{"resultsPerPage":16,"startIndex":0,"totalResults":16,"format":"NVD_CVE","version":"2.0","timestamp":"2026-07-21T01:18:56.380","vulnerabilities":[{"cve":{"id":"CVE-2025-2843","sourceIdentifier":"secalert@redhat.com","published":"2025-11-12T17:15:37.550","lastModified":"2026-07-19T12:16:47.700","vulnStatus":"Deferred","cveTags":[],"descriptions":[{"lang":"en","value":"A flaw was found in the Observability Operator. The Operator creates a ServiceAccount with *ClusterRole* upon deployment of the *Namespace-Scoped* Custom Resource MonitorStack. This issue allows an adversarial Kubernetes Account with only namespaced-level roles, for example, a tenant controlling a namespace, to create a MonitorStack in the authorized namespace and then elevate permission to the cluster level by impersonating the ServiceAccount created by the Operator, resulting in privilege escalation and other issues."}],"affected":[{"source":"secalert@redhat.com","affectedData":[{"vendor":"rhobs","product":"observability-operator","defaultStatus":"unaffected","collectionURL":"https://github.com/rhobs/observability-operator","packageName":"observability-operator","versions":[{"version":"0","lessThan":"1.3.0","versionType":"semver","status":"affected"}]},{"vendor":"Red Hat","product":"Cluster Observability Operator 1.3.1","defaultStatus":"affected","collectionURL":"https://catalog.redhat.com/software/containers/","packageName":"cluster-observability-operator/cluster-observability-rhel9-operator","cpes":["cpe:/a:redhat:cluster_observability_operator:1.3::el9"],"versions":[{"version":"1.3.0-1762825457","lessThan":"*","versionType":"rpm","status":"unaffected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"secalert@redhat.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","baseScore":8.8,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":2.8,"impactScore":5.9}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2025-11-12T20:47:54.311119Z","id":"CVE-2025-2843","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"secalert@redhat.com","type":"Secondary","description":[{"lang":"en","value":"CWE-266"}]}],"references":[{"url":"https://access.redhat.com/errata/RHSA-2025:21146","source":"secalert@redhat.com"},{"url":"https://access.redhat.com/security/cve/CVE-2025-2843","source":"secalert@redhat.com"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2355222","source":"secalert@redhat.com"}]}},{"cve":{"id":"CVE-2026-30796","sourceIdentifier":"2fdefc65-d750-4b8d-96ee-6e2c0c42dbfe","published":"2026-03-05T16:16:21.007","lastModified":"2026-07-19T12:16:48.590","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"Cleartext Transmission of Sensitive Information, Insufficiently Protected Credentials vulnerability in rustdesk-client RustDesk Client rustdesk-client on Windows, MacOS, Linux, iOS, Android (Address book sync, Heartbeat sync loop modules) allows Sniffing Attacks.\n\nThe client places the preset address-book password verbatim into the heartbeat sync JSON body (src/hbbs_http/sync.rs). Over an intact HTTPS session it is not exposed in transit, but it is a reusable shared secret rather than a zero-knowledge proof, so it is recovered by any party that becomes the API endpoint - under the re-homed/rogue API server (CVE-2026-30797) - and the leaked credential then authorizes the server-side address book.\n\nThis vulnerability is associated with program files src/hbbs_http/sync.rs and program routines heartbeat sync body builder (emits preset-address-book-password).\n\nThis issue affects RustDesk Client: through 1.4.8."},{"lang":"es","value":"Vulnerabilidad de transmisión en texto claro de información sensible en rustdesk-server-pro RustDesk Server Pro rustdesk-server-pro en Windows, MacOS, Linux (Módulos de API de sincronización de libreta de direcciones) permite ataques de sniffing. Esta vulnerabilidad está asociada con archivos de programa de código cerrado — punto final de API que gestiona la sincronización de latidos y rutinas de programa gestor de API de latidos (acepta preset-address-book-password en texto claro).\n\nEste problema afecta a RustDesk Server Pro: hasta la 1.7.5."}],"affected":[{"source":"2fdefc65-d750-4b8d-96ee-6e2c0c42dbfe","affectedData":[{"vendor":"rustdesk-client","product":"RustDesk Client","defaultStatus":"affected","collectionURL":"https://github.com/rustdesk/rustdesk/releases","packageName":"rustdesk-client","modules":["Address book sync","Heartbeat sync loop"],"platforms":["Windows","MacOS","Linux","iOS","Android"],"programFiles":["src/hbbs_http/sync.rs"],"programRoutines":[{"name":"heartbeat sync body builder (emits preset-address-book-password verbatim)"}],"repo":"https://github.com/rustdesk/rustdesk,https://github.com/rustdesk/hbb_common","versions":[{"version":"0","lessThanOrEqual":"1.4.8","versionType":"custom","status":"affected","changes":[{"at":"Server Pro","status":"affected"}]}]}]}],"metrics":{"cvssMetricV40":[{"source":"2fdefc65-d750-4b8d-96ee-6e2c0c42dbfe","type":"Secondary","cvssData":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:N/SC:H/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","baseScore":6.9,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","attackRequirements":"PRESENT","privilegesRequired":"NONE","userInteraction":"NONE","vulnConfidentialityImpact":"NONE","vulnIntegrityImpact":"NONE","vulnAvailabilityImpact":"NONE","subConfidentialityImpact":"HIGH","subIntegrityImpact":"NONE","subAvailabilityImpact":"NONE","exploitMaturity":"NOT_DEFINED","confidentialityRequirement":"NOT_DEFINED","integrityRequirement":"NOT_DEFINED","availabilityRequirement":"NOT_DEFINED","modifiedAttackVector":"NOT_DEFINED","modifiedAttackComplexity":"NOT_DEFINED","modifiedAttackRequirements":"NOT_DEFINED","modifiedPrivilegesRequired":"NOT_DEFINED","modifiedUserInteraction":"NOT_DEFINED","modifiedVulnConfidentialityImpact":"NOT_DEFINED","modifiedVulnIntegrityImpact":"NOT_DEFINED","modifiedVulnAvailabilityImpact":"NOT_DEFINED","modifiedSubConfidentialityImpact":"NOT_DEFINED","modifiedSubIntegrityImpact":"NOT_DEFINED","modifiedSubAvailabilityImpact":"NOT_DEFINED","Safety":"NOT_DEFINED","Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","valueDensity":"NOT_DEFINED","vulnerabilityResponseEffort":"NOT_DEFINED","providerUrgency":"NOT_DEFINED"}}],"cvssMetricV31":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","baseScore":7.5,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":3.6}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-03-17T14:31:35.721954Z","id":"CVE-2026-30796","options":[{"exploitation":"poc"},{"automatable":"yes"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"2fdefc65-d750-4b8d-96ee-6e2c0c42dbfe","type":"Secondary","description":[{"lang":"en","value":"CWE-522"}]}],"configurations":[{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:rustdesk:rustdesk_server:*:*:*:*:pro:*:*:*","versionEndIncluding":"1.7.5","matchCriteriaId":"4F6E21F9-385D-4DB4-9CD4-EDB43561D9E5"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:o:apple:macos:-:*:*:*:*:*:*:*","matchCriteriaId":"387021A0-AF36-463C-A605-32EA7DAC172E"},{"vulnerable":false,"criteria":"cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*","matchCriteriaId":"703AF700-7A70-47E2-BC3A-7FD03B3CA9C1"},{"vulnerable":false,"criteria":"cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*","matchCriteriaId":"A2572D17-1DE6-457B-99CC-64AFD54487EA"}]}]}],"references":[{"url":"https://docs.google.com/document/d/e/2PACX-1vSds6jjpd38oO_yIAyd1HYtKNUuea-I-ozAPpGhYI7QgAU-QGJ7D8a4rOZVj1vmiUXV1EcdRHf9aZAW/pub","source":"2fdefc65-d750-4b8d-96ee-6e2c0c42dbfe","tags":["Exploit","Third Party Advisory"]},{"url":"https://rustdesk.com/docs/en/","source":"2fdefc65-d750-4b8d-96ee-6e2c0c42dbfe","tags":["Product","Vendor Advisory"]},{"url":"https://www.vulsec.org/","source":"2fdefc65-d750-4b8d-96ee-6e2c0c42dbfe","tags":["Not Applicable"]}]}},{"cve":{"id":"CVE-2026-53382","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-07-19T12:16:48.970","lastModified":"2026-07-19T12:16:48.970","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nmedia: vidtv: fix NULL pointer dereference in vidtv_mux_push_si\n\nsyzbot reported a general protection fault in\nvidtv_psi_ts_psi_write_into [1].