SB20260907111 - Ubuntu update for linux-oem-7.0



SB20260907111 - Ubuntu update for linux-oem-7.0

Published: September 7, 2026

Security Bulletin ID SB20260907111
CSH Severity
High
Patch available
YES
Number of vulnerabilities 561
Exploitation vector Remote access
Highest impact Code execution

Breakdown by Severity

High 1% Medium 13% Low 86%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 561 vulnerabilities.


1) Improper locking (CVE-ID: CVE-2025-10263)

CWE-ID: CWE-667 - Improper Locking

CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to disclose sensitive information, modify data, or cause a denial of service.

The vulnerability exists due to improper memory synchronization in broadcast TLBI completion in the arm64 TLB invalidation handling when performing broadcast TLB invalidation on affected Arm CPUs. A local user can trigger affected memory access patterns to disclose sensitive information, modify data, or cause a denial of service.

The issue affects completion of memory accesses translated by an invalidated TLB entry, while TLB entries themselves are still invalidated correctly.


2) Race condition (CVE-ID: CVE-2025-10263)

CWE-ID: CWE-362 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')

CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to disclose sensitive information, modify data, or cause a denial of service.

The vulnerability exists due to improper memory synchronization in broadcast TLB invalidation completion handling in the arm64 CPU errata handling for affected Arm CPUs when performing broadcast TLB invalidation sequences. A local user can trigger memory accesses relying on an invalidated TLB entry to disclose sensitive information, modify data, or cause a denial of service.

The issue affects only the completion of memory accesses translated by an invalidated TLB entry; the TLB entries themselves are still invalidated correctly.


3) Improper locking (CVE-ID: CVE-2025-10263)

CWE-ID: CWE-667 - Improper Locking

CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to disclose sensitive information, modify data, or cause a denial of service.

The vulnerability exists due to improper memory access ordering in arm64 TLB invalidation handling when performing broadcast TLB invalidation on affected Arm CPUs. A local user can trigger affected memory access completion conditions to disclose sensitive information, modify data, or cause a denial of service.

The issue affects only memory accesses translated by an invalidated TLB entry; TLB entries themselves are still invalidated correctly.


4) Improper locking (CVE-ID: CVE-2025-10263)

CWE-ID: CWE-667 - Improper Locking

CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to disclose sensitive information, modify data, or cause a denial of service.

The vulnerability exists due to improper synchronization in broadcast TLB invalidation handling in the arm64 TLB invalidation logic when processing TLBI and DSB sequences on affected Arm CPUs. A local user can trigger memory accesses involving translations from an invalidated TLB entry to disclose sensitive information, modify data, or cause a denial of service.

The issue affects only the completion of memory accesses translated by an invalidated TLB entry and does not prevent the actual invalidation of TLB entries.


5) Improper locking (CVE-ID: CVE-2025-10263)

CWE-ID: CWE-667 - Improper Locking

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to improper hardware synchronization in broadcast TLBI completion on affected arm64 CPUs when performing broadcast TLB invalidation. A local user can trigger memory access activity that relies on an invalidated TLB entry to cause a denial of service.

The issue affects only the completion of memory accesses translated by an invalidated TLB entry; the TLB invalidation itself still occurs correctly.


6) Race condition (CVE-ID: CVE-2025-10263)

CWE-ID: CWE-362 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')

CVSSv4: 5.7 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to improper synchronization in broadcast TLBI completion in the arm64 TLB invalidation handling when performing broadcast TLB invalidation on affected Arm CPUs. A local user can trigger memory access patterns that rely on invalidated TLB entries to cause a denial of service.

The issue affects the completion of memory accesses translated by an invalidated TLB entry, while the TLB invalidation itself still occurs correctly.


7) Race condition (CVE-ID: CVE-2025-10263)

CWE-ID: CWE-362 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to improper synchronization in broadcast TLB invalidation completion handling in the arm64 CPU errata logic when performing memory accesses translated by an invalidated TLB entry after a TLBI;DSB sequence. A local user can trigger affected memory access patterns to cause a denial of service.

The issue affects certain Arm CPUs on arm64 systems and does not prevent invalidation of TLB entries themselves.


8) Improper locking (CVE-ID: CVE-2025-10263)

CWE-ID: CWE-667 - Improper Locking

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to improper hardware synchronization in arm64 TLB invalidation handling when processing broadcast TLB invalidation sequences on affected Arm CPUs. A local user can trigger memory accesses that rely on an invalidated TLB entry to cause a denial of service.

The issue affects only the completion of memory accesses translated by an invalidated TLB entry and does not affect the actual invalidation of TLB entries.


9) Race condition (CVE-ID: CVE-2025-10263)

CWE-ID: CWE-362 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to improper synchronization in broadcast TLB invalidation completion handling in the arm64 TLB invalidation logic when performing memory accesses translated by an invalidated TLB entry after a TLBI;DSB sequence. A local user can trigger affected memory access patterns to cause a denial of service.

The issue affects only the completion of memory accesses translated by an invalidated TLB entry and does not prevent the actual invalidation of TLB entries.


10) Improper locking (CVE-ID: CVE-2025-10263)

CWE-ID: CWE-667 - Improper Locking

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to improper memory synchronization in broadcast TLB invalidation completion handling in the arm64 CPU errata logic when performing broadcast TLB invalidation on affected Arm CPUs. A local user can trigger memory access patterns that rely on invalidated TLB entries to cause a denial of service.

The issue affects only completion of memory accesses translated by an invalidated TLB entry and does not prevent the actual invalidation of TLB entries.


11) Improper access control (CVE-ID: CVE-2025-10263)

CWE-ID: CWE-284 - Improper Access Control

CVSSv4: 7.3 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to escalate privileges.

The vulnerability exists due to improper access control in Stage 2 translation handling when invalidating translation lookaside buffer entries on affected Arm systems. A local user can trigger writes from a malicious guest after write permissions have been revoked to escalate privileges.

Only Xen on Arm in multi-core configurations is affected. The issue does not affect reads.


12) Out-of-bounds read (CVE-ID: CVE-2026-80591)

CWE-ID: CWE-125 - Out-of-bounds read

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to an out-of-bounds read in f2fs_listxattr() when processing corrupted xattr entries. A local user can supply a crafted corrupted filesystem image to cause a denial of service.

The issue occurs when an xattr entry lies outside the valid xattr storage area.


13) Use of uninitialized resource (CVE-ID: CVE-2026-74584)

CWE-ID: CWE-908 - Use of Uninitialized Resource

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local user to disclose sensitive information.

The vulnerability exists due to use of uninitialized memory in the bnxt_re shared userspace page allocation in bnxt_re_alloc_ucontext() when mapping the shared page to userspace through BNXT_RE_MMAP_SH_PAGE after IB_USER_VERBS_CMD_GET_CONTEXT. A local user can perform a single mmap() on the exposed page to disclose sensitive information.

Exploitation requires access to /dev/infiniband/uverbsX on a host with a bnxt_re device.


14) Use of Uninitialized Variable (CVE-ID: CVE-2026-68461)

CWE-ID: CWE-457 - Use of Uninitialized Variable

CVSSv4: 5.7 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to use of uninitialized memory in fwnode_init() in the firmware node handling code when initializing a fwnode_handle allocated on the stack or with a non-zeroing heap allocation. A local user can trigger dereference of an uninitialized secondary pointer to cause a denial of service.

Exploitation requires control over the lifetime and initialization context of the firmware node object.


15) Deadlock (CVE-ID: CVE-2026-68460)

CWE-ID: CWE-833 - Deadlock

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to a deadlock condition in f2fs_balance_fs() when handling writeback and garbage collection on nearly exhausted f2fs filesystem space. A local user can trigger filesystem write activity to cause a denial of service.

The issue occurs when the f2fs filesystem space is nearly exhausted.


16) Deadlock (CVE-ID: CVE-2026-68459)

CWE-ID: CWE-833 - Deadlock

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to improper locking in f2fs_balance_fs() gc_merge path when handling filesystem writeback and foreground garbage collection. A local user can trigger filesystem activity that causes a deadlock to cause a denial of service.

Only systems mounted with the gc_merge option are vulnerable.


17) Use-after-free (CVE-ID: CVE-2026-68372)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to a use-after-free in the USB Type-C connector handling in drivers/usb/core/port.c when processing Thunderbolt dock unplug and concurrent partner-disconnect events. A local user can trigger a crafted hot-unplug race to cause a denial of service.

Exploitation requires a race between component unbind, USB disconnect, and UCSI partner-disconnect handling during dock hot-plug events.


18) Improper Initialization (CVE-ID: CVE-2026-68092)

CWE-ID: CWE-665 - Improper Initialization

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to improper initialization in the jiffies clocksource when performing early boot timekeeping initialization. A local user can trigger early boot code paths that use the jiffies clocksource before registration to cause a denial of service.

The issue can cause time to stop making progress during boot, leading to a long boot delay in Xen HVM environments.


19) Improper resource shutdown or release (CVE-ID: CVE-2026-68091)

CWE-ID: CWE-404 - Improper Resource Shutdown or Release

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to improper resource shutdown in wacom_parse_and_register() in the Wacom HID driver when handling post-start probe failures. A local user can trigger a device initialization failure after HID hardware has been started to cause a denial of service.


20) Race condition (CVE-ID: CVE-2026-68090)

CWE-ID: CWE-362 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to a race condition in debugobjects in lib/debugobjects.c when handling object activation or initialization assertions during a concurrent out-of-memory disable. A local user can trigger debug object operations while forcing a concurrent memory exhaustion condition to cause a denial of service.

The issue can cause a valid timer object to become nonfunctional through an unintended fixup path.


21) Use of Uninitialized Variable (CVE-ID: CVE-2026-68089)

CWE-ID: CWE-457 - Use of Uninitialized Variable

CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local user to disclose sensitive information.

The vulnerability exists due to uninitialized data in the iio_debugfs_write_reg function in the industrial I/O core debugfs interface when handling debugfs write operations with a non-zero file position. A local user can write to the debugfs entry with a non-zero offset to disclose sensitive information.


22) Out-of-bounds read (CVE-ID: CVE-2026-68088)

CWE-ID: CWE-125 - Out-of-bounds read

CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to cause a denial of service.

The vulnerability exists due to an out-of-bounds read in rndis_query_response() in the RNDIS USB gadget function when processing a crafted RNDIS query message. A remote attacker can send a specially crafted RNDIS query message to cause a denial of service.


23) Improper synchronization (CVE-ID: CVE-2026-68087)

CWE-ID: CWE-662 - Improper Synchronization

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local attacker to cause a denial of service.

The vulnerability exists due to improper resource access in wacom_wac_queue_flush() when processing raw HID events for USB HID devices. A local attacker can trigger the vulnerable allocation path to cause a denial of service.

The issue occurs because the code runs in atomic context, where sleeping allocations can trigger a "scheduling while atomic" bug.


24) Improper control of a resource through its lifetime (CVE-ID: CVE-2026-68085)

CWE-ID: CWE-664 - Improper control of a resource through its lifetime

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to improper state management in the hci_uart Bluetooth line discipline write_work handling when closing and reopening the device. A local user can repeatedly reopen the device to cause a denial of service.

The issue can block future writes after the device is reopened if write_work was pending.


25) Improper resource shutdown or release (CVE-ID: CVE-2026-68084)

CWE-ID: CWE-404 - Improper Resource Shutdown or Release

CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to improper resource shutdown or release in the tsi148_remove() function in the vme_user tsi148 bridge driver when unbinding the device or unloading the module. A local user can trigger device removal operations to cause a denial of service.


26) Always-Incorrect Control Flow Implementation (CVE-ID: CVE-2026-64604)

CWE-ID: CWE-670 - Always-Incorrect Control Flow Implementation

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to improper state handling in vmx_update_cr8_intercept when creating a vCPU outside guest mode. A local user can issue crafted KVM vCPU creation operations to cause a denial of service.

The issue can trigger a kernel warning due to calling get_vmcs12() when the vCPU is not in guest mode.


27) Race condition (CVE-ID: CVE-2026-64603)

CWE-ID: CWE-362 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to a race condition in the intel-hid ACPI notify_handler() when handling concurrent tablet-mode events on multiple CPU cores. A local user can trigger concurrent notify events to cause a denial of service.

The issue affects convertible and detachable systems matched by DMI chassis types 31 and 32 where the SW_TABLET_MODE input device is registered lazily on the first tablet-mode event.


28) Access of Uninitialized Pointer (CVE-ID: CVE-2026-64602)

CWE-ID: CWE-824 - Access of Uninitialized Pointer

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to an uninitialized pointer dereference in the spear_adc_probe() initialization path and interrupt handler in drivers/iio/adc/spear_adc.c when handling a device interrupt before completion initialization. A local user can trigger a spurious interrupt during device probe to cause a denial of service.

The issue can lead to a kernel panic and was observed as a KASAN wild-memory-access caused by complete() operating on an uninitialized completion object.


29) Use-after-free (CVE-ID: CVE-2026-64601)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to use-after-free in capture_urb_complete() when resubmitting USB request blocks. A local user can trigger stream stop, suspend, or disconnect handling after repeated resubmissions to cause a denial of service.

The issue stems from redundant anchoring of an already anchored URB, which corrupts the anchor's doubly-linked list and inflates the URB reference count.


30) Race condition (CVE-ID: CVE-2026-64600)

CWE-ID: CWE-362 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to a race condition in xfs_reflink_fill_cow_hole and xfs_reflink_fill_delalloc in the XFS reflink code when processing direct I/O writes after cycling the ILOCK. A local user can trigger a racing direct I/O write operation to cause a denial of service.

The issue occurs because a stale data fork mapping can be used after the ILOCK is dropped and reacquired, which can result in incorrect shared-block state during copy-on-write handling.


31) Double free (CVE-ID: CVE-2026-64599)

CWE-ID: CWE-415 - Double Free

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to a double free in meson_crypto_probe() when handling a failure after partial channel list allocation during device probe. A local user can trigger the vulnerable probe path to cause a denial of service.

The issue was reproduced by forcing the second dma_alloc_attrs() call in the gxl-crypto probe path to fail after partial initialization.


32) Improper Check or Handling of Exceptional Conditions (CVE-ID: CVE-2026-64598)

CWE-ID: CWE-703 - Improper Check or Handling of Exceptional Conditions

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to improper handling of an error pointer in smb2_aead_req_alloc() when processing SMB client requests. A local user can trigger the bug to cause a denial of service.


33) Double free (CVE-ID: CVE-2026-64597)

CWE-ID: CWE-415 - Double Free

CVSSv4: 7.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote user to cause a denial of service.

The vulnerability exists due to double free in SMB2_close() in the SMB client close request handling when processing a response-bearing attempt that returns a replayable error. A remote user can trigger a replay sequence that causes the same response buffer to be freed twice to cause a denial of service.


34) Incorrect default permissions (CVE-ID: CVE-2026-64596)

CWE-ID: CWE-276 - Incorrect Default Permissions

CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to improper permission enforcement in pseudo filesystem file mappings when mmaping executable pseudo-fs file descriptors. A local user can mmap a pseudo-fs file descriptor with executable permissions to cause a denial of service.

This issue is reproducible on kernels built with CONFIG_DEBUG_VFS=y, where the condition triggers a kernel warning.


35) Improper Initialization (CVE-ID: CVE-2026-64594)

CWE-ID: CWE-665 - Improper Initialization

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to improper initialization in reset_work handling in the functionfs gadget subsystem when unmounting a functionfs instance. A local user can unmount a crafted or affected functionfs instance to cause a denial of service.

The issue is triggered in the common case where the instance was never deactivated, including when it is not mounted with the "no_disconnect" option.


36) NULL pointer dereference (CVE-ID: CVE-2026-64593)

CWE-ID: CWE-476 - NULL Pointer Dereference

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to a NULL pointer dereference in btrfs_trim_free_extents in the Btrfs filesystem when processing a FITRIM ioctl on a rescanned device that is not writeable. A local user can issue a trim request to trigger a kernel crash and cause a denial of service.

The issue occurs when a previously missing device is rescanned, clearing the missing-device state while the block device pointer remains NULL.


37) Improper Check or Handling of Exceptional Conditions (CVE-ID: CVE-2026-64592)

CWE-ID: CWE-703 - Improper Check or Handling of Exceptional Conditions

CVSSv4: 5.7 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local attacker to cause a denial of service.

The vulnerability exists due to improper memory address translation handling in the riscv memory management fault handling logic when handling spurious page faults. A local attacker can trigger repeated faults to cause a denial of service.

The issue can lead to repeated faulting and a system crash on RISC-V systems.


38) Race condition (CVE-ID: CVE-2026-64591)

CWE-ID: CWE-362 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to improper state management in the Intel IOMMU SVA unbind path when unbinding SVA domains on devices without PCI/PRI support. A local user can trigger SVA unbind operations to cause a denial of service.

The issue triggers a kernel WARNING because the unbind path attempts to disable IOPF for a device that never had it enabled.


39) Improper Check for Unusual or Exceptional Conditions (CVE-ID: CVE-2026-64590)

CWE-ID: CWE-754 - Improper Check for Unusual or Exceptional Conditions

CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to improper handling of overlapping dma mappings in udmabuf scatter-gather table mapping when importing a udmabuf into a DRM driver with DMA API debug enabled. A local user can import a udmabuf to trigger a kernel warning to cause a denial of service.

The issue is observed when CONFIG_DMA_API_DEBUG_SG is enabled.


40) NULL pointer dereference (CVE-ID: CVE-2026-64589)

CWE-ID: CWE-476 - NULL Pointer Dereference

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to a NULL pointer dereference in i2c_register_adapter in the i2c core when handling adapter registration failure. A local user can trigger adapter registration failure to cause a denial of service.


41) Race condition (CVE-ID: CVE-2026-64588)

CWE-ID: CWE-362 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to a race condition in fuse io_uring readiness handling in fs/fuse/dev_uring.c and fs/fuse/dev_uring_i.h when processing concurrent ring readiness checks and request dispatch. A local user can trigger concurrent operations to cause a denial of service.

The issue occurs on weakly-ordered architectures and can lead to requests being dispatched through a stale fiq->ops pointer.


42) Improper control of a resource through its lifetime (CVE-ID: CVE-2026-64556)

CWE-ID: CWE-664 - Improper control of a resource through its lifetime

CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to corrupt kernel memory.

The vulnerability exists due to improper state management in perf_event_remove_on_exec() and event group handling in the perf subsystem when removing events marked remove_on_exec. A local user can trigger event removal for a group leader with surviving siblings to corrupt kernel memory.

The issue occurs when a removed event is a group leader and sibling events without remove_on_exec remain active in a stale group state.


43) Out-of-bounds read (CVE-ID: CVE-2026-64536)

CWE-ID: CWE-125 - Out-of-bounds read

CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to cause a denial of service.

The vulnerability exists due to out-of-bounds read in is_ap_in_tkip() in drivers/staging/rtl8723bs/core/rtw_wlan_util.c when parsing information elements from network data. A remote attacker can provide a truncated or crafted information element buffer to cause a denial of service.


44) Exposure of Resource to Wrong Sphere (CVE-ID: CVE-2026-64529)

CWE-ID: CWE-668 - Exposure of resource to wrong sphere

CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a local user to affect device configuration and control operations.

The vulnerability exists due to an exposed attack surface in the qat_adf_ctl character device and its ioctl interface when handling ioctl requests for device configuration, start, stop, status query, and enumeration. A local user can send crafted ioctl requests to affect device configuration and control operations.

The ioctl interface was not part of any public uAPI header.


45) Always-Incorrect Control Flow Implementation (CVE-ID: CVE-2026-64514)

CWE-ID: CWE-670 - Always-Incorrect Control Flow Implementation

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to improper handling of non-present page table entries in userfaultfd_must_wait() and userfaultfd_huge_must_wait() when checking writability during userfaultfd write-protect fault handling. A local user can trigger a fault involving a swap or migration entry to cause a denial of service.

In the worst case, the affected thread may remain asleep waiting for a wake event that never arrives.


46) Improper Initialization (CVE-ID: CVE-2026-64513)

CWE-ID: CWE-665 - Improper Initialization

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to improper state management in KVM x86 LAPIC and CR8 intercept handling when updating the guest's PPR and entering a virtual machine. A local user can trigger PPR updates in a guest to cause a VM entry failure with hardware error 0x7.

This is typically exposed on older platforms or under nested virtualization on a hypervisor that does not support virtual-interrupt delivery and enforces the TPR_THRESHOLD check.


47) Improper input validation (CVE-ID: CVE-2026-64512)

CWE-ID: CWE-20 - Improper input validation

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local attacker to cause a denial of service.

The vulnerability exists due to improper input validation in the ACPI CPPC register width handling in drivers/acpi/cppc_acpi.c when processing ACPI PCC register definitions. A local attacker can provide a crafted access_width value to trigger a shift-out-of-bounds condition and cause a denial of service.

The issue occurs because the access_width field is reused as a PCC subspace identifier for ACPI_ADR_SPACE_PLATFORM_COMM entries.


48) NULL pointer dereference (CVE-ID: CVE-2026-64511)

CWE-ID: CWE-476 - NULL Pointer Dereference

CVSSv4: 5.1 [CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows an attacker with physical access to cause a denial of service.

The vulnerability exists due to a NULL pointer dereference in acpi_nfit_uc_error_notify() in the ACPI NFIT core when handling an NFIT_NOTIFY_UC_MEMORY_ERROR notification for an NFIT device without initialized driver data. An attacker with physical access can trigger a firmware notification to cause a denial of service.

The issue occurs when the notify handler is installed before the presence of the NFIT table is verified.


49) Use-after-free (CVE-ID: CVE-2026-64510)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local attacker to cause a denial of service.

The vulnerability exists due to use-after-free in the ACPI NFIT core when handling a subsequent ACPI Machine Check Exception after a failed or incomplete NFIT initialization and shutdown path. A local attacker can trigger the vulnerable initialization state to cause a denial of service.

The issue occurs because a freed acpi_desc object may remain referenced in the acpi_descs list and later be accessed by nfit_handle_mce().


50) Improper resource shutdown or release (CVE-ID: CVE-2026-64509)

CWE-ID: CWE-404 - Improper Resource Shutdown or Release

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to improper resource shutdown in GenDiskBuilder::build() and GenDisk::drop() in rust/kernel/block/mq/gen_disk.rs when handling gendisk cleanup on error and release paths. A local user can trigger the vulnerable cleanup paths to cause a denial of service.

Exploitation requires interacting with the Rust block layer gendisk functionality so that a temporary gendisk and request_queue remain unreleased or the final gendisk reference is not dropped during teardown.


51) Protection mechanism failure (CVE-ID: CVE-2026-64508)

CWE-ID: CWE-693 - Protection Mechanism Failure

CVSSv4: 2.3 [CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to bypass branch prediction isolation for reused BPF JIT memory.

The vulnerability exists due to improper isolation of indirect branch predictor state in the BPF JIT allocator when reusing JIT memory for newly written programs. A remote attacker can load and free BPF programs to bypass branch prediction isolation for reused BPF JIT memory.

Allocations larger than a pack are not covered by this condition, and the described attack surface is limited to cBPF programs that fit within pack size constraints.


52) Observable discrepancy (CVE-ID: CVE-2026-64507)

CWE-ID: CWE-203 - Observable discrepancy

CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local user to disclose sensitive information.

The vulnerability exists due to improper protection against speculative execution in BPF JIT memory reuse on x86 systems when reusing JIT-compiled BPF memory under Spectre-v2 conditions. A local user can trigger BPF JIT allocation reuse to disclose sensitive information.

Only systems with BPF-JIT enabled are affected.


53) Out-of-bounds read (CVE-ID: CVE-2026-64505)

CWE-ID: CWE-125 - Out-of-bounds read

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to an out-of-bounds read in rndis_rm_hdr in the RNDIS USB gadget function when parsing a crafted RNDIS header. A local user can provide a truncated header to cause a denial of service.


54) Stack-based buffer overflow (CVE-ID: CVE-2026-64504)

CWE-ID: CWE-121 - Stack-based buffer overflow

CVSSv4: 7 [CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows an attacker with physical access to execute arbitrary code or cause a denial of service.

The vulnerability exists due to a stack-based buffer overflow in __bmc150_accel_fifo_flush() when processing a device-reported FIFO frame count. An attacker with physical access can tamper with the I2C/SPI bus or use a malicious device that reports an oversized frame count to execute arbitrary code or cause a denial of service.

The issue can overwrite the stack canary, saved registers, and return address during FIFO data transfer.


55) Improper resource shutdown or release (CVE-ID: CVE-2026-64503)

CWE-ID: CWE-404 - Improper Resource Shutdown or Release

CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to improper resource shutdown or release in kxsd9_write_raw() when handling write requests for scale values with a non-zero integer part. A local user can send a crafted write request to cause a denial of service.

The issue leaks a runtime PM usage-counter reference, which can prevent the device from autosuspending.


56) Heap-based buffer overflow (CVE-ID: CVE-2026-64502)

CWE-ID: CWE-122 - Heap-based Buffer Overflow

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to corrupt the heap and cause a denial of service.

The vulnerability exists due to a heap-based buffer overflow in ad_sigma_delta_clear_pending_event() when handling pending events with num_resetclks set to 0. A local user can trigger the pending-event drain path to corrupt the heap and cause a denial of service.

The issue can occur for registerless devices without an RDY GPIO and also for devices with an RDY GPIO set when the pending event condition is detected.


57) Improper resource shutdown or release (CVE-ID: CVE-2026-64501)

CWE-ID: CWE-404 - Improper Resource Shutdown or Release

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to improper resource shutdown or release in ad_sigma_delta.c when handling error paths and conversion cleanup. A local user can trigger a failed conversion or buffer post-enable operation to cause a denial of service.

The issue can leave chip select physically asserted, leave the device in continuous conversion mode, and allow subsequent SPI operations to proceed without the bus lock actually being held.


58) Improper Initialization (CVE-ID: CVE-2026-64500)

CWE-ID: CWE-665 - Improper Initialization

CVSSv4: 5.7 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to improper initialization in lpc32xx_adc_probe() and the lpc32xx ADC interrupt handling path when handling a spurious interrupt during device probe before completion initialization. A local user can trigger a device state that causes an interrupt to arrive before init_completion() to cause a denial of service.

The issue can lead to a kernel panic through a NULL pointer dereference and resulting wild memory access in the interrupt wake-up path.


59) Improper resource shutdown or release (CVE-ID: CVE-2026-64499)

CWE-ID: CWE-404 - Improper Resource Shutdown or Release

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to improper resource shutdown or release in ads1119_triggered_buffer_preenable() in the ti-ads1119 ADC driver when starting a conversion after resuming the device. A local user can trigger an I2C transfer failure to cause a denial of service.

The issue can leave the runtime PM usage counter elevated, causing the device to remain runtime-active indefinitely when the preenable callback fails.


60) Integer overflow (CVE-ID: CVE-2026-64497)

CWE-ID: CWE-190 - Integer overflow

CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause incorrect sensor data processing.

The vulnerability exists due to an integer sign-extension bug in the scd30_float_to_fp() function in the SCD30 IIO chemical sensor driver when converting floating-point sensor values. A local user can trigger the conversion of a crafted floating-point value to cause incorrect sensor data processing.

The issue affects the Linux kernel SCD30 sensor driver code path that converts device-provided floating-point values into fixed-point representation.


61) Out-of-bounds read (CVE-ID: CVE-2026-64496)

CWE-ID: CWE-125 - Out-of-bounds read

CVSSv4: 5.7 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local user to disclose sensitive information.

The vulnerability exists due to an out-of-bounds read in the iio event FIFO handling in drivers/iio/industrialio-event.c when reading from a newly created event file descriptor concurrently with FIFO reset. A local user can read from the file descriptor from another thread to disclose sensitive information.

Exploitation requires shared file descriptor table access between threads, creating a race window before the fd number is returned to userspace.


62) Out-of-bounds read (CVE-ID: CVE-2026-64495)

CWE-ID: CWE-125 - Out-of-bounds read

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to out-of-bounds read in bmg160_get_filter() and bmg160_set_filter() when handling sysfs input for the in_anglvel_filter_low_pass_3db_frequency interface. A local user can supply a value that is not present in bmg160_samp_freq_table to cause a denial of service.

The issue is reachable from userspace through the sysfs interface.


63) Improper resource shutdown or release (CVE-ID: CVE-2026-64494)

CWE-ID: CWE-404 - Improper Resource Shutdown or Release

CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to improper resource shutdown or release in gp2ap002_read_raw() when handling read errors from gp2ap002_get_lux(). A local user can trigger a read operation that causes an error to prevent the device from autosuspending and cause a denial of service.

The issue permanently leaks a runtime PM reference on the error path.


64) Improper resource shutdown or release (CVE-ID: CVE-2026-64493)

CWE-ID: CWE-404 - Improper Resource Shutdown or Release

CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to improper resource shutdown or release in mpl115_read_raw() in drivers/iio/pressure/mpl115.c when handling failed reads of processed pressure or raw temperature. A local user can trigger a read error to cause a denial of service.

The issue leaks a runtime PM reference on the error path and can prevent the device from autosuspending.


65) Use-after-free (CVE-ID: CVE-2026-64492)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to a use-after-free in the tmp006 driver trigger registration logic when unloading the module after registering the DRDY trigger. A local user can trigger module unload after the trigger has been registered to cause a denial of service.

The issue occurs because the driver has no .remove() callback, leaving a dangling entry in the global trigger list after the trigger memory is freed.


66) Use-after-free (CVE-ID: CVE-2026-64491)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to use-after-free in tascam_disconnect() in sound/usb/usx2y/us144mkii.c when handling device disconnect events and deferred USB work. A local user can trigger a device disconnect race to cause a denial of service.

The issue occurs because self-resubmitting URBs can complete after work cancellation and re-arm work that later runs on freed memory.


67) Out-of-bounds read (CVE-ID: CVE-2026-64490)

CWE-ID: CWE-125 - Out-of-bounds read

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to out-of-bounds access in virtio-snd control handling in sound/virtio/virtio_kctl.c when processing device-provided control metadata. A local user can provide a malicious or buggy virtio sound device that advertises an invalid control type or an oversized value count to cause a denial of service.

Exploitation requires the presence of a virtio sound device that supplies crafted control metadata to the guest kernel.


68) NULL pointer dereference (CVE-ID: CVE-2026-64489)

CWE-ID: CWE-476 - NULL Pointer Dereference

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to a NULL pointer dereference in snd_ymfpci_create_spdif_controls() when handling control creation after memory allocation failure in snd_ctl_new1(). A local user can trigger memory allocation failure and reach the dereference of a NULL control pointer to cause a denial of service.


69) NULL pointer dereference (CVE-ID: CVE-2026-64488)

CWE-ID: CWE-476 - NULL Pointer Dereference

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to a NULL pointer dereference in sound/aoa/fabrics/layout.c when handling control creation failures in layout_attached_codec(). A local user can trigger a memory allocation failure that leads to dereferencing a NULL control pointer to cause a denial of service.


70) Out-of-bounds read (CVE-ID: CVE-2026-64487)

CWE-ID: CWE-125 - Out-of-bounds read

CVSSv4: 5.1 [CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows an attacker with physical access to cause a denial of service.

