{"resultsPerPage":11,"startIndex":0,"totalResults":11,"format":"NVD_CVE","version":"2.0","timestamp":"2026-07-21T05:15:42.214","vulnerabilities":[{"cve":{"id":"CVE-2026-15379","sourceIdentifier":"secure@symantec.com","published":"2026-07-17T08:16:57.773","lastModified":"2026-07-19T14:16:24.237","vulnStatus":"Awaiting Analysis","cveTags":[],"descriptions":[{"lang":"en","value":"The Altiris WMI provider exposes a class (AltirisAgent_Stream) that allows any local standard user to read the contents of any file accessible to the SYSTEM account, bypassing filesystem ACLs. No admin privileges required. The provider reverts to the LocalSystem context when servicing WMI queries without re-impersonating the caller. Any local standard user can therefore read SYSTEM-readable files — including configuration files, service logs, and secrets stored with SYSTEM/Administrator-only ACLs — by querying the provider directly."}],"affected":[{"source":"secure@symantec.com","affectedData":[{"vendor":"Broadcom","product":"Symantec IT Management Suite","defaultStatus":"unaffected","versions":[{"version":"before SMA_SMP_8_8_PF_v13 and SMA_SMP_8_8_1_PF_v5","status":"affected"}]}]}],"metrics":{"cvssMetricV40":[{"source":"secure@symantec.com","type":"Secondary","cvssData":{"version":"4.0","vectorString":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:Y/R:A/V:C/RE:M/U:Red","baseScore":5.1,"baseSeverity":"MEDIUM","attackVector":"LOCAL","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"LOW","userInteraction":"ACTIVE","vulnConfidentialityImpact":"HIGH","vulnIntegrityImpact":"NONE","vulnAvailabilityImpact":"NONE","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","subAvailabilityImpact":"NONE","exploitMaturity":"NOT_DEFINED","confidentialityRequirement":"NOT_DEFINED","integrityRequirement":"NOT_DEFINED","availabilityRequirement":"NOT_DEFINED","modifiedAttackVector":"NOT_DEFINED","modifiedAttackComplexity":"NOT_DEFINED","modifiedAttackRequirements":"NOT_DEFINED","modifiedPrivilegesRequired":"NOT_DEFINED","modifiedUserInteraction":"NOT_DEFINED","modifiedVulnConfidentialityImpact":"NOT_DEFINED","modifiedVulnIntegrityImpact":"NOT_DEFINED","modifiedVulnAvailabilityImpact":"NOT_DEFINED","modifiedSubConfidentialityImpact":"NOT_DEFINED","modifiedSubIntegrityImpact":"NOT_DEFINED","modifiedSubAvailabilityImpact":"NOT_DEFINED","Safety":"NOT_DEFINED","Automatable":"YES","Recovery":"AUTOMATIC","valueDensity":"CONCENTRATED","vulnerabilityResponseEffort":"MODERATE","providerUrgency":"RED"}}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-07-17T10:09:47.422633Z","id":"CVE-2026-15379","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"references":[{"url":"https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/37995","source":"secure@symantec.com"}]}},{"cve":{"id":"CVE-2026-15380","sourceIdentifier":"secure@symantec.com","published":"2026-07-17T08:16:58.913","lastModified":"2026-07-19T14:16:24.927","vulnStatus":"Awaiting Analysis","cveTags":[],"descriptions":[{"lang":"en","value":"A non-administrator interactive user can obtain full SYSTEM code execution through a DCOM/task scheduler logic chain — no network access, no memory corruption required (ITMS 8.7.3)"}],"affected":[{"source":"secure@symantec.com","affectedData":[{"vendor":"Broadcom","product":"Symantec Management Suite","defaultStatus":"unaffected","versions":[{"version":"before SMA_SMP_8_8_PF_v13 and SMA_SMP_8_8_1_PF_v5","status":"affected"}]}]}],"metrics":{"cvssMetricV40":[{"source":"secure@symantec.com","type":"Secondary","cvssData":{"version":"4.0","vectorString":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:N/AU:Y/R:A/V:C/RE:M/U:Red","baseScore":5.1,"baseSeverity":"MEDIUM","attackVector":"LOCAL","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"LOW","userInteraction":"ACTIVE","vulnConfidentialityImpact":"HIGH","vulnIntegrityImpact":"NONE","vulnAvailabilityImpact":"NONE","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","subAvailabilityImpact":"NONE","exploitMaturity":"NOT_DEFINED","confidentialityRequirement":"NOT_DEFINED","integrityRequirement":"NOT_DEFINED","availabilityRequirement":"NOT_DEFINED","modifiedAttackVector":"NOT_DEFINED","modifiedAttackComplexity":"NOT_DEFINED","modifiedAttackRequirements":"NOT_DEFINED","modifiedPrivilegesRequired":"NOT_DEFINED","modifiedUserInteraction":"NOT_DEFINED","modifiedVulnConfidentialityImpact":"NOT_DEFINED","modifiedVulnIntegrityImpact":"NOT_DEFINED","modifiedVulnAvailabilityImpact":"NOT_DEFINED","modifiedSubConfidentialityImpact":"NOT_DEFINED","modifiedSubIntegrityImpact":"NOT_DEFINED","modifiedSubAvailabilityImpact":"NOT_DEFINED","Safety":"NEGLIGIBLE","Automatable":"YES","Recovery":"AUTOMATIC","valueDensity":"CONCENTRATED","vulnerabilityResponseEffort":"MODERATE","providerUrgency":"RED"}}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-07-17T10:08:32.037888Z","id":"CVE-2026-15380","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"references":[{"url":"https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/37995","source":"secure@symantec.com"}]}},{"cve":{"id":"CVE-2026-63837","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-07-19T15:16:50.480","lastModified":"2026-07-19T15:16:50.480","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nnet: ena: PHC: Check return code before setting timestamp output\n\nena_phc_gettimex64() is setting the output parameter regardless\nof whether ena_com_phc_get_timestamp() succeeded or failed.\n\nWhen ena_com_phc_get_timestamp() returns an error, the timestamp\nparameter may contain uninitialized stack memory (e.g., when PHC is\ndisabled or in blocked state) or invalid hardware values. Passing\nthese to userspace via the PTP ioctl is both a security issue\n(information leak) and a correctness bug.\n\nFix by checking the return code after releasing the lock and only\nsetting the output timestamp on success."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/net/ethernet/amazon/ena/ena_phc.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"e0ea34158ee8c4f7536cd781010339ff28c0d24c","lessThan":"bddf59818ae5102e6d82a4dae5add6df8da38fb0","versionType":"git","status":"affected"},{"version":"e0ea34158ee8c4f7536cd781010339ff28c0d24c","lessThan":"edcb049d836e175e7b3d5e0d05657104545b5e65","versionType":"git","status":"affected"},{"version":"e0ea34158ee8c4f7536cd781010339ff28c0d24c","lessThan":"24a08d7d6218d60c033015cf4870b6096446e734","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/net/ethernet/amazon/ena/ena_phc.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.17","status":"affected"},{"version":"0","lessThan":"6.17","versionType":"semver","status":"unaffected"},{"version":"6.18.33","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.0.10","lessThanOrEqual":"7.0.*","versionType":"semver","status":"unaffected"},{"version":"7.1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/24a08d7d6218d60c033015cf4870b6096446e734","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/bddf59818ae5102e6d82a4dae5add6df8da38fb0","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/edcb049d836e175e7b3d5e0d05657104545b5e65","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-63838","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-07-19T15:16:50.583","lastModified":"2026-07-19T15:16:50.583","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nASoC: rsnd: Fix potential out-of-bounds access of component_dais[]\n\ncomponent_dais[RSND_MAX_COMPONENT] is initially zero-initialized\nand later populated in rsnd_dai_of_node(). However, the existing boundary check:\n  if (i >= RSND_MAX_COMPONENT)\n\ndoes not guarantee that the last valid element remains zero. As a result,\nthe loop can rely on component_dais[RSND_MAX_COMPONENT] being zero,\nwhich may lead to an out-of-bounds access.\n\nFound by Linux Verification Center (linuxtesting.org) with SVACE."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["sound/soc/renesas/rcar/core.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"547b02f74e4ac1e7d295a6266d5bc93a647cd4ac","lessThan":"9f1daac27ca28e98c8c0e4450de42bb68d547250","versionType":"git","status":"affected"},{"version":"547b02f74e4ac1e7d295a6266d5bc93a647cd4ac","lessThan":"15e7b2ac2455995a6af02b9d3da7a432837aaf72","versionType":"git","status":"affected"},{"version":"547b02f74e4ac1e7d295a6266d5bc93a647cd4ac","lessThan":"134c61925e9e9ee0f4fdbab5c3984d5bb024f5f5","versionType":"git","status":"affected"},{"version":"547b02f74e4ac1e7d295a6266d5bc93a647cd4ac","lessThan":"a62b3e6e42359a79158c134e3cf5c74fe160c3f5","versionType":"git","status":"affected"},{"version":"547b02f74e4ac1e7d295a6266d5bc93a647cd4ac","lessThan":"f9e437cddf6cf9e603bdaefe148c1f4792aaf39c","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["sound/soc/renesas/rcar/core.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.6","status":"affected"},{"version":"0","lessThan":"6.6","versionType":"semver","status":"unaffected"},{"version":"6.6.141","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.91","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.33","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.0.10","lessThanOrEqual":"7.0.