy component used in Red Hat Advanced Cluster Management for Kubernetes (RHACM) and multicluster-engine (MCE). The service-proxy appends impersonation group headers to proxied requests without first removing caller-supplied values, and the spoke ServiceAccount holds unrestricted impersonation permissions. An authenticated hub principal can inject an Impersonate-Group header to escalate to cluster-admin on every managed cluster.", "product": "Multicluster Engine for Kubernetes", "category": "cve", "source": "NVD", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-17107", "card": "CVE-2026-17107.webp?v=1784922538", "takeaways": ["CVSS 3.1 : 8.5 HIGH", "Vector: AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H"], "ts": 1784920615, "exploited": 0, "has_score": 1, "created": 1784922434, "updated": 1784974118, "exploited_text": 0, "poc": 0, "score": 8.5, "kev": 0, "flags": []}, {"key": "CVE-2026-66035", "cve": "CVE-2026-66035", "lang": "en", "title": "CVE-2026-66035", "summary": "libssh2 through 1.11.1, fixed in commit 42e33d8, contains a pre-authentication heap buffer overflow vulnerability that allows a malicious SSH server to corrupt heap metadata in any connecting client by sending a packet with a packet_length smaller than the cipher's block size during Encrypt-then-MAC cipher negotiation. In the fullpacket() function in src/transport.c, the ETM path allocates a buffer of packet_length bytes but copies blocksize minus one bytes via memcpy, causing an overflow that on 32-bit glibc writes attacker-controlled bytes into an adjacent chunk's SIZE field, enabling tcache bin confusion, overlapping live objects, and function pointer overwrite during the session handshake before authentication.", "product": "libssh2", "category": "cve", "source": "NVD", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-66035", "card": "CVE-2026-66035.webp?v=1784914606", "takeaways": ["CVSS 4.0 : 7.7 HIGH", "Vector: AV:N/AC:H/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N", "CVSS 3.1 : 7.5 HIGH"], "ts": 1784913455, "exploited": 0, "has_score": 1, "created": 1784914497, "updated": 1784974118, "exploited_text": 0, "poc": 0, "score": 7.7, "kev": 0, "flags": []}, {"key": "CVE-2026-66034", "cve": "CVE-2026-66034", "lang": "en", "title": "CVE-2026-66034", "summary": "libssh2 through 1.11.1, fixed in commit a13bb6c, contains a missing bounds check vulnerability that allows a malicious SSH server to trigger an arbitrary-length heap out-of-bounds read and a free of an uninitialized pointer via the publickey subsystem. In libssh2_publickey_list_fetch(), the version 1 response parser reads a server-controlled comment_len value and advances the parse pointer without verifying sufficient bytes remain in the buffer, causing the out-of-bounds read to leak heap pointers from adjacent allocations defeating ASLR, followed by heap allocator state corruption when the error cleanup path frees an uninitialized pointer from a non-zeroed realloc() region.", "product": "libssh2", "category": "cve", "source": "NVD", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-66034", "card": "CVE-2026-66034.webp?v=1784914606", "takeaways": ["CVSS 4.0 : 7.7 HIGH", "Vector: AV:N/AC:H/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N", "CVSS 3.1 : 7.5 HIGH"], "ts": 1784913455, "exploited": 0, "has_score": 1, "created": 1784914497, "updated": 1784974118, "exploited_text": 0, "poc": 0, "score": 7.7, "kev": 0, "flags": []}, {"key": "CVE-2026-66033", "cve": "CVE-2026-66033", "lang": "en", "title": "CVE-2026-66033", "summary": "libssh2 through 1.11.1, fixed in commit a2ed82d, contains a pre-authentication integer underflow vulnerability in the ssh2_cipher_crypt() function in src/openssl.c that allows a malicious SSH server to crash any connecting client by negotiating AES-GCM ciphers during handshake. Attackers can exploit the underflow in the expression computing blocksize minus aadlen minus authentication tag length to trigger an out-of-bounds read and a memcpy call with a near-SIZE_MAX length argument, causing immediate process crash before any authentication occurs.", "product": "libssh2", "category": "cve", "source": "NVD", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-66033", "card": "CVE-2026-66033.webp?v=1784914605", "takeaways": ["CVSS 4.0 : 8.7 HIGH", "Vector: AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N", "CVSS 3.1 : 7.5 HIGH"], "ts": 1784913455, "exploited": 0, "has_score": 1, "created": 1784914497, "updated": 1784974118, "exploited_text": 0, "poc": 0, "score": 8.7, "kev": 0, "flags": []}, {"key": "CVE-2026-66032", "cve": "CVE-2026-66032", "lang": "en", "title": "CVE-2026-66032", "summary": "libssh2 through 1.11.1, fixed in commit 5e47761, contains a double-free vulnerability in the sftp_open() function in src/sftp.c that allows a malicious SSH server to corrupt the heap of any authenticated client opening an SFTP session. When a server responds to SSH_FXP_OPEN with SSH_FXP_STATUS containing FX_OK, the response data buffer is freed, and if a subsequent sftp_packet_require() call returns a specific error such as LIBSSH2_ERROR_CHANNEL_PACKET_EXCEEDED, the same pointer is freed a second time, enabling tcache dup conditions on glibc systems that allow overlapping allocations and function pointer overwrites.", "product": "libssh2", "category": "cve", "source": "NVD", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-66032", "card": "CVE-2026-66032.webp?v=1784914605", "takeaways": ["CVSS 4.0 : 8.7 HIGH", "Vector: AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N", "CVSS 3.1 : 8.8 HIGH"], "ts": 1784913455, "exploited": 0, "has_score": 1, "created": 1784914497, "updated": 1784974118, "exploited_text": 0, "poc": 0, "score": 8.7, "kev": 0, "flags": []}, {"key": "CVE-2026-65711", "cve": "CVE-2026-65711", "lang": "en", "title": "CVE-2026-65711", "summary": "sysPass through version 3.2.11 contains an OS command injection vulnerability that allows authenticated administrators to execute arbitrary commands as the web server process user by setting a malicious backup path and triggering a backup. The FileBackupService builds a tar shell command via string concatenation, inserting the admin-configurable siteBackupPath setting without escapeshellarg() or equivalent sanitization before passing it to exec(), causing injected commands to persist and execute on every subsequent backup trigger.", "product": "nuxsmin sysPass", "category": "cve", "source": "NVD", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-65711", "card": "CVE-2026-65711.webp?v=1784914607", "takeaways": ["CVSS 4.0 : 8.6 HIGH", "Vector: AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N", "CVSS 3.1 : 7.2 HIGH"], "ts": 1784913454, "exploited": 0, "has_score": 1, "created": 1784914497, "updated": 1784974118, "exploited_text": 0, "poc": 0, "score": 8.6, "kev": 0, "flags": []}, {"key": "CVE-2026-65710", "cve": "CVE-2026-65710", "lang": "en", "title": "CVE-2026-65710", "summary": "sysPass through version 3.2.11 contains a missing authorization vulnerability that allows authenticated users with the PUBLICLINK_CREATE profile flag to trigger unauthorized decryption and persistent storage of any vault account's password by exploiting the absence of AccountAcl checks in the public link creation flow. Attackers can invoke the saveCreateFromAccountAction endpoint to cause AccountService::getDataForLink to load arbitrary target accounts without AccountFilterUser restrictions, decrypt credentials using the session master key, and serialize cleartext passwords into Vault storage on the PublicLink database row, enabling subsequent unauthenticated retrieval if the generated link hash is recovered.", "product": "nuxsmin sysPass", "category": "cve", "source": "NVD", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-65710", "card": "CVE-2026-65710.webp?v=1784914607", "takeaways": ["CVSS 4.0 : 7.1 HIGH", "Vector: AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N", "CVSS 3.1 : 7.1 HIGH"], "ts": 1784913454, "exploited": 0, "has_score": 1, "created": 1784914497, "updated": 1784974118, "exploited_text": 0, "poc": 0, "score": 7.1, "kev": 0, "flags": []}, {"key": "CVE-2026-65709", "cve": "CVE-2026-65709", "lang": "en", "title": "CVE-2026-65709", "summary": "sysPass through version 3.2.11 contains a missing object-level authorization vulnerability in the JSON-RPC API that allows API token holders to enumerate account metadata, overwrite passwords, and delete accounts across the entire vault without per-account access control. Attackers can invoke AccountController methods such as viewAction, editAction, deleteAction, and editPassAction without AccountFilterUser checks to modify or delete accounts beyond the scope of their assigned token permissions.", "product": "nuxsmin sysPass", "category": "cve", "source": "NVD", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-65709", "card": "CVE-2026-65709.webp?v=1784914607", "takeaways": ["CVSS 4.0 : 8.7 HIGH", "Vector: AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N", "CVSS 3.1 : 8.3 HIGH"], "ts": 1784913454, "exploited": 0, "has_score": 1, "created": 1784914497, "updated": 1784974118, "exploited_text": 0, "poc": 0, "score": 8.7, "kev": 0, "flags": []}, {"key": "CVE-2026-65708", "cve": "CVE-2026-65708", "lang": "en", "title": "CVE-2026-65708", "summary": "sysPass through version 3.2.11 contains an insecure direct object reference vulnerability that allows any authenticated attacker to access account file attachments belonging to accounts they do not have ACL permissions for by exploiting missing authorization checks in AccountFileController. Attackers can supply arbitrary numeric file IDs through the download, view, delete, upload, and list actions to enumerate and manipulate any attachment in the vault, bypassing account-level access controls entirely.", "product": "nuxsmin sysPass", "category": "cve", "source": "NVD", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-65708", "card": "CVE-2026-65708.webp?v=1784914606", "takeaways": ["CVSS 4.0 : 8.6 HIGH", "Vector: AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N", "CVSS 3.1 : 8.1 HIGH"], "ts": 1784913454, "exploited": 0, "has_score": 1, "created": 1784914497, "updated": 1784974118, "exploited_text": 0, "poc": 0, "score": 8.6, "kev": 0, "flags": []}, {"key": "CVE-2026-65707", "cve": "CVE-2026-65707", "lang": "en", "title": "CVE-2026-65707", "summary": "Likeshop through 3.0.5 contains an authenticated SQL injection vulnerability that allows admin-level users to extract arbitrary database contents by submitting unsanitized POST parameters to the adjustAccount endpoint. The adjustAccount method in UserLogic.php concatenates the money, integral, growth, and earnings parameters directly into Db::raw() SQL fragments without type casting, numeric validation, or parameter binding, enabling boolean-based binary-search extraction of credentials, PII, and session tokens via distinct success and failure response messages.", "product": "likeadmin-likeshop likeshop", "category": "cve", "source": "NVD", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-65707", "card": "CVE-2026-65707.webp?v=1784914606", "takeaways": ["CVSS 4.0 : 8.5 HIGH", "Vector: AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N", "CVSS 3.1 : 6.5 MEDIUM"], "ts": 1784913454, "exploited": 0, "has_score": 1, "created": 1784914497, "updated": 1784974118, "exploited_text": 0, "poc": 0, "score": 8.5, "kev": 0, "flags": []}, {"key": "CVE-2026-65623", "cve": "CVE-2026-65623", "lang": "en", "title": "CVE-2026-65623", "summary": "Inefficient Algorithmic Complexity vulnerability in mtrudel bandit allows unauthenticated remote denial of service via CPU exhaustion during WebSocket fragment reassembly.\n\nThe size guard 'Elixir.Bandit.WebSocket.Connection':oversize_message?/2 called from handle_frame/3 in lib/bandit/websocket/connection.ex appends each non-final continuation frame to a left-nested iolist and then re-measures the entire accumulated buffer with IO.iodata_length/1 on every frame. Because the buffer grows by one element per frame and is fully re-traversed each time, reassembly work is quadratic (O(n^2)) in the number of continuation frames.\n\nThe max_fragmented_message_size limit (default 8 MB) bounds total bytes but not frame count, and each frame can carry as little as one payload byte, so an attacker can send millions of tiny continuation frames using modest bandwidth to pin a CPU core for minutes to hours. Many concurrent connections can starve the whole server of CPU, denying service to legitimate users. The WebSocket read timeout does not help, because it is an idle timeout evaluated between reads and cannot preempt the synchronous reassembly work spent inside a single callback.\n\nThis issue affe", "product": "mtrudel bandit", "category": "cve", "source": "NVD", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-65623", "card": "CVE-2026-65623.webp?v=1784914606", "takeaways": ["CVSS 4.0 : 8.7 HIGH", "Vector: AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N"], "ts": 1784913454, "exploited": 0, "has_score": 1, "created": 1784914497, "updated": 1784974118, "exploited_text": 0, "poc": 0, "score": 8.7, "kev": 0, "flags": []}, {"key": "CVE-2026-66027", "cve": "CVE-2026-66027", "lang": "en", "title": "CVE-2026-66027", "summary": "Suna before 0.9.102 contains a broken access control vulnerability in the message queue API that allows authenticated attackers to access and manipulate queue resources belonging to other users by exploiting missing ownership and account isolation checks. Attackers can read pending prompt queues of all users, read or delete individual sessions, and inject arbitrary prompts into another user's session queue, causing the background drainer to forward malicious messages to the victim's running AI agent with the victim's credentials and permissions.", "product": "kortix-ai suna", "category": "cve", "source": "NVD", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-66027", "card": "CVE-2026-66027.webp?v=1784910668", "takeaways": ["CVSS 4.0 : 8.7 HIGH", "Vector: AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N", "CVSS 3.1 : 8.3 HIGH"], "ts": 1784909815, "exploited": 0, "has_score": 1, "created": 1784910546, "updated": 1784974118, "exploited_text": 0, "poc": 0, "score": 8.7, "kev": 0, "flags": []}, {"key": "CVE-2026-65693", "cve": "CVE-2026-65693", "lang": "en", "title": "CVE-2026-65693", "summary": "Microweber CMS through 2.0.20 contains a server-side template injection vulnerability that allows authenticated administrators to achieve arbitrary OS command execution by injecting Twig expressions into mail templates. Attackers can exploit the unsandboxed Twig environment in TwigView::render(), which lacks SandboxExtension or a SecurityPolicy, to inject malicious expressions such as filter('system') into mail template bodies stored unsanitized in the database, causing automatic payload execution on each subsequent application event that triggers a mail dispatch.", "product": "microweber", "category": "cve", "source": "NVD", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-65693", "card": "CVE-2026-65693.webp?v=1784910668", "takeaways": ["CVSS 4.0 : 8.6 HIGH", "Vector: AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N", "CVSS 3.1 : 7.2 HIGH"], "ts": 1784909815, "exploited": 0, "has_score": 1, "created": 1784910546, "updated": 1784971759, "exploited_text": 0, "poc": 0, "score": 8.6, "kev": 0, "flags": []}, {"key": "CVE-2026-64255", "cve": "CVE-2026-64255", "lang": "en", "title": "CVE-2026-64255", "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: iwlwifi: mld: validate sta_mask before ffs() in BA session handlers\n\nThree BA session handlers use ffs(ba_data->sta_mask) - 1 to derive a\nstation ID without checking that sta_mask is non-zero. When sta_mask is\nzero, ffs() returns 0 and the subtraction wraps to 0xFFFFFFFF, causing\nan out-of-bounds access on fw_id_to_link_sta[].\n\nAdd WARN_ON_ONCE(!ba_data->sta_mask) guards before each ffs() call,\nconsistent with the existing check in iwl_mld_ampdu_rx_start().", "product": "Linux", "category": "cve", "source": "NVD", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-64255", "card": "CVE-2026-64255.webp?v=1784910667", "takeaways": [], "ts": 1784909815, "exploited": 0, "has_score": 0, "created": 1784910546, "updated": 1784974118, "exploited_text": 0, "poc": 0, "score": 0.0, "kev": 0, "flags": []}, {"key": "CVE-2026-64254", "cve": "CVE-2026-64254", "lang": "en", "title": "CVE-2026-64254", "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\nNTB: epf: Avoid pci_iounmap() with offset when PEER_SPAD and CONFIG share BAR\n\nWhen BAR_PEER_SPAD and BAR_CONFIG share one PCI BAR, the module teardown\npath ends up calling pci_iounmap() on the same iomem with some offset,\nwhich is unnecessary and triggers a kernel warning like the following:\n\n  Trying to vunmap() nonexistent vm area (0000000069a5ffe8)\n  WARNING: mm/vmalloc.c:3470 at vunmap+0x58/0x68, CPU#5: modprobe/2937\n  [...]\n  Call trace:\n   vunmap+0x58/0x68 (P)\n   iounmap+0x34/0x48\n   pci_iounmap+0x2c/0x40\n   ntb_epf_pci_remove+0x44/0x80 [ntb_hw_epf]\n   pci_device_remove+0x48/0xf8\n   device_remove+0x50/0x88\n   device_release_driver_internal+0x1c8/0x228\n   driver_detach+0x50/0xb0\n   bus_remove_driver+0x74/0x100\n   driver_unregister+0x34/0x68\n   pci_unregister_driver+0x34/0xa0\n   ntb_epf_pci_driver_exit+0x14/0xfe0 [ntb_hw_epf]\n  [...]\n\nFix it by unmapping only when PEER_SPAD and CONFIG use difference bars.", "product": "Linux", "category": "cve", "source": "NVD", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-64254", "card": "CVE-2026-64254.webp?v=1784910667", "takeaways": [], "ts": 1784909815, "exploited": 0, "has_score": 0, "created": 1784910546, "updated": 1784974118, "exploited_text": 0, "poc": 0, "score": 0.0, "kev": 0, "flags": []}, {"key": "CVE-2026-64253", "cve": "CVE-2026-64253", "lang": "en", "title": "CVE-2026-64253", "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\nkernel/fork: clear PF_BLOCK_TS in copy_process()\n\nPF_BLOCK_TS is only set in blk_time_get_ns() when current->plug is\nnon-NULL, and blk_finish_plug() clears it via __blk_flush_plug()\nbefore NULLing the plug pointer.  copy_process() breaks the\ninvariant by inheriting PF_BLOCK_TS from the parent while resetting\nthe child's plug to NULL.\n\nClear PF_BLOCK_TS alongside that assignment so callers can rely on\n\"PF_BLOCK_TS set implies current->plug != NULL\" and dereference\ncurrent->plug unguarded.", "product": "Linux", "category": "cve", "source": "NVD", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-64253", "card": "CVE-2026-64253.webp?v=1784910667", "takeaways": [], "ts": 1784909815, "exploited": 0, "has_score": 0, "created": 1784910546, "updated": 1784974118, "exploited_text": 0, "poc": 0, "score": 0.0, "kev": 0, "flags": []}, {"key": "CVE-2026-64252", "cve": "CVE-2026-64252", "lang": "en", "title": "CVE-2026-64252", "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\nMIPS: DEC: Prevent initial console buffer from landing in XKPHYS\n\nIn 64-bit configurations calling the initial console output handler from\na kernel thread other than the initial one will result in a situation\nwhere the stack has been placed in the XKPHYS 64-bit memory segment and\nconsequently so has been the buffer allocated there that is used as the\nargument corresponding to the `%s' output conversion specifier for the\nfirmware's printf() entry point.\n\nThis 64-bit address will then be truncated by 32-bit firmware, resulting\nin an attempt to access the wrong memory location, which in turn will\ncause all kinds of unpredictable behaviour, such as a kernel crash:\n\n  Console: colour dummy device 160x64\n  Calibrating delay loop... 49.36 BogoMIPS (lpj=192512)\n  pid_max: default: 32768 minimum: 301\n  CPU 0 Unable to handle kernel paging request at virtual address 000000000203bd00, epc == ffffffffbfc08364, ra == ffffffffbfc08800\n  Oops[#1]:\n  CPU: 0 PID: 0 Comm: swapper Not tainted 5.18.0-rc2-00254-gfb649bda6f56-dirty #121\n  $ 0   : 0000000000000000 0000000000000001 0000000000000023 ffffffff80684ba0\n  $ 4   : 000000000203", "product": "Linux", "category": "cve", "source": "NVD", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-64252", "card": "CVE-2026-64252.webp?v=1784910669", "takeaways": [], "ts": 1784909814, "exploited": 0, "has_score": 0, "created": 1784910546, "updated": 1785147465, "exploited_text": 0, "poc": 0, "score": 0.0, "kev": 0, "flags": []}, {"key": "CVE-2026-64251", "cve": "CVE-2026-64251", "lang": "en", "title": "CVE-2026-64251", "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\npwrseq: core: fix use-after-free in pwrseq_debugfs_seq_next()\n\npwrseq_debugfs_seq_next() declares 'next' with __free(put_device),\nwhich causes put_device() to be called on the returned pointer when\nthe variable goes out of scope.  This results in a use-after-free\nsince the seq_file framework receives a pointer whose reference has\nalready been dropped.\n\nSimply removing __free(put_device) would fix the UAF but would leak\nthe reference acquired by bus_find_next_device(), as stop() only\ncalls up_read(&pwrseq_sem) and never releases the device reference.\n\nFix this by making the reference counting consistent across all\nseq_file callbacks, matching the standard pattern used by PCI and\nSCSI:\n\n- start(): use get_device() so it returns a referenced pointer.\n- next(): explicitly put_device(curr) to release the previous\n  device's reference (no NULL check needed - the seq_file framework\n  only calls next() while the previous return was non-NULL).\n- stop(): put_device(data) to release the last iterated device's\n  reference, with a NULL guard since stop() may be called with NULL\n  when start() returned NULL or next() reached en", "product": "Linux", "category": "cve", "source": "NVD", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-64251", "card": "CVE-2026-64251.webp?v=1785155583", "takeaways": ["CVSS 3.1 : 7.8 HIGH", "Vector: AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"], "ts": 1784909814, "exploited": 0, "has_score": 1, "created": 1784910546, "updated": 1785155450, "exploited_text": 0, "poc": 0, "score": 7.8, "kev": 0, "flags": []}, {"key": "CVE-2026-64250", "cve": "CVE-2026-64250", "lang": "en", "title": "CVE-2026-64250", "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\nLoongArch: Report dying CPU to RCU in stop_this_cpu()\n\nThis is a port of MIPS commit 9f3f3bdc6d9dac1 (\"MIPS: smp: report dying\nCPU to RCU in stop_this_cpu()\"). smp_send_stop() parks all secondary\nCPUs in stop_this_cpu(). And the function marks the CPU offline for the\nscheduler via set_cpu_online(false) but never informs RCU, so RCU keeps\nexpecting a quiescent state from CPUs that are now spinning forever with\ninterrupts disabled.