The vulnerability exists due to out-of-bounds read in snd_usb_caiaq_tks4_dispatch() when parsing input from a crafted USB device input stream. An attacker with physical access can provide a malformed short final message block to cause a denial of service.

The issue is triggered because the device-controlled input length is not guaranteed to be a multiple of the 16-byte message block size, leading to an unsigned underflow during iteration.


71) NULL pointer dereference (CVE-ID: CVE-2026-64486)

CWE-ID: CWE-476 - NULL Pointer Dereference

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to a null pointer dereference in snd_cmipci_mixer_new in sound/pci/cmipci.c when handling control creation failures from snd_ctl_new1(). A local user can trigger a memory allocation failure and reach a NULL pointer dereference to cause a denial of service.


72) Improper resource shutdown or release (CVE-ID: CVE-2026-64485)

CWE-ID: CWE-404 - Improper Resource Shutdown or Release

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to improper resource shutdown or release in snd_compr_task_new() in sound/core/compress_offload.c when creating compression tasks and allocating file descriptors. A local user can trigger an error condition after a successful task_create() callback to cause a denial of service.

The issue can leak driver-allocated resources when later dma-buffer validation or file descriptor reservation fails, and the dual-file-descriptor allocation path can incorrectly report success after the task has already been discarded.


73) NULL pointer dereference (CVE-ID: CVE-2026-64484)

CWE-ID: CWE-476 - NULL Pointer Dereference

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to a NULL pointer dereference in snd_es1938_mixer() in sound/pci/es1938.c when handling mixer control initialization. A local user can trigger a memory allocation failure and reach the vulnerable code path to cause a denial of service.


74) Out-of-bounds write (CVE-ID: CVE-2026-64483)

CWE-ID: CWE-787 - Out-of-bounds write

CVSSv4: 5.2 [CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows an attacker with physical access to cause a denial of service or execute arbitrary code.

The vulnerability exists due to an out-of-bounds read and out-of-bounds write in isight_packet() when processing crafted FireWire isochronous packets from a device on the bus during normal capture. An attacker with physical access can provide a malicious device that reports an oversized sample count to cause a denial of service or execute arbitrary code.

Exploitation requires a malicious or faulty Apple iSight device connected on the FireWire bus.


75) NULL pointer dereference (CVE-ID: CVE-2026-64482)

CWE-ID: CWE-476 - NULL Pointer Dereference

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to a NULL pointer dereference in snd_gf1_pcm_volume_control() when handling a failed snd_ctl_new1() allocation. A local user can trigger a memory allocation failure leading to a NULL dereference to cause a denial of service.


76) Use-after-free (CVE-ID: CVE-2026-64481)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to a use-after-free in the cs35l41_hda firmware load work and ALSA control handling when a firmware load is requested and queued work executes after component unbind or device removal. A local user can trigger a firmware load request and remove the component or device before the queued work runs to cause a denial of service.

Exploitation requires firmware autostart to be disabled and can occur before DSP initialization.


77) NULL pointer dereference (CVE-ID: CVE-2026-64480)

CWE-ID: CWE-476 - NULL Pointer Dereference

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to a NULL pointer dereference in the ALSA ice1712 driver control creation logic when handling failed snd_ctl_new1() allocations. A local user can trigger memory allocation failure and reach code paths that dereference a NULL pointer to cause a denial of service.


78) Use of Uninitialized Variable (CVE-ID: CVE-2026-64479)

CWE-ID: CWE-457 - Use of Uninitialized Variable

CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local user to disclose sensitive information.

The vulnerability exists due to an uninitialized heap leak in snd_seq_event_dup() when delivering a legacy event to a UMP client with SNDRV_SEQ_FILTER_NO_CONVERT set. A local user can send a crafted event through /dev/snd/seq to disclose sensitive information.

The issue can leak 4 bytes of stale kernel heap data to user space, and exploitation requires a UMP-enabled build.


79) NULL pointer dereference (CVE-ID: CVE-2026-64478)

CWE-ID: CWE-476 - NULL Pointer Dereference

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local attacker to cause a denial of service.

The vulnerability exists due to a null pointer dereference in snd_dualsense_ih_match() when handling repeated device disconnect and reconnect events. A local attacker can trigger a controller disconnect race to cause a denial of service.

The issue can occur when a weak physical connection causes rapid hotplug activity during USB device teardown.


80) Out-of-bounds read (CVE-ID: CVE-2026-64477)

CWE-ID: CWE-125 - Out-of-bounds read

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to an out-of-bounds access in the resctrl RMID reader and limbo handler when offlining a monitoring domain with SNC enabled. A local user can trigger CPU offlining for a monitoring domain with an empty cpu_mask to cause a denial of service.

The issue occurs when LLC occupancy is tracked and the monitoring domain is going offline, causing a NUMA node lookup to be performed with nr_cpu_ids.


81) Improper Initialization (CVE-ID: CVE-2026-64476)

CWE-ID: CWE-665 - Improper Initialization

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to improper state management in vfio-pci runtime power management handling when changing the disable_idle_d3 setting for devices already bound to vfio-pci variant drivers. A local user can change the sysfs module parameter and trigger unbalanced power management operations to cause a denial of service.

The issue occurs because the setting was latched globally at module initialization rather than consistently per device, creating a window where existing bound devices could operate with inconsistent power management behavior.


82) Use-after-free (CVE-ID: CVE-2026-64475)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to a use-after-free in the VGA arbiter callback handling in vfio_pci_core_register_device() when registration of a vfio PCI device fails after VGA arbiter client initialization. A local user can trigger device registration failure and leave a stale callback referencing freed device data to cause a denial of service.

The issue occurs on the error path and depends on a stale VGA arbiter registration remaining after the vfio device state has been freed.


83) Infinite loop (CVE-ID: CVE-2026-64474)

CWE-ID: CWE-835 - Loop with Unreachable Exit Condition ('Infinite Loop')

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to improper handling of an error sentinel in vfio_mig_get_next_state() when processing blocked VFIO migration state transitions. A local user can trigger a blocked transition on a precopy-capable device to cause a denial of service.

The issue can cause the loop to spin forever while holding the driver state mutex, resulting in a soft lockup and potentially a panic if softlockup_panic is set.


84) Use-after-free (CVE-ID: CVE-2026-64473)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to a use-after-free in VFIO device debugfs entries when handling device unregister operations while userspace references remain open. A local user can keep references to the debugfs view during device teardown to cause a denial of service.

The issue affects diagnostic debugfs entries that may remain visible with stale inode private data during unregister.


85) Race condition (CVE-ID: CVE-2026-64472)

CWE-ID: CWE-362 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to a race condition in vfio/mlx5 page tracker and device state flag handling when concurrently updating runtime bitfields. A local user can trigger concurrent device operations to cause a denial of service.

The issue affects flags that can be updated during runtime, including dirty tracking, reset handling, tracker error handling, and VF attach or detach event processing.


86) Use-after-free (CVE-ID: CVE-2026-64471)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local attacker to cause a denial of service.

The vulnerability exists due to use-after-free in the btusb driver probe error handling in drivers/bluetooth/btusb.c when handling Bluetooth USB controller registration failures and subsequent interface disconnection. A local attacker can trigger controller registration failure to cause a denial of service.

The issue can also result in a double-free when the sibling interfaces are eventually disconnected.


87) Use-after-free (CVE-ID: CVE-2026-64470)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a use-after-free.

The vulnerability exists due to use-after-free in the btusb probe path in drivers/bluetooth/btusb.c when handling probe failures after Marvell OOB wakeup configuration. A local user can trigger a device probe failure after TX URBs have been submitted to cause a use-after-free.

The issue occurs in the completion callback for submitted TX URBs.


88) Use-after-free (CVE-ID: CVE-2026-64469)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to a use-after-free in binder_thread_release() when releasing binder threads while transactions are being freed in parallel. A local user can trigger concurrent binder transaction activity to cause a denial of service.

The issue is caused by a race condition involving transaction stack cleanup during thread exit and parallel process teardown.


89) Use-after-free (CVE-ID: CVE-2026-64468)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to use-after-free in binder_free_transaction() when freeing binder transactions. A local user can trigger a race condition involving a binder transaction to cause a denial of service.

The issue occurs because the target process can be freed after its reference is read and before its inner lock is acquired.


90) Incorrect calculation (CVE-ID: CVE-2026-64467)

CWE-ID: CWE-682 - Incorrect Calculation

CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a local user to corrupt binder reference accounting.

The vulnerability exists due to an incorrect integer type usage in the rust_binder allocation cleanup logic in drivers/android/binder/allocation.rs when cleaning up the offsets array on 32-bit kernels. A local user can trigger cleanup of crafted binder objects to corrupt binder reference accounting.

On affected 32-bit kernels, 8-byte offsets entries are processed in 4-byte steps, causing extra cleanup of the object at offset 0 and potentially triggering refcount underflow protection.


91) Missing Release of Resource after Effective Lifetime (CVE-ID: CVE-2026-64466)

CWE-ID: CWE-772 - Missing Release of Resource after Effective Lifetime

CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to improper resource management in the rust binder freeze listener handling when dropping the last reference to a node without clearing its freeze listener. A local user can drop the node reference while leaving a stale freeze listener registered to cause a denial of service.

The issue can leave the listener in both the freeze_listeners rbtree and the remote node's freeze listener list, potentially creating a refcount cycle that results in a memory leak.


92) Improper locking (CVE-ID: CVE-2026-64465)

CWE-ID: CWE-667 - Improper Locking

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to improper lock handling in xhci_free_streams() when freeing USB stream resources during device disconnect. A local user can disconnect a USB device with active stream endpoints to cause a denial of service.

The issue is triggered because memory freeing may sleep while the code is executing in atomic context.


93) Memory leak (CVE-ID: CVE-2026-64464)

CWE-ID: CWE-401 - Missing release of memory after effective lifetime

CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to a memory leak in xhci_ring_to_sgtable() when building an sg_table for a sideband client's endpoint or event ring buffer. A local user can trigger allocation of ring buffers to cause a denial of service.


94) Improper resource shutdown or release (CVE-ID: CVE-2026-64463)

CWE-ID: CWE-404 - Improper Resource Shutdown or Release

CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to improper resource shutdown or release in the rt1711h_probe() TCPCI port registration handling in drivers/usb/typec/tcpm/tcpci_rt1711h.c when handling device probe failures after registering a TCPCI port. A local user can trigger a device probe failure after port registration to cause a denial of service.

The issue occurs because the TCPCI port is not unregistered when later probe steps fail.


95) Use-after-free (CVE-ID: CVE-2026-64462)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to a stale pointer in the altera pcie irq handler teardown logic in drivers/pci/controller/pcie-altera.c when handling a probe failure after irq setup. A local user can trigger a driver probe failure to cause a denial of service.

The issue occurs because the chained IRQ handler and INTx IRQ domain can remain configured after probe failure while the associated devm-managed host bridge storage is released.


96) Improper resource shutdown or release (CVE-ID: CVE-2026-64461)

CWE-ID: CWE-404 - Improper Resource Shutdown or Release

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to improper resource shutdown or release in the MediaTek PCIe controller driver when enabling a port fails during setup. A local user can trigger a port initialization failure to cause a denial of service.

The issue occurs in the probe error path after IRQ domains have already been created for the port.


97) Out-of-bounds read (CVE-ID: CVE-2026-64460)

CWE-ID: CWE-125 - Out-of-bounds read

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to an out-of-bounds read in sriov_restore_vf_rebar_state() when restoring VF Resizable BAR state after configuration reads return an error response. A local user can trigger access to an unresponsive device state to cause a denial of service.

The issue is triggered because error responses cause 3-bit fields in the VF Resizable BAR Control register to evaluate to index values beyond the six-entry barsz[] array.


98) Use-after-free (CVE-ID: CVE-2026-64459)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to a use-after-free in the TCP-AO socket destruction logic when processing crafted TCP-AO traffic during connect(). A local user can send crafted network segments and trigger connect() to cause a denial of service.

Exploitation requires the ability to configure TCP_MD5SIG and TCP_AO keys on a socket.


99) Improper Check for Unusual or Exceptional Conditions (CVE-ID: CVE-2026-64458)

CWE-ID: CWE-754 - Improper Check for Unusual or Exceptional Conditions

CVSSv4: 6.9 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service or perform an out-of-bounds read.

The vulnerability exists due to improper handling of exceptional conditions in damon_hot_score() and damon_max_nr_accesses() when processing user-controlled DAMON monitoring intervals via sysfs. A local user can write zero or excessively large interval values to sysfs settings to cause a denial of service or perform an out-of-bounds read.

Exploitation requires sysfs write permission.


100) NULL pointer dereference (CVE-ID: CVE-2026-64457)

CWE-ID: CWE-476 - NULL Pointer Dereference

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to a NULL pointer dereference in virtio_pci queue handling in vp_del_vqs() when unbinding a virtio balloon device with conditional queue entries absent. A local user can write to the virtio_balloon unbind sysfs interface to cause a denial of service.

The issue occurs when optional stats, free_page, or reporting queues are not present, creating holes in the queue info array and causing a mismatch between sparse and dense queue indexing.


101) Out-of-bounds read (CVE-ID: CVE-2026-64456)

CWE-ID: CWE-125 - Out-of-bounds read

CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to disclose sensitive information.

The vulnerability exists due to an out-of-bounds read in the virtio-rng driver copy_data() function when processing device-reported used.len values from a virtio-rng backend. A remote attacker can provide a specially crafted length value to disclose sensitive information.

The issue can leak adjacent guest-kernel slab contents through the guest RNG and can also be observed directly via /dev/hwrng. No guest userspace interaction is required for the initial out-of-bounds read to occur.


102) Use-after-free (CVE-ID: CVE-2026-64455)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to use-after-free in chaoskey_release() in the chaoskey USB driver when closing the device file after the USB device has been unplugged. A local user can close the device file after device unplug to cause a denial of service.

The invalid access occurs in a debugging log statement after the usb_interface structure has already been deallocated.


103) Improper locking (CVE-ID: CVE-2026-64454)

CWE-ID: CWE-667 - Improper Locking

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to improper lock handling in the dwc3 gadget disconnect callback path when suspending the gadget. A local user can trigger a gadget disconnect during suspend to cause a denial of service.

The issue occurs because the disconnect callback may run in a non-sleepable context with IRQs disabled, which can trigger kernel lockdep warnings and sleeping-function-in-invalid-context failures.


104) Use-after-free (CVE-ID: CVE-2026-64453)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to use-after-free in usbio_disconnect() in drivers/usb/misc/usbio.c when disconnecting a USB interface and tearing down client auxiliary devices. A local user can trigger device disconnect handling to cause a denial of service.

The issue occurs because reverse iteration over the client list can dereference freed memory after an unbound child device is uninitialized.


105) Use-after-free (CVE-ID: CVE-2026-64452)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to cause a denial of service.

The vulnerability exists due to a use-after-free in lowpan_nhc_do_uncompression() when processing a malformed 6LoWPAN packet on an error path. A remote attacker can send a specially crafted packet to cause a denial of service.

The issue is caused by a race condition involving descriptor unregistration and access to nhc->name outside the protection of lowpan_nhc_lock, and it can be reached through the Bluetooth 6LoWPAN L2CAP receive path.


106) NULL pointer dereference (CVE-ID: CVE-2026-64451)

CWE-ID: CWE-476 - NULL Pointer Dereference

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to a NULL pointer dereference in func_set_flag() in the tracing subsystem when writing to a function tracer option file after the active tracer has been switched to a different tracer. A local user can write to the option file in that state to cause a denial of service.

The issue is triggered when a process keeps a function tracer option file open and the current tracer is changed before a subsequent write occurs.


107) Out-of-bounds read (CVE-ID: CVE-2026-64450)

CWE-ID: CWE-125 - Out-of-bounds read

CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to cause a denial of service.

The vulnerability exists due to an out-of-bounds read in the TIPC broadcast Gap ACK blocks handling in tipc_bcast_sync_rcv() when processing a crafted broadcast PROTOCOL/STATE_MSG. A remote attacker can send a specially crafted broadcast STATE_MSG with a malformed Gap ACK blocks record to cause a denial of service.

Exploitation requires a TIPC neighbour that has negotiated TIPC_GAP_ACK_BLOCK.


108) Heap-based buffer overflow (CVE-ID: CVE-2026-64449)

CWE-ID: CWE-122 - Heap-based Buffer Overflow

CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service or execute arbitrary code.

The vulnerability exists due to a heap-based buffer overflow in the SLAVE-path helpers buffer_to_user() and buffer_from_user() in drivers/staging/vme_user/vme_user.c when processing read and write operations with an offset and count that exceed the fixed kern_buf size. A local user can issue crafted read or write operations to cause a denial of service or execute arbitrary code.

The issue occurs when the configured slave window exceeds the 128 KiB kern_buf allocation.


109) Out-of-bounds read (CVE-ID: CVE-2026-64448)

CWE-ID: CWE-125 - Out-of-bounds read

CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to disclose sensitive information.

The vulnerability exists due to an out-of-bounds read in smb2_check_message() and subsequent SMB client protocol decoders when processing crafted SMB2 responses with a data area. A remote attacker can send a specially crafted SMB server response to disclose sensitive information.

The issue is reachable during NEGOTIATE and SESSION_SETUP before the session is established, including through the SPNEGO/negTokenInit and NTLMSSP challenge decoders when mounting against a non-conforming server.


110) Double free (CVE-ID: CVE-2026-64447)

CWE-ID: CWE-415 - Double Free

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to a double free and use-after-free in ipu7_isys_init() and ipu7_psys_init() when handling device initialization error paths. A local user can trigger device initialization failures to cause a denial of service.

The issue occurs in the error paths after device teardown frees pdata, and also affects return-value handling through dereference of an already-freed adev pointer.


111) Heap-based buffer overflow (CVE-ID: CVE-2026-64446)

CWE-ID: CWE-122 - Heap-based Buffer Overflow

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause memory corruption.

The vulnerability exists due to a heap-based buffer overflow in rtw_cfg80211_set_wpa_ie() when handling a crafted WPA or WPA2 information element in a connect request via nl80211. A local user can send a specially crafted connect request to cause memory corruption.

The issue can overflow the 256-byte supplicant_ie buffer by one byte into the adjacent last_mic_err_time field.


112) Improper input validation (CVE-ID: CVE-2026-64445)

CWE-ID: CWE-20 - Improper input validation

CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to cause a denial of service.

The vulnerability exists due to improper input validation in OnAuth() when processing seq=3 shared-key authentication responses. A remote attacker can send a specially crafted authentication frame to cause a denial of service.

The issue is triggered when the Challenge Text information element length differs from the required 128 bytes.


113) Out-of-bounds read (CVE-ID: CVE-2026-64445)

CWE-ID: CWE-125 - Out-of-bounds read

CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to disclose sensitive information.

The vulnerability exists due to an out-of-bounds read in OnAuth() when processing crafted shared-key authentication frames. A remote attacker can send a specially crafted authentication frame to disclose sensitive information.

The issue occurs in the shared-key authentication path when the Privacy bit is set and the frame is too short to contain a valid WEP IV and ICV.


114) Out-of-bounds read (CVE-ID: CVE-2026-64444)

CWE-ID: CWE-125 - Out-of-bounds read

CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to disclose sensitive information.

The vulnerability exists due to an out-of-bounds read in OnAssocRsp() in the rtl8723bs driver when parsing a crafted association response frame. A remote attacker can send a specially crafted association response frame to disclose sensitive information.

The issue can be triggered by a malicious access point through a truncated information element in the frame.


115) Out-of-bounds read (CVE-ID: CVE-2026-64443)

CWE-ID: CWE-125 - Out-of-bounds read

CVSSv4: 5.3 [CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to disclose sensitive information.

The vulnerability exists due to an out-of-bounds read in the update_beacon_info() IE parsing loop in rtl8723bs when parsing a crafted Beacon frame from a malicious access point. A remote attacker can send a specially crafted Beacon frame to disclose sensitive information.

The issue can be triggered when the last information element is truncated or when an information element declares a length that extends past the available frame data.


116) Out-of-bounds read (CVE-ID: CVE-2026-64442)

CWE-ID: CWE-125 - Out-of-bounds read

CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to cause a denial of service.

The vulnerability exists due to out-of-bounds read in IE parsing loops in issue_assocreq() and join_cmd_hdl() when processing AP beacon and probe-response frames with a truncated final information element. A remote attacker can send a malicious AP beacon or probe-response frame with a truncated final information element to cause a denial of service.

The issue is triggered when the stored IE data ends with an element_id byte without a following length byte.


117) Out-of-bounds read (CVE-ID: CVE-2026-64441)

CWE-ID: CWE-125 - Out-of-bounds read

CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local user to disclose sensitive information.

The vulnerability exists due to out-of-bounds read in IE and WPS attribute parsing functions in drivers/staging/rtl8723bs/core/rtw_ieee80211.c when parsing crafted information element buffers. A local user can provide a specially crafted buffer to disclose sensitive information.

The issue affects rtw_get_sec_ie(), rtw_get_wapi_ie(), and rtw_get_wps_attr().


118) Out-of-bounds write (CVE-ID: CVE-2026-64440)

CWE-ID: CWE-787 - Out-of-bounds write

CVSSv4: 7.2 [CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to cause memory corruption.

The vulnerability exists due to an out-of-bounds write in HT_caps_handler() when parsing a crafted 802.11 association response frame. A remote attacker can send a malicious access point response with an oversized HT Capabilities information element to cause memory corruption.

The issue can write beyond the fixed 26-byte HT_cap array into adjacent fields of struct mlme_ext_info.


119) Use-after-free (CVE-ID: CVE-2026-64439)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to a use-after-free in krb5 AEAD encryption and decryption helpers when processing operations with an async AEAD implementation. A local user can trigger crypto operations using an async AEAD provider to cause a denial of service.

The issue is reachable via net/rxrpc/rxgk.c, fs/afs/cm_security.c, and net/ceph/crypto.c only on systems with an async AEAD provider bound to the krb5 enctype name.


120) Use-after-free (CVE-ID: CVE-2026-64438)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to use-after-free in the VF2PF response workqueue handling in the intel_qat SR-IOV implementation when processing VF2PF messages during SR-IOV teardown. A local user can trigger concurrent VF2PF work so that a queued or in-flight worker dereferences freed per-VF state to cause a denial of service.

The issue occurs because PF-side response work stores a raw pointer to per-VF state that may be freed by adf_disable_sriov() before queued work completes.


121) Use of Uninitialized Variable (CVE-ID: CVE-2026-64436)

CWE-ID: CWE-457 - Use of Uninitialized Variable

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to use of uninitialized memory in pfkey_msg2xfrm_state() when processing a PF_KEY IPComp state and migrating it. A local user can add a crafted IPComp security association via PF_KEY and trigger migration to cause a denial of service.

The issue affects the PF_KEY path for IPComp states; the XFRM netlink path is not affected.


122) Race condition (CVE-ID: CVE-2026-64435)

CWE-ID: CWE-362 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to a data race in audit_queue handling in kernel/audit.c when reading queue length concurrently with queue updates. A local user can trigger audit activity to cause a denial of service.

The issue affects multiple lockless readers of the audit queue length in the audit subsystem.


123) Use-after-free (CVE-ID: CVE-2026-64434)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to a use-after-free in the Bluetooth L2CAP channel timeout handler when processing an asynchronous channel timeout after the associated connection has been torn down. A local user can trigger a channel timeout race to cause a denial of service.

The issue arises because the timeout worker may access chan->conn after the underlying connection object has already been freed.


124) Use-after-free (CVE-ID: CVE-2026-64433)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to a use-after-free in add_device_complete in net/bluetooth/mgmt.c when handling concurrent bluetooth management device add and remove operations. A local user can trigger concurrent MGMT requests to access freed memory and cause a denial of service.

The issue occurs because hci_conn_params_lookup() is used without holding the required device lock while the returned object is later dereferenced.


125) Out-of-bounds write (CVE-ID: CVE-2026-64432)

CWE-ID: CWE-787 - Out-of-bounds write

CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service or execute arbitrary code.

The vulnerability exists due to an out-of-bounds write in log_replay in fs/ntfs3/fslog.c when mounting a crafted NTFS image and replaying the $LogFile journal. A local user can provide a specially crafted NTFS image to cause a denial of service or execute arbitrary code.

The issue can be triggered at mount time during the analysis pass when LCNs from an action log record are copied into an existing Dirty Page Table entry, and integer underflow in the target VCN delta can drive the destination index past the allocated page_lcns array.


126) Race condition (CVE-ID: CVE-2026-64430)

CWE-ID: CWE-362 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to improper resource access in the ntb_epf_vec_isr interrupt handler in drivers/ntb/hw/epf/ntb_hw_epf.c when handling interrupts and deriving the vector number through pci_irq_vector() in hardirq context. A local user can trigger the vulnerable interrupt handling path to cause a denial of service.

The issue can result in "scheduling while atomic" kernel splats because pci_irq_vector() reaches code that takes a mutex in hardirq context.


127) Improper locking (CVE-ID: CVE-2026-64429)

CWE-ID: CWE-667 - Improper Locking

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to improper lock handling in the Spreadtrum EIC GPIO interrupt controller driver when starting up a requested IRQ on PREEMPT_RT systems. A local user can request a threaded IRQ to trigger a sleeping lock in an invalid context to cause a denial of service.

The issue occurs because the callback can be reached from a non-sleepable irq_startup() path.


128) Improper locking (CVE-ID: CVE-2026-64428)

CWE-ID: CWE-667 - Improper Locking

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to improper lock type selection in the sch irq startup path when starting up a requested irq on PREEMPT_RT systems. A local user can request a threaded irq that reaches sch_irq_unmask() and sch_irq_mask_unmask() to cause a denial of service.

The issue occurs because the path is not sleepable, but a regular spinlock_t becomes a sleeping lock on PREEMPT_RT.


129) Improper resource shutdown or release (CVE-ID: CVE-2026-64426)

CWE-ID: CWE-404 - Improper Resource Shutdown or Release

CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to improper resource shutdown or release in io_uring NOP handling when processing a NOP request with IOSQE_FIXED_FILE set without IORING_NOP_FIXED_FILE. A local user can submit a crafted io_uring NOP request to cause a denial of service.

The issue results in a file reference leak because a normally acquired file reference is not released on completion.


130) Time-of-check Time-of-use (TOCTOU) Race Condition (CVE-ID: CVE-2026-64425)

CWE-ID: CWE-367 - Time-of-check Time-of-use (TOCTOU) Race Condition

CVSSv4: 5.7 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to improper state management in io_worker_handle_work() in io_uring/io-wq.c when processing linked work items during io_uring worker exit handling. A local user can submit linked work and trigger ring closure to cause a denial of service.

Exploitation requires a race condition where worker exit begins after the first linked item has started but before the remaining linked items are processed.


131) Use-after-free (CVE-ID: CVE-2026-64424)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to use-after-free in netpoll tx_work handling when shutting down netpoll while a pending TX worker runs in parallel with the cleanup path. A local user can trigger netpoll cleanup during concurrent worker execution to cause a denial of service.

The issue occurs because the queued worker can continue running after the associated netpoll data has been freed.


132) Use-after-free (CVE-ID: CVE-2026-64423)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to a use-after-free in the IGMP multicast group handling in net/ipv4/igmp.c when destroying a device while concurrent RCU readers traverse the multicast hash table. A local user can trigger multicast group membership operations and concurrent network processing to cause a denial of service.

The issue occurs because multicast group entries can remain reachable through the device multicast hash table during RCU reclamation.


133) Out-of-bounds read (CVE-ID: CVE-2026-64422)

CWE-ID: CWE-125 - Out-of-bounds read

CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local user to disclose sensitive information.

The vulnerability exists due to an out-of-bounds read in tcp_mtu_probe() when processing an invalid net.ipv4.tcp_reordering value during MTU probing. A local user can write a negative tcp_reordering value to trigger the out-of-bounds read and disclose sensitive information.

Exploitation requires tcp_mtu_probing to be set to 2.


134) Use-after-free (CVE-ID: CVE-2026-64421)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to use-after-free in mxc_isi_remove() and the imx8-isi media cleanup path when removing the imx8_isi module. A local user can trigger module removal to cause a denial of service.

The issue occurs because media links are removed after the media entity pads they reference have already been freed.


135) Use-after-free (CVE-ID: CVE-2026-64420)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to a use-after-free in the cros_ec device probe handling in drivers/mfd/cros_ec_dev.c when sub-drivers access platform device drvdata after probe failure. A local user can trigger a failed probe and subsequent access to a stale pointer to cause a denial of service.

The issue occurs because the stale drvdata pointer remains accessible to sub-drivers such as cros_ec_typec after the underlying cros_ec_dev structure has already been released.


136) Improper locking (CVE-ID: CVE-2026-64419)

CWE-ID: CWE-667 - Improper Locking

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to improper lock handling in shrinker_debugfs_count_show() when reading the debugfs "count" file of a memcg-aware shrinker. A local user can read the debugfs file to cause a denial of service.

The issue occurs because a callback may sleep while executing inside an RCU read-side critical section.


137) Race condition (CVE-ID: CVE-2026-64418)

CWE-ID: CWE-362 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to a race condition leading to use-after-free or double-free in shrinker_info teardown in mm/shrinker.c when handling memcg shrinker_info expansion and teardown during memory cgroup online and shrinker allocation operations. A local user can trigger concurrent memory cgroup and shrinker operations to cause a denial of service.

The issue occurs when a partially initialized or already published shrinker_info array remains visible to iteration during teardown.


138) NULL pointer dereference (CVE-ID: CVE-2026-64417)

CWE-ID: CWE-476 - NULL Pointer Dereference

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to a NULL pointer dereference in shrinker_debugfs_add() debugfs file handling when writing to a debugfs count or scan file for a shrinker with a missing callback. A local user can write to a crafted debugfs file associated with such a shrinker to cause a denial of service.

The issue can be triggered when a shrinker implements only one of the count_objects() or scan_objects() callbacks, such as the xen-backend shrinker example described in the advisory.


139) NULL pointer dereference (CVE-ID: CVE-2026-64416)

CWE-ID: CWE-476 - NULL Pointer Dereference

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local attacker to cause a denial of service.

The vulnerability exists due to a NULL pointer dereference in lookup_swap_cgroup_id() when processing a corrupted swap entry during page table teardown. A local attacker can corrupt a page table entry into a crafted swap entry to cause a denial of service.

The issue is triggered on swapless hosts, and a single corrupted page table entry can crash the host during process exit.


140) Resource exhaustion (CVE-ID: CVE-2026-64415)

CWE-ID: CWE-400 - Resource exhaustion

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local attacker to cause a denial of service.

The vulnerability exists due to improper resource management in swap_reclaim_full_clusters() in mm/swapfile.c when reclaiming large numbers of full swap clusters under heavy memory and swap load. A local attacker can trigger sustained memory and swap stress to cause a denial of service.


141) Improper handling of exceptional conditions (CVE-ID: CVE-2026-64414)

CWE-ID: CWE-755 - Improper Handling of Exceptional Conditions

CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to cause a denial of service.

The vulnerability exists due to improper handling of unreadable fragments in netfilter packet processing when processing packets with unreadable fragments. A remote attacker can send a specially crafted packet to cause a denial of service.