*","versionType":"semver","status":"unaffected"},{"version":"7.1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/134c61925e9e9ee0f4fdbab5c3984d5bb024f5f5","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/15e7b2ac2455995a6af02b9d3da7a432837aaf72","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/9f1daac27ca28e98c8c0e4450de42bb68d547250","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/a62b3e6e42359a79158c134e3cf5c74fe160c3f5","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/f9e437cddf6cf9e603bdaefe148c1f4792aaf39c","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-63839","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-07-19T15:16:50.693","lastModified":"2026-07-19T15:16:50.693","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nplatform/x86: lenovo-wmi-helpers: Fix memory leak in lwmi_dev_evaluate_int()\n\nlwmi_dev_evaluate_int() leaks output.pointer when retval == NULL (found\nby sashiko.dev [1]).\n\nFix it by moving `ret_obj = output.pointer' outside of the `if (retval)'\nblock so that it is always freed by the __free cleanup callback.\n\nNo functional change intended."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/platform/x86/lenovo/wmi-helpers.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"e521d16e76cd9ea99c585e064f4e7daf657b1451","lessThan":"40a984dd0602e238ad893b167751620e751d1199","versionType":"git","status":"affected"},{"version":"e521d16e76cd9ea99c585e064f4e7daf657b1451","lessThan":"0c3887a134f191723b53e2a47e501b534c8723ee","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/platform/x86/lenovo/wmi-helpers.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.17","status":"affected"},{"version":"0","lessThan":"6.17","versionType":"semver","status":"unaffected"},{"version":"7.0.10","lessThanOrEqual":"7.0.*","versionType":"semver","status":"unaffected"},{"version":"7.1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/0c3887a134f191723b53e2a47e501b534c8723ee","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/40a984dd0602e238ad893b167751620e751d1199","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-63859","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-07-19T15:16:52.750","lastModified":"2026-07-19T15:16:52.750","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nnet: airoha: Add missing bits in airoha_qdma_cleanup_tx_queue()\n\nSimilar to airoha_qdma_cleanup_rx_queue(), reset DMA TX descriptors in\nairoha_qdma_cleanup_tx_queue routine. Moreover, reset TX_DMA_IDX to\nTX_CPU_IDX to notify the NIC the QDMA TX ring is empty."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/net/ethernet/airoha/airoha_eth.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"23020f04932701d5c8363e60756f12b43b8ed752","lessThan":"c0cfce4d76702dba9601a4020df1a0bc35806efc","versionType":"git","status":"affected"},{"version":"23020f04932701d5c8363e60756f12b43b8ed752","lessThan":"9b5d56fe389d68ede080c716e6f10895facaf7db","versionType":"git","status":"affected"},{"version":"23020f04932701d5c8363e60756f12b43b8ed752","lessThan":"3309965fe44c00fd65af7cef5016e9e782c021a7","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/net/ethernet/airoha/airoha_eth.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.11","status":"affected"},{"version":"0","lessThan":"6.11","versionType":"semver","status":"unaffected"},{"version":"6.18.33","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.0.10","lessThanOrEqual":"7.0.*","versionType":"semver","status":"unaffected"},{"version":"7.1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/3309965fe44c00fd65af7cef5016e9e782c021a7","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/9b5d56fe389d68ede080c716e6f10895facaf7db","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/c0cfce4d76702dba9601a4020df1a0bc35806efc","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-63861","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-07-19T15:16:52.973","lastModified":"2026-07-19T15:16:52.973","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nspi: mtk-snfi: unregister ECC engine on probe failure and remove() callback\n\nmtk_snand_probe() registers the on-host NAND ECC engine, but teardown was\nmissing from both probe unwind and remove-time cleanup. Add a devm cleanup\naction after successful registration so\nnand_ecc_unregister_on_host_hw_engine() runs automatically on probe\nfailures and during device removal."