\n\nvidtv_mux_get_pid_ctx() can return NULL, but vidtv_mux_push_si() does\nnot check for this before dereferencing the returned pointer to access\nthe continuity counter. This leads to a general protection fault when\naccessing a near-NULL address.\n\nThe root cause is that vidtv_mux_pid_ctx_init() does not check the\nreturn value of vidtv_mux_create_pid_ctx_once() for PMT section PIDs.\nIf the allocation fails, the PID context is never created, but init\nreturns success. The subsequent vidtv_mux_push_si() call then gets\nNULL from vidtv_mux_get_pid_ctx() and crashes.\n\nFix both the root cause (add error check in vidtv_mux_pid_ctx_init\nfor PMT PIDs) and add defensive NULL checks in vidtv_mux_push_si for\nall vidtv_mux_get_pid_ctx() calls.\n\n[1]\nOops: general protection fault, probably for non-canonical address 0xdffffc0000000000: 0000 [#1] SMP KASAN PTI\nKASAN: null-ptr-deref in range [0x0000000000000000-0x0000000000000007]\nWorkqueue: events vidtv_mux_tick\nRIP: 0010:vidtv_psi_ts_psi_write_into+0x54a/0xbc0 drivers/media/test-drivers/vidtv/vidtv_psi.c:197\nCall Trace:\n <TASK>\n vidtv_psi_table_header_write_into drivers/media/test-drivers/vidtv/vidtv_psi.c:799 [inline]\n vidtv_psi_pmt_write_into+0x3b2/0xa70 drivers/media/test-drivers/vidtv/vidtv_psi.c:1231\n vidtv_mux_push_si+0x932/0xe80 drivers/media/test-drivers/vidtv/vidtv_mux.c:196\n vidtv_mux_tick+0xe9b/0x1480 drivers/media/test-drivers/vidtv/vidtv_mux.c:408"}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/media/test-drivers/vidtv/vidtv_mux.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"f90cf6079bf67988f8b1ad1ade70fc89d0080905","lessThan":"455bc12e7b73ab5a2dfcb47822e91e772bc6c42e","versionType":"git","status":"affected"},{"version":"f90cf6079bf67988f8b1ad1ade70fc89d0080905","lessThan":"f0f5a1d7056980a0d512456fdb370cfb72bba86a","versionType":"git","status":"affected"},{"version":"f90cf6079bf67988f8b1ad1ade70fc89d0080905","lessThan":"6df7e16d4f742c80add58995a6e69385b97aa9e6","versionType":"git","status":"affected"},{"version":"f90cf6079bf67988f8b1ad1ade70fc89d0080905","lessThan":"cd923dadefadb9671b5ac341b672ff424d429c39","versionType":"git","status":"affected"},{"version":"f90cf6079bf67988f8b1ad1ade70fc89d0080905","lessThan":"353d9578951dd38bc9679308f5b618ceed1f20fa","versionType":"git","status":"affected"},{"version":"f90cf6079bf67988f8b1ad1ade70fc89d0080905","lessThan":"f965cf22dda7f512f4922415894c3e528269a4ae","versionType":"git","status":"affected"},{"version":"f90cf6079bf67988f8b1ad1ade70fc89d0080905","lessThan":"b28b12be6e8910489e6800ed93ea4d41dfe19683","versionType":"git","status":"affected"},{"version":"f90cf6079bf67988f8b1ad1ade70fc89d0080905","lessThan":"232e4b313ea342672edf8947e067c0de4328405b","versionType":"git","status":"affected"},{"version":"f90cf6079bf67988f8b1ad1ade70fc89d0080905","lessThan":"7d8bf3d8f91073f4db347ed3aa6302b56107499c","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/media/test-drivers/vidtv/vidtv_mux.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"5.10","status":"affected"},{"version":"0","lessThan":"5.10","versionType":"semver","status":"unaffected"},{"version":"5.10.260","lessThanOrEqual":"5.10.*","versionType":"semver","status":"unaffected"},{"version":"5.15.211","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.177","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.144","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.95","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.37","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.0.14","lessThanOrEqual":"7.0.*","versionType":"semver","status":"unaffected"},{"version":"7.1.2","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/232e4b313ea342672edf8947e067c0de4328405b","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/353d9578951dd38bc9679308f5b618ceed1f20fa","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/455bc12e7b73ab5a2dfcb47822e91e772bc6c42e","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/6df7e16d4f742c80add58995a6e69385b97aa9e6","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/7d8bf3d8f91073f4db347ed3aa6302b56107499c","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/b28b12be6e8910489e6800ed93ea4d41dfe19683","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/cd923dadefadb9671b5ac341b672ff424d429c39","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/f0f5a1d7056980a0d512456fdb370cfb72bba86a","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/f965cf22dda7f512f4922415894c3e528269a4ae","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-53385","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-07-19T12:16:49.387","lastModified":"2026-07-19T12:16:49.387","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nvc_screen: fix null-ptr-deref in vcs_notifier() during concurrent vcs_write\n\nA KASAN null-ptr-deref was observed in vcs_notifier():\n\nBUG: KASAN: null-ptr-deref in vcs_notifier+0x98/0x130\nRead of size 2 at addr qmp_cmd_name: qmp_capabilities, arguments: {}\n\nThe issue is a race condition in vcs_write(). When the console_lock is\ntemporarily dropped (to copy data from userspace), the vc_data pointer\nobtained from vcs_vc() may become stale. After re-acquiring the lock,\nvcs_vc() is called again to re-validate the pointer. If the vc has been\ndeallocated in the meantime, vcs_vc() returns NULL, and the while loop\nbreaks (with written > 0). However, after the loop, vcs_scr_updated(vc)\nis still called with the now-NULL vc pointer, leading to a null pointer\ndereference in the notifier chain (vcs_notifier dereferences param->vc).\n\nFix this by adding a NULL check for vc before calling vcs_scr_updated()."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/tty/vt/vc_screen.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"11dddfbb7a4e62489b01074d6c04d9d1b42e4047","lessThan":"43a6281790273c1b0a9ab76609ff0245b968f1e6","versionType":"git","status":"affected"},{"version":"e3d1adcad5b73c7ed0c7edb35ab68abcaa45cf67","lessThan":"b6bbb85cf45bf0b070e741997fe0af3a772c5ad5","versionType":"git","status":"affected"},{"version":"3338d0b9acde770ee588eead5cac32c25e7048fc","lessThan":"ff4806202749a51938236214adc0281481a57366","versionType":"git","status":"affected"},{"version":"8fb9ea65c9d1338b0d2bb0a9122dc942cdd32357","lessThan":"8232fca738011ca2ec865b46ec721d1796dc0580","versionType":"git","status":"affected"},{"version":"8fb9ea65c9d1338b0d2bb0a9122dc942cdd32357","lessThan":"73049768ad57145acd337102c5aa3c788e6642c8","versionType":"git","status":"affected"},{"version":"8fb9ea65c9d1338b0d2bb0a9122dc942cdd32357","lessThan":"7cc3dd79777f6ae4625ec37e84dd18a26dc88bde","versionType":"git","status":"affected"},{"version":"8fb9ea65c9d1338b0d2bb0a9122dc942cdd32357","lessThan":"74be188eb2dc1c99d63986167b9a67d415fe7326","versionType":"git","status":"affected"},{"version":"8fb9ea65c9d1338b0d2bb0a9122dc942cdd32357","lessThan":"09a43e81279b8da15526da09877134b8bcf618b0","versionType