The issue affects the xt_u32 matcher, nfnetlink_queue, nfnetlink_log, and IPv6 fragment header handling in connection tracking reassembly.


142) Improper Initialization (CVE-ID: CVE-2026-64413)

CWE-ID: CWE-665 - Improper Initialization

CVSSv4: 5.7 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to improper initialization in the ebtables table translation logic in net/bridge/netfilter/ebtables.c when allocating and freeing the chainstack array. A local user can trigger an allocation failure during table translation to cause a denial of service.

The issue arises when a sparse cpu_possible_mask causes an uninitialized chainstack entry to be freed during cleanup.


143) Improper input validation (CVE-ID: CVE-2026-64412)

CWE-ID: CWE-20 - Improper input validation

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to improper input validation in the ebtables match handling code in net/bridge/netfilter/ebtables.c when processing a crafted module name. A local user can supply a non-null-terminated module name to cause a denial of service.


144) Out-of-bounds read (CVE-ID: CVE-2026-64411)

CWE-ID: CWE-125 - Out-of-bounds read

CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local user to disclose sensitive information.

The vulnerability exists due to an out-of-bounds read in find_table_lock() table name handling when processing a user-supplied ebtables table name through setsockopt calls. A local user can supply a non-null-terminated table name to trigger a read past the end of the name buffer and disclose sensitive information.

The issue occurs on a lookup miss when module autoload formatting uses the supplied table name.


145) Improper Check for Unusual or Exceptional Conditions (CVE-ID: CVE-2026-64410)

CWE-ID: CWE-754 - Improper Check for Unusual or Exceptional Conditions

CVSSv4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to cause a denial of service.

The vulnerability exists due to improper handling of unsupported hardware offload configurations in netfilter flowtable hardware offload when processing IPIP tunnel flows. A remote attacker can send specially crafted network traffic to cause a denial of service.

The issue occurs in the IPIP tunnel hardware offload path, where unsupported flows may still be enqueued for offload processing.


146) Infinite loop (CVE-ID: CVE-2026-64409)

CWE-ID: CWE-835 - Loop with Unreachable Exit Condition ('Infinite Loop')

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to improper loop termination in btmtksdio_txrx_work() when processing Bluetooth SDIO transmit and receive work. A local user can trigger repeated pending interrupt handling to cause a denial of service.

The issue can cause the workqueue to loop indefinitely and prevent release of the SDIO host.


147) Use-after-free (CVE-ID: CVE-2026-64408)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to a use-after-free in bnep_add_connection() during network device registration when handling a concurrent controller teardown. A local user can trigger a race condition to cause a denial of service.


148) Out-of-bounds read (CVE-ID: CVE-2026-64407)

CWE-ID: CWE-125 - Out-of-bounds read

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local user to disclose sensitive information.

The vulnerability exists due to an out-of-bounds read in nxp_recv_fw_req_v3() in the btnxpuart Bluetooth driver when processing v3 firmware download requests from the controller. A local user can supply a controller that requests an offset or length beyond the firmware image to disclose sensitive information.

The issue occurs during firmware download over UART.


149) Use-after-free (CVE-ID: CVE-2026-64406)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to use-after-free in bt_accept_dequeue() when handling Bluetooth L2CAP socket cleanup and accept queue processing. A local user can trigger socket state transitions that cause freed memory to be accessed to cause a denial of service.

The issue was observed during listening L2CAP socket cleanup.


150) NULL pointer dereference (CVE-ID: CVE-2026-64405)

CWE-ID: CWE-476 - NULL Pointer Dereference

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to a NULL pointer dereference in hci_abort_conn() when handling connection cancellation from the hci_rx_work() receive path. A local user can trigger a pending Bluetooth connection state to cause a denial of service.

The issue can lead to a general protection fault while a connection request is pending and hdev->sent_cmd is NULL.


151) NULL pointer dereference (CVE-ID: CVE-2026-64404)

CWE-ID: CWE-476 - NULL Pointer Dereference

CVSSv4: 5.7 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to a NULL pointer dereference in iso_conn_big_sync() when handling recvmsg on a PA-sync broadcast sink socket during connection teardown. A local user can trigger a race condition to cause a denial of service.

The issue is reachable from iso_sock_recvmsg() for a PA-sync broadcast sink socket with BT_SK_DEFER_SETUP and BT_SK_PA_SYNC set.


152) Out-of-bounds read (CVE-ID: CVE-2026-64403)

CWE-ID: CWE-125 - Out-of-bounds read

CVSSv4: 5.3 [CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to cause a denial of service.

The vulnerability exists due to out-of-bounds read in l2cap_get_conf_opt() when parsing L2CAP configuration options. A remote attacker can send a specially crafted Bluetooth L2CAP packet to cause a denial of service.

The read occurs before the malformed option is rejected, and up to 4 bytes may be read past the end of the buffer.


153) Out-of-bounds write (CVE-ID: CVE-2026-64402)

CWE-ID: CWE-787 - Out-of-bounds write

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to an out-of-bounds write in smb_sync_perf_buffer() when copying hardware trace data into perf AUX ring buffer pages. A local user can trigger the vulnerable code path to cause a denial of service.

The issue occurs when the SMB sink is used as a perf AUX sink.


154) Use-after-free (CVE-ID: CVE-2026-64401)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 5.7 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to a use-after-free in the SMB client witness notification handling in fs/smb/client/cifs_swn.c when processing witness notifications for shared registrations. A local user can trigger notification handling involving a freed tcon pointer to cause a denial of service.

Exploitation requires a same-share second mount so that a registration remains live after the first tcon is unregistered and freed.


155) Path traversal (CVE-ID: CVE-2026-64400)

CWE-ID: CWE-22 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

CVSSv4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote user to create files or directories outside the exported share.

The vulnerability exists due to improper limitation of a pathname to a restricted directory in __ksmbd_vfs_kern_path() when processing crafted paths with parent-directory components during caseless lookup retry. A remote user can send a specially crafted path to create files or directories outside the exported share.

The issue occurs because an -EXDEV error from path traversal detection is not handled before the caseless retry logic runs, and exploitation is limited to zero-length files or directories.


156) Improper access control (CVE-ID: CVE-2026-64399)

CWE-ID: CWE-284 - Improper Access Control

CVSSv4: 7.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote user to overwrite file data.

The vulnerability exists due to improper access control in the FSCTL_DUPLICATE_EXTENTS_TO_FILE arm of smb2_ioctl() when processing SMB ioctl requests that clone file ranges. A remote user can use the operation on a read-only share or with a destination handle lacking FILE_WRITE_DATA permission to overwrite file data.

The issue affects destination files through vfs_clone_file_range() and can be triggered with a handle opened with only FILE_WRITE_ATTRIBUTES.


157) Improper access control (CVE-ID: CVE-2026-64398)

CWE-ID: CWE-284 - Improper Access Control

CVSSv4: 7.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote user to modify file data without the required file write permission.

The vulnerability exists due to improper access control in smb2_ioctl() when processing FSCTL_SET_ZERO_DATA requests. A remote user can use a handle opened with only FILE_WRITE_ATTRIBUTES to zero file data and modify file contents without the required FILE_WRITE_DATA right.

The issue affects ksmbd, and the advisory states it was reproduced by an authenticated SMB client using a handle that was granted FILE_WRITE_ATTRIBUTES but not FILE_WRITE_DATA.


158) Use-after-free (CVE-ID: CVE-2026-64397)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 7.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote user to cause a denial of service.

The vulnerability exists due to a use-after-free in smb2_query_dir() and the ksmbd directory enumeration state when handling concurrent QUERY_DIRECTORY requests using the same file handle. A remote user can send concurrent QUERY_DIRECTORY requests on the same file handle to cause a denial of service.

The issue occurs because a pointer to stack-allocated private data is stored in shared readdir state and can be overwritten while an iterate_dir() callback is still using it.


159) Use-after-free (CVE-ID: CVE-2026-64396)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 6 [CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote user to cause a denial of service.

The vulnerability exists due to use-after-free in the SMB2 lock handling logic in fs/smb/server/smb2pdu.c when canceling a deferred SMB2_LOCK request. A remote user can send crafted SMB lock and cancellation requests to cause a denial of service.

The issue is triggered by a race between deferred-lock cleanup and asynchronous cancellation while processing blocking byte-range locks.


160) Improper access control (CVE-ID: CVE-2026-64395)

CWE-ID: CWE-284 - Improper Access Control

CVSSv4: 7.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote user to disclose sensitive information.

The vulnerability exists due to improper access control in FSCTL_DUPLICATE_EXTENTS_TO_FILE handling in ksmbd when processing duplicate extents requests. A remote user can use a source handle opened without read access to copy file contents into an attacker-readable destination to disclose sensitive information.

The issue affects the source file access check before invoking file range clone or copy operations.


161) Improper access control (CVE-ID: CVE-2026-64394)

CWE-ID: CWE-284 - Improper Access Control

CVSSv4: 7.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote user to modify file access control metadata to grant additional access.

The vulnerability exists due to improper access control in smb2_set_info_sec() when handling SMB2_SET_INFO requests with InfoType SMB2_O_INFO_SECURITY. A remote user can send a specially crafted SMB2_SET_INFO request over a handle opened with FILE_WRITE_ATTRIBUTES only to modify file access control metadata to grant additional access.

The issue affects the SECURITY arm of SMB2 SET_INFO, where no per-handle check for FILE_WRITE_DAC or FILE_WRITE_OWNER is performed before rewriting the file's owner or DACL.


162) Improper access control (CVE-ID: CVE-2026-64393)

CWE-ID: CWE-284 - Improper Access Control

CVSSv4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote user to bypass intended permission checks.

The vulnerability exists due to improper access control in SMB2 SET_INFO handlers when processing SET_INFO requests. A remote user can send a specially crafted SET_INFO request to bypass intended permission checks.

The issue arises because path-based VFS helpers perform permission and LSM checks using worker credentials instead of the credentials captured when the file handle was opened.


163) Improper access control (CVE-ID: CVE-2026-64392)

CWE-ID: CWE-284 - Improper Access Control

CVSSv4: 7.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote user to bypass filesystem permission checks and delete files or remove ADS xattrs.

The vulnerability exists due to improper access control in ksmbd delete-on-close handling when tearing down deferred or durable handles without request work. A remote user can open a file and trigger delete-on-close processing to bypass filesystem permission checks and delete files or remove ADS xattrs.

The issue occurs because final close operations run with ksmbd worker credentials instead of the credentials captured when the file was opened.


164) Improper access control (CVE-ID: CVE-2026-64391)

CWE-ID: CWE-284 - Improper Access Control

CVSSv4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote user to bypass permission checks for alternate data stream I/O.

The vulnerability exists due to improper access control in ksmbd alternate data stream handling when processing read and write operations on alternate data streams. A remote user can access a file over SMB and perform alternate data stream read or write operations to bypass permission checks for alternate data stream I/O.

Alternate data streams are stored as extended attributes, and the vulnerable paths recheck inode permissions and LSM policy using the current task credentials instead of the credentials captured when the SMB handle was opened.


165) Use-after-free (CVE-ID: CVE-2026-64390)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to cause a denial of service.

The vulnerability exists due to a use-after-free in ksmbd byte-range lock handling when processing smb2 lock requests in smb3 multichannel environments. A remote attacker can trigger concurrent lock traversal and removal to cause a denial of service.

The issue occurs because a lock list entry can be removed under a different spinlock than the one protecting the list it belongs to.


166) Incorrect Implementation of Authentication Algorithm (CVE-ID: CVE-2026-64389)

CWE-ID: CWE-303 - Incorrect Implementation of Authentication Algorithm

CVSSv4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote user to modify session key material.

The vulnerability exists due to improper authentication logic in ksmbd NTLMv2 authentication handling when processing SMB3 multichannel binding session setup requests with KEY_XCH. A remote user can send a binding session setup with a bad NT proof and KEY_XCH to modify session key material.

The issue occurs on an existing session because the failed authentication path does not expire binding sessions.


167) Improper access control (CVE-ID: CVE-2026-64388)

CWE-ID: CWE-284 - Improper Access Control

CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local user to bypass ownership and group changes.

The vulnerability exists due to improper access control in cifs_setattr_nounix() when processing chown and chgrp operations on mounts using SMB3 POSIX Extensions. A local user can change file ownership or group attributes in a way that is ignored to bypass ownership and group changes.

The issue occurs only when SMB3 POSIX Extensions are used without the relevant ACL or SID-based mount options enabled.


168) Double free (CVE-ID: CVE-2026-64387)

CWE-ID: CWE-415 - Double Free

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to a double free in SMB2_query_directory in the SMB client when handling replayed query directory responses and reinitialization failures. A local user can trigger a replayable error and subsequent cleanup conditions to cause a denial of service.


169) Double free (CVE-ID: CVE-2026-64386)

CWE-ID: CWE-415 - Double Free

CVSSv4: 7.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote user to cause a denial of service.

The vulnerability exists due to a double free in query_info() in the smb client when handling replayable query_info requests. A remote user can trigger a replayable error sequence to cause a denial of service.


170) Double free (CVE-ID: CVE-2026-64385)

CWE-ID: CWE-415 - Double Free

CVSSv4: 7.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote user to cause a denial of service.

The vulnerability exists due to double free in SMB2_ioctl() when handling replayable ioctl responses. A remote user can trigger a replayable error condition to cause a denial of service.


171) Double free (CVE-ID: CVE-2026-64384)

CWE-ID: CWE-415 - Double Free

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to double free in SMB change notify handling in fs/smb/client/smb2pdu.c when processing replayable error conditions during change notify requests. A local user can trigger a replayable error and subsequent cleanup to free the same response buffer twice to cause a denial of service.


172) Double free (CVE-ID: CVE-2026-64383)

CWE-ID: CWE-415 - Double Free

CVSSv4: 7.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote user to cause a denial of service.

The vulnerability exists due to double free in SMB2_flush() when handling replay attempts for flush responses. A remote user can trigger a replayable flush response followed by a failed retry to cause a denial of service.


173) Double free (CVE-ID: CVE-2026-64382)

CWE-ID: CWE-415 - Double Free

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to double free in SMB2_open() when handling replayable error conditions during SMB2 open request processing. A local user can trigger a replayable error that leads to stale response buffer bookkeeping to cause a denial of service.

The issue affects the Linux kernel SMB client implementation.


174) Memory leak (CVE-ID: CVE-2026-64381)

CWE-ID: CWE-401 - Missing release of memory after effective lifetime

CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to cause a denial of service.

The vulnerability exists due to a memory leak in receive_encrypted_standard() when processing compound SMB PDUs. A remote attacker can send compound SMB messages that exceed MAX_COMPOUND to cause a denial of service.

The issue affects the Linux kernel SMB client.


175) Out-of-bounds read (CVE-ID: CVE-2026-64380)

CWE-ID: CWE-125 - Out-of-bounds read

CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to cause a denial of service.

The vulnerability exists due to an out-of-bounds read in posix_info_sid_size() in the SMB client when parsing truncated POSIX SIDs. A remote attacker can send a specially crafted SMB response to cause a denial of service.


176) Improper input validation (CVE-ID: CVE-2026-64379)

CWE-ID: CWE-20 - Improper input validation

CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to modify file mode bits.

The vulnerability exists due to improper input validation in parse_dacl() when processing a server-provided NFS mode SID. A remote attacker can provide crafted mode values to modify file mode bits.

The issue occurs when modefromsid is active.


177) Race condition (CVE-ID: CVE-2026-64378)

CWE-ID: CWE-362 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to a race condition in cgroup_writeback_umount() and inode_switch_wbs()/cleanup_offline_cgwb() when unmounting a filesystem while switching inode writeback state. A local user can trigger a container exit or unmount operation during concurrent writeback activity to cause a denial of service.

The issue can lead to busy inodes after unmount and a subsequent use-after-free in writeback cleanup paths.


178) Double free (CVE-ID: CVE-2026-64377)

CWE-ID: CWE-415 - Double Free

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to double free in qcom_cpufreq_hw_cpu_exit() when releasing CPU policy data. A local user can trigger CPU policy teardown to cause a denial of service.

The issue occurs because driver_data may reference devm-managed memory, including an interior element of a per-domain array rather than the original allocation base.


179) Improper update of reference count (CVE-ID: CVE-2026-64376)

CWE-ID: CWE-911 - Improper Update of Reference Count

CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to improper reference count management in firmware_upload_register() in drivers/base/firmware_loader/sysfs_upload.c when handling an error after alloc_lookup_fw_priv() fails. A local user can trigger the vulnerable error path to cause a denial of service.


180) Race condition (CVE-ID: CVE-2026-64375)

CWE-ID: CWE-362 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')

CVSSv4: 2 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local user to disclose sensitive information.

The vulnerability exists due to a race condition in proc_pid_get_link() and proc_pid_readlink() when handling access to /proc pid link targets. A local user can trigger concurrent task state changes to disclose sensitive information.

The issue affects file descriptor-related proc links and involves ptrace_may_access() checks performed on a different task lookup than the one used for the actual access.


181) Deadlock (CVE-ID: CVE-2026-64374)

CWE-ID: CWE-833 - Deadlock

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to a live lock condition in the linux kernel scheduler RT_PUSH_IPI logic when handling RT task migration and repeated inter-processor interrupts on non-PREEMPT_RT systems. A local user can trigger heavy networking activity and wake RT tasks to cause a denial of service.

The issue occurs on non-PREEMPT_RT systems when softirqs execute for long periods and prevent the target CPU from returning to task context.


182) Race condition (CVE-ID: CVE-2026-64373)

CWE-ID: CWE-362 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to a race condition in cpufreq_suspend() when rebooting the system while cpu hotplug operations run concurrently. A local user can trigger a reboot while concurrent cpu hotplug activity causes governor_data to be freed during access to cause a denial of service.

The issue can result in a kernel null pointer dereference during the reboot path because processes and kernel threads remain active.


183) Use-after-free (CVE-ID: CVE-2026-64372)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local attacker to cause a denial of service.

The vulnerability exists due to use-after-free in pcc_cpufreq_do_osc() when performing two-phase _OSC negotiation through acpi_evaluate_object(). A local attacker can trigger the vulnerable code path to cause a denial of service.

The issue also involves a double free after the stale pointer is freed again.


184) Race condition (CVE-ID: CVE-2026-64371)

CWE-ID: CWE-362 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')

CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local user to disclose sensitive information.

The vulnerability exists due to improper access control in procfs handlers for task statistics, wchan, map_files, and namespace links when accessing process information during concurrent exec state updates without exec_update_lock protection. A local user can access affected /proc interfaces to disclose sensitive information.

The issue involves calls to ptrace_may_access() without the required exec_update_lock protection.


185) Missing Release of Resource after Effective Lifetime (CVE-ID: CVE-2026-64370)

CWE-ID: CWE-772 - Missing Release of Resource after Effective Lifetime

CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to a reference count leak in do_cpu_nanosleep() when handling an error after creating a POSIX CPU timer. A local user can trigger a failure in posix_cpu_timer_set() to cause a denial of service.


186) Improper handling of exceptional conditions (CVE-ID: CVE-2026-64369)

CWE-ID: CWE-755 - Improper Handling of Exceptional Conditions

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to improper exception handling in load_unaligned_zeropad() and the s390 secure storage access exception handler when reading unaligned data across page boundaries involving donated secure-execution pages. A local user can trigger the vulnerable kernel access pattern to cause a denial of service.

The issue can result in an endless exception loop when the second page access raises an exception for pages donated to the Ultravisor for secure execution purposes.


187) Improper Initialization (CVE-ID: CVE-2026-64368)

CWE-ID: CWE-665 - Improper Initialization

CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local user to disclose sensitive information.

The vulnerability exists due to improper initialization in slab allocation handling in mm/slub.c when allocating kmalloc objects with zeroing enabled. A local user can trigger a memory allocation pattern that leaves part of the allocated object uninitialized to disclose sensitive information.

The issue occurs when requested-size tracking is not enabled while red zoning alone is enabled, which can break krealloc() __GFP_ZERO expectations.


188) Stack-based buffer overflow (CVE-ID: CVE-2026-64367)

CWE-ID: CWE-121 - Stack-based buffer overflow

CVSSv4: 6.9 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service or execute arbitrary code.

The vulnerability exists due to a stack-based buffer overflow in goodix_hid_set_raw_report() when processing a hidraw SET_REPORT ioctl with an oversized report. A local user can send a specially crafted report to cause a denial of service or execute arbitrary code.


189) Out-of-bounds write (CVE-ID: CVE-2026-64366)

CWE-ID: CWE-787 - Out-of-bounds write

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service or execute arbitrary code.

The vulnerability exists due to an out-of-bounds write in wacom_wac_queue_insert in the Wacom HID driver when processing crafted input reports. A local user can send a specially crafted report to cause a denial of service or execute arbitrary code.

The issue is triggered when stale data in an empty kfifo is interpreted as a record length, corrupting the internal fifo state before a memcpy writes past a 256-byte buffer.


190) Use-after-free (CVE-ID: CVE-2026-64365)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 5.1 [CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows an attacker with physical access to cause a use-after-free condition.

The vulnerability exists due to use-after-free in the letsketch HID driver inrange_timer handling when unbinding the device or during the probe error path after raw events arm the timer. An attacker with physical access can trigger device removal or induce the vulnerable cleanup sequence to cause a use-after-free condition.

The issue can be triggered by USB unplug or module removal, and also on the probe error path if I/O has already been enabled and the timer was armed before cleanup.


191) Out-of-bounds write (CVE-ID: CVE-2026-64364)

CWE-ID: CWE-787 - Out-of-bounds write

CVSSv4: 5.1 [CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows an attacker with physical access to cause a denial of service.

The vulnerability exists due to out-of-bounds write in the HID multitouch driver when processing input from a crafted USB or Bluetooth HID multitouch device that advertises a large contact count. An attacker with physical access can provide a crafted device to corrupt adjacent members of struct mt_device and cause a denial of service.

The issue is reachable from an untrusted USB or Bluetooth HID multitouch device, and the kernel panic can be triggered from timer context through the sticky-fingers release path.


192) Use-after-free (CVE-ID: CVE-2026-64363)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 7.3 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local attacker to execute arbitrary code or cause a denial of service.

The vulnerability exists due to use-after-free in the appleir HID driver when processing concurrent device teardown and timer or raw event handling. A local attacker can trigger device disconnection shortly after key events to execute arbitrary code or cause a denial of service.

Exploitation requires a pending key-up timer or concurrent raw event activity to race with device removal.


193) Use-after-free (CVE-ID: CVE-2026-64362)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 5.1 [CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows an attacker with physical access to cause a denial of service.

The vulnerability exists due to use-after-free in the hid-lg-g15 driver work handling logic when a pending work item is triggered and the device is unplugged. An attacker with physical access can trigger a backlight cycle key event and disconnect the keyboard to cause a denial of service.

The issue is reachable as a race condition on device unplug for G15, G15 v2, and G510 models that initialize the work item.


194) Integer overflow (CVE-ID: CVE-2026-64361)

CWE-ID: CWE-190 - Integer overflow

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to an integer overflow in check_and_correct_requested_length() in the hfs and hfsplus filesystem code when processing crafted filesystem metadata. A local user can trigger an underflowed length value that bypasses a bounds check to cause a denial of service.

Exploitation can result in a read far beyond the node buffer during a subsequent memmove operation.


195) Use of Uninitialized Variable (CVE-ID: CVE-2026-64360)

CWE-ID: CWE-457 - Use of Uninitialized Variable

CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local user to disclose sensitive information.

The vulnerability exists due to use of uninitialized memory in hfs_bnode_read() in the hfs and hfsplus bnode handling code when reading bnode data with an invalid offset or a corrected zero length. A local user can trigger an early return and cause callers to use uninitialized stack data to disclose sensitive information.


196) Improper input validation (CVE-ID: CVE-2026-64359)

CWE-ID: CWE-20 - Improper input validation

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to improper input validation in nilfs_clean_segments when processing user-supplied segment numbers through the CLEAN_SEGMENTS ioctl. A local user can submit out-of-range segment numbers to cause a denial of service.

The issue can hold ns_segctor_sem long enough to block concurrent filesystem operations such as chmod().


197) NULL pointer dereference (CVE-ID: CVE-2026-64358)

CWE-ID: CWE-476 - NULL Pointer Dereference

CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to improper handling of a null workqueue callback in mtk_jpeg_release() when releasing a JPEG device context on platforms that do not use the workqueue. A local user can trigger release of the affected device context to cause a denial of service.

The issue results in a WARN_ON condition in __flush_work() because cancel_work_sync() is invoked even when no workqueue callback is defined.


198) Integer overflow (CVE-ID: CVE-2026-64357)

CWE-ID: CWE-190 - Integer overflow

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to an integer overflow in xfs_exchmaps_estimate_overhead() when calculating block reservation overhead for exchange mappings. A local user can trigger the vulnerable calculation to cause a denial of service.

The issue occurs because the limit check is applied to the pre-overhead reservation value instead of the computed reservation value that is later passed to xfs_trans_alloc().


199) Memory leak (CVE-ID: CVE-2026-64356)

CWE-ID: CWE-401 - Missing release of memory after effective lifetime

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to a memory leak in xfs_dqinode_metadir_create() when handling failures during metadirectory creation and commit processing. A local user can trigger the vulnerable error paths to cause a denial of service.

Runtime validation reproduced a stuck mount path during mount -o uquota on a metadir XFS image under fault injection.


200) Out-of-bounds read (CVE-ID: CVE-2026-64355)

CWE-ID: CWE-125 - Out-of-bounds read

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to an out-of-bounds access in dev_map_enqueue_clone() and dev_map_redirect_clone() when cloning fragmented native XDP frames or nonlinear generic XDP packets for devmap broadcast redirects. A local user can trigger clone-based broadcast handling with a crafted fragmented frame to cause a denial of service.

The issue occurs because fragment metadata is not present in the linear cloned frame, and later frame return can interpret uninitialized tail data as skb_shared_info.


201) Out-of-bounds write (CVE-ID: CVE-2026-64354)

CWE-ID: CWE-787 - Out-of-bounds write

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to an out-of-bounds write in btf_repeat_fields() when processing malformed user-supplied BTF during BPF_BTF_LOAD. A local user can submit crafted BTF data to cause a denial of service.

The issue arises from integer wraparound in the expanded field count calculation before repeated fields are copied into a fixed-size scratch array.


202) NULL pointer dereference (CVE-ID: CVE-2026-64353)

CWE-ID: CWE-476 - NULL Pointer Dereference

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to improper handling of lookup result nullness in the bpf verifier when processing constant-key lookups for dynamic inner array maps. A local user can load a crafted bpf program to cause a denial of service.

The issue occurs when an ARRAY_OF_MAPS uses an inner map template created with BPF_F_INNER_MAP and a concrete inner array has a different max_entries value than the template.


203) Improper locking (CVE-ID: CVE-2026-64352)

CWE-ID: CWE-667 - Improper Locking

CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to improper lock handling in the lpm trie implementation when sleepable BPF programs access LPM maps. A local user can trigger lockdep warnings through crafted BPF map lookup, update, or delete operations to cause a denial of service.

This issue is lockdep-only on debug kernels and can spam the console when a sleepable BPF LSM hook touches an LPM trie.


204) Out-of-bounds read (CVE-ID: CVE-2026-64351)

CWE-ID: CWE-125 - Out-of-bounds read

CVSSv4: 2.4 [CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows an attacker with physical access to disclose sensitive information.

The vulnerability exists due to an out-of-bounds read in kalmia_rx_fixup() when processing a crafted short bulk-in frame from a USB device. An attacker with physical access can provide malformed frame lengths to disclose sensitive information.

The issue occurs when framing headers are not both present before frame-length subtraction, causing an integer underflow that lets a device-supplied packet length drive buffer access past the end of the rx buffer.


205) Memory leak (CVE-ID: CVE-2026-64350)

CWE-ID: CWE-401 - Missing release of memory after effective lifetime

CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to a memory leak in cdnsp_alloc_stream_info() when handling stream ring allocation or stream mapping update failures. A local user can trigger allocation failure conditions to cause a denial of service.


206) Memory leak (CVE-ID: CVE-2026-64348)

CWE-ID: CWE-401 - Missing release of memory after effective lifetime

CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to a memory leak in the EHCI and FOTG210 isochronous submit handling when submitting a URB before it is linked to the endpoint queue. A local user can trigger a failed submit to cause a denial of service.

Exploitation requires access to a system using EHCI or FOTG210 USB isochronous transfers.


207) Out-of-bounds read (CVE-ID: CVE-2026-64347)

CWE-ID: CWE-125 - Out-of-bounds read

CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to cause a denial of service.

The vulnerability exists due to an out-of-bounds read in the USB OTG handler in composite_setup() when handling a control transfer with an empty configuration list. A remote attacker can trigger the vulnerable code path to cause a denial of service.

The issue can occur during a teardown race on gadget unbind with a control transfer in flight, or when a driver sets is_otg before adding a configuration.


208) Use-after-free (CVE-ID: CVE-2026-64346)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to use-after-free in gadget_match_driver() in the usb gadget udc core when handling concurrent gadget removal and configfs access. A local user can trigger a race condition via configfs operations to cause a denial of service.

The issue arises because the udc and gadget lifecycles are decoupled, and concurrent mode-switch work can free the udc structure while it is still being accessed.


209) Improper update of reference count (CVE-ID: CVE-2026-64345)

CWE-ID: CWE-911 - Improper Update of Reference Count

CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to improper reference count handling in the printer_open function in the f_printer USB gadget driver when opening the character device while it is already open. A local user can repeatedly attempt a second open to cause a denial of service.


210) Use-after-free (CVE-ID: CVE-2026-64344)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 7.3 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service or execute arbitrary code.

The vulnerability exists due to use-after-free in the idmouse USB driver when release() races with disconnect(). A local user can trigger a device disconnect while the device file is being released to cause a denial of service or execute arbitrary code.

Exploitation requires a race condition involving device disconnection and file release in the idmouse driver.


211) Use-after-free (CVE-ID: CVE-2026-64343)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a use-after-free.

The vulnerability exists due to use-after-free in the ldusb driver when release() races with disconnect(). A local user can trigger a device disconnect while releasing the device to cause a use-after-free.

The issue affects the drivers/usb/misc/ldusb.c code path in the Linux kernel.


212) Use-after-free (CVE-ID: CVE-2026-64342)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service or execute arbitrary code.

The vulnerability exists due to use-after-free in the iowarrior USB driver disconnect handling when processing device disconnect events with submitted write URBs still active. A local user can trigger device disconnect while write completion handling is still possible to cause a denial of service or execute arbitrary code.

Exploitation requires local access to the affected USB device interface.


213) Use-after-free (CVE-ID: CVE-2026-64341)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service or execute arbitrary code.

The vulnerability exists due to use-after-free in the iowarrior USB driver when release() races with disconnect(). A local user can trigger device release and disconnection in a racing condition to cause a denial of service or execute arbitrary code.

Exploitation requires access to the affected USB device interface.


214) Use-after-free (CVE-ID: CVE-2026-64340)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to a use-after-free in the legousbtower USB driver when handling a race between device release and disconnect. A local user can trigger the race condition by opening and releasing the device while it is being disconnected to cause a denial of service.