\n\nAs long as nothing waits for an RCU grace period after smp_send_stop()\nthis is harmless, which is why it went unnoticed. However, since commit\n91840be8f710370 (\"irq_work: Fix use-after-free in irq_work_single() on\nPREEMPT_RT\"), irq_work_sync() calls synchronize_rcu() on architectures\nwithout an irq_work self-IPI, i.e. where arch_irq_work_has_interrupt()\nreturns false. Any irq_work_sync() issued in the reboot/shutdown/halt\npath after smp_send_stop() then blocks on a grace period that can never\ncomplete, hanging the reboot:\n\n  WARNING: CPU: 0 PID: 15 at kernel/irq_work.c:144 irq_work_queue_on\n  ...\n  rcu: INFO: rcu_sched detected stalls on CPUs/tasks:\n  rcu: Offline CPU 1 blocking current ", "product": "Linux", "category": "cve", "source": "NVD", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-64250", "card": "CVE-2026-64250.webp?v=1784910669", "takeaways": [], "ts": 1784909814, "exploited": 0, "has_score": 0, "created": 1784910546, "updated": 1785153455, "exploited_text": 0, "poc": 0, "score": 0.0, "kev": 0, "flags": []}, {"key": "CVE-2026-64249", "cve": "CVE-2026-64249", "lang": "en", "title": "CVE-2026-64249", "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\nfpga: region: fix use-after-free in child_regions_with_firmware()\n\nMove of_node_put(child_region) after the error print to avoid accessing\nfreed memory when pr_err() references child_region.\n\n[ Yilun: Fix the Fixes tag ]", "product": "Linux", "category": "cve", "source": "NVD", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-64249", "card": "CVE-2026-64249.webp?v=1784910669", "takeaways": [], "ts": 1784909814, "exploited": 0, "has_score": 0, "created": 1784910546, "updated": 1785151433, "exploited_text": 0, "poc": 0, "score": 0.0, "kev": 0, "flags": []}, {"key": "CVE-2026-64248", "cve": "CVE-2026-64248", "lang": "en", "title": "CVE-2026-64248", "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\nMIPS: smp: report dying CPU to RCU in stop_this_cpu()\n\nsmp_send_stop() parks all secondary CPUs in stop_this_cpu(). The function\nmarks the CPU offline for the scheduler via set_cpu_online(false) but\nnever informs RCU, so RCU keeps expecting a quiescent state from CPUs\nthat are now spinning forever with interrupts disabled.\n\nAs long as nothing waits for an RCU grace period after smp_send_stop()\nthis is harmless, which is why it went unnoticed. Since commit\n91840be8f710 (\"irq_work: Fix use-after-free in irq_work_single() on PREEMPT_RT\")\nhowever, irq_work_sync() calls synchronize_rcu() on architectures without\nan irq_work self-IPI, i.e. where arch_irq_work_has_interrupt() returns\nfalse. That is the asm-generic default used by MIPS. Any irq_work_sync()\nissued in the reboot/shutdown path after smp_send_stop() then blocks on\na grace period that can never complete, hanging the reboot:\n\n  WARNING: CPU: 0 PID: 15 at kernel/irq_work.c:144 irq_work_queue_on\n  ...\n  rcu: INFO: rcu_sched detected stalls on CPUs/tasks:\n  rcu: Offline CPU 1 blocking current GP.\n  rcu: Offline CPU 2 blocking current GP.\n  rcu: Offline CPU 3 block", "product": "Linux", "category": "cve", "source": "NVD", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-64248", "card": "CVE-2026-64248.webp?v=1784910668", "takeaways": [], "ts": 1784909814, "exploited": 0, "has_score": 0, "created": 1784910546, "updated": 1785149449, "exploited_text": 0, "poc": 0, "score": 0.0, "kev": 0, "flags": []}, {"key": "CVE-2026-64247", "cve": "CVE-2026-64247", "lang": "en", "title": "CVE-2026-64247", "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\nKVM: x86: hyper-v: Bound the bank index when querying sparse banks\n\nWhen checking if a VP ID is included in a sparse bank set, explicitly check\nthat the ID can actually be contained in a sparse bank (the TLFS allows for\na maximum of 64 banks of 64 vCPUs each).  When handling a paravirtual TLB\nflush for L2, the VP ID is copied verbatim from the enlightened VMCS,\nwithout any bounds check, i.e. isn't guaranteed to be under the limit of\n4096.\n\nFailure to check the bounds of the VP ID leads to an out-of-bounds read\nwhen testing the sparse bank, and super strictly speaking could lead to KVM\nperforming an unnecessary TLB flush for an L2 vCPU.\n\n  ==================================================================\n  BUG: KASAN: use-after-free in hv_is_vp_in_sparse_set+0x85/0x100 [kvm]\n  Read of size 8 at addr ffff88811ba5f598 by task hyperv_evmcs/2802\n\n  CPU: 12 UID: 1000 PID: 2802 Comm: hyperv_evmcs Not tainted 7.1.0-rc2 #7 PREEMPT\n  Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS 0.0.0 02/06/2015\n  Call Trace:\n    \n   dump_stack_lvl+0x51/0x60\n   print_report+0xcb/0x5d0\n   kasan_report+0xb4/0xe0\n   kasan_check_ran", "product": "Linux", "category": "cve", "source": "NVD", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-64247", "card": "CVE-2026-64247.webp?v=1785145606", "takeaways": ["CVSS 3.1 : 8.4 HIGH", "Vector: AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:H"], "ts": 1784909814, "exploited": 0, "has_score": 1, "created": 1784910546, "updated": 1785145485, "exploited_text": 0, "poc": 0, "score": 8.4, "kev": 0, "flags": []}, {"key": "CVE-2026-64246", "cve": "CVE-2026-64246", "lang": "en", "title": "CVE-2026-64246", "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\npower: reset: linkstation-poweroff: fix use-after-free in the linkstation_poweroff_init()\n\nMove of_node_put(dn) after the of_match_node() call, which still needs\nthe node pointer. The node reference is correctly released after use.", "product": "Linux", "category": "cve", "source": "NVD", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-64246", "card": "CVE-2026-64246.webp?v=1784910668", "takeaways": [], "ts": 1784909814, "exploited": 0, "has_score": 0, "created": 1784910546, "updated": 1785157443, "exploited_text": 0, "poc": 0, "score": 0.0, "kev": 0, "flags": []}, {"key": "CVE-2026-64245", "cve": "CVE-2026-64245", "lang": "en", "title": "CVE-2026-64245", "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\nfbdev: modedb: fix a possible UAF in fb_find_mode()\n\nIf mode_option is NULL, it is assigned from mode_option_buf:\n\n  if (!mode_option) {\n    fb_get_options(NULL, &mode_option_buf);\n    mode_option = mode_option_buf;\n  }\n\nLater, name is assigned from mode_option:\n\n  const char *name = mode_option;\n\nHowever, mode_option_buf is freed before name is no longer used:\n\n  kfree(mode_option_buf);\n\nwhile name is still accessed by:\n\n  if ((name_matches(db[i], name, namelen) ||\n\nSince name aliases mode_option_buf, this may result in a\nuse-after-free.\n\nFix this by extending the lifetime of mode_option_buf until the end of the\nfunction by using scope-based resource management for cleanup.", "product": "Linux", "category": "cve", "source": "NVD", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-64245", "card": "CVE-2026-64245.webp?v=1784910671", "takeaways": [], "ts": 1784909813, "exploited": 0, "has_score": 0, "created": 1784910546, "updated": 1785125545, "exploited_text": 0, "poc": 0, "score": 0.0, "kev": 0, "flags": []}, {"key": "CVE-2026-64244", "cve": "CVE-2026-64244", "lang": "en", "title": "CVE-2026-64244", "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrivers/base/memory: set mem->altmap after successful device registration\n\nIf __add_memory_block() fails at xa_store() (under memory pressure for\nexample), device_unregister() is called, which eventually triggers\nmemory_block_release() with mem->altmap still set, causing a\nWARN_ON(mem->altmap).  This was triggered by modifying virtio-mem driver.\n\nFix this by delaying the assignment of mem->altmap until after\n__add_memory_block() has succeeded.", "product": "Linux", "category": "cve", "source": "NVD", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-64244", "card": "CVE-2026-64244.webp?v=1784910671", "takeaways": [], "ts": 1784909813, "exploited": 0, "has_score": 0, "created": 1784910546, "updated": 1785125545, "exploited_text": 0, "poc": 0, "score": 0.0, "kev": 0, "flags": []}, {"key": "CVE-2026-64243", "cve": "CVE-2026-64243", "lang": "en", "title": "CVE-2026-64243", "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\nASoC: codecs: simple-mux: Fix enum control bounds check\n\nsimple_mux_control_put() rejects values greater than e->items, but\nenum control values are zero based. For the two-entry mux used by this\ndriver, valid values are 0 and 1, so value 2 must be rejected as well.\n\nAccepting e->items can store an invalid mux state, pass it to the GPIO\nsetter, and pass it on to the DAPM mux update path where it is used as\nan index into the enum text array.\n\nUse the same >= e->items check used by the ASoC enum helpers.", "product": "Linux", "category": "cve", "source": "NVD", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-64243", "card": "CVE-2026-64243.webp?v=1785131635", "takeaways": ["CVSS 3.1 : 7.1 HIGH", "Vector: AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H"], "ts": 1784909813, "exploited": 0, "has_score": 1, "created": 1784910546, "updated": 1785131511, "exploited_text": 0, "poc": 0, "score": 7.1, "kev": 0, "flags": []}, {"key": "CVE-2026-64242", "cve": "CVE-2026-64242", "lang": "en", "title": "CVE-2026-64242", "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\nusb: gadget: net2280: Fix double free in probe error path\n\nusb_initialize_gadget() installs gadget_release() as the release\ncallback for the embedded gadget device.  The struct net2280 instance is\ntherefore released through gadget_release() when the gadget device's last\nreference is dropped.\n\nThe probe error path calls net2280_remove(), which tears down the\npartially initialized device and drops the gadget reference with\nusb_put_gadget().  Calling kfree(dev) afterwards can free the same object\nagain.\n\nDrop the explicit kfree() and let the gadget device release callback\nhandle the final free.  This issue was found by a static analysis tool\nI am developing.", "product": "Linux", "category": "cve", "source": "NVD", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-64242", "card": "CVE-2026-64242.webp?v=1784910670", "takeaways": [], "ts": 1784909813, "exploited": 0, "has_score": 0, "created": 1784910546, "updated": 1785129486, "exploited_text": 0, "poc": 0, "score": 0.0, "kev": 0, "flags": []}, {"key": "CVE-2026-64241", "cve": "CVE-2026-64241", "lang": "en", "title": "CVE-2026-64241", "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\ngpio: rockchip: teardown bugs and resource leaks\n\nAddress several teardown issues and resource leaks in the driver's remove\npath and error handling:\n\n1. Debounce clock reference leak: The debounce clock (bank->db_clk) is\n   obtained using of_clk_get() which increments the clock's reference\n   count, but clk_put() is never called. Register a devm action to\n   cleanly release it on unbind. Note that of_clk_get(..., 1) remains\n   necessary over devm_clk_get() because the DT binding does not define\n   clock-names, precluding name-based lookup.\n\n2. Unregistered chained IRQ handler: The chained IRQ handler is not\n   disconnected in remove(). If a stray interrupt fires after the driver\n   is removed, the kernel attempts to execute a stale handler, leading\n   to a panic. Fix this by clearing the handler in remove().\n\n3. IRQ domain leak: The linear IRQ domain and its generic chips are\n   allocated manually during probe but never removed. Remove the IRQ\n   domain during driver teardown to free the associated generic chips\n   and mappings.\n\n[Bartosz: don't emit an error message on devres allocation failure]", "product": "Linux", "category": "cve", "source": "NVD", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-64241", "card": "CVE-2026-64241.webp?v=1784910670", "takeaways": [], "ts": 1784909813, "exploited": 0, "has_score": 0, "created": 1784910546, "updated": 1785127521, "exploited_text": 0, "poc": 0, "score": 0.0, "kev": 0, "flags": []}, {"key": "CVE-2026-64240", "cve": "CVE-2026-64240", "lang": "en", "title": "CVE-2026-64240", "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\nmedia: rc: igorplugusb: fix control request setup packet\n\nCommit eac69475b01f (\"media: rc: igorplugusb: heed coherency\nrules\") changed the control request storage from an embedded struct to\nan allocated pointer so it can obey DMA coherency rules.\n\nHowever, the driver still passes &ir->request to usb_fill_control_urb().\nThat points the URB setup packet at the pointer field itself rather than\nat the allocated struct usb_ctrlrequest.\n\nUSB core then interprets pointer bytes as the setup packet. This can\nproduce an invalid bRequestType and trigger the control direction warning\nreported by syzbot:\n\n  usb 2-1: BOGUS control dir, pipe 80003580 doesn't match bRequestType 0\n\nPass ir->request itself as the setup packet.", "product": "Linux", "category": "cve", "source": "NVD", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-64240", "card": "CVE-2026-64240.webp?v=1784910670", "takeaways": [], "ts": 1784909813, "exploited": 0, "has_score": 0, "created": 1784910546, "updated": 1785127521, "exploited_text": 0, "poc": 0, "score": 0.0, "kev": 0, "flags": []}, {"key": "CVE-2026-64239", "cve": "CVE-2026-64239", "lang": "en", "title": "CVE-2026-64239", "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\nmm/damon/sysfs-schemes: delete tried region in regions_rmdirs()\n\nDAMON sysfs maintains the DAMOS tried region directory objects via a\nlinked list.  When the user requests refresh of the directories, DAMON\nsysfs removes all the region directories first, and then generate updated\nregions directory on the empty space.  The removal function\n(damon_sysfs_scheme_regions_rm_dirs()) only puts the kobj objects. \nDeletion of the container region object from the linked list is done\ninside the kobj release callback function.\n\nIf somehow the callback invocation is delayed, the list will contain\nregions list that gonna be freed.  If the updated region directories\ncreation is started in this situation, the list can be corrupted and\nuse-after-free can happen.\n\nBecause the kobj objects are managed by only DAMON sysfs, the issue cannot\nhappen in normal situation.  But, such delays can be made on kernels that\nbuilt with CONFIG_DEBUG_KOBJECT_RELEASE.  On the kernel, the issue can\nindeed be reproduced like below.\n\n    # damo start --damos_action stat\n    # cd /sys/kernel/mm/damon/admin/kdamonds/0/\n    # for i in {1..10}; do echo updat", "product": "Linux", "category": "cve", "source": "NVD", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-64239", "card": "CVE-2026-64239.webp?v=1784910670", "takeaways": [], "ts": 1784909813, "exploited": 0, "has_score": 0, "created": 1784910546, "updated": 1785127521, "exploited_text": 0, "poc": 0, "score": 0.0, "kev": 0, "flags": []}, {"key": "CVE-2026-64238", "cve": "CVE-2026-64238", "lang": "en", "title": "CVE-2026-64238", "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\ngpio: shared: fix deadlock on shared proxy's parent removal\n\nCommit 710abda58055 (\"gpio: shared: call gpio_chip::of_xlate() if set\")\nused the mutex embedded in struct gpio_shared_entry to protect the\noffset field which now can be modified after assignment. The critical\nsection however is too wide and introduced a potential deadlock on the\nremoval of the shared GPIO proxy's parent.\n\nMake the critical section shorter - only protect the offset when it's\nbeing read.\n\nWhile at it: mention the fact that the entry lock is now also used to\nprotect against concurrent access to the offset field in the structure's\ndocumentation.", "product": "Linux", "category": "cve", "source": "NVD", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-64238", "card": "CVE-2026-64238.webp?v=1784910670", "takeaways": [], "ts": 1784909813, "exploited": 0, "has_score": 0, "created": 1784910546, "updated": 1785125545, "exploited_text": 0, "poc": 0, "score": 0.0, "kev": 0, "flags": []}, {"key": "CVE-2026-64237", "cve": "CVE-2026-64237", "lang": "en", "title": "CVE-2026-64237", "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\nInput: elan_i2c - validate firmware size before use\n\nEnsure that the firmware file is large enough to contain the expected\nnumber of pages and the signature (which resides at the end of the\nfirmware blob) before accessing them to prevent potential out-of-bounds\nreads.", "product": "Linux", "category": "cve", "source": "NVD", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-64237", "card": "CVE-2026-64237.webp?v=1784912634", "takeaways": [], "ts": 1784909812, "exploited": 0, "has_score": 0, "created": 1784912531, "updated": 1785117697, "exploited_text": 0, "poc": 0, "score": 0.0, "kev": 0, "flags": []}, {"key": "CVE-2026-64236", "cve": "CVE-2026-64236", "lang": "en", "title": "CVE-2026-64236", "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\ni2c: davinci: fix division by zero on missing clock-frequency\n\nWhen the 'clock-frequency' property is missing from the device tree,\nthe driver falls back to DAVINCI_I2C_DEFAULT_BUS_FREQ. However, this\nmacro was defined in kHz (100), whereas the device tree property is\nexpected in Hz.\n\nThe probe function divided the fallback value by 1000, causing\ninteger truncation that resulted in dev->bus_freq = 0. This triggered\na deterministic division-by-zero kernel panic when calculating clock\ndividers later in the probe sequence.\n\nFix this by redefining DAVINCI_I2C_DEFAULT_BUS_FREQ in Hz (100000)\nto match the expected device tree property unit, allowing the existing\ndivision logic to work correctly for both cases.", "product": "Linux", "category": "cve", "source": "NVD", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-64236", "card": "CVE-2026-64236.webp?v=1784912634", "takeaways": [], "ts": 1784909812, "exploited": 0, "has_score": 0, "created": 1784912531, "updated": 1785117697, "exploited_text": 0, "poc": 0, "score": 0.0, "kev": 0, "flags": []}, {"key": "CVE-2026-64235", "cve": "CVE-2026-64235", "lang": "en", "title": "CVE-2026-64235", "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\nx86/ftrace: Relocate %rip-relative percpu refs in dynamic trampolines\n\nWith CONFIG_CALL_DEPTH_TRACKING enabled on an x86 retbleed-affected platform\n(eg: Skylake), with retbleed=stuff, registering a dynamic ftrace trampoline\ncrashes on the first call into the traced function:\n\n  BUG: unable to handle page fault for address: ffff88817ae18880\n  #PF: supervisor write access in kernel mode\n  #PF: error_code(0x0002) - not-present page\n  PGD 4b53067 P4D 4b53067 PUD 0\n  Oops: Oops: 0002 [#1] SMP PTI\n  CPU: 3 UID: 0 PID: 187 Comm: usleep Not tainted 7.0.10 #243 PREEMPT(full)\n  Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS Arch Linux 1.17.0-2-2 04/01/2014\n  Code: 24 78 00 00 00 00 48 89 ea 48 89 54 24 20 48 8b b4 24 b8 00 00 00 48 8b bc 24 b0 00 00 00 48 89 bc 24 80 00 00 00 48 83 ef 05   48 c1 3d 1f a8 b6 02 05 48 8b 15 f6 00 00 00 4c 89 3c 24 4c 89\n  Call Trace:\n    \n   ? find_held_lock\n   ? exc_page_fault\n   ? lock_release\n   ? __x64_sys_clock_nanosleep\n   ? lockdep_hardirqs_on_prepare\n   ? trace_hardirqs_on\n   __x64_sys_clock_nanosleep\n   do_syscall_64\n   ? exc_page_fault\n   ? call_depth_return_thunk\n   en", "product": "Linux", "category": "cve", "source": "NVD", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-64235", "card": "CVE-2026-64235.webp?v=1784912633", "takeaways": [], "ts": 1784909812, "exploited": 0, "has_score": 0, "created": 1784912531, "updated": 1785117697, "exploited_text": 0, "poc": 0, "score": 0.0, "kev": 0, "flags": []}, {"key": "CVE-2026-64234", "cve": "CVE-2026-64234", "lang": "en", "title": "CVE-2026-64234", "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\ntty: serial: pch_uart: add check for dma_alloc_coherent()\n\nAdd a check for dma_alloc_coherent() failure to prevent a potential\nNULL pointer dereference in dma_handle_rx(). Properly release DMA\nchannels and the PCI device reference using a goto ladder if the\nallocation fails.", "product": "Linux", "category": "cve", "source": "NVD", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-64234", "card": "CVE-2026-64234.webp?v=1784912633", "takeaways": [], "ts": 1784909812, "exploited": 0, "has_score": 0, "created": 1784912531, "updated": 1785117697, "exploited_text": 0, "poc": 0, "score": 0.0, "kev": 0, "flags": []}, {"key": "CVE-2026-64233", "cve": "CVE-2026-64233", "lang": "en", "title": "CVE-2026-64233", "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\nusb: gadget: uvc: hold opts->lock across XU walks in uvc_function_bind\n\nuvc_function_bind() walks &opts->extension_units twice without holding\nopts->lock:\n\n  - directly, for the iExtension string-descriptor fixup loop;\n  - indirectly, four times via uvc_copy_descriptors() (once per speed),\n    where the helper iterates uvc->desc.extension_units (which aliases\n    &opts->extension_units) to size and emit XU descriptors.\n\nThe configfs side (uvcg_extension_make / uvcg_extension_drop, in\ndrivers/usb/gadget/function/uvc_configfs.c) takes opts->lock around its\nlist_add_tail / list_del operations.  A privileged userspace process\nthat holds the configfs subtree open and writes the gadget UDC name\nto bind the function while concurrently rmdir()'ing an extensions\nsubdir can race uvcg_extension_drop() against the bind-time list walks\nand dereference a freed struct uvcg_extension.\n\nHold opts->lock from the start of the XU string-descriptor fixup\nthrough the last uvc_copy_descriptors() call, releasing on the\ndescriptor-error path via a new error_unlock label that drops the\nlock before falling through to the existing error labe", "product": "Linux", "category": "cve", "source": "NVD", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-64233", "card": "CVE-2026-64233.webp?v=1784910672", "takeaways": [], "ts": 1784909812, "exploited": 0, "has_score": 0, "created": 1784910546, "updated": 1785117697, "exploited_text": 0, "poc": 0, "score": 0.0, "kev": 0, "flags": []}, {"key": "CVE-2026-64232", "cve": "CVE-2026-64232", "lang": "en", "title": "CVE-2026-64232", "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\nblock: recompute nr_integrity_segments in blk_insert_cloned_request\n\nblk_insert_cloned_request() already recomputes nr_phys_segments\nagainst the bottom queue, because \"the queue settings related to\nsegment counting may differ from the original queue.\" The exact same\nreasoning applies to integrity segments: a stacked driver's underlying\nqueue can have tighter virt_boundary_mask, seg_boundary_mask, or\nmax_segment_size than the top queue, in which case\nblk_rq_count_integrity_sg() against the bottom queue produces a\ndifferent count than the cached rq->nr_integrity_segments inherited\nfrom the source request by blk_rq_prep_clone().