":"git","status":"affected"},{"version":"8fb9ea65c9d1338b0d2bb0a9122dc942cdd32357","lessThan":"a287620312dc6dcb9a093417a0e589bf30fcf38a","versionType":"git","status":"affected"},{"version":"934de9a9b659785fed3e820bc0c813a460c71fea","versionType":"git","status":"affected"},{"version":"0deff678157333d775af190f84696336cdcccd6d","versionType":"git","status":"affected"},{"version":"a4e3c4c65ae8510e01352c9a4347e05c035b2ce2","versionType":"git","status":"affected"},{"version":"1de42e7653d6714a7507ba6696151a1fa028c69f","versionType":"git","status":"affected"},{"version":"5.10.181","lessThan":"5.10.260","versionType":"semver","status":"affected"},{"version":"5.15.113","lessThan":"5.15.211","versionType":"semver","status":"affected"},{"version":"6.1.30","lessThan":"6.1.177","versionType":"semver","status":"affected"},{"version":"4.14.327","lessThan":"4.15","versionType":"semver","status":"affected"},{"version":"4.19.284","lessThan":"4.20","versionType":"semver","status":"affected"},{"version":"5.4.244","lessThan":"5.5","versionType":"semver","status":"affected"},{"version":"6.3.4","lessThan":"6.4","versionType":"semver","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/tty/vt/vc_screen.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.4","status":"affected"},{"version":"0","lessThan":"6.4","versionType":"semver","status":"unaffected"},{"version":"5.10.260","lessThanOrEqual":"5.10.*","versionType":"semver","status":"unaffected"},{"version":"5.15.211","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.177","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.144","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.95","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.37","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.0.14","lessThanOrEqual":"7.0.*","versionType":"semver","status":"unaffected"},{"version":"7.1.2","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/09a43e81279b8da15526da09877134b8bcf618b0","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/43a6281790273c1b0a9ab76609ff0245b968f1e6","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/73049768ad57145acd337102c5aa3c788e6642c8","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/74be188eb2dc1c99d63986167b9a67d415fe7326","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/7cc3dd79777f6ae4625ec37e84dd18a26dc88bde","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/8232fca738011ca2ec865b46ec721d1796dc0580","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/a287620312dc6dcb9a093417a0e589bf30fcf38a","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/b6bbb85cf45bf0b070e741997fe0af3a772c5ad5","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/ff4806202749a51938236214adc0281481a57366","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-53393","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-07-19T12:16:50.367","lastModified":"2026-07-19T12:16:50.367","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nnfsd: reset write verifier on deferred writeback errors\n\nnfsd_vfs_write() and nfsd_commit() both call filemap_check_wb_err() to\ndetect deferred writeback errors, but neither rotates the server's write\nverifier (nn->writeverf) when this check fails. Every other\ndurable-storage-failure path in these functions calls\ncommit_reset_write_verifier() before returning an error.\n\nThe missing rotation means clients holding UNSTABLE write data under the\ncurrent verifier will COMMIT, receive the unchanged verifier back, and\nconclude their data is durable — silently dropping data that failed\nwriteback. This violates the UNSTABLE+COMMIT durability contract\n(RFC 1813 §3.3.7, RFC 8881 §18.32).\n\nAdd commit_reset_write_verifier() calls at both filemap_check_wb_err()\nerror sites, matching the pattern used by adjacent error paths in the\nsame functions. The helper already filters -EAGAIN and -ESTALE\ninternally, so the calls are unconditionally safe."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["fs/nfsd/vfs.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"555dbf1a9aac6d3150c8b52fa35f768a692f4eeb","lessThan":"1dd664b39774a9c89b72de8e59bf9ef4b3aaff2e","versionType":"git","status":"affected"},{"version":"555dbf1a9aac6d3150c8b52fa35f768a692f4eeb","lessThan":"4367afc119c51e17a616f6908772b7e2c2c4013f","versionType":"git","status":"affected"},{"version":"555dbf1a9aac6d3150c8b52fa35f768a692f4eeb","lessThan":"b027cca33c97354149fcc0ddeede4525c41093cd","versionType":"git","status":"affected"},{"version":"555dbf1a9aac6d3150c8b52fa35f768a692f4eeb","lessThan":"2090b05803faab8a9fa62fbff871007862cac1b7","versionType":"git","status":"affected"},{"version":"f14816f2f928c560d28ba344af689f56efcd6f55","versionType":"git","status":"affected"},{"version":"3145fe0ebb16e1715ad541a301bc6675c8375fcd","versionType":"git","status":"affected"},{"version":"5.10.124","lessThan":"5.11","versionType":"semver","status":"affected"},{"version":"5.15.49","lessThan":"5.16","versionType":"semver","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["fs/nfsd/vfs.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"5.17","status":"affected"},{"version":"0","lessThan":"5.17","versionType":"semver","status":"unaffected"},{"version":"6.12.95","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.38","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.3","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/1dd664b39774a9c89b72de8e59bf9ef4b3aaff2e","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/2090b05803faab8a9fa62fbff871007862cac1b7","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/4367afc119c51e17a616f6908772b7e2c2c4013f","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/b027cca33c97354149fcc0ddeede4525c41093cd","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-63794","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-07-19T12:16:51.757","lastModified":"2026-07-19T12:16:51.757","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nKVM: SVM: Fix page overflow in sev_dbg_crypt() for ENCRYPT path\n\nIn sev_dbg_crypt(), the per-iteration transfer length is bounded by\nthe source page offset (PAGE_SIZE - s_off) but not by the destination\npage offset (PAGE_SIZE - d_off).  When d_off > s_off, the encrypt\npath (__sev_dbg_encrypt_user) performs a read-modify-write using a\nsingle-page intermediate buffer (dst_tpage):\n\n  1. __sev_dbg_decrypt() expands the size to round_up(len + (d_off & 15), 16)\n     before issuing the PSP command.  If len + (d_off & 15) > PAGE_SIZE,\n     the PSP writes beyond the end of the 4096-byte dst_tpage allocation.\n\n  2. The subsequent memcpy()/copy_from_user() into\n     page_address(dst_tpage) + (d_off & 15) of 'len' bytes overflows\n     by up to 15 bytes under the same condition.\n\nTrigger example: s_off = 0, d_off = 1, debug.len = PAGE_SIZE -\nthe PSP is instructed to write round_up(4097, 16) = 4112 bytes to\na 4096-byte buffer.\n\nFix by also bounding len by (PAGE_SIZE - d_off), the same check that\nsev_send_update_data() already performs for its single-page guest\nregion.