The issue arises from object lifetime management during concurrent disconnect and release operations.


215) Out-of-bounds read (CVE-ID: CVE-2026-64339)

CWE-ID: CWE-125 - Out-of-bounds read

CVSSv4: 2.4 [CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows an attacker with physical access to disclose sensitive information.

The vulnerability exists due to an out-of-bounds read in usbio_bulk_msg() when processing a crafted bulk IN response from a malicious USB device. An attacker with physical access can supply a device that reports a response length larger than the received transfer to disclose sensitive information.

The issue affects the bulk data path; the control path is not affected.


216) Improper resource shutdown or release (CVE-ID: CVE-2026-64338)

CWE-ID: CWE-404 - Improper Resource Shutdown or Release

CVSSv4: 2.4 [CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a local attacker to cause a denial of service.

The vulnerability exists due to improper resource shutdown or release in uss720_probe() when handling a probe failure after reading the 1284 register. A local attacker can trigger a failed probe with a device that causes get_1284_register() to fail to cause a denial of service.

The issue can leave a registered parport device behind with stale private_data after the common cleanup path releases the associated private data and USB device reference.


217) Improper resource shutdown or release (CVE-ID: CVE-2026-64337)

CWE-ID: CWE-404 - Improper Resource Shutdown or Release

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to improper resource shutdown or release in the mtu3_gadget_queue() function when queuing a USB gadget request and transfer preparation fails. A local user can trigger a queue failure to cause a denial of service.

The issue occurs because a DMA mapping remains active on the failed queue path before the request is linked on the endpoint request list.


218) Information disclosure (CVE-ID: CVE-2026-64336)

CWE-ID: CWE-200 - Exposure of sensitive information to an unauthorized actor

CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local user to disclose sensitive information.

The vulnerability exists due to an information leak in the keyspan_pda USB serial driver write() callback when handling write operations. A local user can trigger a write operation that causes the line discipline to continue reading data beyond the tty write buffer to disclose sensitive information.

The issue occurs because the driver may report accepting more characters than were actually passed to write().


219) Improper control of a resource through its lifetime (CVE-ID: CVE-2026-64335)

CWE-ID: CWE-664 - Improper control of a resource through its lifetime

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to improper state management in the digi_acceleport usb serial driver when reopening a port after it was closed while throttled. A local user can close and reopen a throttled port to cause a denial of service.

The issue prevents the port from receiving further data until the device is reconnected or the driver is rebound.


220) Improper Check or Handling of Exceptional Conditions (CVE-ID: CVE-2026-64334)

CWE-ID: CWE-703 - Improper Check or Handling of Exceptional Conditions

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to improper error handling in the digi_acceleport USB serial driver when sending out-of-band commands during operations that race with device disconnect. A local user can trigger operations such as open, set_termios, or close while the device is being disconnected to cause a denial of service.

The issue can result in an indefinite loop with interrupts disabled, leading to a hard lockup.


221) Out-of-bounds write (CVE-ID: CVE-2026-64333)

CWE-ID: CWE-787 - Out-of-bounds write

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause memory corruption.

The vulnerability exists due to memory corruption in digi_write_inb_command() in the digi_acceleport usb serial driver when handling usb serial write commands while the write urb is in use. A local user can trigger a timeout or no-timeout command path to corrupt the write urb buffer to cause memory corruption.

On 32-bit systems, one corruption path is triggered by a broken jiffies comparison after several minutes of system uptime, while commands such as break control can corrupt the urb immediately when no timeout is used.


222) Memory leak (CVE-ID: CVE-2026-64332)

CWE-ID: CWE-401 - Missing release of memory after effective lifetime

CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to improper memory management in the ULPI device registration logic in drivers/usb/common/ulpi.c when handling early ULPI device registration failures. A local user can trigger a registration failure to cause a denial of service.


223) NULL pointer dereference (CVE-ID: CVE-2026-64331)

CWE-ID: CWE-476 - NULL Pointer Dereference

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to a null pointer dereference in vep_dequeue() when cancelling FunctionFS AIO requests. A local user can trigger request cancellation on the FunctionFS AIO path to cause a denial of service.

The issue is reachable when stressing FunctionFS endpoints via AIO in usbip's vudc path.


224) Out-of-bounds read (CVE-ID: CVE-2026-64330)

CWE-ID: CWE-125 - Out-of-bounds read

CVSSv4: 2.4 [CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to cause incorrect registration of alternate modes.

The vulnerability exists due to an out-of-bounds read in svdm_consume_modes() when processing partner-supplied SVDM Discovery Modes data. A remote attacker can inject crafted SVDM values and drive the SVID index out of bounds to cause incorrect registration of alternate modes.

The issue can read adjacent fields in struct tcpm_port, and a connected USB Type-C partner can influence the loaded SVID value.


225) Use-after-free (CVE-ID: CVE-2026-64329)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 5.7 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to use-after-free in the ucsi_ccg_remove() remove path and threaded IRQ handler when handling connector-change events during device removal. A local user can trigger concurrent remove and IRQ activity to cause a denial of service.

The issue arises from a race condition where an in-flight IRQ handler may access a freed ucsi object.


226) Memory leak (CVE-ID: CVE-2026-64328)

CWE-ID: CWE-401 - Missing release of memory after effective lifetime

CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to a memory leak in ffs_dmabuf_transfer() when handling dma-buf transfers through the USB gadget function filesystem. A local user can trigger repeated transfers to cause a denial of service.


227) Improper Initialization (CVE-ID: CVE-2026-64327)

CWE-ID: CWE-665 - Improper Initialization

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to improper initialization in the f_fs functionfs endpoint file handling when processing early userspace ioctls before USB host connection. A local user can invoke FUNCTIONFS_DMABUF_ATTACH on an endpoint file before the host connects to cause a denial of service.

The issue occurs because endpoint direction checks can use an incorrect DMA direction before the endpoint files are fully initialized for connection state.


228) Improper handling of exceptional conditions (CVE-ID: CVE-2026-64326)

CWE-ID: CWE-755 - Improper Handling of Exceptional Conditions

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to improper exceptional condition handling in bdev_mark_dead() when processing surprise removal of a block device. A local user can trigger surprise device removal to cause a denial of service.

The issue can hang indefinitely while waiting for writeback that can no longer complete, wedging the reset worker and tasks waiting on it.


229) NULL pointer dereference (CVE-ID: CVE-2026-64325)

CWE-ID: CWE-476 - NULL Pointer Dereference

CVSSv4: 8.2 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to cause a denial of service.

The vulnerability exists due to a NULL pointer dereference in mt7921_channel_switch_rx_beacon() and mt7925_channel_switch_rx_beacon() when processing a channel-switch announcement beacon after the channel context has been torn down. A remote attacker can send a channel-switch announcement beacon to trigger a kernel crash and cause a denial of service.

Exploitation requires a race condition where the queued work executes after the station disconnects or the channel context is otherwise removed.


230) Out-of-bounds read (CVE-ID: CVE-2026-64324)

CWE-ID: CWE-125 - Out-of-bounds read

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to an out-of-bounds read in udf_free_blocks() and block bitmap handling in fs/udf/balloc.c when processing crafted UDF filesystem block extents. A local user can supply a crafted filesystem and truncate a writable file on it to cause a denial of service.

On systems where active users can mount removable UDF media without administrative privileges, user interaction is not required beyond mounting the media and truncating a file.


231) Out-of-bounds read (CVE-ID: CVE-2026-64323)

CWE-ID: CWE-125 - Out-of-bounds read

CVSSv4: 4.6 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local user to disclose sensitive information.

The vulnerability exists due to an out-of-bounds read in udf_load_vat() and udf_get_pblock_virt15() when mounting a crafted UDF image with a virtual (VAT) partition. A local user can provide a crafted UDF image with an oversized VAT header length to disclose sensitive information.

User interaction is required to mount the crafted filesystem image.


232) Out-of-bounds write (CVE-ID: CVE-2026-64322)

CWE-ID: CWE-787 - Out-of-bounds write

CVSSv4: 8.4 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a local user to disclose sensitive information and corrupt memory.

The vulnerability exists due to out-of-bounds read and out-of-bounds write in udf sparing table handling in fs/udf/super.c when parsing a crafted UDF image. A local user can mount or otherwise trigger processing of a specially crafted UDF image to disclose sensitive information and corrupt memory.

The issue is caused by validating reallocationTableLen as a byte count even though it is later used as an entry count for sparingEntry array access.


233) Missing Release of Resource after Effective Lifetime (CVE-ID: CVE-2026-64321)

CWE-ID: CWE-772 - Missing Release of Resource after Effective Lifetime

CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to cause a denial of service.

The vulnerability exists due to a reference count leak in nvmet_rdma_queue_connect() in the nvme target rdma component when handling queue connect requests while the host queue backlog is exceeded. A remote attacker can send connection requests that trigger the busy return path to cause a denial of service.


234) Out-of-bounds read (CVE-ID: CVE-2026-64320)

CWE-ID: CWE-125 - Out-of-bounds read

CVSSv4: 8.8 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to disclose sensitive information or cause a denial of service.

The vulnerability exists due to an out-of-bounds heap read in nvmet_execute_disc_get_log_page() in the NVMe target discovery controller when handling a host-supplied log page offset in a Discovery Get Log Page request. A remote attacker can send a specially crafted request with an out-of-range offset to disclose sensitive information or cause a denial of service.

The issue is reachable before authentication by any TCP, RDMA, or FC peer that can reach the nvmet target.


235) Out-of-bounds read (CVE-ID: CVE-2026-64319)

CWE-ID: CWE-125 - Out-of-bounds read

CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to disclose sensitive information.

The vulnerability exists due to an out-of-bounds read in nvmet_auth_reply() when processing a crafted DHCHAP_REPLY message. A remote attacker can send a specially crafted authentication reply message with inconsistent hash and DH value lengths to disclose sensitive information.

Exploitation is possible pre-authentication when DH authentication is configured.


236) Out-of-bounds read (CVE-ID: CVE-2026-64318)

CWE-ID: CWE-125 - Out-of-bounds read

CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local user to disclose sensitive information.

The vulnerability exists due to an out-of-bounds read in the aix partition parser when scanning the physical-partition-extent array from a crafted AIX/IBM partition table. A local user can supply a crafted block-device image to disclose sensitive information.

The issue can be triggered during partition scanning without mounting the filesystem, including when a crafted image is attached with partition scanning enabled or when a device is auto-scanned by udev.


237) Out-of-bounds read (CVE-ID: CVE-2026-64317)

CWE-ID: CWE-125 - Out-of-bounds read

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local user to disclose sensitive information.

The vulnerability exists due to an out-of-bounds read in Rock Ridge SL record handling in fs/isofs/rock.c when parsing a crafted ISO 9660 image containing a malformed symbolic link record. A local user can supply a crafted filesystem image to disclose sensitive information.

The issue can copy adjacent kernel memory into the symlink body returned to user space by readlink().


238) Inclusion of Sensitive Information in Log Files (CVE-ID: CVE-2026-64316)

CWE-ID: CWE-532 - Information Exposure Through Log Files

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local user to disclose sensitive information.

The vulnerability exists due to insertion of sensitive information into log files in the caam crypto driver key-dump code when handling key material in *_setkey() and gen_split_key(). A local user can access debug output containing sensitive key material to disclose sensitive information.

Exposure occurs at runtime when CONFIG_DYNAMIC_DEBUG is enabled.


239) Inclusion of Sensitive Information in Log Files (CVE-ID: CVE-2026-64315)

CWE-ID: CWE-532 - Information Exposure Through Log Files

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local user to disclose sensitive information.

The vulnerability exists due to insertion of sensitive information into log files in the caam crypto driver setkey handlers when dumping key material during key setup with dynamic debug enabled. A local user can access debug output containing sensitive key material to disclose sensitive information.

Exposure occurs at runtime when CONFIG_DYNAMIC_DEBUG is enabled.


240) Improper input validation (CVE-ID: CVE-2026-64314)

CWE-ID: CWE-20 - Improper input validation

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to improper input validation in chachapoly_create() in the chacha20poly1305 crypto template when processing a malformed template instantiation with a missing poly1305 argument. A local user can supply a malformed template instantiation to cause a denial of service.

The issue is triggered because an error pointer returned by crypto_attr_alg_name() is passed to strcmp() when the second template argument is missing.


241) Integer overflow (CVE-ID: CVE-2026-64313)

CWE-ID: CWE-190 - Integer overflow

CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause incorrect cryptographic computation.

The vulnerability exists due to an integer overflow in crypto/ecc.c when performing elliptic curve multiplication. A local user can trigger the vulnerable arithmetic path to cause incorrect cryptographic computation.


242) Always-Incorrect Control Flow Implementation (CVE-ID: CVE-2026-64312)

CWE-ID: CWE-670 - Always-Incorrect Control Flow Implementation

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to improper callback handling in the pcrypt aead fallback path in crypto/pcrypt.c when processing non-parallel fallback after padata submission returns -EBUSY. A local user can trigger asynchronous cryptographic operations that use the fallback path to cause a denial of service.


243) Improper Initialization (CVE-ID: CVE-2026-64310)

CWE-ID: CWE-665 - Improper Initialization

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to improper initialization in the SEV ioctl handling in drivers/crypto/ccp/sev-dev.c when processing /dev/sev ioctl commands that require only SEV firmware. A local user can issue a crafted SEV ioctl request to cause a host crash.

The issue can occur if SEV initialization fails while KVM is actively running normal virtual machines, leading to global clearing of MSR_VM_HSAVE_PA and a general protection fault on the next VMRUN.


244) Improper Initialization (CVE-ID: CVE-2026-64309)

CWE-ID: CWE-665 - Improper Initialization

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to improper state management in the sev ioctl SNP_COMMIT handler when processing ioctl requests. A local user can invoke the SNP_COMMIT ioctl to cause a denial of service.

Exploitation requires access to /dev/sev, and the issue can crash the host by triggering a general protection fault during subsequent VMRUN execution for an active VM.


245) Improper control of a resource through its lifetime (CVE-ID: CVE-2026-64308)

CWE-ID: CWE-664 - Improper control of a resource through its lifetime

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to improper state management in the sev ioctl handler for SNP_VLEK_LOAD when handling ioctl requests to /dev/sev without prior SNP initialization. A local user can issue a crafted ioctl request to trigger host crashes.

Exploitation requires access to the SEV device interface, and the issue can affect hosts running active virtual machines.


246) Improper Initialization (CVE-ID: CVE-2026-64307)

CWE-ID: CWE-665 - Improper Initialization

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to improper state management in the /dev/sev SNP_CONFIG ioctl handler when re-initializing SNP after a failed initialization. A local user can invoke the SNP_CONFIG ioctl to cause a denial of service.

Exploitation requires access to the SEV device interface, and the host crash condition arises when normal KVM virtual machines are actively running.


247) Improper Check or Handling of Exceptional Conditions (CVE-ID: CVE-2026-64306)

CWE-ID: CWE-703 - Improper Check or Handling of Exceptional Conditions

CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local user to disclose sensitive information.

The vulnerability exists due to improper handling of error conditions in drbg_ctr_generate() when processing additional input during CTR_DRBG generation. A local user can trigger a failure in drbg_ctr_update() to disclose sensitive information.

The output buffer may remain uninitialized when the function incorrectly reports success.


248) Use-after-free (CVE-ID: CVE-2026-64305)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to a use-after-free in the qat service_table list handling in adf_init.c when iterating over registered services during device lifecycle and notification operations. A local user can trigger concurrent service registration or unregistration during list traversal to cause a denial of service.

The issue can also lead to list corruption during concurrent access.


249) Out-of-bounds write (CVE-ID: CVE-2026-64304)

CWE-ID: CWE-787 - Out-of-bounds write

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause memory corruption.

The vulnerability exists due to an out-of-bounds write in qat_rsa_setkey_crt() when processing RSA CRT key components larger than half of the key size. A local user can provide a crafted RSA CRT key to cause memory corruption.

The issue occurs because CRT components are bounded by the modulus size in the generic RSA key parser, while the QAT driver allocates half-size DMA buffers for those components.


250) Improper control of a resource through its lifetime (CVE-ID: CVE-2026-64303)

CWE-ID: CWE-664 - Improper control of a resource through its lifetime

CVSSv4: 6.9 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause memory corruption or trigger a use-after-free.

The vulnerability exists due to improper resource shutdown in the fsl-lpspi dma transfer error path in drivers/spi/spi-fsl-lpspi.c when preparing a tx dma descriptor after the rx dma channel has already been submitted and issued. A local user can trigger a tx prepare failure during a spi dma transfer to cause memory corruption or trigger a use-after-free.

The issue occurs because the spi core unmaps dma buffers after the error is returned while the rx dma engine may continue writing to those buffers.


251) Missing Release of Resource after Effective Lifetime (CVE-ID: CVE-2026-64302)

CWE-ID: CWE-772 - Missing Release of Resource after Effective Lifetime

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to improper resource management in vmemmap page freeing in arch/x86/mm/init_64.c when freeing PMD-sized vmemmap pages. A local user can trigger freeing of affected vmemmap pages to cause a denial of service.

The issue can leak all but the first page of a PMD-sized vmemmap allocation because the pages are not compound pages.


252) Missing Release of Resource after Effective Lifetime (CVE-ID: CVE-2026-64301)

CWE-ID: CWE-772 - Missing Release of Resource after Effective Lifetime

CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to a reference count leak in scmi_regulator_probe() in the SCMI regulator driver when processing device tree child nodes. A local user can trigger an error condition during device probing to cause a denial of service.


253) Use-after-free (CVE-ID: CVE-2026-64300)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a use-after-free condition.

The vulnerability exists due to a use-after-free in map_range() in the perf subsystem when mapping auxiliary buffer pages shared between events. A local user can trigger a race between buffer allocation and page mapping to cause a use-after-free condition.

The issue arises when multiple events share one ring buffer via PERF_EVENT_IOC_SET_OUTPUT, and pages mapped as VM_PFNMAP lack refcount protection.


254) Out-of-bounds read (CVE-ID: CVE-2026-64299)

CWE-ID: CWE-125 - Out-of-bounds read

CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local user to disclose sensitive information.

The vulnerability exists due to an out-of-bounds read in regex_match_glob() glob matching in the tracing event filter subsystem when processing non-NUL-terminated string event fields. A local user can supply a crafted glob filter against such fields to disclose sensitive information.

One reported path reaches the issue from the xfs_lookup tracepoint, and the affected string fields may be dynamic char arrays copied without a trailing NUL byte.


255) Improper access control (CVE-ID: CVE-2026-64298)

CWE-ID: CWE-284 - Improper Access Control

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local user to bypass file write permission checks and truncate a file.

The vulnerability exists due to improper access control in nfs_open_permission_mask() when handling open requests with O_TRUNC on NFSv4 delegated opens. A local user can open a file with O_RDONLY | O_TRUNC to bypass file write permission checks and truncate a file.

This issue occurs when the client satisfies the OPEN locally from a cached write delegation and then sends truncation to the server using delegation state.


256) Improper Check or Handling of Exceptional Conditions (CVE-ID: CVE-2026-64297)

CWE-ID: CWE-703 - Improper Check or Handling of Exceptional Conditions

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to improper exception handling in module decompression in kernel/module/decompress.c when processing a module for loading. A local user can trigger an allocation failure condition to cause a denial of service.

The issue can lead to a kernel oops due to a dereference of ZERO_SIZE_PTR after a failed allocation.


257) Out-of-bounds write (CVE-ID: CVE-2026-64296)

CWE-ID: CWE-787 - Out-of-bounds write

CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause an out-of-bounds read and write.

The vulnerability exists due to an out-of-bounds write in exfat_find_dir_entry() when parsing crafted exfat directory entries containing many short name fragments. A local user can provide a crafted directory structure to cause an out-of-bounds read and write.

The issue occurs because the per-entry output pointer advances by a fixed amount while the tracked accumulated name length can remain smaller when a name fragment contains an early NUL.


258) NULL pointer dereference (CVE-ID: CVE-2026-64295)

CWE-ID: CWE-476 - NULL Pointer Dereference

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to a NULL pointer dereference in the page_ext iteration API when handling memory hotplug operations. A local user can trigger memory online operations that advance iteration past the requested page frame number range to cause a denial of service.

The issue occurs at the boundary of the last valid section when the iterator count equals the requested page count.


259) Improper access control (CVE-ID: CVE-2026-64294)

CWE-ID: CWE-284 - Improper Access Control

CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local user to disclose sensitive information.

The vulnerability exists due to improper access control in the mincore() and madvise(MADV_PAGEOUT) ownership checks when handling files on idmapped mounts. A local user can access these interfaces on a crafted idmapped mount to disclose sensitive information.

The issue affects side-channel protection logic and occurs because ownership was checked against an idmap that ignored the file's mount idmap.


260) Out-of-bounds write (CVE-ID: CVE-2026-64293)

CWE-ID: CWE-787 - Out-of-bounds write

CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a local user to overwrite memory in a user-supplied buffer.

The vulnerability exists due to an out-of-bounds write in iommufd_veventq_fops_read() when reading normal vEVENT records. A local user can trigger the function with a crafted buffer size and event data length to overwrite memory in a user-supplied buffer.

This affects 32-bit systems because the bounds check uses the size of a pointer instead of the full header size.


261) Resource exhaustion (CVE-ID: CVE-2026-64292)

CWE-ID: CWE-400 - Resource exhaustion

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to uncontrolled resource consumption in iommufd vevent queue handling when allocating user-influenced event queue memory under a spinlock. A local user can request large queues to exhaust atomic memory reserves to cause a denial of service.

The queue depth is decided by userspace, and allocation occurs in the event reporting path.


262) Improper input validation (CVE-ID: CVE-2026-64291)

CWE-ID: CWE-20 - Improper input validation

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to improper input validation in iommufd_veventq_alloc() when allocating a virtual event queue with a user-supplied veventq_depth value. A local user can provide an excessively large queue depth value to cause a denial of service.


263) Improper handling of exceptional conditions (CVE-ID: CVE-2026-64290)

CWE-ID: CWE-755 - Improper Handling of Exceptional Conditions

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to improper exception handling in iommufd_fault_fops_read() when handling a copy_to_user() failure while reading fault events. A local user can trigger a failing read operation to cause a denial of service.

The issue can lead to an infinite retry loop that spins the reader at 100% CPU while holding fault->mutex.


264) Improper input validation (CVE-ID: CVE-2026-64289)

CWE-ID: CWE-20 - Improper input validation

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to improper input validation in iommufd_hwpt_invalidate() when processing user-controlled invalidation parameters through the ioctl interface. A local user can supply a large entry_len or entry_num value to cause a denial of service.

The issue can trigger a soft-lockup watchdog event or pin the CPU in a non-preemptible kernel during invalidation processing.


265) NULL pointer dereference (CVE-ID: CVE-2026-64288)

CWE-ID: CWE-476 - NULL Pointer Dereference

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to a NULL pointer dereference in arch/arm64/kvm/nested.c when processing VNCR TLB invalidation from MMU notifiers or TLBI instructions. A local user can trigger a race condition involving a vcpu that is not yet onlined or an invalid pseudo-TLB to cause a denial of service.

The issue affects arm64 KVM nested virtualization handling.


266) Out-of-bounds read (CVE-ID: CVE-2026-64287)

CWE-ID: CWE-125 - Out-of-bounds read

CVSSv4: 6.7 [CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local privileged user to cause a denial of service.

The vulnerability exists due to an out-of-bounds access in flush_hyp_vcpu() and the vGIC list register save and restore logic when copying host-controlled vgic_v3 state into the pKVM hyp vCPU. A local privileged user can provide a crafted used_lrs value to trigger out-of-bounds access at EL2 to cause a denial of service.

The issue affects arm64 KVM with pKVM and involves host-to-EL2 state transfer.


267) Use-after-free (CVE-ID: CVE-2026-64286)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to improper handling of a stale pointer in flush_hyp_vcpu() when copying the host vCPU context into the hyp private vCPU. A local user can provide a crafted __hyp_running_vcpu value to cause a denial of service.

The issue occurs on arm64 KVM with pKVM at EL2 during vCPU context handling.


268) Improper access control (CVE-ID: CVE-2026-64285)

CWE-ID: CWE-284 - Improper Access Control

CVSSv4: 5.7 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local user to corrupt read-only memory.

The vulnerability exists due to improper access control in guest_memfd population for SNP guest CPUID data when populating a guest_memfd instance from a user-supplied source page. A local user can provide CPUID data backed by a read-only mapping to corrupt read-only memory.

Exploitation requires the source page to be used for initial CPUID data for an SNP guest, and well-behaved VMMs are unlikely to be affected because such CPUID data is typically generated dynamically by userspace.


269) Race condition (CVE-ID: CVE-2026-64284)

CWE-ID: CWE-362 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')

CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause guest memory dirty logging to be incomplete.

The vulnerability exists due to improper synchronization in KVM x86 exit handling when processing fastpath userspace exits. A local user can trigger a fastpath userspace exit to cause guest memory dirty logging to be incomplete.

The issue affects vendor-specific KVM exit handling paths such as VMX, where operations needed before returning control to userspace may be skipped.


270) Integer overflow (CVE-ID: CVE-2026-64283)

CWE-ID: CWE-190 - Integer overflow

CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local user to bypass a file size check.

The vulnerability exists due to an integer overflow in the KVM guest_memfd memslot binding logic when binding a memslot to a guest_memfd file. A local user can supply a crafted offset and size combination to bypass a file size check.

The issue affects the sum of the offset and size values, where a very large offset can cause the signed 64-bit result to become negative during validation.


271) Missing Release of Resource after Effective Lifetime (CVE-ID: CVE-2026-64282)

CWE-ID: CWE-772 - Missing Release of Resource after Effective Lifetime

CVSSv4: 5.7 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to a resource leak in kvm_translate_vncr() when racing an MMU notifier. A local user can trigger the race condition to cause a denial of service.

The issue affects the arm64 KVM nested virtualization path.


272) Improper input validation (CVE-ID: CVE-2026-64280)

CWE-ID: CWE-20 - Improper input validation

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to improper input validation in afu_ioctl_dma_map() when handling a DFL_FPGA_PORT_DMA_MAP ioctl request with a user-supplied length. A local user can provide an excessively large length value to cause a denial of service.


273) Use-after-free (CVE-ID: CVE-2026-64279)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to a use-after-free in the i2c core adapter lookup and deregistration logic when looking up an adapter by id during adapter deregistration or registration failure. A local user can trigger a race condition to cause a denial of service.


274) Improper control of a resource through its lifetime (CVE-ID: CVE-2026-64278)

CWE-ID: CWE-664 - Improper control of a resource through its lifetime

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to improper resource state handling in the i2c-imx-lpi2c driver when processing I2C transfers during the suspend and resume noirq window. A local user can trigger an I2C transfer while controller resources are unavailable to cause a denial of service.

The issue occurs on some i.MX platforms when periodic workqueue activity continues across system suspend and resume.


275) Out-of-bounds read (CVE-ID: CVE-2026-64277)

CWE-ID: CWE-125 - Out-of-bounds read

CVSSv4: 8.4 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local user to disclose sensitive information and overwrite adjacent kernel memory.

The vulnerability exists due to an out-of-bounds read and out-of-bounds write in the synaptics-rmi4 F3A GPIO keymap handling in drivers/input/rmi4/rmi_f3a.c when processing a device that reports a gpio_count greater than the allocated keymap size. A local user can open the evdev node and invoke keymap ioctls to disclose sensitive information and overwrite adjacent kernel memory.

The information disclosure occurs through EVIOCGKEYCODE leaking adjacent slab memory to user space, while EVIOCSKEYCODE writes a caller-controlled value past the buffer.


276) Out-of-bounds read (CVE-ID: CVE-2026-64276)

CWE-ID: CWE-125 - Out-of-bounds read

CVSSv4: 6.9 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service or disclose sensitive information.

The vulnerability exists due to out-of-bounds read and out-of-bounds write in the rmi_f30_attention handler and EVIOCGKEYCODE/EVIOCSKEYCODE ioctl handling in the synaptics-rmi4 F30 driver when processing a device that reports a gpioled_count greater than 6 with GPIO support enabled. A local user can trigger the attention interrupt or use EVIOCGKEYCODE/EVIOCSKEYCODE ioctls to cause a denial of service or disclose sensitive information.

The issue occurs because the keymap allocation is smaller than the gpioled_count value used for iteration and keycode bounds.


277) Integer underflow (CVE-ID: CVE-2026-64275)

CWE-ID: CWE-191 - Integer underflow

CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local attacker to disclose sensitive information.

The vulnerability exists due to integer underflow in the touch reporting logic of the elan_i2c touchpad driver when handling small calculated or fallback width values. A local attacker can cause width values smaller than ETP_FWIDTH_REDUCE to trigger an underflow and report a massive unsigned integer to userspace.

The issue affects touch width reporting to userspace.


278) Division by zero (CVE-ID: CVE-2026-64275)

CWE-ID: CWE-369 - Divide By Zero

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local attacker to cause a denial of service.

The vulnerability exists due to division by zero in the elan_i2c touchpad driver when processing invalid device firmware or device tree parameters during device probe. A local attacker can provide zero trace-count values to trigger a kernel panic.

The issue occurs during device probe.


279) Stack-based buffer overflow (CVE-ID: CVE-2026-64274)

CWE-ID: CWE-121 - Stack-based buffer overflow

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to cause memory corruption.

The vulnerability exists due to a stack-based out-of-bounds write in goodix_ts_read_input_report() when processing device-reported touch contact data. A remote attacker can tamper with the I2C bus or use a malicious controller to write beyond an on-stack buffer and cause memory corruption.

The issue occurs because the maximum contact count taken from a 4-bit device configuration field can exceed the number of contacts the buffer is sized to hold.


280) Out-of-bounds write (CVE-ID: CVE-2026-64273)

CWE-ID: CWE-787 - Out-of-bounds write

CVSSv4: 5.2 [CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows an attacker with physical access to corrupt kernel memory.

The vulnerability exists due to an out-of-bounds write in iforce_process_packet() when processing a device-reported force-feedback status packet. An attacker with physical access can supply a crafted device payload with an out-of-range effect index to corrupt kernel memory.

The issue affects both USB interrupt endpoint and serio transports, and the status handling path is not gated on force-feedback support being present.


281) Memory corruption (CVE-ID: CVE-2026-64272)

CWE-ID: CWE-119 - Memory corruption

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to improper memory access in the mms114 touchscreen driver when processing touch data packets from MMS134S and MMS136 controllers. A local user can trigger crafted touch event data to cause a denial of service.

The issue affects handling of touch events beyond the first one because 6-byte events are parsed using 8-byte structure indexing.


282) Out-of-bounds write (CVE-ID: CVE-2026-64271)

CWE-ID: CWE-787 - Out-of-bounds write

CVSSv4: 5.2 [CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows an attacker with physical access to overwrite heap memory.

The vulnerability exists due to out-of-bounds write in the tw_interrupt() handler in drivers/input/touchscreen/touchwin.c when processing serial input from a Touchwindow peripheral. An attacker with physical access can send crafted non-zero bytes with mismatched second and third packet bytes to overwrite heap memory.