\n\nWhen the cached count is lower than the bottom queue's actual count,\nblk_rq_map_integrity_sg() trips\n\n\tBUG_ON(segments > rq->nr_integrity_segments);\n\non dispatch. The same families of stacked setups that motivated the\nexisting nr_phys_segments recompute -- dm-multipath fanning out to\nnvme-rdma in particular -- can produce this.\n\nMirror the nr_phys_segments handling: when the request carries\nintegrity, recompute nr_integrity_segments against the bottom queue\nand reject the request if it excee", "product": "Linux", "category": "cve", "source": "NVD", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-64232", "card": "CVE-2026-64232.webp?v=1784910672", "takeaways": [], "ts": 1784909812, "exploited": 0, "has_score": 0, "created": 1784910546, "updated": 1785117697, "exploited_text": 0, "poc": 0, "score": 0.0, "kev": 0, "flags": []}, {"key": "CVE-2026-64231", "cve": "CVE-2026-64231", "lang": "en", "title": "CVE-2026-64231", "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/msm/dsi: don't dump registers past the mapped region\n\nOn DSI 6G platforms the IO address space is internally adjusted by\nio_offset. Later this adjusted address might be used for memory dumping.\nHowever the size that is used for memory dumping isn't adjusted to\naccount for the io_offset, leading to the potential access to the\nunmapped region. Lower ctrl_size by the io_offset value to prevent\naccess past the mapped area.\n\n msm_disp_snapshot_add_block+0x1d4/0x3c8 [msm] (P)\n msm_dsi_host_snapshot+0x4c/0x78 [msm]\n msm_dsi_snapshot+0x28/0x50 [msm]\n msm_disp_snapshot_capture_state+0x74/0x140 [msm]\n msm_disp_snapshot_state_sync+0x60/0x90 [msm]\n _msm_disp_snapshot_work+0x30/0x90 [msm]\n kthread_worker_fn+0xdc/0x460\n kthread+0x120/0x140\n\nPatchwork: https://patchwork.freedesktop.org/patch/721747/", "product": "Linux", "category": "cve", "source": "NVD", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-64231", "card": "CVE-2026-64231.webp?v=1784910672", "takeaways": [], "ts": 1784909812, "exploited": 0, "has_score": 0, "created": 1784910546, "updated": 1785117697, "exploited_text": 0, "poc": 0, "score": 0.0, "kev": 0, "flags": []}, {"key": "CVE-2026-64230", "cve": "CVE-2026-64230", "lang": "en", "title": "CVE-2026-64230", "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\nregulator: tps65219: fix irq_data.rdev not being assigned\n\nCommit 64a6b577490c (\"regulator: tps65219: Remove debugging helper\nfunction\") removed the tps65219_get_rdev_by_name() helper along with\nthe irq_data.rdev assignment that depended on it. This left\nirq_data.rdev uninitialized for all IRQs, causing undefined behavior\nwhen regulator_notifier_call_chain() is called from the IRQ handler:\n\n  Internal error: Oops: 0000000096000004\n  pc : regulator_notifier_call_chain\n  lr : tps65219_regulator_irq_handler\n  Call trace:\n   regulator_notifier_call_chain\n   tps65219_regulator_irq_handler\n   handle_nested_irq\n   regmap_irq_thread\n   irq_thread_fn\n   irq_thread\n   kthread\n   ret_from_fork\n\nInstead of restoring a dedicated lookup array, restructure the probe\nfunction to combine regulator registration with IRQ registration in\nthe same loop. This way the rdev returned by devm_regulator_register()\nis naturally available for assigning to irq_data.rdev without any\nauxiliary data structure.\n\nNon-regulator IRQs (SENSOR, TIMEOUT) that don't correspond to any\nregistered regulator are registered with rdev=NULL, and the IRQ handler", "product": "Linux", "category": "cve", "source": "NVD", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-64230", "card": "CVE-2026-64230.webp?v=1784910671", "takeaways": [], "ts": 1784909812, "exploited": 0, "has_score": 0, "created": 1784910546, "updated": 1785119654, "exploited_text": 0, "poc": 0, "score": 0.0, "kev": 0, "flags": []}, {"key": "CVE-2026-64229", "cve": "CVE-2026-64229", "lang": "en", "title": "CVE-2026-64229", "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\nx86/mm: Disable broadcast TLB flush when PCID is disabled\n\nBooting with \"nopcid\" clears X86_FEATURE_PCID and keeps CR4.PCIDE from being\nset to one. On AMD CPUs that support INVLPGB, broadcast TLB flushing remains\nenabled.\n\nThere are two checks that decide whether the global ASID code runs,\nmm_global_asid() and consider_global_asid(), that key off of the\nX86_FEATURE_INVLPGB feature. Once an mm becomes active on more than three\nCPUs, consider_global_asid() assigns it a global ASID, after which\nflush_tlb_mm_range() takes the broadcast_tlb_flush() path using a non-zero\nPCID. Issuing an INVLPGB with a non-zero PCID while CR4.PCIDE is not set\nresults in a #GP:\n\n  Oops: general protection fault, kernel NULL pointer dereference 0x1: 0000 [#1] SMP NOPTI\n  CPU: 158 UID: 0 PID: 3119 Comm: snap Not tainted 7.1.0-rc3 #1 PREEMPT(full)\n  Hardware name: ...\n  RIP: 0010:broadcast_tlb_flush\n  Code: ... 89 da 48 83 c8 07   01 fe eb 08 cc cc cc ...\n  Call Trace:\n    \n   flush_tlb_mm_range\n   ptep_clear_flush\n   wp_page_copy\n   ? _raw_spin_unlock\n   __handle_mm_fault\n   handle_mm_fault\n   do_user_addr_fault\n   exc_page_fault\n   asm_ex", "product": "Linux", "category": "cve", "source": "NVD", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-64229", "card": "CVE-2026-64229.webp?v=1784910671", "takeaways": [], "ts": 1784909812, "exploited": 0, "has_score": 0, "created": 1784910546, "updated": 1785119654, "exploited_text": 0, "poc": 0, "score": 0.0, "kev": 0, "flags": []}, {"key": "CVE-2026-64228", "cve": "CVE-2026-64228", "lang": "en", "title": "CVE-2026-64228", "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet: ethtool: phy: avoid NULL deref when PHY driver is unbound\n\nphydev->drv can become NULL while the phy_device is still attached to\nits net_device, namely after the PHY driver is unbound via sysfs:\n\n\techo   > /sys/bus/mdio_bus/drivers/ /unbind\n\nphy_remove() clears phydev->drv but doesn't call phy_detach(), so the\nphy_device stays in the link topology xarray and ethnl_req_get_phydev()\nstill hands it back. ETHTOOL_MSG_PHY_GET then oopses on:\n\n\trep_data->drvname = kstrdup(phydev->drv->name, GFP_KERNEL);\n\ndrvname is already treated as optional by phy_reply_size(),\nphy_fill_reply() and phy_cleanup_data(), so just skip the allocation\nwhen there is no driver bound.", "product": "Linux", "category": "cve", "source": "NVD", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-64228", "card": "CVE-2026-64228.webp?v=1784912635", "takeaways": [], "ts": 1784909811, "exploited": 0, "has_score": 0, "created": 1784912531, "updated": 1785107907, "exploited_text": 0, "poc": 0, "score": 0.0, "kev": 0, "flags": []}, {"key": "CVE-2026-64227", "cve": "CVE-2026-64227", "lang": "en", "title": "CVE-2026-64227", "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\nACPI: driver: Check ACPI_COMPANION() against NULL during probe\n\nSince every platform driver can be forced to match a device that doesn't\nmatch its list of device IDs because of device_match_driver_override(),\nplatform drivers that rely on the existence of a device's ACPI companion\nobject should verify its presence.\n\nAccordingly, add requisite ACPI_COMPANION() or ACPI_HANDLE() checks\nagainst NULL to 13 platform drivers handling core ACPI devices.\n\nAlso change the value returned by the ACPI thermal zone driver when\nthe device's ACPI companion is not present to -ENODEV for consistency\nwith the other drivers.", "product": "Linux", "category": "cve", "source": "NVD", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-64227", "card": "CVE-2026-64227.webp?v=1784912635", "takeaways": [], "ts": 1784909811, "exploited": 0, "has_score": 0, "created": 1784912531, "updated": 1785117697, "exploited_text": 0, "poc": 0, "score": 0.0, "kev": 0, "flags": []}, {"key": "CVE-2026-64226", "cve": "CVE-2026-64226", "lang": "en", "title": "CVE-2026-64226", "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\nsched_ext: Avoid UAF in scx_root_enable_workfn() init failure path\n\nIn scx_root_enable_workfn(), put_task_struct(p) is called before scx_error()\ndereferences p->comm and p->pid. If the iterator's reference is the last\ndrop, the task is freed synchronously and the deref becomes a UAF.\n\nMove put_task_struct() past scx_error().", "product": "Linux", "category": "cve", "source": "NVD", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-64226", "card": "CVE-2026-64226.webp?v=1784912634", "takeaways": [], "ts": 1784909811, "exploited": 0, "has_score": 0, "created": 1784912531, "updated": 1785115738, "exploited_text": 0, "poc": 0, "score": 0.0, "kev": 0, "flags": []}, {"key": "CVE-2026-64225", "cve": "CVE-2026-64225", "lang": "en", "title": "CVE-2026-64225", "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\nocteontx2-af: CGX: add bounds check to cgx_speed_mbps index\n\ncgx_speed_mbps has 13 elements but RESP_LINKSTAT_SPEED can yield values\n0-15. If it returns a value >= 13, this causes an out-of-bounds array\naccess. Add a bounds check and default to speed 0 if the index is out of\nrange.", "product": "Linux", "category": "cve", "source": "NVD", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-64225", "card": "CVE-2026-64225.webp?v=1784912634", "takeaways": [], "ts": 1784909811, "exploited": 0, "has_score": 0, "created": 1784912531, "updated": 1785113780, "exploited_text": 0, "poc": 0, "score": 0.0, "kev": 0, "flags": []}, {"key": "CVE-2026-64224", "cve": "CVE-2026-64224", "lang": "en", "title": "CVE-2026-64224", "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\nocteontx2-pf: fix double free in rvu_rep_rsrc_init()\n\nrvu_rep_rsrc_init() allocates queue memory before calling\notx2_init_hw_resources(). When hardware resource setup fails,\notx2_init_hw_resources() already unwinds the partially initialized\nSQ, CQ, and aura state before returning an error. The representor\nerror path then calls otx2_free_hw_resources() again and can free\nthe same resources a second time.\n\nFix this by splitting the cleanup labels so that a failure from\notx2_init_hw_resources() only releases queue memory. Keep the\notx2_free_hw_resources() call for failures that happen after\nhardware resource initialization completed successfully.\n\nThe bug was first flagged by an experimental analysis tool we are\ndeveloping for kernel memory-management bugs while analyzing\nv6.13-rc1. The tool is still under development and is not yet publicly\navailable. Manual inspection confirms that the bug is still\npresent in v7.1-rc3.\n\nRuntime validation was not performed because reproducing this path\nrequires OcteonTX2 representor hardware.", "product": "Linux", "category": "cve", "source": "NVD", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-64224", "card": "CVE-2026-64224.webp?v=1784912634", "takeaways": [], "ts": 1784909811, "exploited": 0, "has_score": 0, "created": 1784912531, "updated": 1785111822, "exploited_text": 0, "poc": 0, "score": 0.0, "kev": 0, "flags": []}, {"key": "CVE-2026-64223", "cve": "CVE-2026-64223", "lang": "en", "title": "CVE-2026-64223", "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: mac80211: consume only present negotiated TTLM maps\n\nieee80211_tid_to_link_map_size_ok() validates negotiated TTLM elements\nagainst the number of link-map entries indicated by link_map_presence.\nieee80211_parse_neg_ttlm() must consume the same layout.\n\nThe parser advanced its cursor for every TID, including TIDs whose\npresence bit is clear and therefore have no map bytes in the element.\nA sparse map can then make a later present TID read past the validated\nelement.\n\nThe bad bytes land in neg_ttlm->{up,down}link[tid] but are gated by\nvalid_links before being applied to driver state, so a peer cannot\nturn the read into a policy change.  Under KUnit + KASAN with an\nexact-sized element allocation the OOB read is reported as a\nslab-out-of-bounds; whether the same trigger fires under the\nproduction RX path depends on surrounding allocator state.\n\nAdvance the cursor only when the current TID has a map present.", "product": "Linux", "category": "cve", "source": "NVD", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-64223", "card": "CVE-2026-64223.webp?v=1784912635", "takeaways": [], "ts": 1784909810, "exploited": 0, "has_score": 0, "created": 1784912531, "updated": 1785107907, "exploited_text": 0, "poc": 0, "score": 0.0, "kev": 0, "flags": []}, {"key": "CVE-2026-64222", "cve": "CVE-2026-64222", "lang": "en", "title": "CVE-2026-64222", "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\nocteontx2-pf: avoid double free of pool->stack on AQ init failure\n\notx2_pool_aq_init() frees pool->stack when mailbox sync or retry\nallocation fails, but leaves the pointer unchanged. Later,\notx2_sq_aura_pool_init() unwinds the partial setup through\notx2_aura_pool_free(), which frees pool->stack again. The CN20K-specific\ncn20k_pool_aq_init() implementation has the same bug in\nits corresponding error path.\n\nSet pool->stack to NULL immediately after the local free so the shared\ncleanup path does not free the same stack again while cleaning up\npartially initialized pool state.\n\nThe bug was first flagged by an experimental analysis tool we are\ndeveloping for kernel memory-management bugs while analyzing\nv6.13-rc1. The tool is still under development and is not yet publicly\navailable. Manual inspection confirms that the bug is still present in\nv7.1-rc3.\n\nRuntime validation was not performed because reproducing this path\nrequires OcteonTX2/CN20K hardware.", "product": "Linux", "category": "cve", "source": "NVD", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-64222", "card": "CVE-2026-64222.webp?v=1784912635", "takeaways": [], "ts": 1784909810, "exploited": 0, "has_score": 0, "created": 1784912531, "updated": 1785107907, "exploited_text": 0, "poc": 0, "score": 0.0, "kev": 0, "flags": []}, {"key": "CVE-2026-64221", "cve": "CVE-2026-64221", "lang": "en", "title": "CVE-2026-64221", "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\nspi: ti-qspi: fix use-after-free after DMA setup failure\n\nThe driver falls back to PIO mode if DMA setup fails during probe.\n\nMake sure to clear the DMA channel pointer also if buffer allocation\nfails to avoid passing a pointer to the released channel to the DMA\nengine (or trying to free the channel a second time on late probe errors\nor driver unbind).\n\nThis issue was flagged by Sashiko when reviewing a devres allocation\nconversion patch.", "product": "Linux", "category": "cve", "source": "NVD", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-64221", "card": "CVE-2026-64221.webp?v=1784912637", "takeaways": [], "ts": 1784909809, "exploited": 0, "has_score": 0, "created": 1784912531, "updated": 1785107907, "exploited_text": 0, "poc": 0, "score": 0.0, "kev": 0, "flags": []}, {"key": "CVE-2026-64220", "cve": "CVE-2026-64220", "lang": "en", "title": "CVE-2026-64220", "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\ndevice property: set fwnode->secondary to NULL in fwnode_init()\n\nIf a firmware node is allocated on the stack (for instance: temporary\nsoftware node whose life-time we control) or on the heap - but using a\nnon-zeroing allocation function - and initialized using fwnode_init(),\nits secondary pointer will contain uninitalized memory which likely will\nbe neither NULL nor IS_ERR() and so may end up being dereferenced (for\nexample: in dev_to_swnode()). Set fwnode->secondary to NULL on\ninitialization.", "product": "Linux", "category": "cve", "source": "NVD", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-64220", "card": "CVE-2026-64220.webp?v=1784912637", "takeaways": [], "ts": 1784909809, "exploited": 0, "has_score": 0, "created": 1784912531, "updated": 1785107907, "exploited_text": 0, "poc": 0, "score": 0.0, "kev": 0, "flags": []}, {"key": "CVE-2026-64219", "cve": "CVE-2026-64219", "lang": "en", "title": "CVE-2026-64219", "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amd/display: Validate payload length and link_index in dc_process_dmub_aux_transfer_async\n\n[Why&How]\ndc_process_dmub_aux_transfer_async() copies payload->length bytes into a\n16-byte stack buffer (dpaux.data[16]) guarded only by an ASSERT(), which\nis a no-op in release builds. If a caller ever passes length > 16 this\nresults in a stack buffer overflow via memcpy.\n\nAdditionally, link_index is used to dereference dc->links[] without\nbounds checking against dc->link_count, risking an out-of-bounds access.\n\nReplace the ASSERT with a hard runtime check that returns false when\npayload->length exceeds the destination buffer size, and add a bounds\ncheck for link_index before it is used.\n\n(cherry picked from commit ba4caa9fecdf7a38f98c878ad05a8a64148b6881)", "product": "Linux", "category": "cve", "source": "NVD", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-64219", "card": "CVE-2026-64219.webp?v=1784912636", "takeaways": [], "ts": 1784909809, "exploited": 0, "has_score": 0, "created": 1784912531, "updated": 1785107907, "exploited_text": 0, "poc": 0, "score": 0.0, "kev": 0, "flags": []}, {"key": "CVE-2026-64218", "cve": "CVE-2026-64218", "lang": "en", "title": "CVE-2026-64218", "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\nbatman-adv: bla: fix report_work leak on backbone_gw purge\n\nbatadv_bla_purge_backbone_gw() removes stale backbone gateway entries,\nbut fails to properly handle their associated report_work:\n\n- If report_work is running, the purge must wait for it to finish before\n  freeing the backbone_gw, otherwise the worker may access freed memory\n  (e.g. bat_priv).\n- If report_work is pending, the purge must cancel it and release the\n  reference held for that pending work item.\n\nThe previous implementation called hlist_for_each_entry_safe() inside a\nspin_lock_bh() section, but cancel_work_sync() may sleep and therefore\ncannot be called from within a spinlock-protected region.\n\nRestructure the loop to handle one entry per spinlock critical section:\nacquire the lock, find the next entry to purge, remove it from the hash\nlist, then release the lock before calling cancel_work_sync() and\ndropping the hash_entry reference. Repeat until no more entries require\npurging.", "product": "Linux", "category": "cve", "source": "NVD", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-64218", "card": "CVE-2026-64218.webp?v=1784912636", "takeaways": [], "ts": 1784909809, "exploited": 0, "has_score": 0, "created": 1784912531, "updated": 1785107907, "exploited_text": 0, "poc": 0, "score": 0.0, "kev": 0, "flags": []}, {"key": "CVE-2026-64217", "cve": "CVE-2026-64217", "lang": "en", "title": "CVE-2026-64217", "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\nnetfs: Fix overrun check in netfs_extract_user_iter()\n\nFix netfs_extract_user_iter() so that if iov_iter_extract_pages() overfills\npages[], then those pages don't get included in the iterator constructed at\nthe end of the function.  If there was an overfill, memory corruption has\nalready happened.", "product": "Linux", "category": "cve", "source": "NVD", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-64217", "card": "CVE-2026-64217.webp?v=1784912636", "takeaways": [], "ts": 1784909809, "exploited": 0, "has_score": 0, "created": 1784912531, "updated": 1785107907, "exploited_text": 0, "poc": 0, "score": 0.0, "kev": 0, "flags": []}, {"key": "CVE-2026-64216", "cve": "CVE-2026-64216", "lang": "en", "title": "CVE-2026-64216", "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\nnetfs: Fix potential UAF in netfs_unlock_abandoned_read_pages()\n\nnetfs_unlock_abandoned_read_pages(rreq) accesses the index of the folios it\nis wanting to unlock and compares that to rreq->no_unlock_folio so that it\ndoesn't unlock a folio being read for netfs_perform_write() or\nnetfs_write_begin().\n\nHowever, given that netfs_unlock_abandoned_read_pages() is called _after_\nNETFS_RREQ_IN_PROGRESS is cleared, the one folio that it's not allowed to\ndereference is the one specified by ->no_unlock_folio as ownership\nimmediately reverts to the caller.\n\nFix this by storing the folio pointer instead and using that rather than\nthe index.  Also fix netfs_unlock_read_folio() where the same applies.", "product": "Linux", "category": "cve", "source": "NVD", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-64216", "card": "CVE-2026-64216.webp?v=1784912636", "takeaways": [], "ts": 1784909809, "exploited": 0, "has_score": 0, "created": 1784912531, "updated": 1785107907, "exploited_text": 0, "poc": 0, "score": 0.0, "kev": 0, "flags": []}, {"key": "CVE-2026-64215", "cve": "CVE-2026-64215", "lang": "en", "title": "CVE-2026-64215", "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/msm/a6xx: Check kzalloc return in a8xx_hfi_send_perf_table\n\nCheck the return value of kzalloc() to prevent a NULL pointer\ndereference on allocation failure.\n\nPatchwork: https://patchwork.freedesktop.org/patch/721342/", "product": "Linux", "category": "cve", "source": "NVD", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-64215", "card": "CVE-2026-64215.webp?v=1784912636", "takeaways": [], "ts": 1784909809, "exploited": 0, "has_score": 0, "created": 1784912531, "updated": 1785107907, "exploited_text": 0, "poc": 0, "score": 0.0, "kev": 0, "flags": []}, {"key": "CVE-2026-64214", "cve": "CVE-2026-64214", "lang": "en", "title": "CVE-2026-64214", "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\npowerpc/time: Remove redundant preempt_disable|enable() calls from arch_irq_work_raise()\n\nA kernel panic is observed when handling machine check exceptions from\nreal mode.\n\n  BUG: Unable to handle kernel data access on read at 0xc00000006be21300\n  Oops: Kernel access of bad area, sig: 11 [#1]\n  MSR:  8000000000001003    CR: 88222248  XER: 00000005\n  CFAR: c00000000003ffc4 DAR: c00000006be21300 DSISR: 40000000 IRQMASK: 0\n  NIP [c000000000029e40] arch_irq_work_raise+0x10/0x70\n  LR [c00000000003ffc8] machine_check_queue_event+0xa8/0x150\n  Call Trace:\n  [c0000000179d3c70] [c00000000003ff64] machine_check_queue_event+0x44/0x150\n  [c0000000179d3d30] [c0000000000084e0] machine_check_early_common+0x1f0/0x2c0\n\nThe crash occurs because arch_irq_work_raise() calls preempt_disable()\nfrom machine check exception (MCE) handlers running in real mode. In\nthis context, accessing the preempt_count can fault, leading to the panic.\n\nThe preempt_disable()/preempt_enable() pair in arch_irq_work_raise()\nwas originally added by commit 0fe1ac48bef0 (\"powerpc/perf_event: Fix\noops due to perf_event_do_pending call\") to avoid races while rai", "product": "Linux", "category": "cve", "source": "NVD", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-64214", "card": "CVE-2026-64214.webp?v=1784912635", "takeaways": [], "ts": 1784909809, "exploited": 0, "has_score": 0, "created": 1784912531, "updated": 1785107907, "exploited_text": 0, "poc": 0, "score": 0.0, "kev": 0, "flags": []}, {"key": "CVE-2026-64213", "cve": "CVE-2026-64213", "lang": "en", "title": "CVE-2026-64213", "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\nhwmon: (lm90) Add lock protection to lm90_alert\n\nSashiko reports:\n\nlm90_alert() executes in the smbus alert context and calls\nlm90_update_confreg() to disable the hardware alert line, without\nacquiring hwmon_lock.