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/spi/spi-mtk-snfi.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"764f1b7481645b2b4488eda26c4da7f331697e6b","lessThan":"6aea4a99410615912d80a4ba0827c4e8d4a8312d","versionType":"git","status":"affected"},{"version":"764f1b7481645b2b4488eda26c4da7f331697e6b","lessThan":"3e79a563377a319d016ed0d3cd8c43171670c0f3","versionType":"git","status":"affected"},{"version":"764f1b7481645b2b4488eda26c4da7f331697e6b","lessThan":"86357e1d0157d8408b78f8768a69ab263d010316","versionType":"git","status":"affected"},{"version":"764f1b7481645b2b4488eda26c4da7f331697e6b","lessThan":"e0b049bd7b279d7b6ad22a637cddced93198a51b","versionType":"git","status":"affected"},{"version":"764f1b7481645b2b4488eda26c4da7f331697e6b","lessThan":"98cf4b58299e0c6a537c68cd32155d9e7569e7cb","versionType":"git","status":"affected"},{"version":"764f1b7481645b2b4488eda26c4da7f331697e6b","lessThan":"ab00febad191d7a4400aa1c3468279fb508258d4","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/spi/spi-mtk-snfi.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"5.19","status":"affected"},{"version":"0","lessThan":"5.19","versionType":"semver","status":"unaffected"},{"version":"6.1.175","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.141","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.91","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.33","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.0.10","lessThanOrEqual":"7.0.*","versionType":"semver","status":"unaffected"},{"version":"7.1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/3e79a563377a319d016ed0d3cd8c43171670c0f3","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/6aea4a99410615912d80a4ba0827c4e8d4a8312d","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/86357e1d0157d8408b78f8768a69ab263d010316","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/98cf4b58299e0c6a537c68cd32155d9e7569e7cb","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/ab00febad191d7a4400aa1c3468279fb508258d4","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/e0b049bd7b279d7b6ad22a637cddced93198a51b","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-63862","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-07-19T15:16:53.097","lastModified":"2026-07-19T15:16:53.097","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nPCI: mediatek-gen3: Prevent leaking IRQ domains when IRQ not found\n\nIn mtk_pcie_setup_irq(), the IRQ domains are allocated before the\ncontroller's IRQ is fetched. If the latter fails, the function\ndirectly returns an error, without cleaning up the allocated domains.\n\nHence, reverse the order so that the IRQ domains are allocated after the\ncontroller's IRQ is found.\n\nThis was flagged by Sashiko during a review of \"[PATCH v6 0/7] PCI:\nmediatek-gen3: add power control support\"."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/pci/controller/pcie-mediatek-gen3.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"814cceebba9b7d1306b8d49587ffb0e81f7b73af","lessThan":"abd3c1927d33766aef39c4640880e3d2637429c2","versionType":"git","status":"affected"},{"version":"814cceebba9b7d1306b8d49587ffb0e81f7b73af","lessThan":"07a5ecb94768cbf76fe659e9924000e9ced0c8a6","versionType":"git","status":"affected"},{"version":"814cceebba9b7d1306b8d49587ffb0e81f7b73af","lessThan":"946b31b5a699a2760ee52af0055e5ebf29c5f4cb","versionType":"git","status":"affected"},{"version":"814cceebba9b7d1306b8d49587ffb0e81f7b73af","lessThan":"0a2d60edc3e57c9512e239ebdfd12204d3368560","versionType":"git","status":"affected"},{"version":"814cceebba9b7d1306b8d49587ffb0e81f7b73af","lessThan":"215d4273347b9010a9deae378b0df79c163f707d","versionType":"git","status":"affected"},{"version":"814cceebba9b7d1306b8d49587ffb0e81f7b73af","lessThan":"5573c44cb3fd01a9f62d569ae9ac870ef5f0e0ba","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/pci/controller/pcie-mediatek-gen3.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"5.13","status":"affected"},{"version":"0","lessThan":"5.13","versionType":"semver","status":"unaffected"},{"version":"6.1.175","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.141","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.91","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.33","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.0.10","lessThanOrEqual":"7.0.