Exploitation requires a malicious, malfunctioning, or counterfeit Touchwindow peripheral.


283) Stack-based buffer overflow (CVE-ID: CVE-2026-64270)

CWE-ID: CWE-121 - Stack-based buffer overflow

CVSSv4: 5.1 [CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local attacker to overwrite stack memory and cause a denial of service.

The vulnerability exists due to a stack-based buffer overflow in mms114_interrupt() when processing a device-reported packet size from the touchscreen controller over the I2C bus. A local attacker can tamper with the I2C bus or use a malicious controller to supply an oversized packet size to overwrite stack memory and cause a denial of service.

The out-of-bounds write occurs on the IRQ-thread stack and may overwrite the stack canary, saved registers, and the return address.


284) Out-of-bounds read (CVE-ID: CVE-2026-64269)

CWE-ID: CWE-125 - Out-of-bounds read

CVSSv4: 8.8 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to disclose sensitive information or cause a denial of service.

The vulnerability exists due to an out-of-bounds read in rdma_write_sg when processing an RTRS READ response with an attacker-controlled descriptor length. A remote attacker can advertise a crafted desc[0].len value larger than max_chunk_size to disclose sensitive information or cause a denial of service.

With no IOMMU or in passthrough mode, adjacent host memory may be returned to the peer; with a translating IOMMU, the out-of-range access is expected to fault and abort the connection.


285) Out-of-bounds write (CVE-ID: CVE-2026-64268)

CWE-ID: CWE-787 - Out-of-bounds write

CVSSv4: 7.2 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote user to write out of bounds.

The vulnerability exists due to an out-of-bounds write in siw_proc_rresp() in drivers/infiniband/sw/siw/siw_qp_rx.c when processing Read Response DDP segments for an outstanding RREAD over an established RDMA connection. A remote user can send Read Response segments with more total payload than requested while keeping the DDP Last flag clear to write out of bounds.

Exploitation requires a connected siw peer on an established RDMA connection over routable TCP.


286) Integer overflow (CVE-ID: CVE-2026-64267)

CWE-ID: CWE-190 - Integer overflow

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to an integer overflow in fuse_notify_prune() in the FUSE notification handling code when processing a crafted FUSE_NOTIFY_PRUNE notification on 32-bit kernels. A local user can send a specially crafted prune notification with a wrapped count value to cause a denial of service.

Exploitation requires a FUSE daemon capable of issuing crafted prune notifications, and the issue affects 32-bit kernel builds.


287) Use-after-free (CVE-ID: CVE-2026-64266)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to use-after-free in fuse_ref_folio() in the FUSE subsystem when handling a subsequent copy chain after unlocking the request. A local user can trigger request abort and asynchronous end callback timing to cause a denial of service.


288) Use-after-free (CVE-ID: CVE-2026-64265)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a local user to disclose sensitive information or cause memory corruption.

The vulnerability exists due to a use-after-free in fuse_read_interrupt and FUSE request interrupt list handling when processing interrupted requests that are resent and later removed after a fatal signal. A local user can trigger request requeueing and request removal to disclose sensitive information or cause memory corruption.

Exploitation requires a previously interrupted request to remain linked on the interrupts list and a subsequent fatal signal before the interrupt list is processed.


289) Improper Check or Handling of Exceptional Conditions (CVE-ID: CVE-2026-64264)

CWE-ID: CWE-703 - Improper Check or Handling of Exceptional Conditions

CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause incorrect handling of a failed request.

The vulnerability exists due to improper error handling in fuse_uring_commit when copying an output header from user memory. A local user can trigger a copy_from_user() failure to cause incorrect handling of a failed request.

The positive residual value can be interpreted as success, causing the caller to proceed with an uninitialised or partially populated req->out.args.


290) NULL pointer dereference (CVE-ID: CVE-2026-64263)

CWE-ID: CWE-476 - NULL Pointer Dereference

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to a null pointer dereference in the fuse-uring request handling code when processing cancellation of available entries moved to the ent_in_userspace list. A local user can trigger cancellation of a crafted entry state to cause a denial of service.

The crash occurs because the first entry on the ent_in_userspace list may be dereferenced even when no fuse request is attached.


291) Improper resource shutdown or release (CVE-ID: CVE-2026-64262)

CWE-ID: CWE-404 - Improper Resource Shutdown or Release

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to improper resource shutdown in fuse_uring_send_in_task() in fs/fuse/dev_uring.c when handling io_uring cancel task work for FUSE requests. A local user can trigger request cancellation to cause a denial of service.

The issue can leave the associated fuse_req unended, causing syscall threads to block in D-state, and repeated cancellations can stall later background operations by exhausting the background request limit.


292) Use-after-free (CVE-ID: CVE-2026-64261)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to use-after-free in fuse_uring_async_stop_queues in fs/fuse/dev_uring.c when stopping fuse uring queues. A local user can trigger queue teardown to cause a denial of service.


293) Race condition (CVE-ID: CVE-2026-64260)

CWE-ID: CWE-362 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to a race condition in fuse_uring_commit_fetch() and queue stop handling in fs/fuse/dev_uring.c when processing FUSE uring queue teardown and request fetch operations. A local user can trigger concurrent operations to cause a denial of service.

The issue occurs because queue->stopped was not consistently set and checked under the queue lock, which could lead to a fuse request being freed while another thread is already performing teardown work.


294) Use-after-free (CVE-ID: CVE-2026-64259)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a use-after-free.

The vulnerability exists due to a use-after-free in fuse_uring_commit_fetch() and fuse_uring_send_in_task() when processing commit sqes that reference requests not yet sent to the fuse server. A local user can send crafted commit sqes with request unique or commit-id values for requests that are not yet completed to cause a use-after-free.

The issue is caused by a race condition where a request becomes findable before preparation and memcpy operations are completed.


295) NULL pointer dereference (CVE-ID: CVE-2026-64258)

CWE-ID: CWE-476 - NULL Pointer Dereference

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to a NULL pointer dereference in fuse_uring request expiration logic in fs/fuse/dev_uring.c when handling a failed copy into the userspace ring buffer. A local user can trigger a failed copy operation to cause a denial of service.


296) Integer overflow (CVE-ID: CVE-2026-64256)

CWE-ID: CWE-190 - Integer overflow

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to an integer overflow in dqiterate in fs/xfs/scrub/dqiterate.c when iterating quota records. A local user can trigger processing of a filesystem containing a quota record with the maximum quota id to cause a denial of service.

The issue can cause the iteration to wrap to zero and start over.


297) Out-of-bounds write (CVE-ID: CVE-2026-64255)

CWE-ID: CWE-787 - Out-of-bounds write

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local attacker to cause a denial of service.

The vulnerability exists due to an out-of-bounds access in BA session handlers in the iwlwifi mld component when processing a zero sta_mask value. A local attacker can trigger BA session handling with a zero sta_mask to cause a denial of service.


298) Improper resource shutdown or release (CVE-ID: CVE-2026-64254)

CWE-ID: CWE-404 - Improper Resource Shutdown or Release

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to improper resource shutdown in ntb_epf_deinit_pci() in the NTB EPF driver when tearing down PCI mappings for BARs that share the same mapped I/O memory. A local user can trigger module removal or device teardown to cause a denial of service.

The issue occurs when PEER_SPAD and CONFIG share a single PCI BAR.


299) Improper control of a resource through its lifetime (CVE-ID: CVE-2026-64253)

CWE-ID: CWE-664 - Improper control of a resource through its lifetime

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to improper state management in copy_process() when creating a child process. A local user can create a process that inherits an inconsistent PF_BLOCK_TS flag state to cause a denial of service.


300) Use-after-free (CVE-ID: CVE-2026-64251)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to use-after-free in pwrseq_debugfs_seq_next() when iterating debugfs seq_file entries. A local user can trigger iteration of the affected debugfs interface to cause a denial of service.

The issue occurs because a device pointer returned to the seq_file framework has its reference dropped before subsequent use.


301) Use-after-free (CVE-ID: CVE-2026-64249)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to use-after-free in child_regions_with_firmware() in drivers/fpga/of-fpga-region.c when handling child FPGA region data. A local user can trigger the error path to cause a denial of service.


302) Out-of-bounds read (CVE-ID: CVE-2026-64247)

CWE-ID: CWE-125 - Out-of-bounds read

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to an out-of-bounds read in hv_is_vp_in_sparse_set() when handling a paravirtual TLB flush for an L2 guest with a copied VP ID from the enlightened VMCS. A local user can provide a crafted VP ID value to cause a denial of service.

The issue can also cause KVM to perform an unnecessary TLB flush for an L2 vCPU.


303) Use-after-free (CVE-ID: CVE-2026-64246)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local attacker to cause a denial of service.

The vulnerability exists due to use-after-free in linkstation_poweroff_init() when initializing the linkstation poweroff driver. A local attacker can trigger the vulnerable initialization path to cause a denial of service.


304) Use-after-free (CVE-ID: CVE-2026-64245)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to use-after-free in fb_find_mode() in the fbdev modedb component when processing a NULL mode option. A local user can trigger the vulnerable code path to cause a denial of service.


305) Improper control of a resource through its lifetime (CVE-ID: CVE-2026-64244)

CWE-ID: CWE-664 - Improper control of a resource through its lifetime

CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a local attacker to cause a denial of service.

The vulnerability exists due to improper state management in add_memory_block() and memory_block_release() when handling failed memory block registration. A local attacker can trigger a failure during memory block registration to cause a denial of service.

This issue can be triggered when __add_memory_block() fails at xa_store() under memory pressure, leading to a kernel WARN_ON on mem->altmap.


306) NULL pointer dereference (CVE-ID: CVE-2026-64207)

CWE-ID: CWE-476 - NULL Pointer Dereference

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to a NULL pointer dereference in qfq_dequeue() and qfq_peek_skb() when processing GSO packets through DualPI2 with QFQ as the parent qdisc. A local user can trigger GSO packet segmentation and packet dequeue operations to cause a denial of service.

Exploitation requires DualPI2 to split a GSO skb and QFQ to be configured as the parent qdisc.


307) Deadlock (CVE-ID: CVE-2026-64206)

CWE-ID: CWE-833 - Deadlock

CVSSv4: 8.2 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to cause a denial of service.

The vulnerability exists due to improper locking in the Bluetooth L2CAP connection teardown path when canceling pending receive work during connection deletion. A remote attacker can trigger Bluetooth L2CAP traffic and connection teardown to cause a denial of service.

The issue can deadlock between the pending_rx_work worker and the teardown path in l2cap_conn_del().


308) Improper control of a resource through its lifetime (CVE-ID: CVE-2026-64205)

CWE-ID: CWE-664 - Improper control of a resource through its lifetime

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to improper resource management in i801_access() in the i2c-i801 driver when handling an error path after a failed pre-check. A local user can trigger concurrent access to the SMBus controller to cause a denial of service.

The issue occurs when the driver clears SMBus hardware status and ownership state without actually owning the controller, which can corrupt the SMBus hardware state machine and lead to a console livelock and hung task panic.


309) Out-of-bounds write (CVE-ID: CVE-2026-64192)

CWE-ID: CWE-787 - Out-of-bounds write

CVSSv4: 6.7 [CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local privileged user to cause a denial of service.

The vulnerability exists due to an out-of-bounds write in BPF_MAP_TYPE_INODE_STORAGE handling when creating and updating inode storage maps while the BPF LSM is uninitialized. A local privileged user can create and update a BPF_MAP_TYPE_INODE_STORAGE map to cause a denial of service.

This issue occurs when CONFIG_BPF_LSM is enabled but the BPF LSM is not enabled at boot time, causing the inode security blob offset to remain uninitialized and leading to a kernel panic during later RCU callback execution.


310) Out-of-bounds read (CVE-ID: CVE-2026-64191)

CWE-ID: CWE-125 - Out-of-bounds read

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to out-of-bounds read and out-of-bounds write in stub_xfer() in the i2c-stub driver when handling an I2C_SMBUS ioctl with I2C_SMBUS_I2C_BLOCK_DATA and an invalid block length. A local user can issue a crafted ioctl request with data->block[0] greater than 32 to cause a denial of service.

The issue affects the development and test i2c-stub driver, which is not built by default and must be loaded with a chip_addr= parameter.


311) Use-after-free (CVE-ID: CVE-2026-64189)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to use-after-free in ip_set_dump_do() and ip_set_dump_done() in the ipset netfilter subsystem when handling netlink dump operations concurrently with ip_set_list resizing. A local user can trigger concurrent netlink dump and set creation operations to cause a denial of service.

The issue can lead to a general protection fault and kernel panic.


312) Use-after-free (CVE-ID: CVE-2026-64188)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to use-after-free in rmnet_dellink() and the rmnet endpoint handling in the Qualcomm rmnet driver when processing network packets on the receive path while an endpoint is being removed. A local user can trigger concurrent packet processing and endpoint deletion to cause a denial of service.

The stale read occurs when lockless RCU readers dereference the egress_dev pointer after the endpoint memory has been freed.


313) NULL pointer dereference (CVE-ID: CVE-2026-64187)

CWE-ID: CWE-476 - NULL Pointer Dereference

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to a null pointer dereference in xlog_recover_reorder_trans in the XFS log recovery code when processing a crafted log during filesystem recovery. A local user can provide a crafted log item with no regions to trigger a kernel fault and cause a denial of service.

This issue only occurs for crafted log data during recovery, as the normal runtime commit path does not generate such a transaction.


314) Race condition (CVE-ID: CVE-2026-63874)

CWE-ID: CWE-362 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')

CVSSv4: 5.7 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to a race condition in the mctp-usb driver when stopping the network device while rx retry work and urb completion are handled concurrently. A local user can trigger concurrent stop and retry activity to cause a denial of service.

The issue can leave a receive urb queued and its completion can reschedule retry work after device shutdown.


315) Missing Release of Resource after Effective Lifetime (CVE-ID: CVE-2026-63873)

CWE-ID: CWE-772 - Missing Release of Resource after Effective Lifetime

CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to a reference leak in aie2_populate_range() when handling retry paths in memory mapping operations. A local user can trigger repeated execution of the affected code path to cause a denial of service.


316) Race condition (CVE-ID: CVE-2026-63871)

CWE-ID: CWE-362 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to a race condition in Bluetooth ISO socket handling in net/bluetooth/iso.c when calling hci_get_route() on iso_pi socket fields without holding the socket lock. A local user can trigger concurrent connect() or setsockopt() operations on the same socket to cause a denial of service.

The issue was reported by KCSAN as a data race during Bluetooth ISO connection and listening operations.


317) Use of uninitialized resource (CVE-ID: CVE-2026-63870)

CWE-ID: CWE-908 - Use of Uninitialized Resource

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to use of uninitialized memory in lowpan_xmit() in the ieee802154 6LoWPAN transmit path when processing a non-IPv6 packet queued for transmission on a 6LoWPAN interface. A local user can queue a non-IPv6 packet for transmission to cause a denial of service.

The issue occurs because address information in skb headroom may remain uninitialized and is later copied and used by the transmit path.


318) Out-of-bounds write (CVE-ID: CVE-2026-63869)

CWE-ID: CWE-787 - Out-of-bounds write

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to an out-of-bounds shift in ieee80211_parse_tx_radiotap() when parsing the radiotap header of an injected frame. A local user can supply a crafted frame from userspace to cause a denial of service.

The issue is triggered by the IEEE80211_RADIOTAP_ANTENNA value being used directly as a shift count, and larger antenna indices cannot be represented by the 2-bit bitmap.


319) Integer underflow (CVE-ID: CVE-2026-63868)

CWE-ID: CWE-191 - Integer underflow

CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to cause a denial of service.

The vulnerability exists due to an unsigned integer underflow in garp_pdu_parse_attr in the GARP receive-side attribute parser when parsing crafted GARP attributes. A remote attacker can send crafted Join or Leave events to cause a denial of service.

The issue can cause received GARP events for common attributes, such as GVRP VLAN registration attributes, to be ignored.


320) Time-of-check Time-of-use (TOCTOU) Race Condition (CVE-ID: CVE-2026-63867)

CWE-ID: CWE-367 - Time-of-check Time-of-use (TOCTOU) Race Condition

CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to cause inconsistent MPTCP receiver window signaling.

The vulnerability exists due to a time-of-check time-of-use race in the MPTCP DSS option handling in net/mptcp/options.c when processing and emitting MPTCP acknowledgments on outgoing packets. A remote attacker can trigger packet processing that causes inconsistent ack_seq values to be used to confuse the peer.

The issue arises because the MPTCP-level ack_seq was accessed locklessly multiple times, allowing different values to be used for the DSS data acknowledgment and the announced receive window within the same packet.


321) Integer overflow (CVE-ID: CVE-2026-63836)

CWE-ID: CWE-190 - Integer overflow

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to an integer overflow leading to divide-by-zero in batadv_tp_update_cwnd() in the batman-adv tp_meter component when processing crafted acknowledgment traffic. A local user can trigger the vulnerable calculation to cause a denial of service.

The issue occurs when the congestion window reaches 0x20000000, causing a left shift in the divisor to wrap to zero under 32-bit arithmetic.


322) Missing Release of Resource after Effective Lifetime (CVE-ID: CVE-2026-63835)

CWE-ID: CWE-772 - Missing Release of Resource after Effective Lifetime

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to improper resource shutdown or release in batadv_v_ogm_queue_on_if() and the OGM aggregation queue handling when processing OGM aggregation on a disabled hard interface. A local user can trigger interface disablement while causing new skbs to be queued to the aggregation list to cause a denial of service.

The issue can lead to skbs being queued after the worker has been disabled, and these queued skbs are never freed or consumed.


323) Resource exhaustion (CVE-ID: CVE-2026-63834)

CWE-ID: CWE-400 - Resource exhaustion

CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to cause a denial of service.

The vulnerability exists due to uncontrolled resource consumption in the batman-adv tp_meter unacked_list handling when processing crafted messages with small lengths and seqno gaps. A remote attacker can send specially crafted messages to cause a denial of service.

The issue can lead to an out-of-memory condition or excessive CPU usage from management overhead while searching the enlarged list.


324) Improper access control (CVE-ID: CVE-2026-63833)

CWE-ID: CWE-284 - Improper Access Control

CVSSv4: 8.4 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local user to escalate privileges.

The vulnerability exists due to improper access control in the ntfs3 xattr handler when handling direct userspace writes to reserved $LX* extended attributes. A local user can set crafted $LXUID, $LXGID, $LXMOD, or $LXDEV values on a file they own to escalate privileges.

Exploitation requires a writable ntfs3 mount and relies on inode reload of WSL permission metadata into inode ownership and mode fields.


325) Use-after-free (CVE-ID: CVE-2026-63832)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to memory corruption in the mt76_sta_add function when handling station addition for published wcid entries. A local user can trigger repeated station add operations to cause a denial of service.

The issue was observed as dev->sta_poll_list corruption on systems using the mt7925 driver.


326) Use-after-free (CVE-ID: CVE-2026-63831)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 6.9 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service or corrupt data.

The vulnerability exists due to use-after-free in the mac802154 llsec crypto processing in net/mac802154/llsec.c when performing in-place cryptographic transformations on shared skb data. A local user can trigger concurrent 802.15.4 traffic with security enabled to cause a denial of service or corrupt data.

The issue can affect both RX and TX paths when skb data buffers are shared across clones.


327) Improper access control (CVE-ID: CVE-2026-63830)

CWE-ID: CWE-284 - Improper Access Control

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local user to modify the page cache contents.

The vulnerability exists due to improper access control in the sk_msg scatter-gather handling logic when processing SK_MSG transformations and BPF message helpers. A local user can trigger scatterlist entry transfers, shifts, splits, or copies that desynchronize sg.copy state to modify the page cache contents.

Exploitation requires the ability to reach a later SK_MSG verdict that exposes sg_virt(sge) as writable BPF ctx->data.


328) Improper access control (CVE-ID: CVE-2026-63829)

CWE-ID: CWE-284 - Improper Access Control

CVSSv4: 6.7 [CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local privileged user to modify tunnel configuration across network namespaces.

The vulnerability exists due to improper access control in ipgre_changelink() and erspan_changelink() when handling RTM_NEWLINK changelink requests for GRE tunnel devices. A local privileged user can send a crafted RTM_NEWLINK request to modify tunnel configuration across network namespaces.

The issue occurs when the device network namespace differs from the tunnel link network namespace, because the check was performed only against dev_net(dev).


329) Improper access control (CVE-ID: CVE-2026-63828)

CWE-ID: CWE-284 - Improper Access Control

CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local user to bypass AppArmor connect restrictions.

The vulnerability exists due to improper access control in apparmor_socket_sendmsg() when processing sendmsg()/sendto() calls with MSG_FASTOPEN and a supplied destination address. A local user can send a crafted fast open request to bypass AppArmor connect restrictions.

The issue affects implicit TCP and MPTCP connection establishment performed as part of sendmsg() fast open handling.


330) Use-after-free (CVE-ID: CVE-2026-63827)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to a use-after-free in aa_replace_profiles() during rawdata_list deduplication when processing policy replacement operations. A local user can trigger AppArmor profile replacement with crafted timing to cause a denial of service.

The issue occurs because entries can remain on the rawdata list after their profile reference count has reached zero and before deferred cleanup runs.


331) Use-after-free (CVE-ID: CVE-2026-63826)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to use-after-free in store_modes() and related framebuffer mode handling in fbdev when processing crafted framebuffer mode changes through ioctl or sysfs interfaces. A local user can trigger stale mode pointer dereferences to cause a denial of service.

The issue involves stale pointers in fb_display[i].mode and fb_info->mode after the framebuffer modelist is replaced and the old list is freed.


332) Out-of-bounds write (CVE-ID: CVE-2026-63825)

CWE-ID: CWE-787 - Out-of-bounds write

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to an out-of-bounds write in inflate_fast() when processing IP payload compression data concurrently on multiple cpus. A local user can trigger concurrent execution of the vulnerable code path to cause a denial of service.

The issue occurs because global gcov counters can change between multiple loads during execution, producing inconsistent loop values.


333) Out-of-bounds write (CVE-ID: CVE-2026-63824)

CWE-ID: CWE-787 - Out-of-bounds write

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause memory corruption.

The vulnerability exists due to a buffer overflow in keyctl_pkey_params_get_2() when processing crafted keyctl public-key operation parameters. A local user can provide a too small buffer length to cause memory corruption.


334) Use-after-free (CVE-ID: CVE-2026-63823)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to use-after-free in request_key_auth handling in the Linux kernel key management subsystem when processing KEYCTL_INSTANTIATE_IOV or related key instantiation and rejection paths concurrently with request_key() completion. A local user can trigger concurrent key operations to cause a denial of service.

The issue occurs because the request_key_auth payload can be freed after helper completion while another path later resumes and accesses rka->target_key.


335) Double free (CVE-ID: CVE-2026-63822)

CWE-ID: CWE-415 - Double Free

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to a double free in the ath11k dp tx_status buffer handling when unbinding a device after an initialization error related to firmware. A local user can trigger device initialization failure and subsequent unbinding to cause a denial of service.

The issue is reproducible in a VM when MSI addressing initialization fails.


336) Improper handling of exceptional conditions (CVE-ID: CVE-2026-63821)

CWE-ID: CWE-755 - Improper Handling of Exceptional Conditions

CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to improper exception handling in rtw_usb_write_data() and rtw_usb_tx_agg_skb() when handling USB write submission failures. A local user can trigger a USB write failure to cause a denial of service.

The issue can be triggered during device disconnect or reconnect scenarios and under memory pressure conditions.


337) Improper Check or Handling of Exceptional Conditions (CVE-ID: CVE-2026-63820)

CWE-ID: CWE-703 - Improper Check or Handling of Exceptional Conditions

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to improper error handling in f2fs_read_data_large_folio() when processing large folio readahead after an error condition. A local user can trigger an error during file read operations to cause a denial of service.

Pending read completion can be left unsignaled for earlier folios, which may cause readers to wait indefinitely on locked folios.


338) Improper input validation (CVE-ID: CVE-2026-63819)

CWE-ID: CWE-20 - Improper input validation

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to improper input validation in f2fs_get_node_folio_ra() when processing a corrupted f2fs inode during filesystem mount and inode truncation. A local user can supply a crafted corrupted f2fs image to trigger a kernel panic and cause a denial of service.

The issue is triggered by an inconsistent node chain in the inode mapping table where a direct node has the same ino and nid in its footer, leading to a bug check in f2fs_do_truncate_blocks().


339) Out-of-bounds read (CVE-ID: CVE-2026-63818)

CWE-ID: CWE-125 - Out-of-bounds read

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to an out-of-bounds read in f2fs_recover_orphan_inodes() when mounting a crafted f2fs image and replaying orphan inodes from the checkpoint pack. A local user can provide a crafted filesystem image with a corrupted orphan block entry count to cause a denial of service.

The issue occurs when the orphan block entry count is larger than F2FS_ORPHANS_PER_BLOCK, causing the recovery code to read past the ino[] array and interpret subsequent data as inode numbers.


340) Improper access control (CVE-ID: CVE-2026-63817)

CWE-ID: CWE-284 - Improper Access Control

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to improper access control in f2fs_iget() meta inode handling when processing a corrupted directory entry with an inode number equal to max_nid while compress_cache is disabled. A local user can create a corrupted directory entry to cause a denial of service.

Only F2FS mounts with compression support present and the compress_cache mount option disabled are affected by this behavior.


341) Use-after-free (CVE-ID: CVE-2026-63816)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to a use-after-free in the f2fs garbage collection code when handling F2FS_IOC_GARBAGE_COLLECT_RANGE on a copy-on-write file. A local user can trigger garbage collection while the associated atomic inode is being evicted to cause a denial of service.

The issue involves access to atomic_inode->i_mapping without holding a reference to the atomic inode.


342) Out-of-bounds read (CVE-ID: CVE-2026-63815)

CWE-ID: CWE-125 - Out-of-bounds read

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local user to disclose sensitive information.

The vulnerability exists due to an out-of-bounds read in f2fs_fill_dentries() and inline directory handling when mounting a crafted filesystem image and reading an inline directory. A local user can mount a specially crafted image and read a crafted directory to disclose sensitive information.

Exploitation requires the flexible_inline_xattr feature to be enabled.


343) Out-of-bounds read (CVE-ID: CVE-2026-63814)

CWE-ID: CWE-125 - Out-of-bounds read

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to an out-of-bounds read in f2fs_acl_from_disk() when parsing a malformed ACL xattr. A local user can supply a crafted ACL entry layout to trigger an out-of-bounds read and cause a denial of service.

The issue occurs because ACL_USER or ACL_GROUP entries can be placed in a slot that contains only a short ACL entry.


344) Race condition (CVE-ID: CVE-2026-63813)

CWE-ID: CWE-362 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')

CVSSv4: 5.7 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to a race condition in the f2fs garbage collection path in move_data_block() when handling folios during garbage collection on f2fs filesystems. A local user can trigger filesystem operations that exercise this race to cause a denial of service.

The issue can lead to list corruption and a kernel panic, and reports indicate it is more likely to occur when the f2fs partition is almost full.


345) Improper control of a resource through its lifetime (CVE-ID: CVE-2026-63812)

CWE-ID: CWE-664 - Improper control of a resource through its lifetime

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to improper state management in __destroy_extent_node() and the f2fs extent cache when handling extent node destruction and concurrent writeback. A local user can trigger inode eviction or writeback activity to cause a kernel sanity check failure and filesystem inconsistency.

The issue can leave the cached largest extent stale after the FI_NO_EXTENT flag is set, and concurrency with writeback is involved in the affected path.


346) NULL pointer dereference (CVE-ID: CVE-2026-63811)

CWE-ID: CWE-476 - NULL Pointer Dereference

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to a null pointer dereference in f2fs atomic write handling when reading COW data during write-begin processing. A local user can update an atomic-write file in a crafted encryption-policy state to cause a denial of service.

The issue occurs when the original inode and its COW inode use different encryption contexts, causing decryption to be attempted on a folio owned by the original inode.


347) NULL pointer dereference (CVE-ID: CVE-2026-63810)

CWE-ID: CWE-476 - NULL Pointer Dereference

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local attacker to cause a denial of service.

The vulnerability exists due to a null pointer dereference in the bdev pseudo-filesystem when userspace mounts it and accesses files. A local attacker can mount the pseudo-filesystem and access files to cause a denial of service.

The issue is triggered through move_mount() using inode_operations pointers that are equal to 0 for this pseudo-filesystem.


348) Release of invalid pointer or reference (CVE-ID: CVE-2026-63809)

CWE-ID: CWE-763 - Release of invalid pointer or reference

CVSSv4: 6.7 [CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local privileged user to cause a denial of service.

The vulnerability exists due to memory corruption in proc_sys_call_handler and __cgroup_bpf_run_filter_sysctl() when processing a sysctl write that replaces the temporary buffer. A local privileged user can write a crafted sysctl value to trigger memory corruption and cause a denial of service.

Exploitation requires access to write to a sysctl entry from a task in the target cgroup, and the fault was reproduced while writing to /proc/sys/kernel/domainname.


349) Use-after-free (CVE-ID: CVE-2026-63808)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to a use-after-free in exfat_find_dir_entry() when parsing a crafted exFAT filesystem image. A local user can supply a crafted exFAT image to trigger a kernel fault and cause a denial of service.

The issue occurs on the TYPE_EXTEND path after a directory entry buffer is released and then dereferenced.


350) Out-of-bounds read (CVE-ID: CVE-2026-63807)

CWE-ID: CWE-125 - Out-of-bounds read

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to an out-of-bounds access in the KVM x86 shadow MMU hugepage recovery logic when recovering hugepages for a direct shadow page whose gfn falls outside the target memslot. A local user can create a guest hugepage mapping that extends below the bounds of a memslot to cause a denial of service.

The issue can manifest as a host page fault in kernel mode during hugepage recovery.


351) Reachable assertion (CVE-ID: CVE-2026-63806)

CWE-ID: CWE-617 - Reachable Assertion

CVSSv4: 5.7 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to an improper handling of unaligned memory access in ioeventfd datamatch handling in KVM when processing a guest store that splits a page and targets emulated MMIO with a datamatch-enabled ioeventfd. A local user can trigger a specially crafted guest store operation to cause a denial of service.

Exploitation requires a guest configuration where the second page contains a datamatch-enabled ioeventfd at offset 0.


352) Type Confusion (CVE-ID: CVE-2026-63805)

CWE-ID: CWE-843 - Type confusion

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to a type confusion in nx_crypto_ctx_exit in the nx crypto driver when releasing AF_ALG-backed crypto contexts. A local user can trigger the vulnerable cleanup path to cause a denial of service.

The issue can be reached when AF_ALG is used opportunistically during local operations such as closing a socket.


353) Use-after-free (CVE-ID: CVE-2026-63804)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to a use-after-free in gfs2_qd_dealloc when processing pending RCU callbacks during filesystem unmount. A local user can trigger quota object disposal and unmount-related cleanup to cause a denial of service.

The issue occurs because an RCU callback may access the superblock after it has already been freed.


354) Use-after-free (CVE-ID: CVE-2026-63803)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to a use-after-free in the hdlc ppp per-protocol timer handling when detaching the ppp protocol or re-attaching it while timers are still active. A local user can trigger protocol teardown while a timer callback is executing to cause a denial of service.