\n\nConcurrently, sysfs write operations (such as lm90_write_convrate) hold\nthe hwmon_lock, temporarily modify data->config, and then restore it.\n\nIf an alert interrupt occurs concurrently with a sysfs write, the sysfs\npath will overwrite the alert handler's modifications to data->config\nand the hardware register.\n\nThis unintentionally re-enables the hardware alert line while the alarm is\nstill active, causing an interrupt storm.\n\nAdd the missing lock to lm90_alert() to solve the problem.", "product": "Linux", "category": "cve", "source": "NVD", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-64213", "card": "CVE-2026-64213.webp?v=1784912638", "takeaways": [], "ts": 1784909808, "exploited": 0, "has_score": 0, "created": 1784912531, "updated": 1785109865, "exploited_text": 0, "poc": 0, "score": 0.0, "kev": 0, "flags": []}, {"key": "CVE-2026-64212", "cve": "CVE-2026-64212", "lang": "en", "title": "CVE-2026-64212", "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: iwlwifi: mld: don't dereference a pointer before NULL checking it\n\nIn iwl_mld_remove_link, the link->fw_id is saved at the beginning of the\nfunction so we have it after we freed the link.\n\nBut the link pointer can be NULL, and is not checked when the fw_id is\nstored.\n\nFix it by simply freeing the link at the end of the function.\n\nfFixes: 0e66a39f4f0e (\"wifi: iwlwifi: fix potential use after free in iwl_mld_remove_link()\")", "product": "Linux", "category": "cve", "source": "NVD", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-64212", "card": "CVE-2026-64212.webp?v=1784912638", "takeaways": [], "ts": 1784909808, "exploited": 0, "has_score": 0, "created": 1784912531, "updated": 1785109865, "exploited_text": 0, "poc": 0, "score": 0.0, "kev": 0, "flags": []}, {"key": "CVE-2026-64211", "cve": "CVE-2026-64211", "lang": "en", "title": "CVE-2026-64211", "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\nsrcu: Don't queue workqueue handlers to never-online CPUs\n\nWhile an srcu_struct structure is in the midst of switching from CPU-0\nto all-CPUs state, it can attempt to invoke callbacks for CPUs that\nhave never been online.  Worse yet, it can attempt in invoke callbacks\nfor CPUs that never will be online, even including imaginary CPUs not in\ncpu_possible_mask.  This can cause hangs on s390, which is not set up to\ndeal with workqueue handlers being scheduled on such CPUs.  This commit\ntherefore causes Tree SRCU to refrain from queueing workqueue handlers\non CPUs that have not yet (and might never) come online.\n\nBecause callbacks are not invoked on CPUs that have not been\nonline, it is an error to invoke call_srcu(), synchronize_srcu(), or\nsynchronize_srcu_expedited() on a CPU that is not yet fully online.\nHowever, it turns out to be less code to redirect the callbacks\nfrom too-early invocations of call_srcu() than to warn about such\ninvocations.  This commit therefore also redirects callbacks queued on\nnot-yet-fully-online CPUs to the boot CPU.", "product": "Linux", "category": "cve", "source": "NVD", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-64211", "card": "CVE-2026-64211.webp?v=1784912638", "takeaways": [], "ts": 1784909808, "exploited": 0, "has_score": 0, "created": 1784912531, "updated": 1785109865, "exploited_text": 0, "poc": 0, "score": 0.0, "kev": 0, "flags": []}, {"key": "CVE-2026-64210", "cve": "CVE-2026-64210", "lang": "en", "title": "CVE-2026-64210", "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet/mlx5e: xsk: Fix unlocked writing to ICOSQ\n\nDuring napi poll, when the affinity changes and there's still XSK work\nto be done, we trigger an ICOSQ interrupt on the new CPU. However, this\ntriggering on the ICOSQ is done unprotected.\n\nThere are 2 such races:\n\nA) mlx5e_trigger_irq() is called while mlx5e_xsk_alloc_rx_mpwqe() is\nrunning from a different CPU due to affinity change. This can happen\nbecause IRQ triggering is done after napi_complete_done(). At this point\nthe NAPI can be scheduled on a different CPU. Like this:\n\n  CPU A (old affinity, NAPI tail)    CPU B (new affinity, fresh NAPI)\n  -------------------------------    --------------------------------\n  napi_complete_done()  clears SCHED\n  mlx5e_cq_arm(...)\n                                     napi_schedule_prep() sets SCHED\n                                     mlx5e_napi_poll()\n                                       mlx5e_xsk_alloc_rx_mpwqe()\n                                         mlx5e_icosq_sync_lock() // noop\n                                         memcpy 640 B UMR body\n                                         advance sq->pc by 10\n  mlx5e_trigger_", "product": "Linux", "category": "cve", "source": "NVD", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-64210", "card": "CVE-2026-64210.webp?v=1784912637", "takeaways": [], "ts": 1784909808, "exploited": 0, "has_score": 0, "created": 1784912531, "updated": 1785109865, "exploited_text": 0, "poc": 0, "score": 0.0, "kev": 0, "flags": []}, {"key": "CVE-2026-64209", "cve": "CVE-2026-64209", "lang": "en", "title": "CVE-2026-64209", "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\nphy: qcom: qmp-usbc: Fix out-of-bounds array access in dp swing config\n\nswing_tbl and pre_emphasis_tbl are 4x4 arrays (valid indices 0-3), but\nthe boundary check uses \"> 4\" instead of \">= 4\", allowing index 4 to\ncause an out-of-bounds access.", "product": "Linux", "category": "cve", "source": "NVD", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-64209", "card": "CVE-2026-64209.webp?v=1784912637", "takeaways": [], "ts": 1784909808, "exploited": 0, "has_score": 0, "created": 1784912531, "updated": 1785107907, "exploited_text": 0, "poc": 0, "score": 0.0, "kev": 0, "flags": []}, {"key": "CVE-2026-64208", "cve": "CVE-2026-64208", "lang": "en", "title": "CVE-2026-64208", "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\ncrypto/krb5, rxrpc: Fix lack of pre-decrypt/pre-verify length checks\n\nChange the krb5 crypto library to provide facilities to precheck the length\nof the message about to be decrypted or verified.\n\nFix AF_RXRPC to make use of this to validate DATA packets secured with\nRxGK.", "product": "Linux", "category": "cve", "source": "NVD", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-64208", "card": "CVE-2026-64208.webp?v=1784912637", "takeaways": [], "ts": 1784909808, "exploited": 0, "has_score": 0, "created": 1784912531, "updated": 1785107907, "exploited_text": 0, "poc": 0, "score": 0.0, "kev": 0, "flags": []}, {"key": "CVE-2026-8789", "cve": "CVE-2026-8789", "lang": "en", "title": "CVE-2026-8789", "summary": "The Easy Appointments plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check and missing nonce verification on the `ea_delete_multiple_connections` AJAX action in all versions up to, and including, 3.12.27. This makes it possible for authenticated attackers, with Contributor-level access and above, to delete arbitrary connection records from the `wp_ea_connections` table, disrupting the plugin's core booking functionality.", "product": "easyappointments Easy Appointments", "category": "cve", "source": "NVD", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-8789", "card": "CVE-2026-8789.webp?v=1784906618", "takeaways": ["CVSS 3.1 : 8.1 HIGH", "Vector: AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H"], "ts": 1784906348, "exploited": 0, "has_score": 1, "created": 1784906504, "updated": 1785105905, "exploited_text": 0, "poc": 0, "score": 8.1, "kev": 0, "flags": []}, {"key": "CVE-2026-58630", "cve": "CVE-2026-58630", "lang": "en", "title": "CVE-2026-58630", "summary": "Improper access control in Azure App Service allows an unauthorized attacker to elevate privileges over a network.", "product": "Microsoft Azure App Service for Linux", "category": "cve", "source": "NVD", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-58630", "card": "CVE-2026-58630.webp?v=1784906618", "takeaways": ["CVSS 3.1 : 10.0 CRITICAL", "Vector: AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N"], "ts": 1784906327, "exploited": 0, "has_score": 1, "created": 1784906504, "updated": 1785105905, "exploited_text": 0, "poc": 0, "score": 10.0, "kev": 0, "flags": []}, {"key": "CVE-2026-58586", "cve": "CVE-2026-58586", "lang": "en", "title": "CVE-2026-58586", "summary": "Image::WebP versions through 0.2 for Perl bundle a vulnerable version of libwebp.\n\nImage::WebP does not link to the system libwebp. Instead, it uses a bundled copy of libwebp 0.3.0 (released 2013-03-20). That version has multiple known vulnerabilities, including CVE-2023-4863.\n\nAny caller that decodes an untrusted WebP image reaches the bundled decoder. Because the library is compiled into the module, upgrading the system libwebp does not remediate this.", "product": "ZAPAD Image::WebP", "category": "cve", "source": "NVD", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-58586", "card": "CVE-2026-58586.webp?v=1784906618", "takeaways": [], "ts": 1784906324, "exploited": 0, "has_score": 0, "created": 1784906504, "updated": 1785105905, "exploited_text": 0, "poc": 0, "score": 0.0, "kev": 0, "flags": []}, {"key": "CVE-2026-57106", "cve": "CVE-2026-57106", "lang": "en", "title": "CVE-2026-57106", "summary": "Server-side request forgery (ssrf) in Data Quality allows an unauthorized attacker to elevate privileges over a network.", "product": "Microsoft Purview Data Governance", "category": "cve", "source": "NVD", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-57106", "card": "CVE-2026-57106.webp?v=1784906618", "takeaways": ["CVSS 3.1 : 10.0 CRITICAL", "Vector: AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H"], "ts": 1784906319, "exploited": 0, "has_score": 1, "created": 1784906504, "updated": 1785105905, "exploited_text": 0, "poc": 0, "score": 10.0, "kev": 0, "flags": []}, {"key": "CVE-2026-56163", "cve": "CVE-2026-56163", "lang": "en", "title": "CVE-2026-56163", "summary": "Missing authentication for critical function in Microsoft Azure Kubernetes Service allows an unauthorized attacker to elevate privileges over a network.", "product": "Microsoft Azure Kubernetes Service", "category": "cve", "source": "NVD", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56163", "card": "CVE-2026-56163.webp?v=1784906619", "takeaways": ["CVSS 3.1 : 10.0 CRITICAL", "Vector: AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H"], "ts": 1784906313, "exploited": 0, "has_score": 1, "created": 1784906504, "updated": 1785105905, "exploited_text": 0, "poc": 0, "score": 10.0, "kev": 0, "flags": []}, {"key": "CVE-2026-55732", "cve": "CVE-2026-55732", "lang": "en", "title": "CVE-2026-55732", "summary": "Out-of-bounds Read (CWE-125) in BACnet packet parsing (`bacdt_datetime_to_tod`) in Loytec LIP-ME201C, L-INX, L-GATE, L-ROC, L-IOB, L-DALI, L-VIS and L-PAD through 8.4.18 on LINX-A64 allows an unauthenticated remote attacker to crash `linx_a64.exe` and ultimately reboot the device via a malformed BACnet TimeSynchronization or UTC-TimeSynchronization packet with an invalid month value. The same vulnerability affects multiple other Loytec products.", "product": "Loytec LIP-ME20xC", "category": "cve", "source": "NVD", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-55732", "card": "CVE-2026-55732.webp?v=1784906619", "takeaways": ["CVSS 4.0 : 8.7 HIGH", "Vector: AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N"], "ts": 1784906311, "exploited": 0, "has_score": 1, "created": 1784906504, "updated": 1785105905, "exploited_text": 0, "poc": 0, "score": 8.7, "kev": 0, "flags": []}, {"key": "CVE-2026-55730", "cve": "CVE-2026-55730", "lang": "en", "title": "CVE-2026-55730", "summary": "Reflected Cross-Site Scripting (CWE-79) in LWEB802 in Loytec LWEB-802 before 5.0.8 on all platforms allows an unauthenticated remote attacker to execute arbitrary JavaScript in a victim's browser and perform actions with the victim's privileges via a crafted link containing a malicious `project` or `mspParams` parameter.", "product": "Loytec LWEB-802", "category": "cve", "source": "NVD", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-55730", "card": "CVE-2026-55730.webp?v=1784906619", "takeaways": ["CVSS 4.0 : 8.7 HIGH", "Vector: AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"], "ts": 1784906311, "exploited": 0, "has_score": 1, "created": 1784906504, "updated": 1785105905, "exploited_text": 0, "poc": 0, "score": 8.7, "kev": 0, "flags": []}, {"key": "CVE-2026-55729", "cve": "CVE-2026-55729", "lang": "en", "title": "CVE-2026-55729", "summary": "Exposure of Sensitive Information (CWE-200) in LWEB802 browser `localStorage` in Loytec LWEB-802 before 5.0.8 on all platforms allows an unauthenticated remote attacker to leak stored management credentials via a crafted link.", "product": "Loytec LWEB-802", "category": "cve", "source": "NVD", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-55729", "card": "CVE-2026-55729.webp?v=1784906619", "takeaways": ["CVSS 4.0 : 7.7 HIGH", "Vector: AV:N/AC:L/AT:P/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"], "ts": 1784906311, "exploited": 0, "has_score": 1, "created": 1784906504, "updated": 1785105905, "exploited_text": 0, "poc": 0, "score": 7.7, "kev": 0, "flags": []}, {"key": "CVE-2026-49326", "cve": "CVE-2026-49326", "lang": "en", "title": "CVE-2026-49326", "summary": "Missing Authorization vulnerability in Apache HBase thrift and rest delegation service.\n\nA scan operation in thrift/rest service has 3 steps, open, fetch(possible multiple times), close.\nThe open step will return an id which will be passed back to server for identifying the scanner instances stored at server side.\nWe missed the owner check in fetch and close steps which means a user can fetch rows from the scanner which is opened by other users, and close scanners which belongs to other users.\n\nThis issue affects Apache HBase:from 3.0.0-alpha-1 through 3.0.0-beta-1, from 2.6.0 through 2.6.5, from 2.5.0 through 2.5.14, through 2.4.*.\n\nUsers are recommended to upgrade to version 3.0.0-beta-2, 2.6.6 and 2.5.15, which fixes the issue.", "product": "Apache Software Foundation Apache HBase", "category": "cve", "source": "NVD", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-49326", "card": "CVE-2026-49326.webp?v=1785106026", "takeaways": ["CVSS 3.1 : 6.5 MEDIUM", "Vector: AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"], "ts": 1784906251, "exploited": 0, "has_score": 1, "created": 1784906504, "updated": 1785105905, "exploited_text": 0, "poc": 0, "score": 6.5, "kev": 0, "flags": []}, {"key": "CVE-2026-16802", "cve": "CVE-2026-16802", "lang": "en", "title": "CVE-2026-16802", "summary": "Cleartext storage of sensitive information in the variables feature in Devolutions PowerShell Universal 2026.2.2 and earlier allows a local actor with file system access to read secret values via secret variables stored in cleartext on disk when no vault is selected.", "product": "Devolutions PowerShell Universal", "category": "cve", "source": "NVD", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-16802", "card": "CVE-2026-16802.webp?v=1785106027", "takeaways": ["CVSS 3.1 : 6.5 MEDIUM", "Vector: AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N"], "ts": 1784906233, "exploited": 0, "has_score": 1, "created": 1784906504, "updated": 1785105905, "exploited_text": 0, "poc": 0, "score": 6.5, "kev": 0, "flags": []}, {"key": "CVE-2026-16801", "cve": "CVE-2026-16801", "lang": "en", "title": "CVE-2026-16801", "summary": "Improper control of generation of code ('Code Injection') in the variables feature in Devolutions PowerShell Universal 2026.2.2 and earlier allows an authenticated user with variable write permission to execute arbitrary PowerShell code via a crafted variable value that is not properly escaped when written to the variables configuration file.", "product": "Devolutions PowerShell Universal", "category": "cve", "source": "NVD", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-16801", "card": "CVE-2026-16801.webp?v=1785106026", "takeaways": ["CVSS 3.1 : 8.8 HIGH", "Vector: AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"], "ts": 1784906233, "exploited": 0, "has_score": 1, "created": 1784906504, "updated": 1785105905, "exploited_text": 0, "poc": 0, "score": 8.8, "kev": 0, "flags": []}, {"key": "CVE-2026-16800", "cve": "CVE-2026-16800", "lang": "en", "title": "CVE-2026-16800", "summary": "Improper control of generation of code ('Code Injection') in the schedule feature in Devolutions PowerShell Universal 2026.2.2 and earlier allows an authenticated user with schedule creation permission to execute arbitrary PowerShell code via crafted schedule parameter names concatenated into a script invocation.", "product": "Devolutions PowerShell Universal", "category": "cve", "source": "NVD", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-16800", "card": "CVE-2026-16800.webp?v=1785106027", "takeaways": ["CVSS 3.1 : 8.8 HIGH", "Vector: AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"], "ts": 1784906232, "exploited": 0, "has_score": 1, "created": 1784906504, "updated": 1785105905, "exploited_text": 0, "poc": 0, "score": 8.8, "kev": 0, "flags": []}, {"key": "CVE-2026-16799", "cve": "CVE-2026-16799", "lang": "en", "title": "CVE-2026-16799", "summary": "Improper access control in the automation tests and workflows features in Devolutions PowerShell Universal 2026.2.2 and earlier allows an authenticated user with only the Reader role to execute automation tests and modify workflow properties via missing server-side authorization checks.", "product": "Devolutions PowerShell Universal", "category": "cve", "source": "NVD", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-16799", "card": "CVE-2026-16799.webp?v=1785106027", "takeaways": ["CVSS 3.1 : 5.0 MEDIUM", "Vector: AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:L/A:N"], "ts": 1784906232, "exploited": 0, "has_score": 1, "created": 1784906504, "updated": 1785105905, "exploited_text": 0, "poc": 0, "score": 5.0, "kev": 0, "flags": []}, {"key": "CVE-2026-16798", "cve": "CVE-2026-16798", "lang": "en", "title": "CVE-2026-16798", "summary": "Insertion of sensitive information into sent data in the automation jobs API in Devolutions PowerShell Universal 2026.2.2 and earlier allows an authenticated user with scoped job or script read permission to obtain another user's stored OAuth refresh token via job read responses that fail to strip the refresh token.", "product": "Devolutions PowerShell Universal", "category": "cve", "source": "NVD", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-16798", "card": "CVE-2026-16798.webp?v=1785106027", "takeaways": ["CVSS 3.1 : 6.5 MEDIUM", "Vector: AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"], "ts": 1784906232, "exploited": 0, "has_score": 1, "created": 1784906504, "updated": 1785105905, "exploited_text": 0, "poc": 0, "score": 6.5, "kev": 0, "flags": []}, {"key": "CVE-2026-12504", "cve": "CVE-2026-12504", "lang": "en", "title": "CVE-2026-12504", "summary": "Improper Authentication (CWE-287) in the PAM configuration in Loytec LIP-ME201C, L-INX, L-GATE, L-ROC, L-IOB, L-DALI, L-VIS and L-PAD through 8.4.16 on LINX-A64 allows a local attacker to authenticate as a uid=0 account without a password and obtain a root shell via an `/etc/passwd` entry with an empty password field.", "product": "Loytec LIP-ME20xC", "category": "cve", "source": "NVD", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-12504", "card": "CVE-2026-12504.webp?v=1784906620", "takeaways": ["CVSS 4.0 : 8.4 HIGH", "Vector: AV:L/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"], "ts": 1784906231, "exploited": 0, "has_score": 1, "created": 1784906504, "updated": 1785105905, "exploited_text": 0, "poc": 0, "score": 8.4, "kev": 0, "flags": []}, {"key": "CVE-2026-12503", "cve": "CVE-2026-12503", "lang": "en", "title": "CVE-2026-12503", "summary": "Improper Link Resolution (CWE-59) in `/usr/bin/larm_starter` in Loytec L-INX, L-GATE, L-ROC, L-IOB, L-DALI, L-VIS and L-PAD through 8.4.16 on LINX-A64 allows an authenticated `larmapp` attacker to make `/etc/passwd` writable by the `larmapp` group (leading to root privilege escalation) via a symlink attack on `/etc/lighttpd/ssl/server.pem`.", "product": "Loytec LIP-ME20xC", "category": "cve", "source": "NVD", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-12503", "card": "CVE-2026-12503.webp?v=1784906621", "takeaways": ["CVSS 4.0 : 9.2 CRITICAL", "Vector: AV:L/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:H/SA:N"], "ts": 1784906230, "exploited": 0, "has_score": 1, "created": 1784906504, "updated": 1785103942, "exploited_text": 0, "poc": 0, "score": 9.2, "kev": 0, "flags": []}, {"key": "CVE-2026-12502", "cve": "CVE-2026-12502", "lang": "en", "title": "CVE-2026-12502", "summary": "Improper Privilege Management (CWE-269) in `/usr/bin/ltsudo` in Loytec LIP-ME201C, L-INX, L-GATE, L-ROC, L-IOB, L-DALI, L-VIS and L-PAD through 8.4.16 on LINX-A64 allows a `superadmin`-group attacker to reset the password of any LARM user (including the `larmapp` service account) via the `set-passwd` subcommand.", "product": "Loytec LIP-ME20xC", "category": "cve", "source": "NVD", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-12502", "card": "CVE-2026-12502.webp?v=1784906621", "takeaways": ["CVSS 4.0 : 8.4 HIGH", "Vector: AV:L/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"], "ts": 1784906230, "exploited": 0, "has_score": 1, "created": 1784906504, "updated": 1785103942, "exploited_text": 0, "poc": 0, "score": 8.4, "kev": 0, "flags": []}, {"key": "CVE-2026-12496", "cve": "CVE-2026-12496", "lang": "en", "title": "CVE-2026-12496", "summary": "Stored Cross-Site Scripting (CWE-79) in the OPC XML-DA server statistics in Loytec LIP-ME201C, L-INX, L-GATE, L-ROC, L-IOB, L-DALI, L-VIS and L-PAD through 8.4.16 on LINX-A64 allows an unauthenticated remote attacker to execute arbitrary JavaScript in an administrator's browser (session hijacking, credential theft, device reconfiguration) via a crafted `User-Agent` header in a `POST /da` request.", "product": "Loytec LIP-ME20xC", "category": "cve", "source": "NVD", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-12496", "card": "CVE-2026-12496.webp?v=1784906621", "takeaways": ["CVSS 4.0 : 8.7 HIGH", "Vector: AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"], "ts": 1784906228, "exploited": 0, "has_score": 1, "created": 1784906504, "updated": 1785103942, "exploited_text": 0, "poc": 0, "score": 8.7, "kev": 0, "flags": []}, {"key": "CVE-2026-9765", "cve": "CVE-2026-9765", "lang": "en", "title": "CVE-2026-9765", "summary": "Note: The CVE and blog post don't exist because we determined this is actually a cloud-only issue.