\n\n ==================================================================\n BUG: KASAN: slab-use-after-free in sev_dbg_crypt+0x993/0xd10 [kvm_amd]\n Write of size 4095 at addr ff110062293bb009 by task sev_dbg_test/228214\n\n CPU: 96 UID: 0 PID: 228214 Comm: sev_dbg_test Tainted: G     U  W           7.0.0-smp--5ce9b0c48211-dbg #156 PREEMPTLAZY\n Tainted: [U]=USER, [W]=WARN\n Hardware name: Google Astoria/astoria, BIOS 0.20250817.1-0 08/25/2025\n Call Trace:\n  <TASK>\n  dump_stack_lvl+0x54/0x70\n  print_report+0xbc/0x260\n  kasan_report+0xa2/0xd0\n  kasan_check_range+0x25f/0x2c0\n  __asan_memcpy+0x40/0x70\n  sev_dbg_crypt+0x993/0xd10 [kvm_amd]\n  sev_mem_enc_ioctl+0x33c/0x450 [kvm_amd]\n  kvm_vm_ioctl+0x65d/0x6d0 [kvm]\n  __se_sys_ioctl+0xb2/0x100\n  do_syscall_64+0xe8/0x870\n  entry_SYSCALL_64_after_hwframe+0x4b/0x53\n  </TASK>\n\n The buggy address belongs to the physical page:\n page: refcount:1 mapcount:0 mapping:0000000000000000 index:0x7fe72b6a0 pfn:0x62293bb\n memcg:ff11000112827d82\n flags: 0x1400000000000000(node=1|zone=1)\n raw: 1400000000000000 0000000000000000 dead000000000122 0000000000000000\n raw: 00000007fe72b6a0 0000000000000000 00000001ffffffff ff11000112827d82\n page dumped because: kasan: bad access detected\n\n Memory state around the buggy address:\n  ff110062293bbf00: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00\n  ff110062293bbf80: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00\n >ff110062293bc000: fa fb fb fb fb fb fb fb fc fc fc fc fc fc fc fc\n                    ^\n  ff110062293bc080: fa fb fb fb fb fb fb fb fc fc fc fc fc fc fc fc\n  ff110062293bc100: fa fb fb fb fb fb fb fb fc fc fc fc fc fc fc fc\n ==================================================================\n Disabling lock debugging due to kernel taint\n\n[sean: add sample KASAN splat, Fixes, and stable@]"}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["arch/x86/kvm/svm/sev.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"24f41fb23a39bc2b6f190dcef35a5813a4bf183a","lessThan":"f701ae476cb92a3a3d8844bb39bb63b4512684c8","versionType":"git","status":"affected"},{"version":"24f41fb23a39bc2b6f190dcef35a5813a4bf183a","lessThan":"64f2449841ffc7d203183aa4c748c9c77951ecc5","versionType":"git","status":"affected"},{"version":"24f41fb23a39bc2b6f190dcef35a5813a4bf183a","lessThan":"9349b50f4b11f135fe73b56cb2c2c872d8bc71d7","versionType":"git","status":"affected"},{"version":"24f41fb23a39bc2b6f190dcef35a5813a4bf183a","lessThan":"889c2a9c59897ca912bf39df5bb92555a0a13df4","versionType":"git","status":"affected"},{"version":"24f41fb23a39bc2b6f190dcef35a5813a4bf183a","lessThan":"e1a0fe288dee07b7da25a71e007c1ecd1080315b","versionType":"git","status":"affected"},{"version":"24f41fb23a39bc2b6f190dcef35a5813a4bf183a","lessThan":"720949ed666f34ff28ffdfe1471a5861d1e41fdf","versionType":"git","status":"affected"},{"version":"24f41fb23a39bc2b6f190dcef35a5813a4bf183a","lessThan":"2753a097d1fe24c4351c608048612c74108aa89f","versionType":"git","status":"affected"},{"version":"24f41fb23a39bc2b6f190dcef35a5813a4bf183a","lessThan":"78ee2d50185a037b3d2452a97f3dad69c3f7f389","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["arch/x86/kvm/svm/sev.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"4.16","status":"affected"},{"version":"0","lessThan":"4.16","versionType":"semver","status":"unaffected"},{"version":"5.10.260","lessThanOrEqual":"5.10.*","versionType":"semver","status":"unaffected"},{"version":"5.15.211","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.177","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.144","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.95","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.38","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.3","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/2753a097d1fe24c4351c608048612c74108aa89f","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/64f2449841ffc7d203183aa4c748c9c77951ecc5","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/720949ed666f34ff28ffdfe1471a5861d1e41fdf","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/78ee2d50185a037b3d2452a97f3dad69c3f7f389","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/889c2a9c59897ca912bf39df5bb92555a0a13df4","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/9349b50f4b11f135fe73b56cb2c2c872d8bc71d7","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/e1a0fe288dee07b7da25a71e007c1ecd1080315b","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/f701ae476cb92a3a3d8844bb39bb63b4512684c8","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-63798","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-07-19T12:16:52.303","lastModified":"2026-07-19T12:16:52.303","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nirqchip/imgpdc: Fix resource leak, add missing chained handler cleanup on remove\n\nThe driver allocates domain generic chips using\nirq_alloc_domain_generic_chips() during probe and sets up chained\nhandlers using irq_set_chained_handler_and_data(). However, on driver\nremoval, the generic chips are not freed and the chained handlers are\nnot removed.\n\nThe generic chips remain on the global gc_list and may later be accessed by\ngeneric interrupt chip suspend, resume, or shutdown callbacks after the\ndriver has been removed, potentially resulting in a use-after-free and\nkernel crash.\n\nThe chained handlers that were installed in probe for peripheral and\nsyswake interrupts are also left dangling, which can lead to spurious\ninterrupts accessing freed memory.\n\nFix these issues by:\n\n  - Setting IRQ_DOMAIN_FLAG_DESTROY_GC flag in domain->flags, so the\n    core code automatically removes generic chips when irq_domain_remove()\n    is called\n\n  - Clearing all chained handlers with NULL in pdc_intc_remove()"}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/irqchip/irq-imgpdc.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"b6ef9161e43ad58c3824bd76dc87716276f0cd70","lessThan":"8176773dfceae7978b01c20b233693e072053700","versionType":"git","status":"affected"},{"version":"b6ef9161e43ad58c3824bd76dc87716276f0cd70","lessThan":"c2c7733101bb8c0b29ac9ee41073eaf602821a59","versionType":"git","status":"affected"},{"version":"b6ef9161e43ad58c3824bd76dc87716276f0cd70","lessThan":"83d7ec14b0938ad8cae008058fd6f912f4a9a312","versionType":"git","status":"affected"},{"version":"b6ef9161e43ad58c3824bd76dc87716276f0cd70","lessThan":"44567537a2623dcd2b4018a7f043cf8069579e5d","versionType":"git","status":"affected"},{"version":"b6ef9161e43ad58c3824bd76dc87716276f0cd70","lessThan":"41826e5297e67cd96a0a46fde06a5069a8ce436a","versionType":"git","status":"affected"},{"version":"b6ef9161e43ad58c3824bd76dc87716276f0cd70","lessThan":"b3a3831b2eb884641906fc5e46207b205b6aea13","versionType":"git","status":"affected"},{"version":"b6ef9161e43ad58c3824bd76dc87716276f0cd70","lessThan":"0405a65e4ebd9eac13a765f9f02ac05851ca5421","versionType":"git","status":"affected"},{"version":"b6ef9161e43ad58c3824bd76dc87716276f0cd70","lessThan":"37738fdf2ab1e504d1c63ce5bc0aeb6452d8f057","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/irqchip/irq-imgpdc.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"3.12","status":"affected"},{"version":"0","lessThan":"3.12","versionType":"semver","status":"unaffected"},{"version":"5.10.260","lessThanOrEqual":"5.10.