The issue affects LCP, IPCP, and IPV6CP control protocol timers embedded in the PPP state.


355) Use-after-free (CVE-ID: CVE-2026-63802)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 5.7 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to use-after-free in __blkcg_rstat_flush() when releasing multiple blkgs in the same blkcg concurrently. A local user can trigger concurrent blkg release operations to cause a denial of service.

The race occurs when one blkg removes another blkg's iostat entries via llist_del_all() while the other blkg is still being processed.


356) Use-after-free (CVE-ID: CVE-2026-63801)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 8.2 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to cause a denial of service.

The vulnerability exists due to use-after-free in tipc_aead_decrypt_done in the TIPC crypto subsystem when processing crafted encrypted frames during asynchronous decryption. A remote attacker can send crafted encrypted frames to trigger a read from freed memory and cause a denial of service.

Exploitation requires the asynchronous decryption path to be used and can occur while the associated network namespace is being torn down.


357) Use-after-free (CVE-ID: CVE-2026-63800)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to use-after-free in pnfs_update_layout() when handling the NFS_LAYOUT_RETURN branch. A local user can trigger the vulnerable code path to cause a denial of service.


358) Out-of-bounds write (CVE-ID: CVE-2026-63799)

CWE-ID: CWE-787 - Out-of-bounds write

CVSSv4: 5.8 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to corrupt kernel memory.

The vulnerability exists due to an out-of-bounds write in mm_cid_schedout() via mm_cid_fixup_cpus_to_tasks() when handling a task with MM_CID_UNSET in the per-CPU to per-task fixup path. A local user can trigger task state transitions such as fork() or execve() during this window to corrupt kernel memory.

The issue occurs only in per-CPU CID mode during the window before the task's next schedule-in assigns a real CID, and the resulting corruption is a deterministic single-bit clear at a fixed offset rather than an arbitrary write.


359) Use-after-free (CVE-ID: CVE-2026-63798)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to a use-after-free in the irq-imgpdc driver when handling interrupts after driver removal. A local user can trigger spurious interrupts that access freed memory to cause a denial of service.

The issue involves dangling chained handlers for peripheral and syswake interrupts, and generic chips may remain reachable by interrupt chip suspend, resume, or shutdown callbacks after the driver has been removed.


360) Use-after-free (CVE-ID: CVE-2026-63797)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to use-after-free in rpmsg_chrdev_probe() and the rpmsg character device endpoint callback handling in drivers/rpmsg/rpmsg_char.c when processing callbacks during a probe error path. A local user can trigger endpoint creation failure and concurrent callback handling to cause a denial of service.

The issue occurs because the default endpoint's priv pointer can reference freed memory before endpoint setup has completed.


361) Out-of-bounds read (CVE-ID: CVE-2026-63796)

CWE-ID: CWE-125 - Out-of-bounds read

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to an out-of-bounds read in the ocfs2 group descriptor bitmap handling in fs/ocfs2/suballoc.c when processing a crafted group bitmap descriptor. A local user can provide a descriptor with oversized bg_size or bg_bits values to cause a denial of service.

Exploitation requires access to a malicious ocfs2 filesystem image or on-disk metadata.


362) Use-after-free (CVE-ID: CVE-2026-63795)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to a use-after-free in p9_client_walk() when handling a failed non-cloning walk after a request has been sent. A local user can trigger a multi-component walk split into multiple p9_client_walk() calls to cause a denial of service.

The issue occurs because fid may alias oldfid, causing a reference owned by the caller to be dropped while the caller still expects the object to remain valid.


363) Out-of-bounds write (CVE-ID: CVE-2026-63794)

CWE-ID: CWE-787 - Out-of-bounds write

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause memory corruption.

The vulnerability exists due to an out-of-bounds write in sev_dbg_crypt() when processing crafted KVM SEV debug encryption requests. A local user can send a crafted ioctl request with page offsets that cause the transfer length to exceed the destination page boundary to cause memory corruption.

The issue affects the encrypt path and can overflow a single-page intermediate buffer by up to 15 bytes when the destination offset is greater than the source offset.


364) NULL pointer dereference (CVE-ID: CVE-2026-53403)

CWE-ID: CWE-476 - NULL Pointer Dereference

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to a null pointer dereference in fb_videomode_to_var in the fbdev subsystem when processing a userspace-supplied modelist that does not contain the current framebuffer mode. A local user can supply a crafted mode list to trigger a kernel crash and cause a denial of service.

Exploitation requires fbcon to be unbound so that the current mode is left without a matching entry before a later console takeover occurs.


365) Out-of-bounds read (CVE-ID: CVE-2026-53402)

CWE-ID: CWE-125 - Out-of-bounds read

CVSSv4: 5.7 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local user to disclose sensitive information.

The vulnerability exists due to an out-of-bounds read in fbcon_do_set_font() and subsequent rendering in the fbcon console subsystem when handling a failed font change rollback and later rendering user-controlled character indices. A local user can trigger a font change failure and then supply character indices greater than 255 to disclose sensitive information.

Exploitation requires a failure in the font-setting error path that leaves the console state desynchronized after vc_resize() fails.


366) Use-after-free (CVE-ID: CVE-2026-53401)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 6.9 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to access freed physical memory.

The vulnerability exists due to a use-after-free in omapfb_mmap when racing a memory mapping request with OMAPFB_SETUP_PLANE and OMAPFB_SETUP_MEM operations. A local user can trigger concurrent framebuffer operations to access freed physical memory.

The issue is caused by inconsistent use of region data and map_count tracking across concurrent execution paths.


367) Race condition (CVE-ID: CVE-2026-53400)

CWE-ID: CWE-362 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to a race condition in the i2c adapter registration logic when looking up adapters by id during registration. A local user can trigger concurrent adapter lookup and registration activity to cause a denial of service.

The issue can lead to access to uninitialized adapter data, including NULL-pointer dereferences or use-after-free.


368) Use-after-free (CVE-ID: CVE-2026-53399)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 6 [CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote user to cause a denial of service.

The vulnerability exists due to a use-after-free in the nfsd layout stateid handling in fs/nfsd/nfs4layouts.c when processing layout stateid allocation failures after a setlease error. A remote user can trigger a setlease failure and subsequent IDR walker access to dereference a dangling pointer to cause a denial of service.

The issue occurs because a published stateid remains referenced in the IDR after the associated memory is freed, and a related destructor path may access uninitialized delayed work on the same failure path.


369) Improper Initialization (CVE-ID: CVE-2026-53398)

CWE-ID: CWE-665 - Improper Initialization

CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to cause a denial of service.

The vulnerability exists due to improper initialization in nfsd4_decode_secinfo_no_name() when processing a truncated XDR stream for the SECINFO_NO_NAME operation. A remote attacker can send a specially crafted request to cause a denial of service.

The issue occurs because stale union contents from a previous operation can leave sin_exp non-NULL, leading the error cleanup path to call exp_put() on an invalid value.


370) Memory leak (CVE-ID: CVE-2026-53397)

CWE-ID: CWE-401 - Missing release of memory after effective lifetime

CVSSv4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a remote user to cause a denial of service.

The vulnerability exists due to a memory leak in the nfsd SETACL request decoding and release handling when processing crafted NFS ACL SETACL requests. A remote user can send a specially crafted SETACL request that triggers a decode failure after partial ACL allocation to cause a denial of service.

The leaked posix_acl object remains allocated for the lifetime of the server.


371) Unchecked Return Value (CVE-ID: CVE-2026-53396)

CWE-ID: CWE-252 - Unchecked Return Value

CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to bypass attribute validation.

The vulnerability exists due to improper check for unusual or exceptional conditions in nfsd4_create_file() when converting NFSv4 ACLs during CREATE processing. A remote attacker can send ACL attributes containing unsupported ACE types to bypass attribute validation.

The server may create the file without any ACL and still return NFS4_OK instead of rejecting unsupported attributes.


372) Improper Check or Handling of Exceptional Conditions (CVE-ID: CVE-2026-53396)

CWE-ID: CWE-703 - Improper Check or Handling of Exceptional Conditions

CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to cause a denial of service.

The vulnerability exists due to improper error handling in nfsd4_create_file() when processing OPEN(CREATE) requests with ACL attributes and an invalid filename. A remote attacker can send a specially crafted OPEN(CREATE) request to cause a denial of service.

The issue can be triggered repeatedly by supplying ACL attributes together with a filename longer than NAME_MAX.


373) Memory leak (CVE-ID: CVE-2026-53395)

CWE-ID: CWE-401 - Missing release of memory after effective lifetime

CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to cause a denial of service.

The vulnerability exists due to a memory leak in nfsd4_create in the NFS server when processing a CREATE request with both FATTR4_WORD0_ACL and FATTR4_WORD2_POSIX_DEFAULT_ACL or FATTR4_WORD2_POSIX_ACCESS_ACL encoded in the same fattr bitmap. A remote attacker can send repeated specially crafted CREATE requests to cause a denial of service.

The issue leaks two posix_acl slab objects per request, which can lead to unbounded slab exhaustion.


374) Memory leak (CVE-ID: CVE-2026-53394)

CWE-ID: CWE-401 - Missing release of memory after effective lifetime

CVSSv4: 6.3 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to cause a denial of service.

The vulnerability exists due to a memory leak in find_or_alloc_open_stateowner() in the NFSv4 server state handling code when processing concurrent NFSv4.0 OPEN operations with the same owner string during an unconfirmed retry race. A remote attacker can trigger repeated racing OPEN requests to cause a denial of service.

The issue requires a narrow but repeatable race condition involving two NFSv4.0 OPEN threads and a concurrent insertion of a new unconfirmed owner between retry iterations.


375) Always-Incorrect Control Flow Implementation (CVE-ID: CVE-2026-53393)

CWE-ID: CWE-670 - Always-Incorrect Control Flow Implementation

CVSSv4: 7.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote user to cause silent data loss.

The vulnerability exists due to improper state management in nfsd_vfs_write() and nfsd_commit() when handling deferred writeback errors for UNSTABLE write data followed by COMMIT. A remote user can trigger writeback errors and then issue COMMIT operations to cause silent data loss.

The issue violates the UNSTABLE+COMMIT durability contract by returning an unchanged write verifier after failed writeback.


376) Improper input validation (CVE-ID: CVE-2026-53392)

CWE-ID: CWE-20 - Improper input validation

CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to cause a denial of service.

The vulnerability exists due to improper input validation in ff_layout_alloc_lseg() in the NFSv4 flexfiles layout handling when processing a malformed flexfiles layout body with a zero filehandle-version array count. A remote attacker can send a specially crafted flexfiles layout to cause a denial of service.

The issue can lead to a null pointer dereference and kernel panic.


377) NULL pointer dereference (CVE-ID: CVE-2026-53391)

CWE-ID: CWE-476 - NULL Pointer Dereference

CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to cause a denial of service.

The vulnerability exists due to a NULL pointer dereference in nfs4_decode_mp_ds_addr() when processing a crafted GETDEVICEINFO multipath-DS body containing a zero-length r_addr or r_netid value. A remote attacker can send malicious metadata server responses to cause a denial of service.

The issue is reachable from a pNFS-flexfile client mounted against a malicious or compromised metadata server.


378) Out-of-bounds read (CVE-ID: CVE-2026-53390)

CWE-ID: CWE-125 - Out-of-bounds read

CVSSv4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote user to disclose sensitive information.

The vulnerability exists due to an out-of-bounds read in smb_check_perm_dacl() when processing a crafted security descriptor during an SMB2_CREATE access check. A remote user can store a crafted ACE via SMB2_SET_INFO to disclose sensitive information.

Exploitation is reachable on a share that uses ACL xattrs, and the malformed descriptor is processed on a subsequent access check.


379) Use-after-free (CVE-ID: CVE-2026-53389)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local user to disclose sensitive information.

The vulnerability exists due to a use-after-free in tcp_ao_delete_key() in net/ipv4/tcp_ao.c when deleting a TCP-AO key asynchronously and later querying TCP_AO_INFO. A local user can delete a key with del_async enabled after setting it as the current or rnext key to disclose sensitive information.

The issue occurs when a key was assigned as the current or rnext key while the socket was in CLOSE state and the socket is later transitioned to LISTEN.


380) Use-after-free (CVE-ID: CVE-2026-53388)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to use-after-free in fuse_try_move_folio() in the FUSE subsystem when moving a page cache folio during FUSE read handling. A local user can trigger a race condition to cause a denial of service.

The issue occurs because the request is not re-locked on the success path, allowing request abortion to free fuse_io_args while subsequent copy logic still accesses it.


381) Out-of-bounds read (CVE-ID: CVE-2026-53387)

CWE-ID: CWE-125 - Out-of-bounds read

CVSSv4: 5.7 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to an out-of-bounds read in the veml6075_request_measurement function when processing the VEML6075_CONF_IT register value. A local user can trigger an out-of-range index value to cause a denial of service.

Exploitation requires fault device behavior, misprogramming, or bus corruption to produce a reserved register value.


382) Out-of-bounds read (CVE-ID: CVE-2026-53386)

CWE-ID: CWE-125 - Out-of-bounds read

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to an out-of-bounds read in the ads1298_get_scale function when processing register values used to index the ads1298_pga_settings array. A local user can trigger an out-of-range index to cause a denial of service.

The issue occurs when the extracted PGA field contains the reserved value b111.


383) NULL pointer dereference (CVE-ID: CVE-2026-53385)

CWE-ID: CWE-476 - NULL Pointer Dereference

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to a null pointer dereference caused by a race condition in vcs_notifier() in drivers/tty/vt/vc_screen.c when handling concurrent vcs_write operations. A local user can trigger concurrent write activity to cause a denial of service.

The issue occurs after the console lock is temporarily dropped and re-acquired, allowing the vc_data pointer to become stale before notifier processing.


384) Use-after-free (CVE-ID: CVE-2026-53384)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service or execute arbitrary code.

The vulnerability exists due to a use-after-free in the 8250_dw serial driver when handling a failed clock notifier registration during device probe. A local user can trigger the error path and access the stale port slot to cause a denial of service or execute arbitrary code.

The issue occurs because the 8250 port remains registered after probe failure while its associated driver data has already been freed.


385) Improper access control (CVE-ID: CVE-2026-53383)

CWE-ID: CWE-284 - Improper Access Control

CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to cause a denial of service.

The vulnerability exists due to improper access control in smb2_check_user_session() and the ksmbd compound request handling path when processing a crafted compound SMB request with a non-valid session. A remote attacker can send a specially crafted compound request to cause a denial of service.

By using SESSION_SETUP as the first compound operation and a related TREE_CONNECT request with SessionId set to ULLONG_MAX as the second operation, an in-progress session can reach a NULL pointer dereference because sess->user remains NULL.


386) NULL pointer dereference (CVE-ID: CVE-2026-53382)

CWE-ID: CWE-476 - NULL Pointer Dereference

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to a NULL pointer dereference in vidtv_mux_push_si when handling PID contexts during stream information processing. A local user can trigger allocation failure conditions that leave a PID context unset to cause a denial of service.

The issue can lead to a general protection fault in the vidtv test driver workqueue path.


387) Use-after-free (CVE-ID: CVE-2026-53381)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to a use-after-free in fuse_release_end() during virtiofs auto_submount unmount processing when releasing files during submount unmount after the superblock has already been destroyed. A local user can trigger submount unmount activity to cause a denial of service.

The issue affects the virtiofs auto_submounts case, where the wait counter is tracked per connection rather than per superblock.


388) Out-of-bounds write (CVE-ID: CVE-2026-53366)

CWE-ID: CWE-787 - Out-of-bounds write

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to an out-of-bounds write in __ip_append_data() when processing IPv4 packet data on the paged allocation path. A local user can trigger the faulty length calculations to cause a denial of service.

The issue occurs because fraggap bytes copied from the previous skb are placed into the new skb linear area while the allocation size does not account for those bytes.


389) Improper control of a resource through its lifetime (CVE-ID: CVE-2026-53363)

CWE-ID: CWE-664 - Improper control of a resource through its lifetime

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to improper state management in iptfs_consume_frags() when transferring paged fragments between socket buffers. A local user can trigger processing of fragments backed by read-only page-cache pages to cause a denial of service.

The issue occurs because the shared-fragment marker is not preserved, which can cause ESP to make an incorrect decision about whether in-place encryption is safe.


390) Out-of-bounds write (CVE-ID: CVE-2026-53362) Exploited

CWE-ID: CWE-787 - Out-of-bounds write

CVSSv4: 6.9 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to corrupt kernel memory.

The vulnerability exists due to an out-of-bounds write in __ip6_append_data() when processing UDPv6 socket data with MSG_MORE and MSG_SPLICE_PAGES on the paged allocation path. A local user can send crafted data through a UDPv6 socket to corrupt kernel memory.

The issue occurs when fraggap is non-zero and the paged-allocation branch is taken, causing writes past skb->end into trailing skb_shared_info.


391) Race condition (CVE-ID: CVE-2026-53361)

CWE-ID: CWE-362 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')

CVSSv4: 5.7 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to a race condition in unix_gc() and unix_peek_fpl() in the af_unix garbage collection logic when processing MSG_PEEK operations during garbage collection scheduling. A local user can trigger concurrent garbage collection activity to cause a denial of service.

The issue occurs because gc_in_progress may be false while unix_gc() is running, which can confuse garbage collection by MSG_PEEK.


392) Use of Out-of-range Pointer Offset (CVE-ID: CVE-2026-53356)

CWE-ID: CWE-823 - Use of Out-of-range Pointer Offset

CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local user to disclose or modify unintended memory contents.

The vulnerability exists due to improper pointer handling in i915_gem_object_pread_phys and i915_gem_object_pwrite_phys in the i915 GEM physical buffer object handling code when processing pread or pwrite operations with a non-zero offset. A local user can supply crafted offset values to access the wrong parts of a physical buffer object to disclose or modify unintended memory contents.

The issue affects physical buffer objects on impacted platforms using overlay or cursor planes with physical mapping.


393) Use-after-free (CVE-ID: CVE-2026-53355)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to a use-after-free in the rds ib connection teardown path when unwinding a failed queue pair setup. A local user can trigger a setup failure after allocating the send ring to cause a denial of service.

The issue occurs when rds_ib_setup_qp() fails after allocating i_sends but before allocating i_recvs, leaving a stale pointer that may be treated as a live allocation during a later shutdown pass.


394) Race condition (CVE-ID: CVE-2026-53354)

CWE-ID: CWE-362 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to improper synchronization in broadcast TLBI completion handling in the arm64 CPU errata logic when performing broadcast TLB invalidation on affected Arm CPUs. A local user can trigger memory management activity to cause a denial of service.

The issue affects completion of memory accesses translated by an invalidated TLB entry, while TLB invalidation itself still occurs correctly.


395) Improper Check for Unusual or Exceptional Conditions (CVE-ID: CVE-2026-53353)

CWE-ID: CWE-754 - Improper Check for Unusual or Exceptional Conditions

CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to improper handling of a missing internal state in hsr_addr_is_self() when processing packets during device teardown. A local user can send packets through an HSR device during the teardown window to cause a kernel warning.

The issue occurs in a window where the device remains discoverable after self_node has been cleared.


396) Race condition (CVE-ID: CVE-2026-53352)

CWE-ID: CWE-362 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to a race condition in zap_other_threads() when handling a concurrent execve() during a pending group stop. A local user can trigger this race to cause a denial of service.

The issue occurs when a multithreaded process receives a stop signal while one thread concurrently calls execve().


397) Improper Check or Handling of Exceptional Conditions (CVE-ID: CVE-2026-53351)

CWE-ID: CWE-703 - Improper Check or Handling of Exceptional Conditions

CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to improper handling of core dump note types in riscv ptrace REGSET_CFI support when dumping a core file. A local user can trigger a core dump to cause a denial of service.

The issue is evidenced by a kernel warning in elf_core_dump on RISC-V systems.


398) NULL pointer dereference (CVE-ID: CVE-2026-53350)

CWE-ID: CWE-476 - NULL Pointer Dereference

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to a null pointer dereference in wm_adsp_control_remove() when removing firmware controls. A local user can trigger removal of a control without associated private control data to cause a denial of service.

The issue occurs for controls where private data is not created, including SYSTEM controls and controls hidden by a codec driver's control_add() callback.


399) Use-after-free (CVE-ID: CVE-2026-53349)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 5.6 [CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local privileged user to cause a denial of service.

The vulnerability exists due to a use-after-free in netfilter nf_conntrack expectation handling when processing an expected connection after a NAT helper module has been unloaded. A local privileged user can unload a NAT helper module while live expectations remain and then trigger the expected connection to cause a denial of service.

Reaching the vulnerable state requires CAP_SYS_MODULE in the initial user namespace to remove a NAT helper that still has live expectations.


400) NULL pointer dereference (CVE-ID: CVE-2026-53348)

CWE-ID: CWE-476 - NULL Pointer Dereference

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local attacker to cause a denial of service.

The vulnerability exists due to a NULL pointer dereference in sdca_dev_unregister_functions when unregistering SDCA function devices after partial registration failure or cleanup races with probe deferral. A local attacker can trigger device registration failure or a cleanup race to cause a denial of service.

This can result in a kernel oops during SoundWire device cleanup.


401) Use of uninitialized resource (CVE-ID: CVE-2026-53347)

CWE-ID: CWE-908 - Use of Uninitialized Resource

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to access of uninitialized data in the virtio-gpu driver removal path when removing or unbinding the driver with KMS disabled. A local user can trigger driver removal or unbinding to cause a denial of service.

Only configurations where the virtio-gpu driver is built with KMS disabled are affected.


402) Always-Incorrect Control Flow Implementation (CVE-ID: CVE-2026-53346)

CWE-ID: CWE-670 - Always-Incorrect Control Flow Implementation

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to improper generation of unwind table metadata in arm64 Rust build handling when booting a kernel with CONFIG_UNWIND_PATCH_PAC_INTO_SCS enabled. A local user can execute code in a vulnerable kernel build to trigger a crash during boot.

The issue affects compiler-generated constructors such as kasan constructors, where incorrect dwarf information can cause illegal patching of paciasp and autiasp instructions.


403) Improper Check or Handling of Exceptional Conditions (CVE-ID: CVE-2026-53345)

CWE-ID: CWE-703 - Improper Check or Handling of Exceptional Conditions

CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to improper handling of a warning condition in KVM memory dirty page tracking in virt/kvm/kvm_main.c when destroying a vCPU after certain SEV-ES VM-Exits without a subsequent KVM_RUN. A local user can trigger this condition to cause a denial of service.

The issue occurs in SEV-ES guest scenarios where KVM retains a writable mapping of a guest page across an exit to userspace.


404) NULL pointer dereference (CVE-ID: CVE-2026-53344)

CWE-ID: CWE-476 - NULL Pointer Dereference

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local attacker to cause a denial of service.

The vulnerability exists due to a NULL pointer dereference in the mcp23s08 probe path when initializing regmap during device probe. A local attacker can trigger device probe to cause a denial of service.

The issue occurs because regmap initialization triggers an SPI read to populate the cache before the device and address fields are initialized.


405) Memory corruption (CVE-ID: CVE-2026-53343)

CWE-ID: CWE-119 - Memory corruption

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local attacker to cause a denial of service.

The vulnerability exists due to improper memory access in __switch_to() when performing a dummy read from the KASAN VMAP stack shadow. A local attacker can trigger execution on an affected ARM system to cause a denial of service.

Only ARM systems with CONFIG_KASAN_VMALLOC and CONFIG_VMAP_STACK enabled are affected, and the issue can cause an alignment exception before reaching init.


406) Improper resource shutdown or release (CVE-ID: CVE-2026-53342)

CWE-ID: CWE-404 - Improper Resource Shutdown or Release

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to improper resource shutdown in free_hotplug_pgtable_page() when freeing hot-removed page tables. A local user can trigger memory hot-remove operations to cause a denial of service.

With DEBUG_VM enabled, the issue can trigger a bad page state warning. If ALLOC_SPLIT_PTLOCKS is defined, it can also leak page table lock allocations and corrupt NR_PAGETABLE accounting.


407) Use-after-free (CVE-ID: CVE-2026-53341)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 5.7 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to a use-after-free in may_decode_fh() when handling open_by_handle_at requests during concurrent mount namespace teardown. A local user can trigger a race condition to cause a denial of service.

The issue is reachable only on systems with CONFIG_PREEMPTION or CONFIG_RCU_STRICT_GRACE_PERIOD enabled.


408) Improper control of a resource through its lifetime (CVE-ID: CVE-2026-53340)

CWE-ID: CWE-664 - Improper control of a resource through its lifetime

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to improper state management in i2c_imx_runtime_suspend() and i2c_imx_runtime_resume() when handling runtime power management state transitions. A local user can trigger runtime suspend and subsequent hardware access to cause a denial of service.

The issue can leave the clock disabled after a suspend failure, causing a system crash when the hardware is subsequently accessed.


409) NULL pointer dereference (CVE-ID: CVE-2026-53339)

CWE-ID: CWE-476 - NULL Pointer Dereference

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to a NULL pointer dereference in cci_remove() in the i2c-qcom-cci driver when removing or unbinding the driver on systems where only one I2C master is initialized. A local user can trigger device unbinding or driver removal to cause a denial of service.

Only systems where the Qualcomm CCI controller exposes two I2C masters but only one master is enabled are affected.


410) NULL pointer dereference (CVE-ID: CVE-2026-53338)

CWE-ID: CWE-476 - NULL Pointer Dereference

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local attacker to cause a denial of service.

The vulnerability exists due to a NULL pointer dereference in airoha_qdma_init_hfwd_queues() when processing a missing reserved memory region referenced by the "memory-region" phandle. A local attacker can trigger the vulnerable code path to cause a denial of service.

The issue can occur when the referenced reserved memory entry is absent from the reserved memory table, such as with a misconfigured device tree.


411) NULL pointer dereference (CVE-ID: CVE-2026-53337)

CWE-ID: CWE-476 - NULL Pointer Dereference

CVSSv4: 6.7 [CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local privileged user to cause a denial of service.

The vulnerability exists due to a NULL pointer dereference in bond_do_ioctl() when handling bonding ioctl requests with a non-existent slave interface name. A local privileged user can send a bonding ioctl request referencing a non-existent slave interface to cause a denial of service.

The issue is reachable from userspace through the bonding ioctl interface.


412) Infinite loop (CVE-ID: CVE-2026-53336)

CWE-ID: CWE-835 - Loop with Unreachable Exit Condition ('Infinite Loop')

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local attacker to cause a denial of service.

The vulnerability exists due to an infinite loop in the onie-tlv nvmem layout driver when parsing EEPROM entries with unknown types. A local attacker can provide a crafted EEPROM image containing a vendor-specific or otherwise unknown TLV entry to cause a denial of service.


413) NULL pointer dereference (CVE-ID: CVE-2026-53335)

CWE-ID: CWE-476 - NULL Pointer Dereference

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to a NULL pointer dereference in damon_lru_sort_enabled_store() when handling DAMON_LRU_SORT enablement after damon_ctx allocation failure. A local user can trigger the vulnerable code path to cause a denial of service.


414) NULL pointer dereference (CVE-ID: CVE-2026-53334)

CWE-ID: CWE-476 - NULL Pointer Dereference

CVSSv4: 5.7 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to a NULL pointer dereference in damon_reclaim_enabled_store() in mm/damon/reclaim.c when handling DAMON_RECLAIM enablement after damon_ctx allocation failure. A local user can trigger the vulnerable code path to cause a denial of service.

The issue occurs only if allocation of the damon_ctx object fails before the affected code path is reached.


415) Improper Check or Handling of Exceptional Conditions (CVE-ID: CVE-2026-53333)

CWE-ID: CWE-703 - Improper Check or Handling of Exceptional Conditions

CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to improper handling of non-swap entries in mincore_swap() in mm/mincore.c when processing migration, hwpoison, or shmem swapin-error entries on kernels built without swap support. A local user can trigger mincore page table handling of such entries to cause a denial of service.

Only kernels built without swap support are affected, and the issue can arise when migration or memory failure related features are enabled.


416) Use of Uninitialized Variable (CVE-ID: CVE-2026-53332)

CWE-ID: CWE-457 - Use of Uninitialized Variable

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local attacker to cause a denial of service.

The vulnerability exists due to use of uninitialized data in the qcom-ngd-ctrl driver when callbacks are triggered during NGD driver probing before device initialization completes. A local attacker can trigger parallel remoteproc startup or hardware interrupt handling to cause a denial of service.

The issue can prevent affected boards from booting.


417) Improper locking (CVE-ID: CVE-2026-53331)

CWE-ID: CWE-667 - Improper Locking

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to improper lock handling in qcom_slim_ngd_ssr_pdr_notify() and slim_report_absent() when processing SSR/PDR down notifications. A local user can trigger the vulnerable locking sequence to cause a denial of service.

The issue arises from inconsistent lock ordering between ctrl->tx_lock and ctrl->lock, creating a possible deadlock.


418) Out-of-bounds read (CVE-ID: CVE-2026-53330)

CWE-ID: CWE-125 - Out-of-bounds read

CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local attacker to disclose sensitive information.

The vulnerability exists due to out-of-bounds read in dp_get_eq_aux_rd_interval() when processing DisplayPort repeater capability data. A local attacker can provide crafted repeater count information to trigger an out-of-bounds read and disclose sensitive information.

The issue occurs when a sink reports 8 LTTPR repeaters, causing access beyond the declared aux_rd_interval array bounds.


419) Integer overflow (CVE-ID: CVE-2026-53329)

CWE-ID: CWE-190 - Integer overflow

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to an integer overflow in dal_vector_reserve() in the AMD display vector implementation when resizing a vector buffer. A local user can trigger allocation size wraparound to cause a denial of service.

Successful exploitation can lead to a heap overflow on subsequent vector appends.


420) NULL pointer dereference (CVE-ID: CVE-2026-53328)

CWE-ID: CWE-476 - NULL Pointer Dereference

CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to improper handling of a NULL pointer state in scx_cgroup_move_task() when processing cgroup migration events under a sched_ext scheduler. A local user can trigger cgroup subtree_control changes to cause a kernel warning and destabilize the system.

The issue occurs when migration is driven by css identity rather than cgroup identity, allowing a legitimate css-only migration to reach the function with cgrp_moving_from unset.


421) Improper locking (CVE-ID: CVE-2026-53327)

CWE-ID: CWE-667 - Improper Locking

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to improper lock state handling in debugobjects fill_pool logic in lib/debugobjects.c when refilling the debug object pool on RT-enabled kernels while the current task is blocked on an rt_mutex. A local user can trigger the vulnerable code path to cause a denial of service.

Only RT-enabled kernel configurations are affected.


422) Improper locking (CVE-ID: CVE-2026-53326)

CWE-ID: CWE-667 - Improper Locking

CVSSv4: 5.7 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to improper lock handling in debugobjects pool refill logic in lib/debugobjects.c when handling hard interrupts during early boot on PREEMPT_RT kernels. A local user can trigger an interrupt in a context that holds a lock required by the allocation path to cause a denial of service.