\n\nAccess Controls are “Broken” when a user can access resources they are not authorized to access. An attacker can bypass any access control mechanisms in a web application, and gain unauthorized access to resources that are not available with their permissions. \n\nBroken access control can allow attackers to:\nAccess resources only accessible to certain users, thus allowing unauthorized access to data\nPerform operations on behalf of other users, leading to account takeovers in the worst cases\nAttempt privilege escalation\nAttempt to take over an account", "product": "Grafana IRM", "category": "cve", "source": "NVD", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-9765", "card": "CVE-2026-9765.webp?v=1784900706", "takeaways": ["CVSS 3.1 : 7.1 HIGH", "Vector: AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:L"], "ts": 1784899111, "exploited": 0, "has_score": 1, "created": 1784900576, "updated": 1785103942, "exploited_text": 0, "poc": 0, "score": 7.1, "kev": 0, "flags": []}, {"key": "CVE-2026-66144", "cve": "CVE-2026-66144", "lang": "en", "title": "CVE-2026-66144", "summary": "Although remote policy references are not retrieved during policy normalization, if they are manually retrieved via the API it can cause a denial of service attack if a huge policy is retrieved. Users are recommended to upgrade to version 3.2.3, which fixes this issue by imposing a default maximum size on data read from remote policy references.", "product": "Apache Software Foundation Apache Neethi", "category": "cve", "source": "NVD", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-66144", "card": "CVE-2026-66144.webp?v=1785104043", "takeaways": ["CVSS 3.1 : 7.5 HIGH", "Vector: AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"], "ts": 1784899109, "exploited": 0, "has_score": 1, "created": 1784900576, "updated": 1785103942, "exploited_text": 0, "poc": 0, "score": 7.5, "kev": 0, "flags": []}, {"key": "CVE-2026-66143", "cve": "CVE-2026-66143", "lang": "en", "title": "CVE-2026-66143", "summary": "It is possible to bypass the maximum number of normalized policy alternatives that was introduced in Apache Neethi 3.2.2 via certain crafted policies, which may lead to a denial of service attack via resource consumption. Users are recommended to upgrade to version 3.2.3, which fixes this issue.", "product": "Apache Software Foundation Apache Neethi", "category": "cve", "source": "NVD", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-66143", "card": "CVE-2026-66143.webp?v=1785104043", "takeaways": ["CVSS 3.1 : 7.5 HIGH", "Vector: AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"], "ts": 1784899109, "exploited": 0, "has_score": 1, "created": 1784900576, "updated": 1785103942, "exploited_text": 0, "poc": 0, "score": 7.5, "kev": 0, "flags": []}, {"key": "CVE-2026-66142", "cve": "CVE-2026-66142", "lang": "en", "title": "CVE-2026-66142", "summary": "Apache Neethi is vulnerable to uncontrolled recursion when parsing policies that lack policy Ids or with deeply nested structures, which may lead to a denial of service attack when parsing policies due to runtime memory exhaustion. Users are recommended to upgrade to version 3.2.3, which fixes this issue.", "product": "Apache Software Foundation Apache Neethi", "category": "cve", "source": "NVD", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-66142", "card": "CVE-2026-66142.webp?v=1785104042", "takeaways": ["CVSS 3.1 : 7.5 HIGH", "Vector: AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"], "ts": 1784899109, "exploited": 0, "has_score": 1, "created": 1784900576, "updated": 1785103942, "exploited_text": 0, "poc": 0, "score": 7.5, "kev": 0, "flags": []}, {"key": "CVE-2026-46452", "cve": "CVE-2026-46452", "lang": "en", "title": "CVE-2026-46452", "summary": "Improper Input Validation vulnerability in Apache NimBLE in Mesh Proxy SAR reassembly could result in passing broken data toward application resulting in memory pressure and unstable parsing behavior.\n\nThis issue affects Apache NimBLE: through 1.9.0.\n\nUsers are recommended to upgrade to version 1.10.0, which fixes the issue.", "product": "Apache Software Foundation Apache NimBLE", "category": "cve", "source": "NVD", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-46452", "card": "CVE-2026-46452.webp?v=1785104043", "takeaways": ["CVSS 3.1 : 5.3 MEDIUM", "Vector: AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"], "ts": 1784899105, "exploited": 0, "has_score": 1, "created": 1784900576, "updated": 1785103942, "exploited_text": 0, "poc": 0, "score": 5.3, "kev": 0, "flags": []}, {"key": "CVE-2026-45816", "cve": "CVE-2026-45816", "lang": "en", "title": "CVE-2026-45816", "summary": "NULL Pointer Dereference vulnerability in Apache NimBLE in LE Long Term Key Request event.\n\nThis requires disabled asserts (otherwise assert would trigger before NULL dereference) and bogus (or misbehaving) controller, thus severity is low.\n\nThis issue affects Apache NimBLE: through 1.9.0.\n\nUsers are recommended to upgrade to version 1.10.0, which fixes the issue.", "product": "Apache Software Foundation Apache NimBLE", "category": "cve", "source": "NVD", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-45816", "card": "CVE-2026-45816.webp?v=1785104044", "takeaways": ["CVSS 3.1 : 7.5 HIGH", "Vector: AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"], "ts": 1784899104, "exploited": 0, "has_score": 1, "created": 1784900576, "updated": 1785103942, "exploited_text": 0, "poc": 0, "score": 7.5, "kev": 0, "flags": []}, {"key": "CVE-2026-45815", "cve": "CVE-2026-45815", "lang": "en", "title": "CVE-2026-45815", "summary": "Reachable Assertion vulnerability in Apache NimBLE.\nA specially crafted ATT Read Multiple Variable Response (BLE_ATT_OP_READ_MULT_VAR_RSP) may trigger assert in ATT parser.\n\nSeverity is medium as this requires DUT to first send ATT Read Multiple Variable Request.\n\nThis issue affects Apache NimBLE: through 1.9.0.\n\nUsers are recommended to upgrade to version 1.10.0, which fixes the issue.", "product": "Apache Software Foundation Apache NimBLE", "category": "cve", "source": "NVD", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-45815", "card": "CVE-2026-45815.webp?v=1785104044", "takeaways": ["CVSS 3.1 : 7.5 HIGH", "Vector: AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"], "ts": 1784899104, "exploited": 0, "has_score": 1, "created": 1784900576, "updated": 1785103942, "exploited_text": 0, "poc": 0, "score": 7.5, "kev": 0, "flags": []}, {"key": "CVE-2026-45813", "cve": "CVE-2026-45813", "lang": "en", "title": "CVE-2026-45813", "summary": "Out-of-bounds Write, Integer Underflow (Wrap or Wraparound) vulnerability in Apache NimBLE BASS service.\nImproper validation when parsing BASS service  \"Add Source\" and \"Modify Source\" operation PDU could results in stack buffer overflow or arbitrary out-of-bound read.\n\n\nThis can be triggered by nearby devices over Bluetooth connection, however pairing is required prior to accessing BASS service, which depending on device configuration may or may not require user action.\n\nThis issue affects Apache NimBLE: through 1.9.0.\n\nUsers are recommended to upgrade to version 1.10.0, which fixes the issue.", "product": "Apache Software Foundation Apache NimBLE", "category": "cve", "source": "NVD", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-45813", "card": "CVE-2026-45813.webp?v=1785104043", "takeaways": ["CVSS 3.1 : 8.8 HIGH", "Vector: AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"], "ts": 1784899104, "exploited": 0, "has_score": 1, "created": 1784900576, "updated": 1785103942, "exploited_text": 0, "poc": 0, "score": 8.8, "kev": 0, "flags": []}, {"key": "CVE-2026-45812", "cve": "CVE-2026-45812", "lang": "en", "title": "CVE-2026-45812", "summary": "Incorrect Calculation of Buffer Size vulnerability in Apache NimBLE when processing Legacy Advertising Report HCI event.\n\nWhen a single HCI advertising report event bundles multiple reports, NimBLE miscalculated the offset to the next report. This can cause the host to read past the end of the buffer and deliver a GAP event with bogus data to the application.\n\nSeverity is low: NimBLE's own controller never batches multiple reports into one event, so this only matters when NimBLE's host is paired with a third-party controller that does.\n\nThis issue affects Apache NimBLE: through 1.9.0.\n\nUsers are recommended to upgrade to version 1.10.0, which fixes the issue.", "product": "Apache Software Foundation Apache NimBLE", "category": "cve", "source": "NVD", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-45812", "card": "CVE-2026-45812.webp?v=1785104044", "takeaways": ["CVSS 3.1 : 6.5 MEDIUM", "Vector: AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"], "ts": 1784899103, "exploited": 0, "has_score": 1, "created": 1784900576, "updated": 1785103942, "exploited_text": 0, "poc": 0, "score": 6.5, "kev": 0, "flags": []}, {"key": "CVE-2026-45811", "cve": "CVE-2026-45811", "lang": "en", "title": "CVE-2026-45811", "summary": "Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') vulnerability in Apache NimBLE.\nThe HCI socket transport did not check whether a received HCI event would fit the configured event pool before copying it, allowing a buffer overflow. Severity is low: exploitation requires either a misconfigured pool size or a malicious/compromised controller on the other end of the HCI socket link, not over-the-air Bluetooth access.\n\nThis issue affects Apache NimBLE: through 1.9.0.\n\nUsers are recommended to upgrade to version 1.10.0, which fixes the issue.", "product": "Apache Software Foundation Apache NimBLE", "category": "cve", "source": "NVD", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-45811", "card": "CVE-2026-45811.webp?v=1785104044", "takeaways": ["CVSS 3.1 : 7.5 HIGH", "Vector: AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H"], "ts": 1784899103, "exploited": 0, "has_score": 1, "created": 1784900576, "updated": 1785103942, "exploited_text": 0, "poc": 0, "score": 7.5, "kev": 0, "flags": []}, {"key": "CVE-2026-15810", "cve": "CVE-2026-15810", "lang": "en", "title": "CVE-2026-15810", "summary": "A Cross-Site Scripting (XSS) vulnerability in Google Cloud Looker versions prior to 25.6.103, 25.12.65, 25.18.68, 26.0.66, 26.2.47, 26.4.36, 26.6.28, and 26.8.7 on Looker-hosted and Self-hosted allows an attacker to execute arbitrary JavaScript leading to administrative account takeover using a maliciously crafted URL.\n\n\nLooker-hosted and Self-hosted were found to be vulnerable.\nThis issue has already been mitigated for Looker-hosted instances. No user action is required for these.\n\n\nSelf-hosted instances must be upgraded to the patched versions: 25.6.103+, 25.12.65+, 25.18.68+, 26.0.66+, 26.2.47+, 26.4.36+, 26.6.28+, or 26.8.7+.", "product": "Google Cloud Looker", "category": "cve", "source": "NVD", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-15810", "card": "CVE-2026-15810.webp?v=1784896713", "takeaways": ["CVSS 4.0 : 8.7 HIGH", "Vector: AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:L/SI:L/SA:L/U:Amber"], "ts": 1784895407, "exploited": 0, "has_score": 1, "created": 1784896609, "updated": 1785103942, "exploited_text": 0, "poc": 0, "score": 8.7, "kev": 0, "flags": []}, {"key": "CVE-2026-15243", "cve": "CVE-2026-15243", "lang": "en", "title": "CVE-2026-15243", "summary": "Apereo CAS Client accepts any CA-trusted certificate for any hostname, provided the URL the client is calling matches the configured allowlist or regex. An attacker with a MITM position (DNS poisoning, rogue Wi-Fi, malicious proxy, etc.) can provide any CA-signed certificate for a hostname that matches the configured allowlist or regex. This can lead to intercepting the CAS exchange, capturing the Ticket-Granting Ticket (TGT), and subsequently obtaining Service Tickets on behalf of the victim. \n\n\nBecause maintainers contact attempts were unsuccessful, vulnerabilities have only been confirmed in version 4.1.0 (Java Apereo CAS Client) and 3.6.4 (Jasig CAS Client) but may also affect other versions.", "product": "Java Apereo CAS Client", "category": "cve", "source": "NVD", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-15243", "card": "CVE-2026-15243.webp?v=1784896714", "takeaways": ["CVSS 4.0 : 7.4 HIGH", "Vector: AV:N/AC:L/AT:P/PR:N/UI:A/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N"], "ts": 1784895406, "exploited": 0, "has_score": 1, "created": 1784896609, "updated": 1785103942, "exploited_text": 0, "poc": 0, "score": 7.4, "kev": 0, "flags": []}, {"key": "CVE-2026-10610", "cve": "CVE-2026-10610", "lang": "en", "title": "CVE-2026-10610", "summary": "Local privilege escalation potentially allowed an attacker to execute arbitrary code as a privileged user.", "product": "ESET Endpoint Security for macOS", "category": "cve", "source": "NVD", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-10610", "card": "CVE-2026-10610.webp?v=1784896714", "takeaways": ["CVSS 4.0 : 8.5 HIGH", "Vector: AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"], "ts": 1784895405, "exploited": 0, "has_score": 1, "created": 1784896609, "updated": 1785103942, "exploited_text": 0, "poc": 0, "score": 8.5, "kev": 0, "flags": []}, {"key": "CVE-2026-7483", "cve": "CVE-2026-7483", "lang": "en", "title": "CVE-2026-7483", "summary": "Local privilege escalation potentially allowed an attacker to write an arbitrary file with fully controlled content as a privileged user.", "product": "ESET Endpoint Security for macOS", "category": "cve", "source": "NVD", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-7483", "card": "CVE-2026-7483.webp?v=1784888816", "takeaways": ["CVSS 4.0 : 8.5 HIGH", "Vector: AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"], "ts": 1784888192, "exploited": 0, "has_score": 1, "created": 1784888692, "updated": 1785103942, "exploited_text": 0, "poc": 0, "score": 8.5, "kev": 0, "flags": []}, {"key": "CVE-2026-16634", "cve": "CVE-2026-16634", "lang": "en", "title": "CVE-2026-16634", "summary": "TOML::XS versions before 0.06 for Perl bundle an unsupported and vulnerable version of tomlc99.\n\nThe tomlc99 library is no longer maintained, and has an uncontrolled recursion vulnerability publicly reported in the issue tracker.\n\nAny caller that passes untrusted TOML to from_toml risks a stack overflow from a deeply-nested document.\n\nTOML::XS version 0.06 or later uses the successor tomlc17 library.", "product": "FELIPE TOML::XS", "category": "cve", "source": "NVD", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-16634", "card": "CVE-2026-16634.webp?v=1784888817", "takeaways": [], "ts": 1784888191, "exploited": 0, "has_score": 0, "created": 1784888692, "updated": 1785103942, "exploited_text": 0, "poc": 0, "score": 0.0, "kev": 0, "flags": []}, {"key": "CVE-2026-15401", "cve": "CVE-2026-15401", "lang": "en", "title": "CVE-2026-15401", "summary": "The VikBooking Hotel Booking Engine & PMS plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'vbfX' parameter in all versions up to, and including, 1.8.13 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. The vbfX custom-field value is stored via the public-facing saveorder task, which has no capability or authentication check enforced by default, enabling fully unauthenticated submission of malicious payloads.", "product": "VikBooking Hotel Booking Engine & PMS", "category": "cve", "source": "NVD", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-15401", "card": "CVE-2026-15401.webp?v=1784888816", "takeaways": ["CVSS 3.1 : 7.2 HIGH", "Vector: AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N"], "ts": 1784888191, "exploited": 0, "has_score": 1, "created": 1784888692, "updated": 1785103942, "exploited_text": 0, "poc": 0, "score": 7.2, "kev": 0, "flags": []}, {"key": "CVE-2026-10033", "cve": "CVE-2026-10033", "lang": "en", "title": "CVE-2026-10033", "summary": "The EventON Action User plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 2.5.14. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for unauthenticated attackers to grant EventON management capabilities and the upload_files capability to any non-administrator WordPress role or user, escalating their privileges within the site. The administrator role is protected by an early-return guard in update_role_caps(), so only non-administrator roles and individual users can be targeted; however, the same unauthenticated exposure also allows attackers to enumerate all WordPress users with their IDs and display names, disclose role and user capability state along with nonce values, and tamper with event-to-user term assignments.", "product": "EventON Action User", "category": "cve", "source": "NVD", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-10033", "card": "CVE-2026-10033.webp?v=1784888817", "takeaways": ["CVSS 3.1 : 7.3 HIGH", "Vector: AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L"], "ts": 1784888189, "exploited": 0, "has_score": 1, "created": 1784888692, "updated": 1785103942, "exploited_text": 0, "poc": 0, "score": 7.3, "kev": 0, "flags": []}, {"key": "CVE-2026-63317", "cve": "CVE-2026-63317", "lang": "en", "title": "CVE-2026-63317", "summary": "Arbitrary Class Instantiation via XML Feature Generator Descriptor and Format Name in Apache OpenNLP\n\nVersions Affected: \n\n- before 2.5.10\n- before 3.0.0-M5\n\nDescription: \n\nThree code paths in Apache OpenNLP load a class by its fully-qualified name via Class.forName() and invoke its no-arg constructor without any prior validation of the class name or its type. \n\nThe affected paths are: \n\n(1) GeneratorFactory, which reads the class attribute of generator elements in an XML feature generator descriptor; such descriptors are embedded as artifacts in model archives (e.g. TokenNameFinder and POSTagger models) and are parsed during model loading, so an attacker who can supply a crafted model archive controls the class name directly. \n\n(2) StreamFactoryRegistry.getFactory(Class, String), which falls back to interpreting an unregistered format name as the fully-qualified class name of an ObjectStreamFactory; this is exploitable in applications that pass untrusted format names (e.g. exposing the -format parameter of the command-line tooling to external input). \n\n(3) StringInterners, which instantiates the interner implementation named by the opennlp.interner.class system property; this valu", "product": "Apache OpenNLP", "category": "cve", "source": "NVD", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-63317", "card": "CVE-2026-63317.webp?v=1785104041", "takeaways": ["CVSS 3.1 : 5.6 MEDIUM", "Vector: AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L"], "ts": 1784884585, "exploited": 0, "has_score": 1, "created": 1784884754, "updated": 1785103942, "exploited_text": 0, "poc": 0, "score": 5.6, "kev": 0, "flags": []}, {"key": "CVE-2026-49745", "cve": "CVE-2026-49745", "lang": "en", "title": "CVE-2026-49745", "summary": "Kernel software installed and running inside a Guest VM may post improper commands to the GPU Firmware to trigger a write of data outside the Guest's virtualised GPU memory.\n\n\n\nSoftware installed and run under a Guest VM can send commands to the GPU which result in out of bounds memory accesses. These can be used to escalate privileges.", "product": "Imagination Technologies Graphics DDK", "category": "cve", "source": "NVD", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-49745", "card": "CVE-2026-49745.webp?v=1785104042", "takeaways": ["CVSS 3.1 : 7.8 HIGH", "Vector: AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"], "ts": 1784884584, "exploited": 0, "has_score": 1, "created": 1784884754, "updated": 1785103942, "exploited_text": 0, "poc": 0, "score": 7.8, "kev": 0, "flags": []}, {"key": "CVE-2026-49744", "cve": "CVE-2026-49744", "lang": "en", "title": "CVE-2026-49744", "summary": "Kernel software installed and running inside a Guest VM may post improper commands to the GPU Firmware to trigger a write of data outside the Guest's virtualised GPU memory.\n\n\n\nOut of bounds accesses triggered by malware introduced to a Guest KMD could allow privilege escalation which escapes virtualization boundaries.", "product": "Imagination Technologies Graphics DDK", "category": "cve", "source": "NVD", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-49744", "card": "CVE-2026-49744.webp?v=1785102084", "takeaways": ["CVSS 3.1 : 7.8 HIGH", "Vector: AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"], "ts": 1784884584, "exploited": 0, "has_score": 1, "created": 1784884754, "updated": 1785101985, "exploited_text": 0, "poc": 0, "score": 7.8, "kev": 0, "flags": []}, {"key": "CVE-2026-49743", "cve": "CVE-2026-49743", "lang": "en", "title": "CVE-2026-49743", "summary": "Software installed and run as a non-privileged user may conduct improper GPU system calls to manipulate the lifetimes of synchronisation objects in the kernel, leading to read/write UAFs.\n\n\n\nDuring workload submission involving a fence exported by the GPU driver, the reference count of the underlying synchronisation primitive is not properly incremented. This can be exploited, by destroying the exported fence and prematurely release the underlying primitive, resulting in a potential use-after-free condition.", "product": "Imagination Technologies Graphics DDK", "category": "cve", "source": "NVD", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-49743", "card": "CVE-2026-49743.webp?v=1785104041", "takeaways": ["CVSS 3.1 : 7.8 HIGH", "Vector: AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"], "ts": 1784884584, "exploited": 0, "has_score": 1, "created": 1784884754, "updated": 1785103942, "exploited_text": 0, "poc": 0, "score": 7.8, "kev": 0, "flags": []}, {"key": "CVE-2026-24727", "cve": "CVE-2026-24727", "lang": "en", "title": "CVE-2026-24727", "summary": "An unrestricted upload of file with dangerous type vulnerability in the e-paper draft upload function of SUNNET Corporate Training Management System through v10.3 allows remote authenticated users with administrator privileges to execute arbitrary commands by uploading a crafted ZIP archive containing a server-executable file.", "product": "Corporate Training Management System", "category": "cve", "source": "NVD", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-24727", "card": "CVE-2026-24727.webp?v=1784884870", "takeaways": ["CVSS 4.0 : 9.3 CRITICAL", "Vector: AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:L/SI:L/SA:H"], "ts": 1784884584, "exploited": 0, "has_score": 1, "created": 1784884754, "updated": 1785103942, "exploited_text": 0, "poc": 0, "score": 9.3, "kev": 0, "flags": []}, {"key": "CVE-2026-15704", "cve": "CVE-2026-15704", "lang": "en", "title": "CVE-2026-15704", "summary": "In Eclipse BaSyx Go Components versions up to and including 1.0.0, ABAC-enabled deployments are vulnerable to an authorization bypass caused by inconsistent trailing-slash handling between the ABAC middleware and the HTTP router.