*","versionType":"semver","status":"unaffected"},{"version":"5.15.211","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.177","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.144","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.95","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.38","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.3","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/0405a65e4ebd9eac13a765f9f02ac05851ca5421","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/37738fdf2ab1e504d1c63ce5bc0aeb6452d8f057","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/41826e5297e67cd96a0a46fde06a5069a8ce436a","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/44567537a2623dcd2b4018a7f043cf8069579e5d","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/8176773dfceae7978b01c20b233693e072053700","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/83d7ec14b0938ad8cae008058fd6f912f4a9a312","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/b3a3831b2eb884641906fc5e46207b205b6aea13","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/c2c7733101bb8c0b29ac9ee41073eaf602821a59","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-63804","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-07-19T12:16:53.120","lastModified":"2026-07-19T12:16:53.120","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\ngfs2: fix use-after-free in gfs2_qd_dealloc\n\ngfs2_qd_dealloc(), called as an RCU callback from gfs2_qd_dispose(),\naccesses the superblock object sdp through qd->qd_sbd after freeing qd.\nIt does so to decrement sd_quota_count and wake up sd_kill_wait.\n\nHowever, by the time the RCU callback runs, gfs2_put_super() may have\nalready freed sdp via free_sbd().  This can happen when\ngfs2_quota_cleanup() is called during unmount: it disposes of quota\nobjects via call_rcu() and then waits on sd_kill_wait with a 60-second\ntimeout.  If the timeout expires, or if gfs2_gl_hash_clear() triggers\nadditional qd_put() calls that schedule more RCU callbacks after the\nwait completes, gfs2_put_super() will proceed to free the superblock\nwhile RCU callbacks referencing it are still pending.\n\nAdd an rcu_barrier() before free_sbd() in gfs2_put_super() to ensure\nall pending RCU callbacks (including gfs2_qd_dealloc) have completed\nbefore the superblock is freed."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["fs/gfs2/super.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"a475c5dd16e57c570113eccba51955b5df8bb052","lessThan":"4fe388218826df8607ae41a6305df67db08a9093","versionType":"git","status":"affected"},{"version":"a475c5dd16e57c570113eccba51955b5df8bb052","lessThan":"8745d9f7e1682c39f0a1578895ac74205e2a6757","versionType":"git","status":"affected"},{"version":"a475c5dd16e57c570113eccba51955b5df8bb052","lessThan":"b85ef03f726b15047a6fa6d11b639bdf6c0ee4f0","versionType":"git","status":"affected"},{"version":"a475c5dd16e57c570113eccba51955b5df8bb052","lessThan":"9d0d5ba20cad661f7f287d4c66d2c19022ce2fd0","versionType":"git","status":"affected"},{"version":"a475c5dd16e57c570113eccba51955b5df8bb052","lessThan":"f9c9ec2c319f843b70ecdf939d48b52d189bc081","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["fs/gfs2/super.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.6","status":"affected"},{"version":"0","lessThan":"6.6","versionType":"semver","status":"unaffected"},{"version":"6.6.144","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.95","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.38","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.3","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/4fe388218826df8607ae41a6305df67db08a9093","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/8745d9f7e1682c39f0a1578895ac74205e2a6757","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/9d0d5ba20cad661f7f287d4c66d2c19022ce2fd0","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/b85ef03f726b15047a6fa6d11b639bdf6c0ee4f0","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/f9c9ec2c319f843b70ecdf939d48b52d189bc081","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-63810","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-07-19T12:16:53.910","lastModified":"2026-07-19T12:16:53.910","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nblock: Avoid mounting the bdev pseudo-filesystem in userspace\n\nThe bdev pseudo-filesystem is an internal kernel filesystem with which\nuserspace should not interfere. Unregister it so that userspace cannot\neven attempt to mount it.\n\nThis fixes a bug [1] that occurs when attempting to access files,\nbecause the system call move_mount() uses pointers declared in the\ninode_operations structure, which for the bdev pseudo-filesystem\nare always equal to 0. `inode->i_op = &empty_iops;`\n\n[1]\n\n BUG: kernel NULL pointer dereference, address: 0000000000000000\n #PF: supervisor instruction fetch in kernel mode\n #PF: error_code(0x0010) - not-present page\n PGD 23380067 P4D 23380067 PUD 23381067 PMD 0\n Oops: 0010 [#1] PREEMPT SMP KASAN NOPTI\n CPU: 2 PID: 17125 Comm: syz-executor.0 Not tainted 6.1.155-syzkaller-00350-g84221fde2681 #0\n Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS 1.12.0-1 04/01/2014\n RIP: 0010:0x0\n\n Call Trace:\n <TASK>\n lookup_open.isra.0+0x700/0x1180 fs/namei.c:3460\n open_last_lookups fs/namei.c:3550 [inline]\n path_openat+0x953/0x2700 fs/namei.c:3780\n do_filp_open+0x1c5/0x410 fs/namei.c:3810\n do_sys_openat2+0x171/0x4d0 fs/open.c:1318\n do_sys_open fs/open.c:1334 [inline]\n __do_sys_openat fs/open.c:1350 [inline]\n __se_sys_openat fs/open.c:1345 [inline]\n __x64_sys_openat+0x13c/0x1f0 fs/open.c:1345\n do_syscall_x64 arch/x86/entry/common.c:51 [inline]\n do_syscall_64+0x35/0x80 arch/x86/entry/common.c:81\n entry_SYSCALL_64_after_hwframe+0x6e/0xd8\n\nFound by Linux Verification Center (linuxtesting.org) with Syzkaller."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["block/bdev.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"197971e6ffc0a6356b2ba2b22beb42bc0f7e412d","versionType":"git","status":"affected"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"3804e6de30ae7b053d53341d9d6944356cf23b40","versionType":"git","status":"affected"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"717f721eb67d2dacd3ed5f7495aef2f442e84ce4","versionType":"git","status":"affected"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"f73aa66dffcb8e61e78f01b56163ec16a15d06d2","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["block/bdev.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"2.6.12","status":"affected"},{"version":"0","lessThan":"2.6.12","versionType":"semver","status":"unaffected"},{"version":"6.12.95","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.38","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.3","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/197971e6ffc0a6356b2ba2b22beb42bc0f7e412d","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/3804e6de30ae7b053d53341d9d6944356cf23b40","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/717f721eb67d2dacd3ed5f7495aef2f442e84ce4","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/f73aa66dffcb8e61e78f01b56163ec16a15d06d2","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-63811","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-07-19T12:16:54.023","lastModified":"2026-07-19T12:16:54.023","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nf2fs: read COW data with the original inode during atomic write\n\nWhen updating an atomic-write file, f2fs_write_begin() may read the\npreviously written data back from the COW inode:\nprepare_atomic_write_begin() locates the block in the COW inode and sets\nuse_cow, and the read bio is then built with the COW inode:\n\n\tf2fs_submit_page_read(use_cow ? F2FS_I(inode)->cow_inode : inode,\n\t\t\t      ...);\n\nand f2fs_grab_read_bio() decides whether to schedule fs-layer decryption\n(STEP_DECRYPT) for the bio based on that inode via\nfscrypt_inode_uses_fs_layer_crypto().\n\nHowever, the folio being filled belongs to the original inode\n(folio->mapping->host == inode), and the data stored in the COW block was\nencrypted (or left as plaintext) using the original inode's context, not\nthe COW inode's -- see f2fs_encrypt_one_page(), which keys off\nfio->page->mapping->host.  fscrypt_decrypt_pagecache_blocks() likewise\noperates on folio->mapping->host.