Exploitation requires a debug PREEMPT_RT kernel on an ARM64 system during the early boot window before scheduling is enabled.


423) Improper handling of exceptional conditions (CVE-ID: CVE-2026-53325)

CWE-ID: CWE-755 - Improper Handling of Exceptional Conditions

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to improper exception handling in agp_amd64_probe() in the AMD64 AGP driver when probing for AMD northbridge hardware in a virtualized environment without a physical AMD northbridge. A local user can trigger driver initialization to cause a denial of service.

The issue occurs because a negative error from cache_nbs() is not handled correctly, allowing initialization to continue until a NULL pointer is dereferenced in amd64_fetch_size().


424) Use-after-free (CVE-ID: CVE-2026-53276)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to use-after-free in iso_sock_rebind_bc() when handling a concurrent socket close during Bluetooth ISO socket rebinding. A local user can trigger a concurrent close operation to cause a denial of service.

The issue involves the hci_conn pointer in the Linux kernel Bluetooth ISO subsystem.


425) Use-after-free (CVE-ID: CVE-2026-53275)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 7.1 [CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to cause a denial of service.

The vulnerability exists due to use-after-free in __mld_query_work in net/ipv6/mcast.c when processing crafted MLD queries. A remote attacker can send a specially crafted MLD query packet to cause a denial of service.

The issue occurs because a pointer to the multicast group address is dereferenced after skb header reallocation following pskb_may_pull() calls.


426) Improper locking (CVE-ID: CVE-2026-53274)

CWE-ID: CWE-667 - Improper Locking

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to a logic flaw in __smc_setsockopt() when copying user-supplied socket option data while holding the socket lock. A local user can pass a userfaultfd-monitored or FUSE-backed memory page as the optval argument to cause a denial of service.

Exploitation can keep the socket lock held indefinitely and, when combined with asynchronous tear-down operations such as shutdown(), can exhaust kernel worker threads and trigger the hung task watchdog.


427) Use-after-free (CVE-ID: CVE-2026-53273)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to a use-after-free in the optee supplicant request handling in drivers/tee/optee/supp.c when a client exits before the supplicant finishes processing its request. A local user can trigger a race condition to cause a denial of service.

The issue occurs because the request can be freed by the client while its request ID remains referenced on the supplicant path.


428) Use-after-free (CVE-ID: CVE-2026-53272)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 5.7 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to a use-after-free in z_erofs_decompress_kickoff() when racing I/O completion with filesystem unmount. A local user can trigger the race condition to cause a denial of service.

The issue involves access to sbi->sync_decompress after the superblock information has been freed during unmount.


429) NULL pointer dereference (CVE-ID: CVE-2026-53271)

CWE-ID: CWE-476 - NULL Pointer Dereference

CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to cause a denial of service.

The vulnerability exists due to a null pointer dereference in smb2_oplock_break_noti() and smb2_lease_break_noti() in fs/smb/server/oplock.c when handling oplock or lease break notifications during a concurrent SMB2 LOGOFF. A remote attacker can trigger a concurrent logoff condition to cause a denial of service.

The issue is remotely triggerable and results in a kernel oops when ksmbd_conn_r_count_inc(conn) dereferences a NULL connection pointer.


430) Use-after-free (CVE-ID: CVE-2026-53270)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 6.7 [CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local privileged user to cause a denial of service.

The vulnerability exists due to a use-after-free in the IPVS scheduler handling in ip_vs_edit_service() when editing a service and unbinding the old scheduler. A local privileged user can trigger service reconfiguration while packets are being scheduled to cause a denial of service.

The issue occurs because packets may continue using the old scheduler after its scheduling data has been freed following an RCU grace period.


431) Race condition (CVE-ID: CVE-2026-53269)

CWE-ID: CWE-362 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to a race condition in the synproxy hook reference counting logic in netfilter when concurrently adding the first iptables target or nftables expression. A local user can trigger concurrent registration or teardown operations to cause a denial of service.

The issue affects on-demand netfilter hook registration performed by the SYNPROXY infrastructure from both iptables and nftables frontends.


432) Out-of-bounds read (CVE-ID: CVE-2026-53268)

CWE-ID: CWE-125 - Out-of-bounds read

CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to cause a denial of service.

The vulnerability exists due to out-of-bounds read in the conntrack_irc helper when parsing IRC DCC commands. A remote attacker can send specially crafted IRC traffic to cause a denial of service.


433) Stack-based buffer overflow (CVE-ID: CVE-2026-53267)

CWE-ID: CWE-121 - Stack-based buffer overflow

CVSSv4: 6.9 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause memory corruption.

The vulnerability exists due to a stack-based buffer overflow in nft_ct_get_eval and nft_ct_get_fast_eval in the netfilter nft_ct subsystem when processing a crafted nftables rule that uses a template conntrack object. A local user can create a crafted rule sequence to cause memory corruption.

The issue is triggered when a conntrack template created by a preceding expression is treated as a real conntrack entry by a subsequent expression on the same skb.


434) Improper control of a resource through its lifetime (CVE-ID: CVE-2026-53266)

CWE-ID: CWE-664 - Improper control of a resource through its lifetime

CVSSv4: 5.7 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to improper memory handling in the ebtables SNAT target ARP sender hardware address rewrite in net/bridge/netfilter/ebt_snat.c when processing ARP packets in bridge netfilter hooks. A local user can trigger ARP sender hardware address rewriting on a crafted nonlinear skb to cause a denial of service.

Exploitation requires the ARP sender hardware address rewrite path to be reached with a nonlinear skb fragment backed by a splice-imported file page.


435) Time-of-check Time-of-use (TOCTOU) Race Condition (CVE-ID: CVE-2026-53265)

CWE-ID: CWE-367 - Time-of-check Time-of-use (TOCTOU) Race Condition

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to a check-then-act race condition in smq_invalidate_mapping() in the dm-cache-policy-smq component when invalidating cache blocks concurrently. A local user can trigger concurrent invalidation operations to cause a denial of service.

The issue can corrupt the SMQ queues or hash table and may result in a double free condition.


436) Use-after-free (CVE-ID: CVE-2026-53264)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 5.7 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to a use-after-free in the net/sched action lifecycle handling in act_api when NEWTFILTER and DELFILTER are run concurrently. A local user can trigger concurrent filter operations to cause a denial of service.

The issue arises from a race between action lookup and action deletion under RCU-protected access.


437) Off-by-one (CVE-ID: CVE-2026-53263)

CWE-ID: CWE-193 - Off-by-one Error

CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to disclose sensitive information.

The vulnerability exists due to an off-by-one error in lowpan_iphc_mcast_ctx_addr_compress() when compressing multicast context addresses. A remote attacker can send network traffic that triggers the vulnerable compression path to disclose sensitive information.

Uninitialized kernel stack memory may be transmitted over the network via lowpan_push_hc_data().


438) Use-after-free (CVE-ID: CVE-2026-53262)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 7.3 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service or execute arbitrary code.

The vulnerability exists due to use-after-free in pppol2tp_ioctl() when processing ioctl requests while a concurrent socket close frees the associated l2tp_session after a controllable sleep during copy_from_user(). A local user can trigger a userfaultfd-assisted page fault sleep and race a socket close to dereference a stale session pointer to cause a denial of service or execute arbitrary code.

Exploitation requires local access to issue the ioctl and induce the race condition.


439) Memory leak (CVE-ID: CVE-2026-53261)

CWE-ID: CWE-401 - Missing release of memory after effective lifetime

CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to a memory leak in devlink_free() when freeing an unregistered devlink instance with a nested relation. A local user can trigger a probe failure after creating such a relation to cause a denial of service.

This can occur when a child devlink is linked to its parent before registration and the probe later fails.


440) Use-after-free (CVE-ID: CVE-2026-53259)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local attacker to cause a denial of service.

The vulnerability exists due to a use-after-free in ipv6 anycast address handling in net/ipv6/anycast.c when racing anycast address insertion and device teardown. A local attacker can trigger concurrent anycast join and teardown operations to cause a denial of service.

The issue occurs because a freed ifacaddr6 object can remain linked in the global inet6_acaddr_lst[] hash and later be dereferenced by readers under RCU.


441) Memory leak (CVE-ID: CVE-2026-53258)

CWE-ID: CWE-401 - Missing release of memory after effective lifetime

CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to a memory leak in cfg80211_scan() when handling split 6 ghz scanning failures. A local user can trigger a scan request that causes cfg80211_scan() to fail to cause a denial of service.

The issue occurs because the internal scan request is not released when scan setup fails during split 6 ghz scanning.


442) Improper input validation (CVE-ID: CVE-2026-53257)

CWE-ID: CWE-20 - Improper input validation

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to improper input validation in nl80211_calculate_ap_params() when processing wireless AP parameters. A local user can provide inconsistent HE or EHT capability and operation elements to cause a denial of service.

The issue can lead to a crash in mac80211 when EHT capability data is present without corresponding EHT operation data.


443) Use-after-free (CVE-ID: CVE-2026-53256)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 8.2 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to cause a denial of service.

The vulnerability exists due to a use-after-free in rfcomm_connect_ind() and rfcomm_get_sock_by_channel() when handling RFCOMM connection indications for a listener socket during a concurrent close. A remote attacker can trigger a race condition to cause a denial of service.

The issue occurs in the Linux kernel Bluetooth RFCOMM socket handling path when a listener socket is closed while a child socket is being queued, and KASAN reported the resulting slab-use-after-free in lock_sock_nested().


444) Out-of-bounds read (CVE-ID: CVE-2026-53255)

CWE-ID: CWE-125 - Out-of-bounds read

CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local user to disclose sensitive information.

The vulnerability exists due to an out-of-bounds read in the tlv_data_is_valid() advertising data parser in net/bluetooth/mgmt.c when processing a crafted MGMT_OP_ADD_ADVERTISING request. A local user can send a specially crafted advertising data field to disclose sensitive information.

The issue is triggered when a malformed field length byte appears at the end of the supplied buffer.


445) Out-of-bounds read (CVE-ID: CVE-2026-53254)

CWE-ID: CWE-125 - Out-of-bounds read

CVSSv4: 7.1 [CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to cause a denial of service.

The vulnerability exists due to out-of-bounds read in the Bluetooth RFCOMM MCC handlers when processing truncated MCC frames from a remote Bluetooth device. A remote attacker can send specially crafted truncated MCC frames to cause a denial of service.

The issue affects the RFCOMM MCC handling paths including rfcomm_recv_mcc(), rfcomm_recv_pn(), rfcomm_recv_rpn(), rfcomm_recv_rls(), and rfcomm_recv_msc().


446) Out-of-bounds read (CVE-ID: CVE-2026-53253)

CWE-ID: CWE-125 - Out-of-bounds read

CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to cause a denial of service.

The vulnerability exists due to an out-of-bounds read in bnep_rx_frame() and bnep_rx_control() in the BNEP packet parser when processing short BNEP frames. A remote attacker can send a specially crafted short BNEP SDU to cause a denial of service.

The issue is triggered by malformed control packets with missing fixed fields or an empty control payload.


447) Memory leak (CVE-ID: CVE-2026-53252)

CWE-ID: CWE-401 - Missing release of memory after effective lifetime

CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to a memory leak in bt_host_release() when handling failed Bluetooth HCI device initialization before hci_register_dev() completes. A local user can trigger device initialization failures to cause a denial of service.

The issue occurs because the unregistered device cleanup path bypasses hci_release_dev(), leaving the SRCU structure allocated in hci_alloc_dev() uncleared.


448) Improper update of reference count (CVE-ID: CVE-2026-53251)

CWE-ID: CWE-911 - Improper Update of Reference Count

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to improper reference count management in iso_conn_big_sync when handling Bluetooth ISO BIG sync operations. A local user can trigger the vulnerable code path to cause a denial of service.


449) Time-of-check Time-of-use (TOCTOU) Race Condition (CVE-ID: CVE-2026-53250)

CWE-ID: CWE-367 - Time-of-check Time-of-use (TOCTOU) Race Condition

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause out-of-bounds memory access.

The vulnerability exists due to a time-of-check time-of-use race condition in xsk_skb_metadata() when processing transmit metadata from a userspace-writable UMEM buffer. A local user can race to overwrite csum_start and csum_offset between validation and assignment to cause out-of-bounds memory access.

The issue occurs during checksum computation in the transmit path.


450) Improper access control (CVE-ID: CVE-2026-53249)

CWE-ID: CWE-284 - Improper Access Control

CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local user to disclose sensitive information.

The vulnerability exists due to improper access control in ip_options_get() in net/ipv4/ip_options.c when setting IPv4 Loose Source and Record Route or Strict Source and Record Route options. A local user can set crafted IP options to force packets through attacker-controlled nodes to disclose sensitive information.

Exposure depends on network paths that support and forward these IPv4 options.


451) Use-after-free (CVE-ID: CVE-2026-53248)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to use-after-free in airoha metadata dst teardown in the airoha network driver when processing received packets that retain a non-refcounted metadata_dst pointer. A local user can trigger teardown while stale skb dst references remain to cause a denial of service.

The issue arises because skb_dst_set_noref() requires RCU read-side protection and the destination object must remain valid until all RCU readers have completed.


452) Improper input validation (CVE-ID: CVE-2026-53245)

CWE-ID: CWE-20 - Improper input validation

CVSSv4: 7.1 [CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to cause a denial of service.

The vulnerability exists due to improper input validation in mrp_pdu_parse_vecattr when parsing crafted MRP vector attributes in protocol data units. A remote attacker can send a specially crafted MRP packet to cause a denial of service.

The issue can be triggered when a VectorAttribute uses a zero-length value set or event counts that cross byte boundaries.


453) Improper resource shutdown or release (CVE-ID: CVE-2026-53244)

CWE-ID: CWE-404 - Improper Resource Shutdown or Release

CVSSv4: 7.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote user to cause a denial of service.

The vulnerability exists due to improper resource shutdown or release in nfsd4_create_file() when handling NFS file creation on exported filesystems that use ->atomic_create and an error is returned. A remote user can trigger a file creation operation that causes atomic_create() to return an error to cause a denial of service.

The issue can leave the parent directory locked because an error pointer is passed to end_creating().


454) Use of Uninitialized Variable (CVE-ID: CVE-2026-53243)

CWE-ID: CWE-457 - Use of Uninitialized Variable

CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local user to disclose sensitive information.

The vulnerability exists due to use of an uninitialized variable in rseq_exit_user_update() when updating rseq state for a task. A local user can trigger the vulnerable code path to disclose sensitive information.


455) Race condition (CVE-ID: CVE-2026-53242)

CWE-ID: CWE-362 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to improper synchronization in snd_pcm_drain() when handling linked PCM streams during concurrent unlink operations. A local user can trigger concurrent drain and unlink activity to cause a denial of service.

The issue can corrupt wait queue lists and lead to a kernel panic through a NULL function pointer dereference during a subsequent wake-up.


456) Out-of-bounds read (CVE-ID: CVE-2026-53241)

CWE-ID: CWE-125 - Out-of-bounds read

CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local user to disclose sensitive information.

The vulnerability exists due to an out-of-bounds read in the ALSA sequencer dummy port event forwarding logic when processing UMP events for subscriber delivery. A local user can send a crafted UMP event to disclose sensitive information.


457) Use-after-free (CVE-ID: CVE-2026-53240)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to a use-after-free in __input_process_payload() in the xfrm iptfs implementation when processing packet reassembly state concurrently. A local user can trigger concurrent reassembly handling to cause a denial of service.

The issue arises from a race condition involving concurrent execution of iptfs_reassem_cont() or the drop_timer hrtimer during partial reassembly.


458) Use-after-free (CVE-ID: CVE-2026-53239)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to a use-after-free in xfrm_policy_bysel_ctx() and inexact bin handling in the xfrm policy subsystem when processing concurrent policy deletion and hash rebuild operations. A local user can trigger a race condition to cause a denial of service.

The issue occurs because an inexact bin may be freed during a window after the policy lock is released and before pruning is performed.


459) Out-of-bounds read (CVE-ID: CVE-2026-53238)

CWE-ID: CWE-125 - Out-of-bounds read

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to an out-of-bounds read in netlbl_unlabel_addrinfo_get() when handling crafted Generic Netlink requests with a shorter unlabeled address mask attribute. A local user can send a specially crafted Generic Netlink request to cause a denial of service.


460) NULL pointer dereference (CVE-ID: CVE-2026-53237)

CWE-ID: CWE-476 - NULL Pointer Dereference

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to a NULL pointer dereference in the mvebu GPIO suspend/resume handling in drivers/gpio/gpio-mvebu.c when processing suspend and resume operations for GPIO banks without PWM functionality. A local user can trigger a suspend or resume operation to cause a denial of service.

Only GPIO banks that do not have PWM functionality are affected.


461) Improper access control (CVE-ID: CVE-2026-53236)

CWE-ID: CWE-284 - Improper Access Control

CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local user to disclose sensitive information.

The vulnerability exists due to improper access control in SO_ATTACH_FILTER on TCP sockets when attaching a cBPF filter. A local user can attach a filter to leak TCP sequence and acknowledgment numbers to disclose sensitive information.

Exploitation requires access to create or control a TCP socket and use the socket option interface.


462) Improper input validation (CVE-ID: CVE-2026-53235)

CWE-ID: CWE-20 - Improper input validation

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local attacker to cause a denial of service.

The vulnerability exists due to improper input validation in skb_gro_receive_list() when processing GRO packets with non-linear skb data. A local attacker can trigger the vulnerable code path with a crafted packet state to cause a denial of service.

The issue can occur when an skb arrives via napi_gro_frags() with a zero skb_headlen and a non-zero GRO offset, leading to a BUG_ON condition in __skb_pull().


463) Use-after-free (CVE-ID: CVE-2026-53234)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local attacker to cause a denial of service.

The vulnerability exists due to use-after-free in the ibm emac network driver removal path when processing network activity during device removal after deferred network device unregistration. A local attacker can trigger packet processing during device removal to cause a denial of service.


464) Double free (CVE-ID: CVE-2026-53233)

CWE-ID: CWE-415 - Double Free

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to double free in netdev_nl_bind_rx_doit() in net/core/netdev-genl.c when handling netlink bind requests that trigger a genlmsg_reply() failure. A local user can send a crafted request with an already-full receive buffer to cause a denial of service.


465) Improper control of a resource through its lifetime (CVE-ID: CVE-2026-53232)

CWE-ID: CWE-664 - Improper control of a resource through its lifetime

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to improper state management in the phy probing logic for the sfp upstream handling when probe failure paths are processed. A local user can trigger phy probing failure and subsequent SFP events to cause a denial of service.

The issue can leave a dangling upstream reference on the sfp-bus that may later be used during SFP events.


466) Improper locking (CVE-ID: CVE-2026-53231)

CWE-ID: CWE-667 - Improper Locking

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to improper lock handling in phy_sfp_probe in the PHY setup path when setting up PHY-driven SFP cages for genphy devices. A local user can trigger PHY probing on a genphy-driven device to cause a denial of service.

The issue results in an RTNL deadlock.


467) Out-of-bounds read (CVE-ID: CVE-2026-53230)

CWE-ID: CWE-125 - Out-of-bounds read

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to an out-of-bounds read in mlx5_query_nic_vport_mac_list when querying a VF vport MAC list with a larger configured maximum than the PF capability-based buffer size. A local user can configure or trigger processing of a VF vport with a larger MAC list to cause a denial of service.

The issue occurs in the mlx5 driver while handling vport address list updates.


468) Improper resource shutdown or release (CVE-ID: CVE-2026-53229)

CWE-ID: CWE-404 - Improper Resource Shutdown or Release

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to improper resource shutdown or release in mlx5e_xmit_xdp_buff() in the mlx5 XDP transmit path when handling XDP_TX transmission failures in the XSK branch. A local user can trigger an XDP_TX transmit failure to cause a denial of service.

The issue occurs when sq->xmit_xdp_frame() returns false, such as when the XDPSQ is full, leaving DMA mappings and xdp_frame objects unreleased.


469) NULL pointer dereference (CVE-ID: CVE-2026-53227)

CWE-ID: CWE-476 - NULL Pointer Dereference

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to an invalid pointer dereference in the openvswitch datapath flow command handler when handling crafted flow set operations after a reply skb allocation failure. A local user can trigger the error-handling path to cause a denial of service.


470) Use-after-free (CVE-ID: CVE-2026-53226)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to a use-after-free in the rockchip gpio irq domain handling in drivers/gpio/gpio-rockchip.c when removing a gpio bank and later processing generic irq chip suspend, resume, or shutdown callbacks. A local user can trigger device removal so that stale generic irq chip entries are later dereferenced to cause a denial of service.

The issue is associated with leaked domain generic chip structures that remain on the global gc_list after the gpio bank has been removed.


471) Out-of-bounds read (CVE-ID: CVE-2026-53223)

CWE-ID: CWE-125 - Out-of-bounds read

CVSSv4: 6.9 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a local user to disclose sensitive information.

The vulnerability exists due to an out-of-bounds read in the generic timestamp cmsg path in net/socket.c when processing timestamped messages for AF_PACKET sockets. A local user can send or receive crafted packets on an AF_PACKET socket to disclose sensitive information.

Exploitation requires timestamping to be enabled, and information disclosure can occur when SO_RXQ_OVFL is enabled and a non-linear skb is processed.


472) Use-after-free (CVE-ID: CVE-2026-53222)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to use-after-free in the ptp_ocp_detach() driver removal path when unregistering the PTP clock after pin resources have already been freed. A local user can trigger driver removal to cause a denial of service.

The issue can occur while interrupt handling is still in flight during device unregistration.


473) NULL pointer dereference (CVE-ID: CVE-2026-53220)

CWE-ID: CWE-476 - NULL Pointer Dereference

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to a NULL pointer dereference in ebt_redirect_tg() in net/bridge/netfilter/ebt_redirect.c when reinjecting an NFQUEUE packet after bridge port state changes. A local user can remove or reassign the bridge port before reinjection to cause a denial of service.

The issue occurs if the bridge port is removed between the original hook invocation and NFQUEUE reinjection, and the device may also be moved to a different virtual device such as macvlan.


474) Information disclosure (CVE-ID: CVE-2026-53219)

CWE-ID: CWE-200 - Exposure of sensitive information to an unauthorized actor

CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local user to disclose sensitive information.

The vulnerability exists due to improper handling of partially failed copy_to_user operations in x_tables get-entries implementations when copying rule entries to userspace. A local user can provide a userspace buffer that faults during the initial header copy to disclose sensitive information.

On SMP kernels, the leaked value is the internal percpu counter allocation pointer. The issue affects the IPv4, IPv6, and ARP native and compat get-entries paths.


475) Use of uninitialized resource (CVE-ID: CVE-2026-53218)

CWE-ID: CWE-908 - Use of Uninitialized Resource

CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local user to disclose sensitive information.

The vulnerability exists due to an uninitialized memory exposure in nft_exthdr_init and the nft_exthdr evaluation paths when processing a userspace request with the NFT_EXTHDR_F_PRESENT flag set and an invalid length value. A local user can supply a crafted netfilter expression that causes uninitialized stack data from nft_regs to be retained in registers and disclose sensitive information.

The issue occurs because the initialized register bitmap can mark more bytes as written than the evaluation paths actually store when the presence flag is used.


476) Out-of-bounds read (CVE-ID: CVE-2026-53217)

CWE-ID: CWE-125 - Out-of-bounds read

CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local attacker to disclose sensitive information.

The vulnerability exists due to improper memory synchronization in mvpp2_rx() in the mvpp2 network driver when processing received packets on non-coherent DMA systems. A local attacker can send network traffic that triggers reception of a crafted frame to disclose sensitive information.

Only non-coherent DMA systems are affected.


477) NULL pointer dereference (CVE-ID: CVE-2026-53214)

CWE-ID: CWE-476 - NULL Pointer Dereference

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to a null pointer dereference in cleanup_prefix_route() when handling netlink requests to delete IPv6 addresses. A local user can send a crafted netlink message to trigger the null pointer dereference and cause a denial of service.

The issue occurs when addrconf_get_prefix_route() returns the fib6_null_entry sentinel with a NULL fib6_table pointer.


478) Memory leak (CVE-ID: CVE-2026-53213)

CWE-ID: CWE-401 - Missing release of memory after effective lifetime

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to improper handling of memory allocation failure in vc4 shader validation when processing crafted shader data. A local user can trigger a failed memory reallocation to cause a denial of service.


479) Use of Uninitialized Variable (CVE-ID: CVE-2026-53211)

CWE-ID: CWE-457 - Use of Uninitialized Variable

CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local user to disclose sensitive information.

The vulnerability exists due to an uninitialized memory exposure in nft_meta_bridge_get_eval() when handling NFT_META_BRI_IIFHWADDR register data. A local user can trigger a downstream load of the affected register span to disclose sensitive information.

The issue occurs because only 6 bytes are copied into a declared 8-byte destination register span, leaving 2 bytes of stale stack data available to userspace.


480) Memory leak (CVE-ID: CVE-2026-53210)

CWE-ID: CWE-401 - Missing release of memory after effective lifetime

CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to a memory leak in register_shm_helper() in the tee shared memory registration handler when processing a TEE_IOC_SHM_REGISTER request with a zero length. A local user can send a crafted ioctl request to cause a denial of service.

The issue is triggered when struct tee_ioctl_shm_register_data specifies a length of 0.


481) Stack-based buffer overflow (CVE-ID: CVE-2026-53209)

CWE-ID: CWE-121 - Stack-based buffer overflow

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to a stack-based buffer overflow in hci_adv_bcast_annoucement() when rebuilding Bluetooth advertising data with a prepended Broadcast Announcement. A local user can trigger handling of an oversized advertising payload to cause a denial of service.

The issue occurs when an existing advertising instance already contains the maximum extended advertising payload.


482) Improper input validation (CVE-ID: CVE-2026-53208)

CWE-ID: CWE-20 - Improper input validation

CVSSv4: 5.3 [CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to cause a denial of service.

The vulnerability exists due to improper input validation in l2cap_sig_channel() when processing oversized Bluetooth BR/EDR signaling packets. A remote attacker can send a specially crafted fixed-channel CID 0x0001 packet containing many L2CAP_ECHO_REQ commands to cause a denial of service.

Exploitation is possible by a Bluetooth BR/EDR peer within radio range before pairing.


483) Deadlock (CVE-ID: CVE-2026-53207)

CWE-ID: CWE-833 - Deadlock

CVSSv4: 5.7 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to a recursive spinlock self-deadlock in get_huge_page_for_hwpoison() when handling concurrent madvise(MADV_HWPOISON) calls on the same hugetlb page while racing with a concurrent unmap. A local user can trigger concurrent madvise(MADV_HWPOISON) operations to cause a denial of service.

The issue occurs when folio_put() drops the folio reference count to zero while hugetlb_lock is still held, leading free_huge_folio() to attempt to re-acquire the same non-recursive lock.


484) Improper input validation (CVE-ID: CVE-2026-53206)

CWE-ID: CWE-20 - Improper input validation

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to improper input validation in the firmware image parser in drivers/accel/ivpu/ivpu_fw.c when parsing firmware image headers. A local user can supply a specially crafted firmware image with misaligned or undersized runtime memory values to cause a denial of service.


485) Out-of-bounds read (CVE-ID: CVE-2026-53205)

CWE-ID: CWE-125 - Out-of-bounds read

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to an out-of-bounds read in the firmware log buffer handling in drivers/accel/ivpu/ivpu_fw_log.c when processing firmware-supplied log indices. A local user can supply invalid read or write indices to trigger out-of-bounds buffer access and cause a denial of service.

Exploitation requires firmware to provide invalid log buffer index values.


486) NULL pointer dereference (CVE-ID: CVE-2026-53204)

CWE-ID: CWE-476 - NULL Pointer Dereference

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to a NULL pointer dereference in stratix10_rsu_probe() and the stratix10 RSU receive callback path when handling rsu_send_msg() timeouts during probe. A local user can trigger a timeout condition so that additional requests are queued on a channel whose scl pointer has been cleared to cause a denial of service.

The issue occurs in error paths for COMMAND_RSU_DCMF_VERSION, COMMAND_RSU_DCMF_STATUS, COMMAND_RSU_MAX_RETRY, and COMMAND_RSU_GET_SPT_TABLE.


487) Heap-based buffer overflow (CVE-ID: CVE-2026-53203)

CWE-ID: CWE-122 - Heap-based Buffer Overflow

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to a heap-based buffer overflow in the ivpu_ms_get_info_ioctl function when processing a metric stream info query from firmware and copying the returned data into an allocated buffer. A local user can trigger the metric stream info query with a returned size larger than the allocated buffer to cause a denial of service.

The issue involves the accel/ivpu driver metric stream get_info ioctl path.


488) Stack-based buffer overflow (CVE-ID: CVE-2026-53202)

CWE-ID: CWE-121 - Stack-based buffer overflow

CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to execute arbitrary code.

The vulnerability exists due to a stack-based buffer overflow in the ivpu_ipc_receive function when processing firmware-supplied IPC message data. A local user can supply a crafted data_size value to trigger an oversized memcpy operation and execute arbitrary code.

Exploitation requires control over firmware-supplied message data.


489) Improper control of a resource through its lifetime (CVE-ID: CVE-2026-53201)

CWE-ID: CWE-664 - Improper control of a resource through its lifetime

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to improper state management in the drm/xe exec queue suspend handling when invalidating userptr VMAs during GPU suspend in LR/preempt-fence VM mode. A local user can trigger userptr invalidation while the queue is treated as idle to cause a denial of service.

The issue can result in missed TLB invalidation and page faults during userptr invalidation tests.


490) Improper access control (CVE-ID: CVE-2026-53200)

CWE-ID: CWE-284 - Improper Access Control

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local user to bypass execute permission restrictions.

The vulnerability exists due to improper access control in KVM arm64 nested virtualization translation handling when processing XN bits on systems without FEAT_XNX. A local user can manipulate a nested translation state to bypass execute permission restrictions.

The issue occurs because XN[0] is handled incorrectly when FEAT_XNX is not supported, which can result in execute permissions being granted unconditionally.


491) Memory corruption (CVE-ID: CVE-2026-53199)

CWE-ID: CWE-119 - Memory corruption

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to improper memory access in netvsc_copy_to_send_buf() when copying skb fragments into the VMBus send buffer. A local user can trigger packet transmission with page-backed fragments to cause a denial of service.

The issue occurs on 32-bit x86 systems with CONFIG_HIGHMEM enabled when fragment pages reside above the LOWMEM boundary, and the fault happens on the transmit softirq path.


492) Use-after-free (CVE-ID: CVE-2026-53198)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 7.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote user to cause a denial of service.

The vulnerability exists due to a use-after-free in smb2_cancel in ksmbd when handling a second SMB2_CANCEL for the same AsyncId after cancellation of a deferred byte-range lock. A remote user can send specially crafted SMB2_CANCEL requests to cause a denial of service.

Exploitation requires authentication to the SMB service and involves a deferred SMB2_LOCK request that blocks.


493) Deadlock (CVE-ID: CVE-2026-53197)

CWE-ID: CWE-833 - Deadlock

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to an improper lock handling race condition in iptfs_destroy_state() in the xfrm iptfs subsystem when canceling active high-resolution timers during state destruction. A local user can trigger timer activity and state destruction to cause a denial of service.