*","versionType":"semver","status":"unaffected"},{"version":"7.1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/07a5ecb94768cbf76fe659e9924000e9ced0c8a6","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/0a2d60edc3e57c9512e239ebdfd12204d3368560","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/215d4273347b9010a9deae378b0df79c163f707d","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/5573c44cb3fd01a9f62d569ae9ac870ef5f0e0ba","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/946b31b5a699a2760ee52af0055e5ebf29c5f4cb","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/abd3c1927d33766aef39c4640880e3d2637429c2","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-63868","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-07-19T15:16:53.740","lastModified":"2026-07-19T15:16:53.740","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nnet: garp: fix unsigned integer underflow in garp_pdu_parse_attr\n\nThe receive-side GARP attribute parser computes dlen with reversed\noperands:\n\n        dlen = sizeof(*ga) - ga->len;\n\nga->len is the on-wire attribute length and includes the GARP attribute\nheader. For normal attributes with data, ga->len is larger than\nsizeof(*ga), so the subtraction underflows in unsigned arithmetic.\n\nThe resulting value is later passed to garp_attr_lookup(), whose length\nargument is u8. After truncation, the parsed data length usually no\nlonger matches the length stored for locally registered attributes, so\nreceived Join/Leave events are ignored. This breaks the GARP receive path\nfor common attributes, such as GVRP VLAN registration attributes.\n\nCompute the data length as the attribute length minus the header length."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["net/802/garp.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"eca9ebac651f774d8b10fce7c5d173c3c3d3394f","lessThan":"29f28172afb2ae7b31e9bf3e978396f20b381688","versionType":"git","status":"affected"},{"version":"eca9ebac651f774d8b10fce7c5d173c3c3d3394f","lessThan":"973cf7c433d27f4d9556d0b7c332543be7ed7a6e","versionType":"git","status":"affected"},{"version":"eca9ebac651f774d8b10fce7c5d173c3c3d3394f","lessThan":"d8dcd14aa886b8effd83022c550669f4f262854b","versionType":"git","status":"affected"},{"version":"eca9ebac651f774d8b10fce7c5d173c3c3d3394f","lessThan":"74e02121be1dcc0efcd56ebdf0171d6129105659","versionType":"git","status":"affected"},{"version":"eca9ebac651f774d8b10fce7c5d173c3c3d3394f","lessThan":"d4c86ea09ae3e63ee5aa86e941fcc38e0e39874a","versionType":"git","status":"affected"},{"version":"eca9ebac651f774d8b10fce7c5d173c3c3d3394f","lessThan":"04e22fefac1af3e32f245e9045382348773b5d59","versionType":"git","status":"affected"},{"version":"eca9ebac651f774d8b10fce7c5d173c3c3d3394f","lessThan":"a11f1a671b1361f0f1278dc0041374f2730df73f","versionType":"git","status":"affected"},{"version":"eca9ebac651f774d8b10fce7c5d173c3c3d3394f","lessThan":"16e408e607a94b646fb14a2a98422c6877ae4b3c","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["net/802/garp.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"2.6.27","status":"affected"},{"version":"0","lessThan":"2.6.27","versionType":"semver","status":"unaffected"},{"version":"5.10.259","lessThanOrEqual":"5.10.*","versionType":"semver","status":"unaffected"},{"version":"5.15.210","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.176","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.143","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.94","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.36","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.0.13","lessThanOrEqual":"7.0.*","versionType":"semver","status":"unaffected"},{"version":"7.1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/04e22fefac1af3e32f245e9045382348773b5d59","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/16e408e607a94b646fb14a2a98422c6877ae4b3c","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/29f28172afb2ae7b31e9bf3e978396f20b381688","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/74e02121be1dcc0efcd56ebdf0171d6129105659","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/973cf7c433d27f4d9556d0b7c332543be7ed7a6e","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/a11f1a671b1361f0f1278dc0041374f2730df73f","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/d4c86ea09ae3e63ee5aa86e941fcc38e0e39874a","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/d8dcd14aa886b8effd83022c550669f4f262854b","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-63871","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-07-19T15:16:54.133","lastModified":"2026-07-19T15:16:54.133","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nBluetooth: ISO: Fix data-race on iso_pi fields in hci_get_route calls\n\niso_connect_bis(), iso_connect_cis(), iso_listen_bis(), and\niso_conn_big_sync() call hci_get_route() using iso_pi(sk)->dst,\niso_pi(sk)->src, and iso_pi(sk)->src_type without holding lock_sock().