\n\nThe COW inode is created as a tmpfile in the parent directory and inherits\nits encryption policy from there.  With test_dummy_encryption the newly\ncreated COW inode gets the dummy policy and becomes encrypted, while a\npre-existing regular file -- created before the policy applied, e.g.\nalready present in the on-disk image -- stays unencrypted.  The read\npath then sets STEP_DECRYPT based on the encrypted COW inode and calls\nfscrypt_decrypt_pagecache_blocks() on a folio whose host (the unencrypted\noriginal inode) has a NULL ->i_crypt_info, dereferencing it:\n\n  Oops: general protection fault, probably for non-canonical address ...\n  KASAN: null-ptr-deref in range [0x0000000000000008-0x000000000000000f]\n  RIP: 0010:fscrypt_decrypt_pagecache_blocks+0xa0/0x310\n  Workqueue: f2fs_post_read_wq f2fs_post_read_work\n  Call Trace:\n   fscrypt_decrypt_bio+0x1eb/0x340\n   f2fs_post_read_work+0xba/0x140\n   process_one_work+0x91c/0x1a40\n   worker_thread+0x677/0xe90\n   kthread+0x2bc/0x3a0\n\nThe COW inode is only needed to locate the on-disk block, and that block\naddress is already resolved into @blkaddr by prepare_atomic_write_begin()\nvia __find_data_block(cow_inode, ...); f2fs_submit_page_read() then reads\nfrom that physical @blkaddr directly, so the inode argument only selects\nthe post-read crypto context, not which block is fetched.  Reading with\n@inode therefore returns the same (latest, not-yet-committed) COW data,\nwhile making both the fs-layer decryption decision and the inline crypto\npath use the correct (original inode's) key.\n\nWith the COW inode no longer used at the read site, the use_cow flag has no\nremaining consumer; drop it from f2fs_write_begin() and\nprepare_atomic_write_begin()."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["fs/f2fs/data.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"591fc34e1f98b0d7eef4aa3440bfdff3c5a1cadd","lessThan":"a92332f32a8d31a7eee47b1dc1d751cb3319908f","versionType":"git","status":"affected"},{"version":"591fc34e1f98b0d7eef4aa3440bfdff3c5a1cadd","lessThan":"a41075acde0124d2f8a5f563068a5d63e8ffd57b","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["fs/f2fs/data.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.4","status":"affected"},{"version":"0","lessThan":"6.4","versionType":"semver","status":"unaffected"},{"version":"7.1.3","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/a41075acde0124d2f8a5f563068a5d63e8ffd57b","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/a92332f32a8d31a7eee47b1dc1d751cb3319908f","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-63820","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-07-19T12:16:55.103","lastModified":"2026-07-19T12:16:55.103","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nf2fs: fix missing read bio submission on large folio error\n\nf2fs_read_data_large_folio() can keep a read bio across multiple\nreadahead folios.  If a later folio hits an error before any of its\nblocks are added to the bio, folio_in_bio is false and the current error\npath returns immediately after ending that folio.\n\nThis can leave the bio accumulated for earlier folios unsubmitted.  Those\nfolios then never receive read completion, and readers can wait\nindefinitely on the locked folios.\n\nRoute errors through the common out path so any pending bio is submitted\nbefore returning.  Stop consuming more readahead folios once an error is\nseen, and only wait on and clear the current folio when it was actually\nadded to the bio."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["fs/f2fs/data.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"a5d8b9d94e1863f3ebb7182c238b2c713f6f4efd","lessThan":"48c92559e7b66fdc3cbc74f6e152e66ec0150a0a","versionType":"git","status":"affected"},{"version":"a5d8b9d94e1863f3ebb7182c238b2c713f6f4efd","lessThan":"74c8d2ec95c59a5651ecd975c466998af1961fd4","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["fs/f2fs/data.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"7.0","status":"affected"},{"version":"0","lessThan":"7.0","versionType":"semver","status":"unaffected"},{"version":"7.1.3","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/48c92559e7b66fdc3cbc74f6e152e66ec0150a0a","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/74c8d2ec95c59a5651ecd975c466998af1961fd4","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-63821","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-07-19T12:16:55.203","lastModified":"2026-07-19T12:16:55.203","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: rtw88: usb: fix memory leaks on USB write failures\n\nWhen rtw_usb_write_port() fails to submit a USB Request Block (URB)\n(e.g., due to device disconnect or ENOMEM), the completion callback is\nnever executed.\n\nCurrently, the driver ignores the return value of rtw_usb_write_port()\nin rtw_usb_write_data() and rtw_usb_tx_agg_skb(). Because these\nfunctions rely on the completion callback to free the socket buffers\n(skbs) and the transaction control block (txcb), a submission failure\nresults in:\n1. A memory leak of the allocated skb in rtw_usb_write_data().\n2. A memory leak of the txcb structure and all aggregated skbs in\n   rtw_usb_tx_agg_skb().\n\nFix this by checking the return value of rtw_usb_write_port(). If it\nfails, explicitly free the skb in rtw_usb_write_data(), and properly\npurge the tx_ack_queue and free the txcb in rtw_usb_tx_agg_skb().\n\nThe issue was discovered in practice during device disconnect/reconnect\nscenarios and memory pressure conditions. Tested by verifying normal TX\noperation continues after the fix without regressions."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/net/wireless/realtek/rtw88/usb.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"a82dfd33d1237f6c0fb8a7077022189d1fc7ec98","lessThan":"2b2060c2075a72bc2de43ce5e1b9347d6c5e27bb","versionType":"git","status":"affected"},{"version":"a82dfd33d1237f6c0fb8a7077022189d1fc7ec98","lessThan":"53fed4061a09755de99c89fdc7fae5b794da455f","versionType":"git","status":"affected"},{"version":"a82dfd33d1237f6c0fb8a7077022189d1fc7ec98","lessThan":"200d58c851b8f63f77a05570072dd20f79bc3681","versionType":"git","status":"affected"},{"version":"a82dfd33d1237f6c0fb8a7077022189d1fc7ec98","lessThan":"8206d173d18ef5a077423119f4e9a93cb3a6f4eb","versionType":"git","status":"affected"},{"version":"a82dfd33d1237f6c0fb8a7077022189d1fc7ec98","lessThan":"6b964941bbfe6e0f18b1a5e008486dbb62df440a","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/net/wireless/realtek/rtw88/usb.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.2","status":"affected"},{"version":"0","lessThan":"6.2","versionType":"semver","status":"unaffected"},{"version":"6.6.144","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.95","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.38","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.3","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/200d58c851b8f63f77a05570072dd20f79bc3681","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/2b2060c2075a72bc2de43ce5e1b9347d6c5e27bb","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/53fed4061a09755de99c89fdc7fae5b794da455f","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/6b964941bbfe6e0f18b1a5e008486dbb62df440a","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/8206d173d18ef5a077423119f4e9a93cb3a6f4eb","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-63822","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-07-19T12:16:55.330","lastModified":"2026-07-19T12:16:55.330","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: ath11k: fix warning when unbinding\n\nIf there is an error during some initialization related to firmware,\nthe buffers dp->tx_ring[i].tx_status are released.