The issue can lead to an ABBA deadlock on SMP systems.


494) Heap-based buffer overflow (CVE-ID: CVE-2026-53196)

CWE-ID: CWE-122 - Heap-based Buffer Overflow

CVSSv4: 5.1 [CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows an attacker with physical access to cause a denial of service or execute arbitrary code.

The vulnerability exists due to a heap-based buffer overflow in get_manuf_info() in the io_ti USB serial driver when processing a crafted USB device EEPROM descriptor. An attacker with physical access can connect a malicious USB device with a forged Size field to trigger the overflow and cause a denial of service or execute arbitrary code.

The out-of-bounds access is compounded because a checksum routine also iterates over the device-controlled length after the EEPROM data is read.


495) Heap-based buffer overflow (CVE-ID: CVE-2026-53195)

CWE-ID: CWE-122 - Heap-based Buffer Overflow

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to a heap-based buffer overflow in build_i2c_fw_hdr() in the io_ti USB serial driver when parsing a crafted firmware file. A local user can supply a firmware image with an oversized Length field to cause a denial of service.

The issue arises because the Length field from the firmware image is not validated against the available destination buffer space before copying.


496) Out-of-bounds write (CVE-ID: CVE-2026-53194)

CWE-ID: CWE-787 - Out-of-bounds write

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to an out-of-bounds write in klsi_105_prepare_write_buffer() when processing writes to the tty device. A local user can write bulk_out_size or more bytes to the tty to cause a denial of service.

The issue is triggered when the write fifo holds at least the full bulk-out buffer size, causing data to be copied starting two bytes into a 64-byte buffer.


497) Use-after-free (CVE-ID: CVE-2026-53193)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service or potentially execute arbitrary code.

The vulnerability exists due to a use-after-free in the ALSA timer subsystem when closing and freeing timer objects that still have pending timer instances, including slave instances associated with a master instance. A local user can open and close a userspace-driven timer while other applications continue accessing the timer to cause a denial of service or potentially execute arbitrary code.

The issue can be triggered particularly when userspace-driven timers are enabled with CONFIG_SND_UTIMER.


498) Use-after-free (CVE-ID: CVE-2026-53192)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to use-after-free in snd_timer_user_params() when handling a concurrent SNDRV_TIMER_IOCTL_PARAMS ioctl during timer object release. A local user can trigger concurrent timer operations to cause a denial of service.

The issue affects userspace timer handling with CONFIG_SND_UTIMER enabled.


499) Improper control of a resource through its lifetime (CVE-ID: CVE-2026-53191)

CWE-ID: CWE-664 - Improper control of a resource through its lifetime

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to improper state management in io_uring bundle recv handling in io_uring/net when processing bundle recv retries with provided buffer rings in incremental mode. A local user can trigger partial buffer consumption across retry iterations to cause a denial of service.

Userspace may wrongly advance the ring head past an entry the kernel still uses.


500) Missing Release of Resource after Effective Lifetime (CVE-ID: CVE-2026-53190)

CWE-ID: CWE-772 - Missing Release of Resource after Effective Lifetime

CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to a reference count leak in virtio_gpu_dma_fence_wait() when handling fence wait errors inside dma_fence_unwrap_for_each(). A local user can trigger an error during fence waiting to cause a denial of service.


501) Use-after-free (CVE-ID: CVE-2026-53189)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to a use-after-free in __split_huge_pmd_locked() when splitting a huge PMD mapping. A local user can trigger the affected memory-management path to cause a denial of service.

The issue occurs because file/shmem RSS accounting may access freed folio state after the last folio reference is dropped.


502) Improper access control (CVE-ID: CVE-2026-53188)

CWE-ID: CWE-284 - Improper Access Control

CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local user to bypass device type validation.

The vulnerability exists due to improper access control in ib_get_ucaps() when handling a file descriptor for a device with a matching dev_t value. A local user can supply a file descriptor for a block device that masquerades as a ucap cdev to bypass device type validation.

The issue arises because relying only on dev_t is unsafe due to char/block aliasing.


503) Out-of-bounds read (CVE-ID: CVE-2026-53187)

CWE-ID: CWE-125 - Out-of-bounds read

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to an out-of-bounds read in UVERBS_METHOD_DMAH_ALLOC in drivers/infiniband/core/uverbs_std_types_dmah.c when processing a user-supplied UVERBS_ATTR_ALLOC_DMAH_CPU_ID value. A local user can supply a cpu_id outside the valid CPU range to cause a denial of service.

On systems built with CONFIG_DEBUG_PER_CPU_MAPS and panic_on_warn enabled, the issue can result in a machine reboot.


504) Use-after-free (CVE-ID: CVE-2026-53185)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to use-after-free in zram_bvec_write_partial() when processing partial writes for ZRAM_WB slots. A local user can trigger an asynchronous backing device read and subsequent access to a freed page to cause a denial of service.

The issue occurs because the read operation may still be in flight when the buffer page is freed.


505) Type Confusion (CVE-ID: CVE-2026-53184)

CWE-ID: CWE-843 - Type confusion

CVSSv4: 8.2 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to cause a denial of service.

The vulnerability exists due to a type confusion in udp_read_skb() when processing UDP packets for a socket in a sockmap with an attached SK_SKB verdict program that performs a socket lookup. A remote attacker can send a specially crafted packet to cause a denial of service.

Exploitation requires a UDP socket to be in a sockmap and the attached verdict program to call a socket-lookup helper.


506) Resource exhaustion (CVE-ID: CVE-2026-53183)

CWE-ID: CWE-400 - Resource exhaustion

CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to cause a denial of service.

The vulnerability exists due to improper resource management in MPTCP DSS option handling in net/mptcp/options.c when processing incoming MPTCP traffic with out-of-order data in the MPTCP sequence space or data landing in the backlog. A remote attacker can send traffic that triggers artificial inflation of the MPTCP receive window to cause a denial of service.

The issue can allow incoming traffic to exceed the receiver rcvbuf size even when the sender is not misbehaving.


507) Improper input validation (CVE-ID: CVE-2026-53182)

CWE-ID: CWE-20 - Improper input validation

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to improper input validation in nl80211_parse_rnr_elems() when parsing nested NL80211_ATTR_EMA_RNR_ELEMS input. A local user can send a specially crafted nl80211 message to cause a denial of service.

The issue is related to the element count being stored in a u8-backed cfg80211_rnr_elems::cnt field and incremented past its supported limit.


508) Improper control of a resource through its lifetime (CVE-ID: CVE-2026-53181)

CWE-ID: CWE-664 - Improper control of a resource through its lifetime

CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to cause a denial of service.

The vulnerability exists due to improper state management in vmci_transport_recv_listen() when handling failed connection handshakes. A remote attacker can send malformed packets that trigger repeated handshake failures to cause a denial of service.

The issue can permanently prevent the listener from accepting new connections until the affected process is restarted.


509) Always-Incorrect Control Flow Implementation (CVE-ID: CVE-2026-53180)

CWE-ID: CWE-670 - Always-Incorrect Control Flow Implementation

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to improper handling of expired timers in tmigr_handle_remote_cpu() in timer migration code when processing remote timer expiry handling. A local user can trigger the affected timer handling path to cause a denial of service.

The issue can cause an indefinite spin in the goto-again loop after an expired timer callback is never invoked and the timer remains reported as expired.


510) Out-of-bounds read (CVE-ID: CVE-2026-53179)

CWE-ID: CWE-125 - Out-of-bounds read

CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local user to disclose sensitive information.

The vulnerability exists due to an out-of-bounds read in rtw_update_protection when processing an ies buffer with a pointer offset but an unadjusted length. A local user can trigger the vulnerable code path to disclose sensitive information.


511) Integer underflow (CVE-ID: CVE-2026-53178)

CWE-ID: CWE-191 - Integer underflow

CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to cause a denial of service.

The vulnerability exists due to an unsigned integer underflow in rtw_mlme.c when processing wireless network information elements. A remote attacker can provide a specially crafted beacon or management frame to cause a denial of service.

The issue is in the rtl8723bs staging driver during network selection and WPS/RSN information element handling.


512) NULL pointer dereference (CVE-ID: CVE-2026-53177)

CWE-ID: CWE-476 - NULL Pointer Dereference

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to a NULL pointer dereference in the bnxt_io_error_detected error recovery path when handling PCIe error recovery on a closed NIC. A local user can trigger PCIe error recovery for a device whose bnapi state is not allocated to cause a denial of service.

The issue occurs because error recovery services may run on subordinate devices regardless of administrative state.


513) Out-of-bounds write (CVE-ID: CVE-2026-53173)

CWE-ID: CWE-787 - Out-of-bounds write

CVSSv4: 6.9 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause memory corruption.

The vulnerability exists due to an out-of-bounds write in ethosu_gem_cmdstream_copy_and_validate() when parsing a crafted command stream through the ioctl interface. A local user can supply crafted buffer contents and a size value to trigger the out-of-bounds write and cause memory corruption.

The issue occurs when a 64-bit command word is encountered at the end of the allocated command buffer.


514) Out-of-bounds write (CVE-ID: CVE-2026-53172)

CWE-ID: CWE-787 - Out-of-bounds write

CVSSv4: 6.9 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to corrupt kernel heap memory.

The vulnerability exists due to an out-of-bounds write in the ethosu command stream parser when processing a crafted NPU_SET_IFM_REGION command from userspace. A local user can supply a region index greater than 7 to corrupt kernel heap memory.

The issue is caused by using the region index directly as an array subscript into the allocated info structure.


515) Integer overflow (CVE-ID: CVE-2026-53171)

CWE-ID: CWE-190 - Integer overflow

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to bypass bounds validation and cause out-of-bounds memory access.

The vulnerability exists due to integer overflow and underflow handling errors in dma_length() and command stream validation in the Ethos-U accelerator driver when processing command stream DMA parameters. A local user can supply a specially crafted command stream to under-report region usage and bypass bounds validation to cause out-of-bounds memory access.

The issue affects region_size[] calculations that are later used to validate command stream accesses against GEM buffer sizes.


516) Integer overflow (CVE-ID: CVE-2026-53170)

CWE-ID: CWE-190 - Integer overflow

CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a local user to bypass DMA bounds checks.

The vulnerability exists due to an integer overflow in dma_length() in the ethosu driver when processing DMA commands with an uninitialized length. A local user can omit the DMA length setup command and issue a DMA start command to bypass DMA bounds checks.

The issue can leave region_size[] as 0 and allow hardware DMA to proceed with stale physical addresses.


517) Improper Check or Handling of Exceptional Conditions (CVE-ID: CVE-2026-53169)

CWE-ID: CWE-703 - Improper Check or Handling of Exceptional Conditions

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to improper handling of an unimplemented command in DRM_IOCTL_ETHOSU_GEM_CREATE when processing a userspace NPU_OP_RESIZE command. A local user can submit a specially crafted ioctl request to cause a denial of service.

The issue can trigger unbounded kernel log spam, and systems configured with panic_on_warn enabled may panic. Access to the DRM device is required.


518) Improper access control (CVE-ID: CVE-2026-53168)

CWE-ID: CWE-284 - Improper Access Control

CVSSv4: 7.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote user to cause a denial of service.

The vulnerability exists due to improper access control in fuse_notify_store() and fuse_notify_retrieve() when processing FUSE pagecache notification operations on directories. A remote user can issue crafted FUSE_NOTIFY_STORE or FUSE_NOTIFY_RETRIEVE operations on a directory inode to cause a denial of service.

The issue affects directory inodes that use kernel-internal pagecache storage.


519) Use of uninitialized resource (CVE-ID: CVE-2026-53167)

CWE-ID: CWE-908 - Use of Uninitialized Resource

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local user to disclose sensitive information.

The vulnerability exists due to an exposure of uninitialized memory in FUSE_NOTIFY_RETRIEVE in fs/fuse/dev.c when retrieving data from page cache folios. A local user can trigger FUSE_NOTIFY_RETRIEVE on a non-uptodate folio to disclose sensitive information.

This has security impact only on systems that do not enable automatic zero-initialization of page allocations.


520) NULL pointer dereference (CVE-ID: CVE-2026-53165)

CWE-ID: CWE-476 - NULL Pointer Dereference

CVSSv4: 5.7 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to a null pointer dereference race condition in iomap_finish_folio_read() when reporting buffered read errors during concurrent read completion and truncate operations. A local user can trigger a buffered read failure while racing read completion with truncate activity to cause a denial of service.

The issue occurs because the folio can be unlocked and detached before the error reporting path dereferences folio->mapping.


521) Always-Incorrect Control Flow Implementation (CVE-ID: CVE-2026-53164)

CWE-ID: CWE-670 - Always-Incorrect Control Flow Implementation

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to improper handling of a zero-length mapping and incorrect error unwind logic in iommu_dma_iova_link_swiotlb() when processing unaligned swiotlb mappings. A local user can trigger unaligned memory mappings to corrupt the mapping state and cause a denial of service.

This can be triggered by certain thunderbolt NVMe drives using forced SWIOTLB with oddly aligned buffers for passthrough commands from smartctl.


522) NULL pointer dereference (CVE-ID: CVE-2026-53163)

CWE-ID: CWE-476 - NULL Pointer Dereference

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to a null pointer dereference in remove_waiter() in the rtmutex futex proxy locking path when handling FUTEX_CMP_REQUEUE_PI operations during deadlock detection or proxy lock acquisition. A local user can invoke crafted futex operations to cause a denial of service.


523) Race condition (CVE-ID: CVE-2026-53162)

CWE-ID: CWE-362 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')

CVSSv4: 5.8 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local attacker to cause memory corruption.

The vulnerability exists due to memory corruption in refill_stock in mm/memcontrol.c when memcg charge draining occurs in nmi context. A local attacker can trigger re-entry into the random subsystem during an NMI to cause memory corruption.

The issue occurs because get_random_u32_below() is not reentrant- or NMI-safe and may corrupt per-cpu ChaCha batch state during a mid-update recursion.


524) Use-after-free (CVE-ID: CVE-2026-53161)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to a use-after-free in the fastrpc workqueue cleanup path when processing DSP responses during file descriptor release. A local user can trigger a race by closing the file descriptor while an in-flight DSP invocation completes to cause a denial of service.

The issue occurs because context cleanup may run in parallel with device release after the user structure has already been freed.


525) Use-after-free (CVE-ID: CVE-2026-53160)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a use-after-free condition.

The vulnerability exists due to a use-after-free race in fastrpc_map_create in drivers/misc/fastrpc.c when handling concurrent MEM_UNMAP operations during map lookup and reference acquisition. A local user can trigger concurrent map operations to cause a use-after-free condition.

The issue occurs because a raw pointer is returned after releasing fl->lock and is later referenced without atomic reference acquisition under the lock.


526) Integer underflow (CVE-ID: CVE-2026-53159)

CWE-ID: CWE-191 - Integer underflow

CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local user to corrupt a DMA address.

The vulnerability exists due to an integer underflow in fastrpc_get_args() when processing a user-provided pointer that falls in a gap before a returned VMA. A local user can supply a crafted pointer value to corrupt a DMA address.

The corrupted DMA address is sent to the DSP.


527) NULL pointer dereference (CVE-ID: CVE-2026-53158)

CWE-ID: CWE-476 - NULL Pointer Dereference

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local attacker to cause a denial of service.

The vulnerability exists due to a NULL pointer dereference in fastrpc_rpmsg_callback() when handling a glink message before probe initialization has completed. A local attacker can trigger the callback during early channel activation to cause a denial of service.

This issue can occur during boot when the rpmsg channel becomes live before driver initialization is fully complete.


528) Use-after-free (CVE-ID: CVE-2026-53157)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to use-after-free in phonet_device_destroy() when walking the per-net phonet device list with RCU readers after device removal. A local user can trigger destruction of a phonet_device while concurrent readers still hold a stale pointer to cause a denial of service.

The issue arises because the object is removed with RCU list semantics but may be freed before the RCU grace period has elapsed.


529) Use-after-free (CVE-ID: CVE-2026-53156)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to use-after-free in drivers/nvmem/core.c when handling error paths and device reference release. A local user can trigger a code path that releases an nvmem device reference and then continues using the freed structure to cause a denial of service.


530) Always-Incorrect Control Flow Implementation (CVE-ID: CVE-2026-53155)

CWE-ID: CWE-670 - Always-Incorrect Control Flow Implementation

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to improper handling of device-private PMD entry flags in set_pmd_migration_entry() in mm/huge_memory.c when processing device-private huge page migration entries. A local user can trigger page migration and write activity on a crafted memory range to cause a denial of service.

The issue can corrupt rmap state and trigger a kernel assertion during migration of device-private THP ranges.


531) Improper control of a resource through its lifetime (CVE-ID: CVE-2026-53154)

CWE-ID: CWE-664 - Improper control of a resource through its lifetime

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to improper state management in mm/hugetlb.c hugetlb folio copy paths when handling failed hugetlb folio copy operations. A local user can trigger a failed UFFDIO_COPY operation or a fork-time copy-on-write path failure to cause a denial of service.

The issue can leak a reservation from a private hugetlb VMA reserve map, which may cause a later fault at the same address to take the no-reservation path and receive SIGBUS under hugetlb pool pressure.


532) Race condition (CVE-ID: CVE-2026-53153)

CWE-ID: CWE-362 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')

CVSSv4: 6.9 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause memory corruption.

The vulnerability exists due to a race condition in memcg_reparent_list_lrus() in mm/list_lru.c when reparenting list lru entries for a dying memory cgroup during concurrent list_lru operations. A local user can trigger concurrent list_lru activity to cause memory corruption.

The issue occurs because different threads may modify the same physical list under different per-node locks during the reparenting window.


533) NULL pointer dereference (CVE-ID: CVE-2026-53152)

CWE-ID: CWE-476 - NULL Pointer Dereference

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to a NULL-pointer dereference in the dw_mmc-rockchip driver when initializing very old Rockchip MMC controllers. A local user can trigger initialization of an affected controller to cause a denial of service.

The issue affects rk2928, rk3066, and rk3188 controllers that do not support UHS speeds and therefore lacked driver private data for phase handling.


534) Race condition (CVE-ID: CVE-2026-53145)

CWE-ID: CWE-362 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')

CVSSv4: 5.7 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to a race condition in drm_gem_change_handle_ioctl when handling concurrent gem_close and gem_change_handle ioctl operations. A local user can trigger concurrent ioctl activity to cause a denial of service.

The issue affects the GEM handle change operation in the DRM subsystem.


535) NULL pointer dereference (CVE-ID: CVE-2026-53144)

CWE-ID: CWE-476 - NULL Pointer Dereference

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to a NULL pointer dereference in get_queue_ids() and its callers in the amdkfd debug trap queue handling path when processing a debug trap ioctl request with num_queues greater than zero and a missing queue array pointer. A local user can supply crafted ioctl parameters to trigger a kernel panic and cause a denial of service.

The issue is triggered via kfd_ioctl_set_debug_trap().


536) Heap-based buffer overflow (CVE-ID: CVE-2026-53143)

CWE-ID: CWE-122 - Heap-based Buffer Overflow

CVSSv4: 8.4 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a local user to disclose sensitive information and corrupt memory.

The vulnerability exists due to a heap-based buffer overflow in the amdkfd v11 MQD manager SDMA queue checkpoint and restore handlers when processing CRIU checkpoint and restore operations for SDMA queues on GFX11. A local user can trigger checkpoint or restore of an SDMA queue to disclose sensitive information and corrupt memory.

The issue is specific to v11 SDMA queues on Navi3x during CRIU checkpoint and restore.


537) NULL pointer dereference (CVE-ID: CVE-2026-53142)

CWE-ID: CWE-476 - NULL Pointer Dereference

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to a NULL pointer dereference in the xe display initialization and cleanup logic when handling suspend or shutdown on systems without display hardware present. A local user can trigger suspend or shutdown processing to cause a denial of service.

The issue occurs when display support is probed but display hardware is later determined to be unavailable or disabled at runtime initialization.


538) Improper update of reference count (CVE-ID: CVE-2026-53141)

CWE-ID: CWE-911 - Improper Update of Reference Count

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to improper reference counting in v3d performance monitor handling when processing SET_GLOBAL and CLEAR_GLOBAL ioctl requests and perfmon deletion. A local user can issue crafted ioctl operations to cause a denial of service.


539) Improper resource shutdown or release (CVE-ID: CVE-2026-53140)

CWE-ID: CWE-404 - Improper Resource Shutdown or Release

CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to improper resource shutdown or release in v3d_rewrite_csd_job_wg_counts_from_indirect() when processing indirect CSD workgroup buffers with zeroed workgroup counts. A local user can trigger an early return path to cause a denial of service.


540) Always-Incorrect Control Flow Implementation (CVE-ID: CVE-2026-53139)

CWE-ID: CWE-670 - Always-Incorrect Control Flow Implementation

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to improper handling of zero-valued workgroup counts in v3d compute shader dispatch handling when processing an indirect CSD job. A local user can submit a crafted indirect CSD job with a zeroed workgroup dimension to cause a denial of service.

A zero value in any workgroup dimension is interpreted by the hardware as 65536 instead of a no-op.


541) Out-of-bounds read (CVE-ID: CVE-2026-53138)

CWE-ID: CWE-125 - Out-of-bounds read

CVSSv4: 5.2 [CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows an attacker with physical access to cause a denial of service or disclose sensitive information.

The vulnerability exists due to an out-of-bounds read and unbounded iteration in amd display bios_parser.c and bios_parser2.c record-chain walk loops when parsing a malformed VBIOS image during probe time. An attacker with physical access can provide a crafted VBIOS image missing the terminator record to cause a denial of service or disclose sensitive information.

The issue is triggered when the VBIOS record chain lacks the 0xFF terminator record or uses a zero-sized termination condition incorrectly.


542) Out-of-bounds write (CVE-ID: CVE-2026-53137)

CWE-ID: CWE-787 - Out-of-bounds write

CVSSv4: 5.1 [CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows an attacker with physical access to cause a denial of service.

The vulnerability exists due to an out-of-bounds write in mod_hdcp_read_rx_id_list() when processing a malicious HDMI HDCP 2.x repeater ReceiverID list over I2C. An attacker with physical access can provide a malicious HDMI repeater that advertises an oversized message length to cause a denial of service.

The issue occurs during HDCP 2.x repeater authentication over HDMI.


543) Heap-based buffer overflow (CVE-ID: CVE-2026-53136)

CWE-ID: CWE-122 - Heap-based Buffer Overflow

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service or execute arbitrary code.

The vulnerability exists due to a heap-based buffer overflow in get_integrated_info_v11() and get_integrated_info_v2_1() in the AMD display BIOS parser when parsing a malformed VBIOS during driver probe. A local user can provide a specially crafted VBIOS with oversized HDMI retimer register counts to cause a denial of service or execute arbitrary code.

Exploitation requires control over the VBIOS data consumed by the driver.


544) Out-of-bounds read (CVE-ID: CVE-2026-53135)

CWE-ID: CWE-125 - Out-of-bounds read

CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local user to disclose sensitive information.

The vulnerability exists due to an out-of-bounds read in dp_sdp_message_debugfs_write() in the AMD display debugfs interface when handling writes to the sdp_message debugfs node with a user-supplied buffer smaller than 36 bytes. A local user can provide a short user buffer to disclose sensitive information.


545) NULL pointer dereference (CVE-ID: CVE-2026-53135)

CWE-ID: CWE-476 - NULL Pointer Dereference

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to a NULL pointer dereference in dp_sdp_message_debugfs_write() in the AMD display debugfs interface when handling writes to the sdp_message debugfs node. A local user can write to the debugfs node to cause a denial of service.

A connector may be connected but not bound to any CRTC, such as after hot-plug before the next atomic commit.


546) Use of Uninitialized Variable (CVE-ID: CVE-2026-53134)

CWE-ID: CWE-457 - Use of Uninitialized Variable

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local user to disclose sensitive information.

The vulnerability exists due to uninitialized memory exposure in the nft_fib IPv4/IPv6 evaluation logic when processing nftables fib expressions that use the OIFNAME result or an invalid NFTA_FIB_F_PRESENT combination. A local user can configure and trigger a crafted fib expression to disclose sensitive information.

The issue occurs because only part of the declared destination register span is written on certain evaluation paths, leaving stale kernel stack data available to a downstream expression that reads the full register span.


547) Integer overflow (CVE-ID: CVE-2026-53133)

CWE-ID: CWE-190 - Integer overflow

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to integer overflow in __rdma_block_iter_next() in the RDMA umem block iterator when reassembling split scatter-gather entries during IOMMU-backed mapping linearization. A local user can trigger processing of a very large mapped block to cause a denial of service.

The issue occurs for block sizes greater than or equal to 4G when a single large block is split across multiple scatter-gather entries.


548) Allocation of Resources Without Limits or Throttling (CVE-ID: CVE-2026-53132)

CWE-ID: CWE-770 - Allocation of Resources Without Limits or Throttling

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to improper resource management in virtio_transport_inc_rx_pkt() and the virtio vsock receive queue when processing crafted packets with zero-length payloads and the VIRTIO_VSOCK_SEQ_EOM flag. A local user can send a large number of specially crafted packets to cause a denial of service.

The issue occurs because queued packets may not increase the tracked byte count, allowing the receive queue to grow excessively.


549) Integer overflow (CVE-ID: CVE-2026-52948)

CWE-ID: CWE-190 - Integer overflow

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to integer overflow in the I2C_TIMEOUT ioctl handler in i2c-dev when processing a user-supplied timeout value. A local user can supply a large timeout value to cause a denial of service.

The issue can corrupt the SMBus controller state machine and leave it in an unrecoverable state.


550) Use-after-free (CVE-ID: CVE-2026-52947)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to a use-after-free in qrtr_port_remove in the qrtr socket subsystem when handling concurrent qrtr port removal and lookup operations under RCU. A local user can trigger the race condition to cause a denial of service.

The issue arises because a socket pointer can remain reachable through the qrtr_ports XArray before the RCU grace period elapses.


551) Out-of-bounds read (CVE-ID: CVE-2026-52942)

CWE-ID: CWE-125 - Out-of-bounds read

CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local user to disclose sensitive information.

The vulnerability exists due to an out-of-bounds read in dump_mac_header() in the netfilter nf_log syslog logger when processing an skb sent through AF_PACKET with PACKET_QDISC_BYPASS and an unset MAC header. A local user can send a specially crafted packet to disclose sensitive information.

Only skbs with an unset MAC header are affected.


552) Use of Uninitialized Variable (CVE-ID: CVE-2026-52940)

CWE-ID: CWE-457 - Use of Uninitialized Variable

CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local user to disclose sensitive information.

The vulnerability exists due to an uninitialized stack memory usage in tun_put_user() when processing reads of non-tunnel packets with a 24-byte vnet header size. A local user can set the vnet header size with TUNSETVNETHDRSZ and read a non-tunnel packet to disclose sensitive information.

Up to 14 bytes of kernel stack memory may be leaked on each read.


553) NULL pointer dereference (CVE-ID: CVE-2026-52939)

CWE-ID: CWE-476 - NULL Pointer Dereference

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to a NULL pointer dereference in rds_ib_send_cqe_handler() and rds_ib_send_unmap_op() when processing an atomic cmsg over an active RDS/IB connection. A local user can send a crafted AF_RDS sendmsg() request to cause a denial of service.

On hardware that natively accepts masked atomic operations, no additional setup is required.


554) NULL pointer dereference (CVE-ID: CVE-2026-52938)

CWE-ID: CWE-476 - NULL Pointer Dereference

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to a NULL pointer dereference in bpf_sk_storage_clone() and bpf_sk_storage_diag_put_all() when processing socket local storage entries during concurrent access. A local user can trigger concurrent operations that leave smap as NULL while the storage element remains visible to RCU readers to cause a denial of service.

The issue arises in the BPF socket storage handling paths under a race condition involving RCU readers.


555) Out-of-bounds read (CVE-ID: CVE-2026-52935)

CWE-ID: CWE-125 - Out-of-bounds read

CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local user to disclose sensitive information.

The vulnerability exists due to an out-of-bounds read in espintcp_sendmsg() when handling a new send while a previous partial send is still in progress. A local user can trigger a partial send and initiate another send to disclose sensitive information.

The issue occurs in the send path because a stale offset from a live partial-send state can remain attached to a new sk_msg.


556) Race condition (CVE-ID: CVE-2026-52930)

CWE-ID: CWE-362 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to a race condition in shared memory orphan cleanup in ipc/shm.c when cleaning up orphaned shared memory segments while attachment counts are updated concurrently. A local user can trigger concurrent shared memory attach and cleanup operations to cause a denial of service.

The issue occurs because shm_destroy_orphaned() may decide that an orphaned segment is unused before taking the object lock.


557) NULL pointer dereference (CVE-ID: CVE-2026-52929)

CWE-ID: CWE-476 - NULL Pointer Dereference

CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to cause a denial of service.

The vulnerability exists due to a null-pointer dereference in the SCTP stream scheduler state handling in net/sctp/stream.c when processing a denied ADD_OUT_STREAMS operation and a later stream re-add. A remote attacker can trigger SCTP stream reset operations that leave stale removed stream metadata behind to cause a denial of service.

The issue occurs because removed outgoing stream state is not fully rolled back, leaving scheduler-private stream metadata inconsistent for later reuse.


558) Out-of-bounds read (CVE-ID: CVE-2026-52917)

CWE-ID: CWE-125 - Out-of-bounds read

CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local user to disclose sensitive information.

The vulnerability exists due to an out-of-bounds read in the SCTP sock_diag dump-one path when processing an exact association lookup after taking the socket lock on a stale association. A local user can trigger a stale association lookup to disclose sensitive information.

The issue occurs when association state is reaped or detached from the endpoint while the lookup path resumes after blocking on the socket lock.


559) Out-of-bounds read (CVE-ID: CVE-2026-52910)

CWE-ID: CWE-125 - Out-of-bounds read

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to an out-of-bounds read in the reuseport cBPF program handling in sk_reuseport_prog_free() when detaching or replacing a reuseport program while UDP packets are being processed concurrently. A local user can trigger concurrent reuseport program updates and packet transmission to cause a denial of service.

The issue occurs because the classic BPF reuseport program may be freed before RCU readers have completed.


560) Improper access control (CVE-ID: CVE-2026-52909)

CWE-ID: CWE-284 - Improper Access Control

CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local user to move a fallback tunnel device to another network namespace.

The vulnerability exists due to improper access control in the ip6_vti fallback tunnel device initialization when initializing the per-network-namespace fallback device. A local user can move the ip6_vti0 device to another network namespace to move a fallback tunnel device to another network namespace.

The issue affects the per-netns fallback tunnel device ip6_vti0.


561) Improper access control (CVE-ID: CVE-2026-52908)

CWE-ID: CWE-284 - Improper Access Control

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local user to gain write access to memory regions that were not properly pinned as writable.

The vulnerability exists due to improper access control in RDMA memory region re-registration handling when changing IB_MR_REREG_ACCESS from read-only to read-write. A local user can re-register a memory region with writable access to gain write access to memory regions that were not properly pinned as writable.

The issue occurs when a driver reuses an existing umem during memory region re-registration.


Remediation

Install update from vendor's website.