\n\nThese fields may be modified concurrently by connect() or setsockopt()\non the same socket, resulting in data-races reported by KCSAN.\n\nFix this by snapshotting the required fields under lock_sock() before\ncalling hci_get_route().\n\nBUG: KCSAN: data-race in memcmp+0x45/0xb0\n\nrace at unknown origin, with read to 0xffff8880122135cf of 1 bytes\nby task 333 on cpu 1:\n memcmp+0x45/0xb0\n hci_get_route+0x27e/0x490\n iso_connect_cis+0x4c/0xa10\n iso_sock_connect+0x60e/0xb30\n __sys_connect_file+0xbd/0xe0\n __sys_connect+0xe0/0x110\n __x64_sys_connect+0x40/0x50\n x64_sys_call+0xcad/0x1c60\n do_syscall_64+0x133/0x590\n entry_SYSCALL_64_after_hwframe+0x77/0x7f"}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["net/bluetooth/iso.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"241f51931c35085449502c10f64fb3ecd6e02171","lessThan":"9798f7d41d85ff763afd1f1cc0533b5c416c8348","versionType":"git","status":"affected"},{"version":"241f51931c35085449502c10f64fb3ecd6e02171","lessThan":"ab84fd7779a2a7ff5d2c8eac212c43733f56216e","versionType":"git","status":"affected"},{"version":"241f51931c35085449502c10f64fb3ecd6e02171","lessThan":"859bb1f4cb615d98c9c1ab2bd76ebb0b8fe46020","versionType":"git","status":"affected"},{"version":"241f51931c35085449502c10f64fb3ecd6e02171","lessThan":"9ca7053d6215d89c33f28893bfd1625a32919d3f","versionType":"git","status":"affected"},{"version":"c524f9561c657b8af26dd4f67092b8928261aa62","versionType":"git","status":"affected"},{"version":"6.1.9","lessThan":"6.2","versionType":"semver","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["net/bluetooth/iso.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.2","status":"affected"},{"version":"0","lessThan":"6.2","versionType":"semver","status":"unaffected"},{"version":"6.12.94","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.36","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.0.13","lessThanOrEqual":"7.0.*","versionType":"semver","status":"unaffected"},{"version":"7.1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/859bb1f4cb615d98c9c1ab2bd76ebb0b8fe46020","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/9798f7d41d85ff763afd1f1cc0533b5c416c8348","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/9ca7053d6215d89c33f28893bfd1625a32919d3f","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/ab84fd7779a2a7ff5d2c8eac212c43733f56216e","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-63873","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-07-19T15:16:54.347","lastModified":"2026-07-19T15:16:54.347","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\naccel/amdxdna: Fix mm_struct reference leak in aie2_populate_range()\n\naie2_populate_range() jumps back to the again label without calling\nmmput(mm), leaking a reference to the mm_struct.\n\nAdd the missing mmput() before jumping to again."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/accel/amdxdna/aie2_ctx.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"e486147c912f653ef4b60a6c7dbd4168a4c56a9f","lessThan":"e83fc4c28226be75fbc0c41f2846935ba2b5f949","versionType":"git","status":"affected"},{"version":"e486147c912f653ef4b60a6c7dbd4168a4c56a9f","lessThan":"21dfec59939120b20d2c7794caaa421f9450be0a","versionType":"git","status":"affected"},{"version":"e486147c912f653ef4b60a6c7dbd4168a4c56a9f","lessThan":"2f41af638c92bac6f1f9275ea2d1901baef578f3","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/accel/amdxdna/aie2_ctx.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.16","status":"affected"},{"version":"0","lessThan":"6.16","versionType":"semver","status":"unaffected"},{"version":"6.18.36","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.0.13","lessThanOrEqual":"7.0.*","versionType":"semver","status":"unaffected"},{"version":"7.1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/21dfec59939120b20d2c7794caaa421f9450be0a","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/2f41af638c92bac6f1f9275ea2d1901baef578f3","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/e83fc4c28226be75fbc0c41f2846935ba2b5f949","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}}]}