\nHowever this is released again when the device is unbinded (ath11k_pci),\nand we get:\nWARNING: CPU: 0 PID: 6231 at mm/slub.c:4368 free_large_kmalloc+0x57/0x90\nCall Trace:\nfree_large_kmalloc\nath11k_dp_free\nath11k_core_deinit\nath11k_pci_remove\n...\n\nThe issue is always reproducible from a VM because the MSI addressing\ninitialization is failing.\n\nIn order to fix the issue, just set the buffers to NULL after releasing in\norder to avoid the double free."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/net/wireless/ath/ath11k/dp.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"d5c65159f2895379e11ca13f62feabe93278985d","lessThan":"e569a5cb401a267168621aa9a1e7f07fcc9612c3","versionType":"git","status":"affected"},{"version":"d5c65159f2895379e11ca13f62feabe93278985d","lessThan":"0aa097a370277deab5337030b9e2d395742f469c","versionType":"git","status":"affected"},{"version":"d5c65159f2895379e11ca13f62feabe93278985d","lessThan":"0a946abb82f29abe9a15173b707a449cb039b43e","versionType":"git","status":"affected"},{"version":"d5c65159f2895379e11ca13f62feabe93278985d","lessThan":"318703b6f71d1a29ee0ac46c32a38f7734d4cfb2","versionType":"git","status":"affected"},{"version":"d5c65159f2895379e11ca13f62feabe93278985d","lessThan":"7b2e62b9080bf4a5f4e70cfe47156df8d93a4f13","versionType":"git","status":"affected"},{"version":"d5c65159f2895379e11ca13f62feabe93278985d","lessThan":"40aa3c2b0cb8e34e0576fc94cc70e4e33db03c0a","versionType":"git","status":"affected"},{"version":"d5c65159f2895379e11ca13f62feabe93278985d","lessThan":"051f954b94479d72222c9fbc82a3eef4777bca01","versionType":"git","status":"affected"},{"version":"d5c65159f2895379e11ca13f62feabe93278985d","lessThan":"8b7a26b6681922a38cd5a7829ace61f8e54df9b7","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/net/wireless/ath/ath11k/dp.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"5.6","status":"affected"},{"version":"0","lessThan":"5.6","versionType":"semver","status":"unaffected"},{"version":"5.10.260","lessThanOrEqual":"5.10.*","versionType":"semver","status":"unaffected"},{"version":"5.15.211","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.177","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.144","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.95","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.38","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.3","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/051f954b94479d72222c9fbc82a3eef4777bca01","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/0a946abb82f29abe9a15173b707a449cb039b43e","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/0aa097a370277deab5337030b9e2d395742f469c","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/318703b6f71d1a29ee0ac46c32a38f7734d4cfb2","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/40aa3c2b0cb8e34e0576fc94cc70e4e33db03c0a","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/7b2e62b9080bf4a5f4e70cfe47156df8d93a4f13","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/8b7a26b6681922a38cd5a7829ace61f8e54df9b7","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/e569a5cb401a267168621aa9a1e7f07fcc9612c3","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-63834","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-07-19T12:16:56.840","lastModified":"2026-07-19T12:16:56.840","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nbatman-adv: tp_meter: restrict number of unacked list entries\n\nWhen the unacked_list is unbound, an attacker could send messages with\nsmall lengths and appropriated seqno + gaps to force the receiver to\nallocate more and more unacked_list entries. And the end either causing an\nout-of-memory situation or increase the management overhead for the (large)\nlist that significant portions of CPU cycles are wasted in searching\nthrough the list.\n\nWhen limiting the list to a specific number, it is important to still\ncorrectly add a new entry to the list. But if the list became larger than\nthe limit, the last entry of the list (with the highest seqno) must be\ndropped to still allow the earlier seqnos to finish and therefore to\ncontinue the process. Otherwise, the process might get stuck with too high\nseqnos which are not handled by batadv_tp_ack_unordered()."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["net/batman-adv/tp_meter.c","net/batman-adv/types.h"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"33a3bb4a3345bb511f9c69c913da95d4693e2a4e","lessThan":"31a88792bfba142be3c9521538c1db805677381f","versionType":"git","status":"affected"},{"version":"33a3bb4a3345bb511f9c69c913da95d4693e2a4e","lessThan":"1111a3381bca2d1f084a07686bc783af5ab23df7","versionType":"git","status":"affected"},{"version":"33a3bb4a3345bb511f9c69c913da95d4693e2a4e","lessThan":"1c616b0be4bd8399d485e25e91859373b95d6013","versionType":"git","status":"affected"},{"version":"33a3bb4a3345bb511f9c69c913da95d4693e2a4e","lessThan":"f8c499fd275e59203b77fca76ae6ef2d096c2133","versionType":"git","status":"affected"},{"version":"33a3bb4a3345bb511f9c69c913da95d4693e2a4e","lessThan":"c6231d628d06d841bc1617b2f7034f5f39876b16","versionType":"git","status":"affected"},{"version":"33a3bb4a3345bb511f9c69c913da95d4693e2a4e","lessThan":"2233787658db859f0a9b83cb397cf783bb8be865","versionType":"git","status":"affected"},{"version":"33a3bb4a3345bb511f9c69c913da95d4693e2a4e","lessThan":"1fb8762600a393d1caccd63be5d07e1756982d68","versionType":"git","status":"affected"},{"version":"33a3bb4a3345bb511f9c69c913da95d4693e2a4e","lessThan":"e7c775110e1858e5a7471a23a9c9658c0af9df89","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["net/batman-adv/tp_meter.c","net/batman-adv/types.h"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"4.8","status":"affected"},{"version":"0","lessThan":"4.8","versionType":"semver","status":"unaffected"},{"version":"5.10.260","lessThanOrEqual":"5.10.*","versionType":"semver","status":"unaffected"},{"version":"5.15.211","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.177","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.144","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.95","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.38","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.3","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/1111a3381bca2d1f084a07686bc783af5ab23df7","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/1c616b0be4bd8399d485e25e91859373b95d6013","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/1fb8762600a393d1caccd63be5d07e1756982d68","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/2233787658db859f0a9b83cb397cf783bb8be865","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/31a88792bfba142be3c9521538c1db805677381f","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/c6231d628d06d841bc1617b2f7034f5f39876b16","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/e7c775110e1858e5a7471a23a9c9658c0af9df89","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/f8c499fd275e59203b77fca76ae6ef2d096c2133","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-63835","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-07-19T12:16:56.970","lastModified":"2026-07-19T12:16:56.970","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nbatman-adv: v: prevent OGM aggregation on disabled hardif\n\nWhen an interface gets disabled, the worker is correctly disabled by\nbatadv_hardif_disable_interface() -> ... -> batadv_v_ogm_iface_disable().