\n\n\n\nThe shared router configuration used Chi's `middleware.StripSlashes`, so a request such as `GET /shells/` was dispatched to the registered `GET /shells` route. However, the ABAC middleware evaluated the original request path including the trailing slash. If ABAC route lookup did not find a matching slash-suffixed route, the request was passed onward and the router then stripped the slash and executed the protected handler without the intended ABAC authorization decision and without the expected ABAC query filters.\n\n\n\nAn unauthenticated or unauthorized network attacker could append a trailing slash to protected API routes to reach handlers that should have been denied by ABAC policy. Depending on the exposed component, HTTP method, and deployed policy, this could allow unauthorized read, create, update, delete, or upload operations.\n\n\n\nThe issue affects ABAC-enabled deployments of services that use the shared router and ABAC middleware, including AAS Rep", "product": "Eclipse BaSyx Go Components", "category": "cve", "source": "NVD", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-15704", "card": "CVE-2026-15704.webp?v=1784884870", "takeaways": ["CVSS 3.1 : 9.8 CRITICAL", "Vector: AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"], "ts": 1784884584, "exploited": 0, "has_score": 1, "created": 1784884754, "updated": 1785103942, "exploited_text": 0, "poc": 0, "score": 9.8, "kev": 0, "flags": []}, {"key": "CVE-2026-16519", "cve": "CVE-2026-16519", "lang": "en", "title": "CVE-2026-16519", "summary": "A\nDLL hijacking vulnerability exists in the GeoVision GV-IP Device Utility\ndesktop application. The application loads one or more dynamic-link libraries\n(DLLs) from an unsafe search path, allowing a local attacker to place a\nmalicious DLL in a location searched before the legitimate library\nlocation.", "product": "GeoVision Inc. GV-IP Device Utility", "category": "cve", "source": "NVD", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-16519", "card": "CVE-2026-16519.webp?v=1784882894", "takeaways": ["CVSS 3.1 : 7.3 HIGH", "Vector: AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H"], "ts": 1784880986, "exploited": 0, "has_score": 1, "created": 1784882786, "updated": 1785100018, "exploited_text": 0, "poc": 0, "score": 7.3, "kev": 0, "flags": []}, {"key": "CVE-2026-14603", "cve": "CVE-2026-14603", "lang": "en", "title": "CVE-2026-14603", "summary": "The WowOptin: Next-Gen Popup Maker  WordPress plugin before 1.4.38 does not have proper authorization on a REST endpoint, allowing unauthenticated users to disable all of the site's opt-in forms and insert new template-based opt-in rows into the database.", "product": "WowOptin: Next-Gen Popup Maker", "category": "cve", "source": "NVD", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-14603", "card": "CVE-2026-14603.webp?v=1785098159", "takeaways": ["CVSS 3.1 : 7.5 HIGH", "Vector: AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"], "ts": 1784877393, "exploited": 0, "has_score": 1, "created": 1784878835, "updated": 1785098061, "exploited_text": 0, "poc": 0, "score": 7.5, "kev": 0, "flags": []}, {"key": "CVE-2026-14172", "cve": "CVE-2026-14172", "lang": "en", "title": "CVE-2026-14172", "summary": "Rapid7 InsightVM, Nexpose, and the Insight Agent execute discovered executables during authenticated assessment without validating file ownership, allowing a local low-privileged user to run code as the scan credential (Scan Engine) or as root/SYSTEM (Insight Agent). Fixed in Scan Engine content 1.1.3935 and Insight Agent content component 0.0.245.0.", "product": "Rapid7 InsightVM", "category": "cve", "source": "NVD", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-14172", "card": "CVE-2026-14172.webp?v=1784878948", "takeaways": ["CVSS 3.1 : 7.8 HIGH", "Vector: AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"], "ts": 1784877392, "exploited": 0, "has_score": 1, "created": 1784878835, "updated": 1785100018, "exploited_text": 0, "poc": 0, "score": 7.8, "kev": 0, "flags": []}, {"key": "CVE-2026-12981", "cve": "CVE-2026-12981", "lang": "en", "title": "CVE-2026-12981", "summary": "The CAFEHAUS API WordPress plugin through 1.0.0 does not have any authentication or authorisation when updating user passwords, allowing unauthenticated attackers to set the password of any user, including administrators, and fully take over their accounts.", "product": "CAFEHAUS API", "category": "cve", "source": "NVD", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-12981", "card": "CVE-2026-12981.webp?v=1785100120", "takeaways": ["CVSS 3.1 : 7.5 HIGH", "Vector: AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"], "ts": 1784877392, "exploited": 0, "has_score": 1, "created": 1784878835, "updated": 1785100018, "exploited_text": 0, "poc": 0, "score": 7.5, "kev": 0, "flags": []}, {"key": "CVE-2026-12877", "cve": "CVE-2026-12877", "lang": "en", "title": "CVE-2026-12877", "summary": "The Project Management, Bug and Issue Tracking Plugin  WordPress plugin before 5.1.0 does not sanitise and escape user supplied input before using it in a SQL query, allowing unauthenticated attackers to perform SQL injection attacks. This is exploitable in the Project Management, Bug and Issue Tracking Plugin  WordPress plugin before 5.1.0's standard front-end issue-tracker configuration.", "product": "Project Management, Bug and Issue Tracking Plugin", "category": "cve", "source": "NVD", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-12877", "card": "CVE-2026-12877.webp?v=1785067066", "takeaways": [], "ts": 1784877392, "exploited": 0, "has_score": 0, "created": 1784878835, "updated": 1785067061, "exploited_text": 0, "poc": 0, "score": 0.0, "kev": 0, "flags": []}, {"key": "CVE-2026-12690", "cve": "CVE-2026-12690", "lang": "en", "title": "CVE-2026-12690", "summary": "The ProfileGrid  WordPress plugin before 5.9.9.7 does not perform a capability check on its license management actions, relying only on a nonce that is exposed to any logged-in user, allowing authenticated users with Subscriber-level access and above to overwrite the site's premium license settings.", "product": "ProfileGrid", "category": "cve", "source": "NVD", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-12690", "card": "CVE-2026-12690.webp?v=1785100120", "takeaways": ["CVSS 3.1 : 3.8 LOW", "Vector: AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:N"], "ts": 1784877392, "exploited": 0, "has_score": 1, "created": 1784878835, "updated": 1785100018, "exploited_text": 0, "poc": 0, "score": 3.8, "kev": 0, "flags": []}, {"key": "CVE-2026-12689", "cve": "CVE-2026-12689", "lang": "en", "title": "CVE-2026-12689", "summary": "The ProfileGrid  WordPress plugin before 5.9.9.7 does not perform any authorization or ownership check on some of its private-message thread actions, allowing authenticated users with Subscriber-level access and above to soft-delete, tamper with the metadata of, and mark as read other users' private message threads.", "product": "ProfileGrid", "category": "cve", "source": "NVD", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-12689", "card": "CVE-2026-12689.webp?v=1785100120", "takeaways": ["CVSS 3.1 : 5.4 MEDIUM", "Vector: AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N"], "ts": 1784877392, "exploited": 0, "has_score": 1, "created": 1784878835, "updated": 1785100018, "exploited_text": 0, "poc": 0, "score": 5.4, "kev": 0, "flags": []}, {"key": "CVE-2026-12688", "cve": "CVE-2026-12688", "lang": "en", "title": "CVE-2026-12688", "summary": "The ProfileGrid  WordPress plugin before 5.9.9.7 does not verify PayPal IPN notifications before granting paid group membership, allowing unauthenticated attackers to forge a payment notification and mark any user as a paid member of any group without any payment being made.", "product": "ProfileGrid", "category": "cve", "source": "NVD", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-12688", "card": "CVE-2026-12688.webp?v=1785100119", "takeaways": ["CVSS 3.1 : 6.5 MEDIUM", "Vector: AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N"], "ts": 1784877392, "exploited": 0, "has_score": 1, "created": 1784878835, "updated": 1785100018, "exploited_text": 0, "poc": 0, "score": 6.5, "kev": 0, "flags": []}, {"key": "CVE-2026-12497", "cve": "CVE-2026-12497", "lang": "en", "title": "CVE-2026-12497", "summary": "The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content  WordPress plugin before 4.16.18 does not consistently enforce the role restriction configured on its front-end registration role-selection field. The set of roles offered to the visitor and the set of roles the registration handler accepts are derived by two different parsers, and for some valid ways of configuring the offered roles the handler ignores the restriction and falls back to accepting any non-administrator role. Combined with the absence of a nonce on the public registration handler, this allows an unauthenticated visitor to register an account with a higher role, such as Editor or Author, than the form was configured to offer.", "product": "Paid Membership Plugin, Ecommerce, User Registration Form, L", "category": "cve", "source": "NVD", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-12497", "card": "CVE-2026-12497.webp?v=1785067065", "takeaways": [], "ts": 1784877392, "exploited": 0, "has_score": 0, "created": 1784878835, "updated": 1785067061, "exploited_text": 0, "poc": 0, "score": 0.0, "kev": 0, "flags": []}, {"key": "CVE-2026-16870", "cve": "CVE-2026-16870", "lang": "en", "title": "CVE-2026-16870", "summary": "Multiple security vulnerabilities in Snowflake libsnowflakeclient versions prior to 2.9.2 could allow remote code execution and credential exfiltration. A stack-based buffer overflow in the file download path could allow remote code execution on a victim host. An attacker could exploit this by uploading a file with a crafted encryption metadata field to a shared internal stage that a victim process later downloads, and impact would be limited to deployments where principals with different privilege levels share the same internal stage. A related out-of-bounds write in the same download path could allow memory corruption with attacker-controlled write primitives. An attacker may exploit this through a crafted initialization vector metadata field on a shared stage, and impact would be limited by the same stage-write precondition. Improper validation of connection parameters could allow an attacker-controlled input to redirect outbound authentication requests — including credentials and tokens — to an attacker-controlled endpoint. Impact is limited to embedding deployments where a lower-privileged principal can influence connection configuration while higher-privileged service credent", "product": "Snowflake libsnowflakeclient", "category": "cve", "source": "NVD", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-16870", "card": "CVE-2026-16870.webp?v=1784874963", "takeaways": ["CVSS 3.1 : 8.8 HIGH", "Vector: AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"], "ts": 1784873802, "exploited": 0, "has_score": 1, "created": 1784874856, "updated": 1785098061, "exploited_text": 0, "poc": 0, "score": 8.8, "kev": 0, "flags": []}, {"key": "CVE-2026-66141", "cve": "CVE-2026-66141", "lang": "en", "title": "CVE-2026-66141", "summary": "Exim before 4.99.5 allows .forward privilege escalation because force_command for a pipe transport is mishandled.", "product": "Exim", "category": "cve", "source": "NVD", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-66141", "card": "CVE-2026-66141.webp?v=1784871033", "takeaways": ["CVSS 3.1 : 7.4 HIGH", "Vector: AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H"], "ts": 1784870209, "exploited": 0, "has_score": 1, "created": 1784870929, "updated": 1785098061, "exploited_text": 0, "poc": 0, "score": 7.4, "kev": 0, "flags": []}, {"key": "CVE-2026-66140", "cve": "CVE-2026-66140", "lang": "en", "title": "CVE-2026-66140", "summary": "Exim before 4.99.5 allows directory traversal to access files outside of the spool area, and consequently gain privileges, because arguments related to queue-name are mishandled.", "product": "Exim", "category": "cve", "source": "NVD", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-66140", "card": "CVE-2026-66140.webp?v=1784871033", "takeaways": ["CVSS 3.1 : 8.4 HIGH", "Vector: AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"], "ts": 1784870209, "exploited": 0, "has_score": 1, "created": 1784870929, "updated": 1785098061, "exploited_text": 0, "poc": 0, "score": 8.4, "kev": 0, "flags": []}, {"key": "CVE-2026-66138", "cve": "CVE-2026-66138", "lang": "en", "title": "CVE-2026-66138", "summary": "In OpenStack Ironic Python Agent through 11.6.0, a project-scoped user with the manager role can achieve arbitrary code execution on a running Ironic-Python-Agent via a maliciously constructed configuration, because the value of ntp_server is passed to a shell.", "product": "OpenStack Ironic Python Agent", "category": "cve", "source": "NVD", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-66138", "card": "CVE-2026-66138.webp?v=1784871032", "takeaways": ["CVSS 3.1 : 7.2 HIGH", "Vector: AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H"], "ts": 1784870209, "exploited": 0, "has_score": 1, "created": 1784870929, "updated": 1785098061, "exploited_text": 0, "poc": 0, "score": 7.2, "kev": 0, "flags": []}, {"key": "CVE-2026-12736", "cve": "CVE-2026-12736", "lang": "en", "title": "CVE-2026-12736", "summary": "The Wpify Woo plugin for WordPress is vulnerable to Privilege Escalation in versions up to, and including, 5.4.16. This is due to the SettingsApi::save_option() REST route (POST /wp-json/wpify-woo/v1/option) passing the request-supplied 'option' and 'data' parameters directly to update_option() without any option-name allowlist or value sanitization, while the permission_callback only verifies the manage_woocommerce capability. This makes it possible for authenticated attackers, with Shop Manager-level access and above, to elevate their privileges to Administrator by overwriting arbitrary WordPress options (for example setting default_role to administrator and users_can_register to 1, or disabling security plugins via active_plugins).", "product": "wpify VAT, QR payments, Heureka and more for WooCommerce", "category": "cve", "source": "NVD", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-12736", "card": "CVE-2026-12736.webp?v=1785067066", "takeaways": ["CVSS 3.1 : 8.0 HIGH", "Vector: AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H"], "ts": 1784866611, "exploited": 0, "has_score": 1, "created": 1784866984, "updated": 1785067061, "exploited_text": 0, "poc": 0, "score": 8.0, "kev": 0, "flags": []}, {"key": "CVE-2026-62825", "cve": "CVE-2026-62825", "lang": "en", "title": "CVE-2026-62825", "summary": "Improper authentication in Azure Key Vault allows an unauthorized attacker to elevate privileges over a network.", "product": "Microsoft Azure Key Vault", "category": "cve", "source": "NVD", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-62825", "card": "CVE-2026-62825.webp?v=1784857247", "takeaways": ["CVSS 3.1 : 10.0 CRITICAL", "Vector: AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:H/A:H"], "ts": 1784855867, "exploited": 0, "has_score": 1, "created": 1784857129, "updated": 1785098061, "exploited_text": 0, "poc": 0, "score": 10.0, "kev": 0, "flags": []}, {"key": "CVE-2026-58275", "cve": "CVE-2026-58275", "lang": "en", "title": "CVE-2026-58275", "summary": "Missing authorization in Azure DNS allows an unauthorized attacker to elevate privileges over a network.", "product": "Microsoft Azure DNS", "category": "cve", "source": "NVD", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-58275", "card": "CVE-2026-58275.webp?v=1784857247", "takeaways": ["CVSS 3.1 : 10.0 CRITICAL", "Vector: AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:H/A:H"], "ts": 1784855860, "exploited": 0, "has_score": 1, "created": 1784857129, "updated": 1785098061, "exploited_text": 0, "poc": 0, "score": 10.0, "kev": 0, "flags": []}, {"key": "CVE-2026-56191", "cve": "CVE-2026-56191", "lang": "en", "title": "CVE-2026-56191", "summary": "Improper authentication in Microsoft Exchange Online allows an unauthorized attacker to perform tampering over a network.", "product": "Microsoft Exchange Online", "category": "cve", "source": "NVD", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56191", "card": "CVE-2026-56191.webp?v=1784857247", "takeaways": ["CVSS 3.1 : 10.0 CRITICAL", "Vector: AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H"], "ts": 1784855856, "exploited": 0, "has_score": 1, "created": 1784857129, "updated": 1785098061, "exploited_text": 0, "poc": 0, "score": 10.0, "kev": 0, "flags": []}, {"key": "CVE-2026-56167", "cve": "CVE-2026-56167", "lang": "en", "title": "CVE-2026-56167", "summary": "Server-side request forgery (ssrf) in Azure AI Search allows an authorized attacker to elevate privileges over a network.", "product": "Microsoft Azure AI Search", "category": "cve", "source": "NVD", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56167", "card": "CVE-2026-56167.webp?v=1784857248", "takeaways": ["CVSS 3.1 : 8.5 HIGH", "Vector: AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N"], "ts": 1784855854, "exploited": 0, "has_score": 1, "created": 1784857129, "updated": 1785092173, "exploited_text": 0, "poc": 0, "score": 8.5, "kev": 0, "flags": []}, {"key": "CVE-2026-56165", "cve": "CVE-2026-56165", "lang": "en", "title": "CVE-2026-56165", "summary": "Heap-based buffer overflow in Microsoft Account allows an unauthorized attacker to execute code over a network.", "product": "Microsoft Account", "category": "cve", "source": "NVD", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56165", "card": "CVE-2026-56165.webp?v=1784857248", "takeaways": ["CVSS 3.1 : 9.8 CRITICAL", "Vector: AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"], "ts": 1784855854, "exploited": 0, "has_score": 1, "created": 1784857129, "updated": 1785092173, "exploited_text": 0, "poc": 0, "score": 9.8, "kev": 0, "flags": []}, {"key": "CVE-2026-56160", "cve": "CVE-2026-56160", "lang": "en", "title": "CVE-2026-56160", "summary": "Improper authorization in Azure Red Hat OpenShift (ARO) allows an authorized attacker to elevate privileges over a network.", "product": "Microsoft Azure Red Hat OpenShift (ARO)", "category": "cve", "source": "NVD", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56160", "card": "CVE-2026-56160.webp?v=1784857247", "takeaways": ["CVSS 3.1 : 9.1 CRITICAL", "Vector: AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H"], "ts": 1784855854, "exploited": 0, "has_score": 1, "created": 1784857129, "updated": 1785092173, "exploited_text": 0, "poc": 0, "score": 9.1, "kev": 0, "flags": []}, {"key": "CVE-2026-54120", "cve": "CVE-2026-54120", "lang": "en", "title": "CVE-2026-54120", "summary": "Improper input validation in Microsoft Surface allows an authorized attacker to execute code over a network.", "product": "Microsoft Surface Management Services", "category": "cve", "source": "NVD", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-54120", "card": "CVE-2026-54120.webp?v=1784857248", "takeaways": ["CVSS 3.1 : 9.9 CRITICAL", "Vector: AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H"], "ts": 1784855845, "exploited": 0, "has_score": 1, "created": 1784857129, "updated": 1785092173, "exploited_text": 0, "poc": 0, "score": 9.9, "kev": 0, "flags": []}, {"key": "CVE-2026-50517", "cve": "CVE-2026-50517", "lang": "en", "title": "CVE-2026-50517", "summary": "Deserialization of untrusted data in M365 Copilot allows an authorized attacker to execute code over a network.", "product": "Microsoft 365 Copilot", "category": "cve", "source": "NVD", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-50517", "card": "CVE-2026-50517.webp?v=1784857248", "takeaways": ["CVSS 3.1 : 9.9 CRITICAL", "Vector: AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H"], "ts": 1784855822, "exploited": 0, "has_score": 1, "created": 1784857129, "updated": 1785092173, "exploited_text": 0, "poc": 0, "score": 9.9, "kev": 0, "flags": []}, {"key": "CVE-2026-35425", "cve": "CVE-2026-35425", "lang": "en", "title": "CVE-2026-35425", "summary": "Improper access control in Azure API Management (APIM) allows an authorized attacker to execute code over a network.", "product": "Microsoft Azure API Management (APIM)", "category": "cve", "source": "NVD", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-35425", "card": "CVE-2026-35425.webp?v=1784857248", "takeaways": ["CVSS 3.1 : 8.0 HIGH", "Vector: AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H"], "ts": 1784855796, "exploited": 0, "has_score": 1, "created": 1784857129, "updated": 1785092173, "exploited_text": 0, "poc": 0, "score": 8.0, "kev": 0, "flags": []}, {"key": "CVE-2026-50044", "cve": "CVE-2026-50044", "lang": "en", "title": "CVE-2026-50044", "summary": "Pronetiqs IntraVUE versions 3.2.1a14 and prior have an inadequate encryption strength vulnerability which could allow an attacker to steal admin credentials via weak hash or a pass-the-hash attack.", "product": "Pronetiqs Panduit Intravue", "category": "cve", "source": "NVD", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-50044", "card": "CVE-2026-50044.webp?v=1784849300", "takeaways": ["CVSS 4.0 : 7.6 HIGH", "Vector: AV:N/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N", "CVSS 3.1 : 6.8 MEDIUM"], "ts": 1784848609, "exploited": 0, "has_score": 1, "created": 1784849199, "updated": 1785092173, "exploited_text": 0, "poc": 0, "score": 7.6, "kev": 0, "flags": []}, {"key": "CVE-2026-42933", "cve": "CVE-2026-42933", "lang": "en", "title": "CVE-2026-42933", "summary": "Pronetiqs IntraVUE versions 3.2.1a14 and prior have an unintended proxy or intermediary vulnerability which could allow an attacker to use an active proxy, which would bypass OT segmentation.", "product": "Pronetiqs Panduit Intravue", "category": "cve", "source": "NVD", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-42933", "card": "CVE-2026-42933.webp?v=1784849301", "takeaways": ["CVSS 4.0 : 10.0 CRITICAL", "Vector: AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H", "CVSS 3.1 : 10.0 CRITICAL"], "ts": 1784848608, "exploited": 0, "has_score": 1, "created": 1784849199, "updated": 1785092173, "exploited_text": 0, "poc": 0, "score": 10.0, "kev": 0, "flags": []}, {"key": "CVE-2026-40430", "cve": "CVE-2026-40430", "lang": "en", "title": "CVE-2026-40430", "summary": "Pronetiqs IntraVUE Versions 3.2.1a14 and prior have a plaintext storage of a password vulnerability that could expose cleartext credentials through