\nIn this process, the skb aggr_list is also freed.\n\nBut batadv_v_ogm_send_meshif() can still queue new skbs (via\nbatadv_v_ogm_queue_on_if()) to the aggr_list. This will only stop after all\ncores can no longer find the RCU protected list of hard interfaces. These\nqueued skbs will never be freed or consumed by batadv_v_ogm_aggr_work.\n\nThe batadv_v_ogm_iface_disable() function must block\nbatadv_v_ogm_queue_on_if() to avoid leak of skbs."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["net/batman-adv/bat_v.c","net/batman-adv/bat_v_ogm.c","net/batman-adv/types.h"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"f89255a02f1d75d8e1b9d1c31435fcb64840cb2a","lessThan":"d462ced79dd430200cf888984e8005da77fc810b","versionType":"git","status":"affected"},{"version":"f89255a02f1d75d8e1b9d1c31435fcb64840cb2a","lessThan":"f79deaaf822ab0ee2424cf28781f9ab91576bea3","versionType":"git","status":"affected"},{"version":"f89255a02f1d75d8e1b9d1c31435fcb64840cb2a","lessThan":"d3569327fc7395b2b0461a0a0cb77a0bb74786c0","versionType":"git","status":"affected"},{"version":"f89255a02f1d75d8e1b9d1c31435fcb64840cb2a","lessThan":"97644fdaaf6446ffbe182c5eb804fceb5b1a51b7","versionType":"git","status":"affected"},{"version":"f89255a02f1d75d8e1b9d1c31435fcb64840cb2a","lessThan":"f04dde74399431fb07abbdd9cd5d0ed624771d04","versionType":"git","status":"affected"},{"version":"f89255a02f1d75d8e1b9d1c31435fcb64840cb2a","lessThan":"3d4548c96d6f21ac1a9b06c5f82f3ef439c87023","versionType":"git","status":"affected"},{"version":"f89255a02f1d75d8e1b9d1c31435fcb64840cb2a","lessThan":"86ab6b6fb5b82163bf6c45780bb72150021d7349","versionType":"git","status":"affected"},{"version":"f89255a02f1d75d8e1b9d1c31435fcb64840cb2a","lessThan":"d11c00b95b2a3b3934007fc003dccc6fdcc061ad","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["net/batman-adv/bat_v.c","net/batman-adv/bat_v_ogm.c","net/batman-adv/types.h"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"5.4","status":"affected"},{"version":"0","lessThan":"5.4","versionType":"semver","status":"unaffected"},{"version":"5.10.260","lessThanOrEqual":"5.10.*","versionType":"semver","status":"unaffected"},{"version":"5.15.211","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.177","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.144","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.95","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.38","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.3","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/3d4548c96d6f21ac1a9b06c5f82f3ef439c87023","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/86ab6b6fb5b82163bf6c45780bb72150021d7349","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/97644fdaaf6446ffbe182c5eb804fceb5b1a51b7","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/d11c00b95b2a3b3934007fc003dccc6fdcc061ad","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/d3569327fc7395b2b0461a0a0cb77a0bb74786c0","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/d462ced79dd430200cf888984e8005da77fc810b","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/f04dde74399431fb07abbdd9cd5d0ed624771d04","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/f79deaaf822ab0ee2424cf28781f9ab91576bea3","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-63836","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-07-19T12:16:57.103","lastModified":"2026-07-19T12:16:57.103","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nbatman-adv: tp_meter: avoid divide-by-zero for dec_cwnd\n\nThe cwnd is always MSS <= cwnd <= 0x20000000. But the calculation in\nbatadv_tp_update_cwnd() assumes unsigned 32 bit arithmetics.\n\n    ((mss * 8) ** 2) / (cwnd * 8)\n\nIn case cwnd is actually 0x20000000, it will be shifted by 3 bit to the\nleft end up at 0x100000000 or U32_MAX + 1. It will therefore wrap around\nand be 0 - resulting in:\n\n    ((mss * 8) ** 2) / 0\n\nThis is of course invalid and cannot be calculated. The calculation should\nmust be simplified to avoid this overflow:\n\n   (mss ** 2) * 8 / cwnd\n\nIt will keep the precision enhancement from the scaling (by 8) but avoid\nthe overflow in the divisor.\n\nIn theory, there could still be an overflow in the dividend. It is at the\nmoment fixed to BATADV_TP_PLEN in batadv_tp_recv_ack() - so it is not an\nimminent problem. But allowing it to use the whole u32 bit range, would\nmean that it can still use up to 67 bits. To keep this calculation safe for\n32 bit arithmetic, mss must never use more than floor((32 - 3) / 2) bits -\nor in other words: must never be larger than 16383."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["net/batman-adv/tp_meter.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"33a3bb4a3345bb511f9c69c913da95d4693e2a4e","lessThan":"35264c4d46067d6312871488c810cef387f8c1f6","versionType":"git","status":"affected"},{"version":"33a3bb4a3345bb511f9c69c913da95d4693e2a4e","lessThan":"1381b021bf886b793fa5ffb895a8efae7ba0318f","versionType":"git","status":"affected"},{"version":"33a3bb4a3345bb511f9c69c913da95d4693e2a4e","lessThan":"d08b69da40a101df1e28bfe1e8fa7a09ffa41107","versionType":"git","status":"affected"},{"version":"33a3bb4a3345bb511f9c69c913da95d4693e2a4e","lessThan":"cd74176cf1685f35a2e5f212d15748bbfecb53b6","versionType":"git","status":"affected"},{"version":"33a3bb4a3345bb511f9c69c913da95d4693e2a4e","lessThan":"ac229c86e49fdb96d91f51bc2fa37a9c4f58c44f","versionType":"git","status":"affected"},{"version":"33a3bb4a3345bb511f9c69c913da95d4693e2a4e","lessThan":"7d2a44bc6bbe39aed03c68864aa0e54e04a50278","versionType":"git","status":"affected"},{"version":"33a3bb4a3345bb511f9c69c913da95d4693e2a4e","lessThan":"585616dab0aa9c45bc11b2c8082ca78533bc00e9","versionType":"git","status":"affected"},{"version":"33a3bb4a3345bb511f9c69c913da95d4693e2a4e","lessThan":"33ccd52f3cc9ed46ce395199f89aa3234dc83314","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["net/batman-adv/tp_meter.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"4.8","status":"affected"},{"version":"0","lessThan":"4.8","versionType":"semver","status":"unaffected"},{"version":"5.10.260","lessThanOrEqual":"5.10.*","versionType":"semver","status":"unaffected"},{"version":"5.15.211","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.177","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.144","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.95","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.38","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.3","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/1381b021bf886b793fa5ffb895a8efae7ba0318f","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/33ccd52f3cc9ed46ce395199f89aa3234dc83314","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/35264c4d46067d6312871488c810cef387f8c1f6","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/585616dab0aa9c45bc11b2c8082ca78533bc00e9","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/7d2a44bc6bbe39aed03c68864aa0e54e04a50278","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/ac229c86e49fdb96d91f51bc2fa37a9c4f58c44f","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/cd74176cf1685f35a2e5f212d15748bbfecb53b6","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/d08b69da40a101df1e28bfe1e8fa7a09ffa41107","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}}]}