the API.", "product": "Pronetiqs Panduit Intravue", "category": "cve", "source": "NVD", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-40430", "card": "CVE-2026-40430.webp?v=1784849301", "takeaways": ["CVSS 4.0 : 8.7 HIGH", "Vector: AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N", "CVSS 3.1 : 7.5 HIGH"], "ts": 1784848608, "exploited": 0, "has_score": 1, "created": 1784849199, "updated": 1785092173, "exploited_text": 0, "poc": 0, "score": 8.7, "kev": 0, "flags": []}, {"key": "CVE-2026-28698", "cve": "CVE-2026-28698", "lang": "en", "title": "CVE-2026-28698", "summary": "Pronetiqs IntraVUE versions 3.2.1a14 and prior have an exposure of sensitive system information to an unauthorized control sphere vulnerability which could expose the underlying host/share filesystem.", "product": "Pronetiqs Panduit Intravue", "category": "cve", "source": "NVD", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-28698", "card": "CVE-2026-28698.webp?v=1784849301", "takeaways": ["CVSS 4.0 : 9.2 CRITICAL", "Vector: AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N", "CVSS 3.1 : 8.6 HIGH"], "ts": 1784848608, "exploited": 0, "has_score": 1, "created": 1784849199, "updated": 1785092173, "exploited_text": 0, "poc": 0, "score": 9.2, "kev": 0, "flags": []}, {"key": "CVE-2026-65694", "cve": "CVE-2026-65694", "lang": "en", "title": "CVE-2026-65694", "summary": "Microweber CMS through 2.0.20 contains a path traversal vulnerability in the static file controller that allows unauthenticated remote attackers to read arbitrary files by supplying directory traversal sequences in the path query parameter. Attackers can send a single unauthenticated HTTP GET request exploiting the failure of normalize_path() to strip traversal sequences, disclosing sensitive files such as environment configuration files containing credentials and system files.", "product": "microweber", "category": "cve", "source": "NVD", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-65694", "card": "CVE-2026-65694.webp?v=1784845373", "takeaways": ["CVSS 4.0 : 8.7 HIGH", "Vector: AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N", "CVSS 3.1 : 7.5 HIGH"], "ts": 1784845013, "exploited": 0, "has_score": 1, "created": 1784845261, "updated": 1785088256, "exploited_text": 0, "poc": 0, "score": 8.7, "kev": 0, "flags": []}, {"key": "CVE-2026-65604", "cve": "CVE-2026-65604", "lang": "en", "title": "CVE-2026-65604", "summary": "Skipper contains an incomplete fix for CVE-2026-50197 in which oversized request bodies bypass Open Policy Agent (OPA) deny-on-presence Rego policies. When a request body exceeds the configured maxBodyBytes limit, Skipper forwards the full payload to the upstream service while OPA evaluates against an empty parsed_body, so policies that deny requests based on body content are not enforced and forbidden actions proceed. No fixed version is available; v0.27.26 adds documentation guidance only.", "product": "zalando skipper", "category": "cve", "source": "NVD", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-65604", "card": "CVE-2026-65604.webp?v=1784845373", "takeaways": ["CVSS 4.0 : 8.8 HIGH", "Vector: AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N", "CVSS 3.1 : 8.2 HIGH"], "ts": 1784845013, "exploited": 0, "has_score": 1, "created": 1784845261, "updated": 1785088256, "exploited_text": 0, "poc": 0, "score": 8.8, "kev": 0, "flags": []}, {"key": "CVE-2026-63732", "cve": "CVE-2026-63732", "lang": "en", "title": "CVE-2026-63732", "summary": "9router 0.4.59 (fixed in 0.4.60) contains a chain of vulnerabilities: a hardcoded default password (123456) that authenticates any fresh installation, a bypass of the LOCAL_ONLY network gate via a spoofed Host header, and unvalidated arguments passed to child_process.spawn() when registering MCP plugins. A remote, unauthenticated attacker can log in with the default credential, spoof the Host header to reach local-only routes, and register a malicious MCP plugin (e.g. node -e  ) to achieve arbitrary code execution on the host operating system when the plugin's SSE endpoint is triggered.", "product": "decolua 9router", "category": "cve", "source": "NVD", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-63732", "card": "CVE-2026-63732.webp?v=1784845373", "takeaways": ["CVSS 4.0 : 9.4 CRITICAL", "Vector: AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H", "CVSS 3.1 : 9.9 CRITICAL"], "ts": 1784845013, "exploited": 0, "has_score": 1, "created": 1784845261, "updated": 1785088256, "exploited_text": 0, "poc": 0, "score": 9.4, "kev": 0, "flags": []}, {"key": "CVE-2026-63313", "cve": "CVE-2026-63313", "lang": "en", "title": "CVE-2026-63313", "summary": "9Router before 0.4.72 contains a server-side request forgery (SSRF) vulnerability in the /v1/web/fetch endpoint. The endpoint accepts a user-controlled url parameter and passes it to a configured external scraping provider (Firecrawl, Jina Reader, Tavily, or Exa) to fetch content. The URL is only validated as syntactically valid via new URL() with no blocklist for private IP ranges, cloud metadata endpoints (e.g., 169.254.169.254), link-local addresses, or internal hostnames. An authenticated or locally-connected user can cause the server to fetch arbitrary internal URLs and have the response content returned, enabling read-access SSRF that can expose cloud metadata credentials, reach internal services, and bypass authentication on localhost endpoints.", "product": "decolua 9router", "category": "cve", "source": "NVD", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-63313", "card": "CVE-2026-63313.webp?v=1784845374", "takeaways": ["CVSS 4.0 : 8.3 HIGH", "Vector: AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N", "CVSS 3.1 : 7.7 HIGH"], "ts": 1784845012, "exploited": 0, "has_score": 1, "created": 1784845261, "updated": 1785080381, "exploited_text": 0, "poc": 0, "score": 8.3, "kev": 0, "flags": []}, {"key": "CVE-2026-16807", "cve": "CVE-2026-16807", "lang": "en", "title": "CVE-2026-16807", "summary": "Out of bounds write in Codecs in Google Chrome prior to 150.0.7871.186 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)", "product": "Google Chrome", "category": "cve", "source": "NVD", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-16807", "card": "CVE-2026-16807.webp?v=1785078521", "takeaways": ["CVSS 3.1 : 8.8 HIGH", "Vector: AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"], "ts": 1784845012, "exploited": 0, "has_score": 1, "created": 1784845261, "updated": 1785078423, "exploited_text": 0, "poc": 0, "score": 8.8, "kev": 0, "flags": []}, {"key": "CVE-2026-16806", "cve": "CVE-2026-16806", "lang": "en", "title": "CVE-2026-16806", "summary": "Use after free in WebMCP in Google Chrome prior to 150.0.7871.186 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)", "product": "Google Chrome", "category": "cve", "source": "NVD", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-16806", "card": "CVE-2026-16806.webp?v=1785080481", "takeaways": ["CVSS 3.1 : 8.8 HIGH", "Vector: AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"], "ts": 1784845012, "exploited": 0, "has_score": 1, "created": 1784845261, "updated": 1785080381, "exploited_text": 0, "poc": 0, "score": 8.8, "kev": 0, "flags": []}, {"key": "CVE-2026-16232", "cve": "CVE-2026-16232", "lang": "en", "title": "CVE-2026-16232 - Check Point SmartConsole Improper Authentication Vulnerability", "summary": "Check Point SmartConsole contains an improper authentication vulnerability which could allow an unauthenticated remote attacker to obtain an application login token and use it to authenticate with full administrative privileges.", "product": "Check Point SmartConsole", "category": "exploited", "source": "NVD", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-16232", "card": "CVE-2026-16232.webp?v=1784748315", "takeaways": ["Actively exploited (CISA KEV) - patch before 2026-07-25"], "ts": 1784729835, "exploited": 1, "has_score": 0, "created": 1784730347, "updated": 1784748205, "exploited_text": 1, "poc": 0, "score": 0.0, "kev": 1, "flags": ["kev", "exploited", "0day"]}, {"key": "CVE-2026-0770", "cve": "CVE-2026-0770", "lang": "en", "title": "CVE-2026-0770 - Langflow Inclusion of Functionality from Untrusted Control Sphere Vulnerability", "summary": "Langflow contains an inclusion of functionality from untrusted control sphere vulnerability that allows remote attackers to execute arbitrary code on affected installations.", "product": "Langflow Langflow", "category": "exploited", "source": "CISA Known Exploited Vulnerabilities", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-0770", "card": "CVE-2026-0770.webp?v=1784646137", "takeaways": ["Actively exploited (CISA KEV) - patch before 2026-07-24", "CVSS 3.0 : 9.8 CRITICAL", "Vector: AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"], "ts": 1784592000, "exploited": 1, "has_score": 1, "created": 1784646015, "updated": 1784646015, "exploited_text": 1, "poc": 0, "score": 9.8, "kev": 1, "flags": ["kev", "exploited", "0day"]}, {"key": "CVE-2026-63030", "cve": "CVE-2026-63030", "lang": "en", "title": "CVE-2026-63030 - WordPress Core Interpretation Conflict Vulnerability", "summary": "WordPress Core contains an interpretation conflict vulnerability that could allow an attacker to perform SQL Injection and achieve Remote Code Execution. This vulnerability can be chained with CVE-2026-60137.", "product": "WordPress Core", "category": "exploited", "source": "NVD", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-63030", "card": "CVE-2026-63030.webp?v=1784646137", "takeaways": ["Actively exploited (CISA KEV) - patch before 2026-07-24", "CVSS 3.1 : 9.8 CRITICAL", "Vector: AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"], "ts": 1784319448, "exploited": 1, "has_score": 1, "created": 1784320542, "updated": 1784646015, "exploited_text": 1, "poc": 0, "score": 9.8, "kev": 1, "flags": ["kev", "exploited", "0day"]}, {"key": "CVE-2026-60137", "cve": "CVE-2026-60137", "lang": "en", "title": "Multiples vulnérabilités dans WordPress", "summary": "Le 17 juillet 2026, WordPress a publié un correctif pour deux vulnérabilités : CVE-2026-60137 : une injection SQL (SQLi) ; CVE-2026-63030 : celle-ci permet un contournement de la politique de sécurité. Un attaquant peut exploiter ces deux vulnérabilités, de manière combinée, pour obtenir une exécution de code arbitraire à distance dans les versions 6.9 et ultérieures de WordPress Core. Le CERT-FR a connaissance d'une preuve de concept publique et anticipe des tentatives d'exploitations en masse. ## Mesures de contournement Le CERT-FR recommande l'application des correctifs dans les plus brefs délais. Si cela n'est pas possible, les chercheurs à l'origine de la découverte de ces vulnérabilités recommandent de bloquer l'accès non authentifié à l'API REST de WordPress (cf. section Documentation). Selon eux, couper l'accès au chemin /wp-json/batch/v1 aux requêtes contenant le paramètre rest_route=/batch/v1 , grâce à un pare-feu applicatif (WAF), est une manière de se protéger contre l'exploitation de ces deux vulnérabilités.", "product": "WordPress", "category": "exploited", "source": "NVD", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-60137", "card": "CVE-2026-60137.webp?v=1784574504", "takeaways": ["Actively exploited (CISA KEV)", "CVE : CVE-2026-60137, CVE-2026-63030"], "ts": 1784319447, "exploited": 1, "has_score": 0, "created": 1784320542, "updated": 1784574403, "exploited_text": 1, "poc": 1, "score": 0.0, "kev": 1, "flags": ["kev", "exploited", "0day", "poc"]}, {"key": "CVE-2021-27137", "cve": "CVE-2021-27137", "lang": "en", "title": "CVE-2021-27137 - DD-WRT Stack-Based Buffer Overflow Vulnerability", "summary": "DD-WRT contains a stack-based buffer overflow vulnerability that could allow an unauthenticated attacker to overflow an internal buffer used by UPnP and trigger a code execution vulnerability.", "product": "DD-WRT DD-WRT", "category": "exploited", "source": "NVD", "url": "https://nvd.nist.gov/vuln/detail/CVE-2021-27137", "card": "CVE-2021-27137.webp?v=1784646137", "takeaways": ["Actively exploited (CISA KEV) - patch before 2026-07-24", "CVSS 3.1 : 8.1 HIGH", "Vector: AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H"], "ts": 1784225799, "exploited": 1, "has_score": 1, "created": 1784230269, "updated": 1784646015, "exploited_text": 1, "poc": 0, "score": 8.1, "kev": 1, "flags": ["kev", "exploited", "0day"]}, {"key": "CVE-2026-39808", "cve": "CVE-2026-39808", "lang": "en", "title": "CVE-2026-39808 - Fortinet FortiSandbox OS Command Injection Vulnerability", "summary": "Fortinet FortiSandbox contains an OS command injection vulnerability that could allow an unauthenticated attacker to execute unauthorized code or commands via crafted HTTP requests.", "product": "Fortinet FortiSandbox", "category": "exploited", "source": "CISA Known Exploited Vulnerabilities", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39808", "card": "CVE-2026-39808.webp?v=1784225463", "takeaways": ["Actively exploited (CISA KEV) - patch before 2026-07-19", "CVSS 3.1 : 9.8 CRITICAL", "Vector: AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"], "ts": 1784160000, "exploited": 1, "has_score": 1, "created": 1784225356, "updated": 1784225356, "exploited_text": 1, "poc": 0, "score": 9.8, "kev": 1, "flags": ["kev", "exploited", "0day"]}, {"key": "CVE-2026-25089", "cve": "CVE-2026-25089", "lang": "en", "title": "CVE-2026-25089 - Fortinet FortiSandbox OS Command Injection Vulnerability", "summary": "Fortinet FortiSandbox, FortiSandbox Cloud, and FortiSandbox PaaS contain an OS command injection vulnerability that allows an unauthenticated attacker to execute unauthorized commands via specifically crafted HTTP requests.", "product": "Fortinet FortiSandbox", "category": "exploited", "source": "CISA Known Exploited Vulnerabilities", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-25089", "card": "CVE-2026-25089.webp?v=1784225463", "takeaways": ["Actively exploited (CISA KEV) - patch before 2026-07-19", "CVSS 3.1 : 9.8 CRITICAL", "Vector: AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"], "ts": 1784160000, "exploited": 1, "has_score": 1, "created": 1784225356, "updated": 1784225356, "exploited_text": 1, "poc": 0, "score": 9.8, "kev": 1, "flags": ["kev", "exploited", "0day"]}, {"key": "CVE-2023-4346", "cve": "CVE-2023-4346", "lang": "en", "title": "CVE-2023-4346 - KNX Association KNX Protocol Connection Authorization Option 1 Overly Restrictive Account Lockout Mechanism Vulnerability", "summary": "KNX Association KNX Protocol Connection Authorization Option 1 contains an overly restrictive account lockout mechanism vulnerability that could allow an attacker to purge all devices without additional security options enabled and set a BCU key to lock the device.", "product": "KNX Association KNX Protocol Connection ", "category": "exploited", "source": "CISA Known Exploited Vulnerabilities", "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-4346", "card": "CVE-2023-4346.webp?v=1784137606", "takeaways": ["Actively exploited (CISA KEV) - patch before 2026-07-29", "CVSS 3.1 : 7.5 HIGH", "Vector: AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"], "ts": 1784073600, "exploited": 1, "has_score": 1, "created": 1784137498, "updated": 1784137498, "exploited_text": 1, "poc": 0, "score": 7.5, "kev": 1, "flags": ["kev", "exploited", "0day"]}, {"key": "CVE-2026-46817", "cve": "CVE-2026-46817", "lang": "en", "title": "CVE-2026-46817 - Oracle E-Business Suite Improper Privilege Management Vulnerability", "summary": "Oracle E-Business Suite contains an improper privilege management vulnerability that allows an unauthenticated attacker with network access via HTTP to compromise Oracle Payments. Successful attacks of this vulnerability can result in takeover of Oracle Payments.", "product": "Oracle E-Business Suite", "category": "exploited", "source": "CISA Known Exploited Vulnerabilities", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-46817", "card": "CVE-2026-46817.webp?v=1784137606", "takeaways": ["Actively exploited (CISA KEV) - patch before 2026-07-18", "CVSS 3.1 : 9.8 CRITICAL", "Vector: AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"], "ts": 1784073600, "exploited": 1, "has_score": 1, "created": 1784137498, "updated": 1784137498, "exploited_text": 1, "poc": 0, "score": 9.8, "kev": 1, "flags": ["kev", "exploited", "0day"]}, {"key": "CVE-2026-58644", "cve": "CVE-2026-58644", "lang": "en", "title": "CVE-2026-58644 - Microsoft SharePoint Deserialization of Untrusted Data Vulnerability", "summary": "Microsoft SharePoint contains a deserialization of untrusted data vulnerability that allows an unauthorized attacker to execute code over a network.", "product": "Microsoft SharePoint", "category": "exploited", "source": "NVD", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-58644", "card": "CVE-2026-58644.webp?v=1784225464", "takeaways": ["Actively exploited (CISA KEV) - patch before 2026-07-19", "CVSS 3.1 : 9.8 CRITICAL", "Vector: AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"], "ts": 1784049434, "exploited": 1, "has_score": 1, "created": 1784050778, "updated": 1784225356, "exploited_text": 1, "poc": 0, "score": 9.8, "kev": 1, "flags": ["kev", "exploited", "0day"]}, {"key": "CVE-2026-50522", "cve": "CVE-2026-50522", "lang": "en", "title": "Multiples vulnérabilités dans Microsoft Sharepoint", "summary": "Le 14 juillet 2026, à l'occasion de sa mise à jour mensuelle, Microsoft a publié, entre autres, des correctifs pour deux vulnérabilités critiques affectant SharePoint. Les vulnérabilités CVE-2026-50522 et CVE-2026-58644 permettent à un attaquant non authentifié d'exécuter du code arbitraire à distance. Dans son avis du 14 juillet 2026, Microsoft a indiqué que la vulnérabilité CVE-2026-58644 est activement exploitée. Dans une communication en date du 21 juillet 2026, l'entreprise de sécurité informatique watchTowr déclare avoir connaissance d'une preuve de concept publique, ainsi que d'exploitations actives de la vulnérabilité CVE-2026-50522. Le CERT-FR recommande donc l'application des correctifs dans les plus brefs délais. En cas de soupçons de compromission, le CERT-FR recommande également le changement des secrets, incluant la rotation des clés de machine ASP.NET du SharePoint Server. En effet, le vol de ces secrets peut permettre à l'attaquant de revenir après l'application de la mise à jour.", "product": "Microsoft Sharepoint", "category": "exploited", "source": "NVD", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-50522", "card": "CVE-2026-50522.webp?v=1784732443", "takeaways": ["Actively exploited (CISA KEV)", "CVE : CVE-2026-50522, CVE-2026-58644", "CVSS 3.1 : 9.8 CRITICAL", "Vector: AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"], "ts": 1784049421, "exploited": 1, "has_score": 1, "created": 1784092746, "updated": 1784732334, "exploited_text": 1, "poc": 1, "score": 9.8, "kev": 1, "flags": ["kev", "exploited", "0day", "poc"]}, {"key": "CVE-2026-15410", "cve": "CVE-2026-15410", "lang": "en", "title": "CVE-2026-15410 - SonicWall SMA1000 Appliances Code Injection Vulnerability", "summary": "SonicWall SMA1000 Appliances contain a code injection vulnerability which in specific conditions could potentially enable a remote authenticated attacker as administrator to execute arbitrary OS commands.", "product": "SonicWall SMA1000 Appliances", "category": "exploited", "source": "CISA Known Exploited Vulnerabilities", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-15410", "card": "CVE-2026-15410.webp?v=1784098807", "takeaways": ["Actively exploited (CISA KEV) - patch before 2026-07-17", "CVSS 3.1 : 7.2 HIGH", "Vector: AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H"], "ts": 1783987200, "exploited": 1, "has_score": 1, "created": 1784098689, "updated": 1784098689, "exploited_text": 1, "poc": 0, "score": 7.2, "kev": 1, "flags": ["kev", "exploited", "0day"]}, {"key": "CVE-2026-15409", "cve": "CVE-2026-15409", "lang": "en", "title": "CVE-2026-15409 - SonicWall SMA1000 Appliances Server-Side Request Forgery Vulnerability", "summary": "SonicWall SMA1000 Appliances contain a server-side request forgery vulnerability that could allow a remote unauthenticated attacker to potentially cause the appliance to make requests to unintended location.", "product": "SonicWall SMA1000 Appliances", "category": "exploited", "source": "CISA Known Exploited Vulnerabilities", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-15409", "card": "CVE-2026-15409.webp?v=1784098807", "takeaways": ["Actively exploited (CISA KEV) - patch before 2026-07-17", "CVSS 3.1 : 10.0 CRITICAL", "Vector: AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H"], "ts": 1783987200, "exploited": 1, "has_score": 1, "created": 1784098689, "updated": 1784098689, "exploited_text": 1, "poc": 0, "score": 10.0, "kev": 1, "flags": ["kev", "exploited", "0day"]}, {"key": "CVE-2026-56164", "cve": "CVE-2026-56164", "lang": "en", "title": "CVE-2026-56164 - Microsoft SharePoint Server Missing Authentication for Critical Function Vulnerability", "summary": "Microsoft SharePoint contains a missing authentication for critical function vulnerability that allows an unauthorized attacker to elevate privileges over a network.", "product": "Microsoft SharePoint Server", "category": "exploited", "source": "CISA Known Exploited Vulnerabilities", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56164", "card": "CVE-2026-56164.webp?v=1784098807", "takeaways": ["Actively exploited (CISA KEV) - patch before 2026-07-17", "CVSS 3.1 : 5.3 MEDIUM", "Vector: AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N"], "ts": 1783987200, "exploited": 1, "has_score": 1, "created": 1784098689, "updated": 1784098689, "exploited_text": 1, "poc": 0, "score": 5.3, "kev": 1, "flags": ["kev", "exploited", "0day"]}, {"key": "CVE-2026-56155", "cve": "CVE-2026-56155", "lang": "en", "title": "CVE-2026-56155 - Microsoft Active Directory Federation Services Insufficient Granularity of Access Control Vulnerability ", "summary": "Microsoft Active Directory Federation Services contains an insufficient granularity of access control vulnerability that allows an authorized attacker to elevate privileges locally.", "product": "Microsoft Active Directory Federation Se", "category": "exploited", "source": "CISA Known Exploited Vulnerabilities", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56155", "card": "CVE-2026-56155.webp?v=1784098807", "takeaways": ["Actively exploited (CISA KEV) - patch before 2026-07-28", "CVSS 3.1 : 7.8 HIGH", "Vector: AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"], "ts": 1783987200, "exploited": 1, "has_score": 1, "created": 1784098689, "updated": 1784098689, "exploited_text": 1, "poc": 0, "score": 7.8, "kev": 1, "flags": ["kev", "exploited", "0day"]}, {"key": "CVE-2008-4128", "cve": "CVE-2008-4128", "lang": "en", "title": "CVE-2008-4128 - Cisco IOS Cross-Site Request Forgery Vulnerability", "summary": "Cisco IOS 12.4 contains multiple cross-site forgery vulnerabilities that allows remote attackers to execute arbitrary commands via (1) a certain \"show privilege\" command to the /level/15/exec/- URI, and (2) a certain \"alias exec\" command to the /level/15/exec/-/configure/http URI.", "product": "Cisco IOS", "category": "exploited", "source": "CISA Known Exploited Vulnerabilities", "url": "https://nvd.nist.gov/vuln/detail/CVE-2008-4128", "card": "CVE-2008-4128.webp?v=1783963455", "takeaways": ["Actively exploited (CISA KEV) - patch before 2026-07-16", "CVSS 3.1 : 4.3 MEDIUM", "Vector: AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N", "CVSS 2.0 : 9.3 HIGH"], "ts": 1783900800, "exploited": 1, "has_score": 1, "created": 1783963330, "updated": 1783963330, "exploited_text": 1, "poc": 1, "score": 4.3, "kev": 1, "flags": ["kev", "exploited", "0day", "poc"]}, {"key": "CVE-2026-48939", "cve": "CVE-2026-48939", "lang": "en", "title": "CVE-2026-48939 - iCagenda Unrestricted Upload of File with Dangerous Type Vulnerability", "summary": "iCagenda contains an unrestricted upload of file with dangerous type vulnerability that allows the upload of arbitrary files in the file attachment feature, ultimately resulting in PHP code upload and execution.", "product": "iCagenda iCagenda", "category": "exploited", "source": "CISA Known Exploited Vulnerabilities", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-48939", "card": "CVE-2026-48939.webp?v=1783705007", "takeaways": ["Actively exploited (CISA KEV) - patch before 2026-07-13", "CVSS 4.0 : 10.0 CRITICAL", "Vector: AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:A/AU:Y/U:Red", "CVSS 3.1 : 9.8 CRITICAL"], "ts": 1783641600, "exploited": 1, "has_score": 1, "created": 1783704876, "updated": 1783704876, "exploited_text": 1, "poc": 0, "score": 10.0, "kev": 1, "flags": ["kev", "exploited", "0day"]}, {"key": "CVE-2026-56291", "cve": "CVE-2026-56291", "lang": "en", "title": "CVE-2026-56291 - Balbooa Forms Unrestricted Upload of File with Dangerous Type Vulnerability", "summary": "Balbooa Forms contains an unrestricted upload of file with dangerous type vulnerability that allows an unauthenticated arbitrary file upload which could allow uploading of executable files leading to full RCE.", "product": "Balbooa Forms", "category": "exploited", "source": "NVD", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56291", "card": "CVE-2026-56291.webp?v=1783705007", "takeaways": ["Actively exploited (CISA KEV) - patch before 2026-07-13", "CVSS 4.0 : 10.0 CRITICAL", "Vector: AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:A/AU:Y/U:Red", "CVSS 3.1 : 9.8 CRITICAL"], "ts": 1783595800, "exploited": 1, "has_score": 1, "created": 1783597411, "updated": 1783704876, "exploited_text": 1, "poc": 0, "score": 10.0, "kev": 1, "flags": ["kev", "exploited", "0day"]}, {"key": "CVE-2026-55255", "cve": "CVE-2026-55255", "lang": "en", "title": "CVE-2026-55255 - Langflow Authorization Bypass Through User-Controlled Key Vulnerability", "summary": "Langflow contains an authorization bypass through user-controlled key vulnerability which allows an authenticated attacker to execute any flow belonging to another user by specifying the victim's flow ID in the request.", "product": "Langflow Langflow", "category": "exploited", "source": "CISA Known Exploited Vulnerabilities", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-55255", "card": "CVE-2026-55255.webp?v=1783445428", "takeaways": ["Actively exploited (CISA KEV) - patch before 2026-07-10", "CVSS 3.1 : 9.9 CRITICAL", "Vector: AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:L"], "ts": 1783382400, "exploited": 1, "has_score": 1, "created": 1783445301, "updated": 1783445301, "exploited_text": 0, "poc": 0, "score": 9.9, "kev": 1, "flags": ["kev", "exploited", "0day"]}, {"key": "CVE-2026-48908", "cve": "CVE-2026-48908", "lang": "en", "title": "CVE-2026-48908 - JoomShaper SP Page Builder Unrestricted Upload of File with Dangerous Type Vulnerability", "summary": "JoomShaper SP Page Builder contains an unrestricted upload of file with dangerous type vulnerability that allows unauthenticated users to upload arbitrary files, ultimately resulting in the upload and execution of PHP code.", "product": "JoomShaper SP Page Builder", "category": "exploited", "source": "CISA Known Exploited Vulnerabilities", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-48908", "card": "CVE-2026-48908.webp?v=1783445427", "takeaways": ["Actively exploited (CISA KEV) - patch before 2026-07-10", "CVSS 4.0 : 10.0 CRITICAL", "Vector: AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:A/AU:Y/U:Red", "CVSS 3.1 : 9.8 CRITICAL"], "ts": 1783382400, "exploited": 1, "has_score": 1, "created": 1783445301, "updated": 1783445301, "exploited_text": 0, "poc": 0, "score": 10.0, "kev": 1, "flags": ["kev", "exploited", "0day"]}, {"key": "CVE-2026-12569", "cve": "CVE-2026-12569", "lang": "en", "title": "CVE-2026-12569 - PTC Windchill and FlexPLM Improper Input Validation Vulnerability", "summary": "PTC Windchill and FlexPLM contains an improper input validation vulnerability allowing an unauthenticated, remote attacker to execute arbitrary code by sending a malicious request to the network.", "product": "PTC Windchill PDMLink", "category": "exploited", "source": "CISA Known Exploited Vulnerabilities", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-12569", "card": "CVE-2026-12569.webp?v=1783144882", "takeaways": ["Actively exploited (CISA KEV) - patch before 2026-06-28", "CVSS 4.0 : 9.3 CRITICAL", "Vector: AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:L/SI:L/SA:L/AU:Y/R:U/V:C/U:Red", "CVSS 3.1 : 9.8 CRITICAL"], "ts": 1782345600, "exploited": 1, "has_score": 1, "created": 1783077570, "updated": 1783141643, "exploited_text": 0, "poc": 0, "score": 9.3, "kev": 1, "flags": ["kev", "exploited", "0day"]}, {"key": "CVE-2026-20230", "cve": "CVE-2026-20230", "lang": "en", "title": "CVE-2026-20230 - Cisco Unified Communications Manager Server-Side Request Forgery (SSRF) Vulnerability", "summary": "Cisco Unified Communications Manager (Unified CM) and Cisco Unified Communications Manager Session Management Edition (Unified CM SME) contain a server-side request forgery (SSRF) Vulnerability that could allow an unauthenticated, remote attacker to write files to the underlying operating system that could be used later to elevate to root.", "product": "Cisco Unified Communications Manager", "category": "exploited", "source": "CISA Known Exploited Vulnerabilities", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-20230", "card": "CVE-2026-20230.webp?v=1783144882", "takeaways": ["Actively exploited (CISA KEV) - patch before 2026-06-28", "CVSS 3.1 : 8.6 HIGH", "Vector: AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:H/A:N"], "ts": 1782345600, "exploited": 1, "has_score": 1, "created": 1783077570, "updated": 1783085407, "exploited_text": 0, "poc": 0, "score": 8.6, "kev": 1, "flags": ["kev", "exploited", "0day"]}, {"key": "CVE-2025-67038", "cve": "CVE-2025-67038", "lang": "en", "title": "CVE-2025-67038 - Lantronix EDS5000 Code Injection Vulnerability", "summary": "Lantronix EDS5000 contains a code injection vulnerability that could allow attackers to inject arbitrary OS commands into the username parameter. Injected commands are executed with root privileges.", "product": "Lantronix EDS5000", "category": "exploited", "source": "CISA Known Exploited Vulnerabilities", "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-67038", "card": "CVE-2025-67038.webp?v=1783144882", "takeaways": ["Actively exploited (CISA KEV) - patch before 2026-06-26", "CVSS 3.1 : 9.8 CRITICAL", "Vector: AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"], "ts": 1782172800, "exploited": 1, "has_score": 1, "created": 1783077570, "updated": 1783085407, "exploited_text": 0, "poc": 0, "score": 9.8, "kev": 1, "flags": ["kev", "exploited", "0day"]}, {"key": "CVE-2026-34910", "cve": "CVE-2026-34910", "lang": "en", "title": "CVE-2026-34910 - Ubiquiti UniFi OS Improper Input Validation Vulnerability", "summary": "Ubiquiti UniFi OS contains an improper input validation vulnerability which could allow a malicious actor with access to the network to conduct command injection.", "product": "Ubiquiti Inc UniFi OS Server", "category": "exploited", "source": "CISA Known Exploited Vulnerabilities", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-34910", "card": "CVE-2026-34910.webp?v=1783144881", "takeaways": ["Actively exploited (CISA KEV) - patch before 2026-06-26", "CVSS 3.1 : 10.0 CRITICAL", "Vector: AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H"], "ts": 1782172800, "exploited": 1, "has_score": 1, "created": 1783077570, "updated": 1783141643, "exploited_text": 0, "poc": 0, "score": 10.0, "kev": 1, "flags": ["kev", "exploited", "0day"]}, {"key": "CVE-2026-34909", "cve": "CVE-2026-34909", "lang": "en", "title": "CVE-2026-34909 - Ubiquiti UniFi OS Path Traversal Vulnerability", "summary": "Ubiquiti UniFi OS contains a path traversal vulnerability which could allow a malicious actor with access to the network to access files on the underlying system that could be manipulated to access an underlying account.", "product": "Ubiquiti Inc UniFi OS Server", "category": "exploited", "source": "CISA Known Exploited Vulnerabilities", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-34909", "card": "CVE-2026-34909.webp?v=1783144881", "takeaways": ["Actively exploited (CISA KEV) - patch before 2026-06-26", "CVSS 3.1 : 10.0 CRITICAL", "Vector: AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H"], "ts": 1782172800, "exploited": 1, "has_score": 1, "created": 1783077570, "updated": 1783141643, "exploited_text": 0, "poc": 0, "score": 10.0, "kev": 1, "flags": ["kev", "exploited", "0day"]}, {"key": "CVE-2026-34908", "cve": "CVE-2026-34908", "lang": "en", "title": "CVE-2026-34908 - Ubiquiti UniFi OS Improper Access Control Vulnerability", "summary": "Ubiquiti UniFi OS contains an improper access control vulnerability which could allow a malicious actor with access to the network to make unauthorized changes to the system.", "product": "Ubiquiti Inc UniFi OS Server", "category": "exploited", "source": "CISA Known Exploited Vulnerabilities", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-34908", "card": "CVE-2026-34908.webp?v=1783144881", "takeaways": ["Actively exploited (CISA KEV) - patch before 2026-06-26", "CVSS 3.1 : 10.0 CRITICAL", "Vector: AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H"], "ts": 1782172800, "exploited": 1, "has_score": 1, "created": 1783077570, "updated": 1783141643, "exploited_text": 0, "poc": 0, "score": 10.0, "kev": 1, "flags": ["kev", "exploited", "0day"]}, {"key": "CVE-2026-20253", "cve": "CVE-2026-20253", "lang": "en", "title": "CVE-2026-20253 - Splunk Enterprise Missing Authentication for Critical Function Vulnerability", "summary": "Splunk Enterprise contains a missing authentication for critical function vulnerability which could allow an unauthenticated user to create or truncate arbitrary files through a PostgreSQL sidecar service endpoint.", "product": "Splunk Enterprise", "category": "exploited", "source": "CISA Known Exploited Vulnerabilities", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-20253", "card": "CVE-2026-20253.webp?v=1783144881", "takeaways": ["Actively exploited (CISA KEV) - patch before 2026-06-21", "CVSS 3.1 : 9.8 CRITICAL", "Vector: AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"], "ts": 1781740800, "exploited": 1, "has_score": 1, "created": 1783077570, "updated": 1783085407, "exploited_text": 0, "poc": 0, "score": 9.8, "kev": 1, "flags": ["kev", "exploited", "0day"]}, {"key": "CVE-2026-48907", "cve": "CVE-2026-48907", "lang": "en", "title": "CVE-2026-48907 - Widget Factory Joomla Content Editor Improper Access Control Vulnerability", "summary": "Widget Factory Joomla Content Editor contains an improper access control vulnerability which could allow for upload and execution of PHP code via the creation of new editor profiles for unauthenticated users.", "product": "Joomla Content Editor (JCE) extension fo", "category": "exploited", "source": "CISA Known Exploited Vulnerabilities", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-48907", "card": "CVE-2026-48907.webp?v=1783144881", "takeaways": ["Actively exploited (CISA KEV) - patch before 2026-06-19", "CVSS 4.0 : 10.0 CRITICAL", "Vector: AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:A/AU:Y/U:Red", "CVSS 3.1 : 9.8 CRITICAL"], "ts": 1781568000, "exploited": 1, "has_score": 1, "created": 1783077570, "updated": 1783141643, "exploited_text": 0, "poc": 0, "score": 10.0, "kev": 1, "flags": ["kev", "exploited", "0day"]}, {"key": "CVE-2026-54420", "cve": "CVE-2026-54420", "lang": "en", "title": "CVE-2026-54420 - LiteSpeed cPanel Plugin UNIX Symbolic Link (Symlink) Following Vulnerability", "summary": "LiteSpeed cPanel plugin contains a UNIX symbolic link (Symlink) following vulnerability that could allow a user with FTP or web shell access on a shared hosting server running CloudLinux/CageFS.", "product": "LiteSpeed Technologies cPanel Plugin", "category": "exploited", "source": "CISA Known Exploited Vulnerabilities", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-54420", "card": "CVE-2026-54420.webp?v=1783144881", "takeaways": ["Actively exploited (CISA KEV) - patch before 2026-06-18", "CVSS 3.1 : 8.5 HIGH", "Vector: AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H"], "ts": 1781481600, "exploited": 1, "has_score": 1, "created": 1783077570, "updated": 1783141643, "exploited_text": 0, "poc": 0, "score": 8.5, "kev": 1, "flags": ["kev", "exploited", "0day"]}, {"key": "CVE-2026-20262", "cve": "CVE-2026-20262", "lang": "en", "title": "CVE-2026-20262 - Cisco Catalyst SD-WAN Manager Directory or Path Traversal Vulnerability", "summary": "Cisco Catalyst SD-WAN Manager contains a directory or path traversal vulnerability that could allow an authenticated, remote attacker to create a file or overwrite any file on the filesystem of an affected system.", "product": "Cisco Catalyst SD-WAN Manager", "category": "exploited", "source": "CISA Known Exploited Vulnerabilities", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-20262", "card": "CVE-2026-20262.webp?v=1783144880", "takeaways": ["Actively exploited (CISA KEV) - patch before 2026-06-29", "CVSS 3.1 : 6.5 MEDIUM", "Vector: AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N"], "ts": 1781481600, "exploited": 1, "has_score": 1, "created": 1783077570, "updated": 1783085407, "exploited_text": 0, "poc": 0, "score": 6.5, "kev": 1, "flags": ["kev", "exploited", "0day"]}, {"key": "CVE-2026-35273", "cve": "CVE-2026-35273", "lang": "en", "title": "CVE-2026-35273 - Oracle PeopleSoft Enterprise PeopleTools Missing Authentication for Critical Function Vulnerability", "summary": "Oracle PeopleSoft Enterprise PeopleTools contains a missing authentication for critical function vulnerability which could allow an unauthenticated attacker to obtain takeover of PeopleSoft Enterprise PeopleTools.", "product": "PeopleSoft Enterprise PeopleTools", "category": "exploited", "source": "CISA Known Exploited Vulnerabilities", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-35273", "card": "CVE-2026-35273.webp?v=1785159639", "takeaways": ["Actively exploited (CISA KEV) - patch before 2026-06-15", "CVSS 3.1 : 9.8 CRITICAL", "Vector: AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"], "ts": 1781222400, "exploited": 1, "has_score": 1, "created": 1783077570, "updated": 1783141643, "exploited_text": 0, "poc": 0, "score": 9.8, "kev": 1, "flags": ["kev", "exploited", "0day"]}, {"key": "CVE-2026-10520", "cve": "CVE-2026-10520", "lang": "en", "title": "CVE-2026-10520 - Ivanti Sentry OS Command Injection Vulnerability", "summary": "Ivanti Sentry (formerly known as MobileIron Sentry) contains an OS command injection vulnerability which could allow a remote unauthenticated user to achieve root-level remote code execution. This vulnerability can be successfully exploited in cases where the Sentry appliance is in an unmanaged state with its endpoints externally reachable. The use of mTLS with EPMM or restricted HTTPS access through Neurons for MDM makes interfaces inaccessible to external actors.", "product": "ivanti Sentry", "category": "exploited", "source": "CISA Known Exploited Vulnerabilities", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-10520", "card": "CVE-2026-10520.webp?v=1785159639", "takeaways": ["Actively exploited (CISA KEV) - patch before 2026-06-14", "CVSS 3.1 : 10.0 CRITICAL", "Vector: AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H"], "ts": 1781136000, "exploited": 1, "has_score": 1, "created": 1783077570, "updated": 1783141643, "exploited_text": 0, "poc": 0, "score": 10.0, "kev": 1, "flags": ["kev", "exploited", "0day"]}, {"key": "CVE-2026-11645", "cve": "CVE-2026-11645", "lang": "en", "title": "CVE-2026-11645 - Google Chromium V8 Out-of-Bounds Read and Write Vulnerability", "summary": "Google Chromium V8 out-of-bounds read and write vulnerability that could allow a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.", "product": "Google Chrome", "category": "exploited", "source": "CISA Known Exploited Vulnerabilities", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-11645", "card": "CVE-2026-11645.webp?v=1785159639", "takeaways": ["Actively exploited (CISA KEV) - patch before 2026-06-23", "CVSS 3.1 : 8.8 HIGH", "Vector: AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"], "ts": 1780963200, "exploited": 1, "has_score": 1, "created": 1783077569, "updated": 1783141643, "exploited_text": 0, "poc": 0, "score": 8.8, "kev": 1, "flags": ["kev", "exploited", "patched"]}, {"key": "CVE-2026-7473", "cve": "CVE-2026-7473", "lang": "en", "title": "CVE-2026-7473 - Arista Extensible Operating System Incomplete Comparison with Missing Factors Vulnerability", "summary": "Arista Extensible Operating System (EOS) contains an incomplete comparison with missing factors vulnerability when the switch incorrectly decapsulate and forwards other unexpected tunneled packet with a destination IP matching its configured decapsulation IP.", "product": "Arista Networks EOS", "category": "exploited", "source": "CISA Known Exploited Vulnerabilities", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-7473", "card": "CVE-2026-7473.webp?v=1785159640", "takeaways": ["Actively exploited (CISA KEV) - patch before 2026-06-23", "CVSS 4.0 : 6.9 MEDIUM", "Vector: AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:L/SA:N", "CVSS 3.1 : 5.8 MEDIUM"], "ts": 1780963200, "exploited": 1, "has_score": 1, "created": 1783077569, "updated": 1783141643, "exploited_text": 0, "poc": 0, "score": 6.9, "kev": 1, "flags": ["kev", "exploited", "0day"]}, {"key": "CVE-2026-20245", "cve": "CVE-2026-20245", "lang": "en", "title": "CVE-2026-20245 - Cisco Catalyst SD-WAN Manager Improper Encoding or Escaping of Output Vulnerability", "summary": "Cisco Catalyst SD-WAN Manager formerly SD-WAN vManage contains an improper encoding or escaping of output vulnerability. This vulnerability could allow an authenticated, local attacker to execute arbitrary commands as root by supplying a crafted file to the affected system.", "product": "Cisco Catalyst SD-WAN Controller", "category": "exploited", "source": "CISA Known Exploited Vulnerabilities", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-20245", "card": "CVE-2026-20245.webp?v=1785159640", "takeaways": ["Actively exploited (CISA KEV) - patch before 2026-06-23", "CVSS 3.1 : 7.8 HIGH", "Vector: AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"], "ts": 1780963200, "exploited": 1, "has_score": 1, "created": 1783077569, "updated": 1783141643, "exploited_text": 0, "poc": 0, "score": 7.8, "kev": 1, "flags": ["kev", "exploited", "0day"]}, {"key": "CVE-2026-42271", "cve": "CVE-2026-42271", "lang": "en", "title": "CVE-2026-42271 - BerriAI LiteLLM Command Injection Vulnerability", "summary": "BerriAI LiteLLM contains a command injection vulnerability that could allow any authenticated user, including holders of low-privilege internal-user keys, to run arbitrary commands on the host.", "product": "BerriAI litellm", "category": "exploited", "source": "CISA Known Exploited Vulnerabilities", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-42271", "card": "CVE-2026-42271.webp?v=1785159640", "takeaways": ["Actively exploited (CISA KEV) - patch before 2026-06-22", "CVSS 4.0 : 8.7 HIGH", "Vector: AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:N/SA:N", "CVSS 3.1 : 8.8 HIGH"], "ts": 1780876800, "exploited": 1, "has_score": 1, "created": 1783077569, "updated": 1783141643, "exploited_text": 0, "poc": 0, "score": 8.7, "kev": 1, "flags": ["kev", "exploited", "0day"]}, {"key": "CVE-2026-50751", "cve": "CVE-2026-50751", "lang": "en", "title": "CVE-2026-50751 - Check Point Security Gateway Improper Authentication Vulnerability", "summary": "Check Point Security Gateway contains an improper authentication vulnerability in IKEv1 key exchange that could allow an unauthenticated remote attacker to bypass user authentication and establish a remote access VPN connection without a valid user password.", "product": "checkpoint Quantum Security Gateway", "category": "exploited", "source": "CISA Known Exploited Vulnerabilities", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-50751", "card": "CVE-2026-50751.webp?v=1785159640", "takeaways": ["Actively exploited (CISA KEV) - patch before 2026-06-11", "CVSS 3.1 : 9.3 CRITICAL", "Vector: AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:L/A:N"], "ts": 1780876800, "exploited": 1, "has_score": 1, "created": 1783077569, "updated": 1783141643, "exploited_text": 0, "poc": 0, "score": 9.3, "kev": 1, "flags": ["kev", "exploited", "0day"]}, {"key": "CVE-2026-28318", "cve": "CVE-2026-28318", "lang": "en", "title": "CVE-2026-28318 - SolarWinds Serv-U Uncontrolled Resource Consumption Vulnerability", "summary": "SolarWinds Serv-U contains an uncontrolled resource consumption vulnerability that allows specially crafted POST requests using the Content-Encoding: deflate header to crash the Serv-U service without authentication.", "product": "SolarWinds Serv-U", "category": "exploited", "source": "CISA Known Exploited Vulnerabilities", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-28318", "card": "CVE-2026-28318.webp?v=1785159640", "takeaways": ["Actively exploited (CISA KEV) - patch before 2026-06-19", "CVSS 3.1 : 7.5 HIGH", "Vector: AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"], "ts": 1780617600, "exploited": 1, "has_score": 1, "created": 1783077569, "updated": 1783085407, "exploited_text": 0, "poc": 0, "score": 7.5, "kev": 1, "flags": ["kev", "exploited", "0day"]}]