{"resultsPerPage":131,"startIndex":0,"totalResults":131,"format":"NVD_CVE","version":"2.0","timestamp":"2026-07-21T10:29:37.368","vulnerabilities":[{"cve":{"id":"CVE-2025-4373","sourceIdentifier":"secalert@redhat.com","published":"2025-05-06T15:16:05.320","lastModified":"2026-07-19T18:16:29.707","vulnStatus":"Deferred","cveTags":[],"descriptions":[{"lang":"en","value":"A flaw was found in GLib, which is vulnerable to an integer overflow in the g_string_insert_unichar() function. When the position at which to insert the character is large, the position will overflow, leading to a buffer underwrite."},{"lang":"es","value":"Se encontró una falla en GLib que causa un desbordamiento de enteros en la función g_string_insert_unichar(). Cuando la posición donde se inserta el carácter es grande, esta se desborda, lo que provoca una subscritura del búfer."}],"affected":[{"source":"secalert@redhat.com","affectedData":[{"defaultStatus":"unaffected","collectionURL":"https://gitlab.gnome.org/GNOME/glib","packageName":"glib","versions":[{"version":"0","lessThan":"2.84.2","versionType":"semver","status":"affected"}]},{"vendor":"Red Hat","product":"Red Hat Enterprise Linux 10","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"glib2","cpes":["cpe:/o:redhat:enterprise_linux:10.0"],"versions":[{"version":"0:2.80.4-4.el10_0.6","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat Enterprise Linux 8","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"glib2","cpes":["cpe:/a:redhat:enterprise_linux:8::crb","cpe:/o:redhat:enterprise_linux:8::baseos"],"versions":[{"version":"0:2.56.4-166.el8_10","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat Enterprise Linux 8.2 Advanced Update Support","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"glib2","cpes":["cpe:/o:redhat:rhel_aus:8.2::baseos"],"versions":[{"version":"0:2.56.4-8.el8_2.2","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"glib2","cpes":["cpe:/o:redhat:rhel_aus:8.4::baseos","cpe:/o:redhat:rhel_eus_long_life:8.4::baseos"],"versions":[{"version":"0:2.56.4-10.el8_4.2","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"glib2","cpes":["cpe:/o:redhat:rhel_aus:8.4::baseos","cpe:/o:redhat:rhel_eus_long_life:8.4::baseos"],"versions":[{"version":"0:2.56.4-10.el8_4.2","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"glib2","cpes":["cpe:/o:redhat:rhel_aus:8.6::baseos","cpe:/o:redhat:rhel_e4s:8.6::baseos","cpe:/o:redhat:rhel_tus:8.6::baseos"],"versions":[{"version":"0:2.56.4-158.el8_6.2","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat Enterprise Linux 8.6 Telecommunications Update Service","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"glib2","cpes":["cpe:/o:redhat:rhel_aus:8.6::baseos","cpe:/o:redhat:rhel_e4s:8.6::baseos","cpe:/o:redhat:rhel_tus:8.6::baseos"],"versions":[{"version":"0:2.56.4-158.el8_6.2","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat Enterprise Linux 8.6 Update Services for SAP Solutions","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"glib2","cpes":["cpe:/o:redhat:rhel_aus:8.6::baseos","cpe:/o:redhat:rhel_e4s:8.6::baseos","cpe:/o:redhat:rhel_tus:8.6::baseos"],"versions":[{"version":"0:2.56.4-158.el8_6.2","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat Enterprise Linux 8.8 Telecommunications Update Service","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"glib2","cpes":["cpe:/o:redhat:rhel_e4s:8.8::baseos","cpe:/o:redhat:rhel_tus:8.8::baseos"],"versions":[{"version":"0:2.56.4-162.el8_8","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"glib2","cpes":["cpe:/o:redhat:rhel_e4s:8.8::baseos","cpe:/o:redhat:rhel_tus:8.8::baseos"],"versions":[{"version":"0:2.56.4-162.el8_8","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat Enterprise Linux 9","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"glib2","cpes":["cpe:/a:redhat:enterprise_linux:9::appstream","cpe:/a:redhat:enterprise_linux:9::crb","cpe:/o:redhat:enterprise_linux:9::baseos"],"versions":[{"version":"0:2.68.4-16.el9_6.2","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat Enterprise Linux 9","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"glib2","cpes":["cpe:/a:redhat:enterprise_linux:9::appstream","cpe:/a:redhat:enterprise_linux:9::crb","cpe:/o:redhat:enterprise_linux:9::baseos"],"versions":[{"version":"0:2.68.4-16.el9_6.2","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"glib2","cpes":["cpe:/a:redhat:rhel_e4s:9.0::appstream","cpe:/o:redhat:rhel_e4s:9.0::baseos"],"versions":[{"version":"0:2.68.4-5.el9_0.2","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"glib2","cpes":["cpe:/a:redhat:rhel_e4s:9.2::appstream","cpe:/o:redhat:rhel_e4s:9.2::baseos"],"versions":[{"version":"0:2.68.4-7.el9_2.2","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat Enterprise Linux 9.4 Extended Update Support","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"glib2","cpes":["cpe:/a:redhat:rhel_eus:9.4::appstream","cpe:/a:redhat:rhel_eus:9.4::crb","cpe:/o:redhat:rhel_eus:9.4::baseos"],"versions":[{"version":"0:2.68.4-14.el9_4.3","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat Insights proxy 1.5","defaultStatus":"affected","collectionURL":"https://catalog.redhat.com/software/containers/","packageName":"insights-proxy/insights-proxy-container-rhel9","cpes":["cpe:/a:redhat:insights_proxy:1.5::el9"],"versions":[{"version":"1.5.5-1754504343","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat OpenShift distributed tracing 3.6.1","defaultStatus":"affected","collectionURL":"https://catalog.redhat.com/software/containers/","packageName":"rhosdt/jaeger-agent-rhel8","cpes":["cpe:/a:redhat:openshift_distributed_tracing:3.6::el8"],"versions":[{"version":"rhosdt-3.6-1753265330","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat OpenShift distributed tracing 3.6.1","defaultStatus":"affected","collectionURL":"https://catalog.redhat.com/software/containers/","packageName":"rhosdt/jaeger-all-in-one-rhel8","cpes":["cpe:/a:redhat:openshift_distributed_tracing:3.6::el8"],"versions":[{"version":"rhosdt-3.6-1753265394","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat OpenShift distributed tracing 3.6.1","defaultStatus":"affected","collectionURL":"https://catalog.redhat.com/software/containers/","packageName":"rhosdt/jaeger-collector-rhel8","cpes":["cpe:/a:redhat:openshift_distributed_tracing:3.6::el8"],"versions":[{"version":"rhosdt-3.6-1753265332","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat OpenShift distributed tracing 3.6.1","defaultStatus":"affected","collectionURL":"https://catalog.redhat.com/software/containers/","packageName":"rhosdt/jaeger-es-index-cleaner-rhel8","cpes":["cpe:/a:redhat:openshift_distributed_tracing:3.6::el8"],"versions":[{"version":"rhosdt-3.6-1753265435","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat OpenShift distributed tracing 3.6.1","defaultStatus":"affected","collectionURL":"https://catalog.redhat.com/software/containers/","packageName":"rhosdt/jaeger-es-rollover-rhel8","cpes":["cpe:/a:redhat:openshift_distributed_tracing:3.6::el8"],"versions":[{"version":"rhosdt-3.6-1753265342","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat OpenShift distributed tracing 3.6.1","defaultStatus":"affected","collectionURL":"https://catalog.redhat.com/software/containers/","packageName":"rhosdt/jaeger-ingester-rhel8","cpes":["cpe:/a:redhat:openshift_distributed_tracing:3.6::el8"],"versions":[{"version":"rhosdt-3.6-1753265332","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat OpenShift distributed tracing 3.6.1","defaultStatus":"affected","collectionURL":"https://catalog.redhat.com/software/containers/","packageName":"rhosdt/jaeger-operator-bundle","cpes":["cpe:/a:redhat:openshift_distributed_tracing:3.6::el8"],"versions":[{"version":"rhosdt-3.6-1753269432","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat OpenShift distributed tracing 3.6.1","defaultStatus":"affected","collectionURL":"https://catalog.redhat.com/software/containers/","packageName":"rhosdt/jaeger-query-rhel8","cpes":["cpe:/a:redhat:openshift_distributed_tracing:3.6::el8"],"versions":[{"version":"rhosdt-3.6-1753265411","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat OpenShift distributed tracing 3.6.1","defaultStatus":"affected","collectionURL":"https://catalog.redhat.com/software/containers/","packageName":"rhosdt/jaeger-rhel8-operator","cpes":["cpe:/a:redhat:openshift_distributed_tracing:3.6::el8"],"versions":[{"version":"rhosdt-3.6-1753265314","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat Enterprise Linux 10","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"bootc","cpes":["cpe:/o:redhat:enterprise_linux:10"]},{"vendor":"Red Hat","product":"Red Hat Enterprise Linux 10","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"glycin-loaders","cpes":["cpe:/o:redhat:enterprise_linux:10"]},{"vendor":"Red Hat","product":"Red Hat Enterprise Linux 10","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"loupe","cpes":["cpe:/o:redhat:enterprise_linux:10"]},{"vendor":"Red Hat","product":"Red Hat Enterprise Linux 10","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"mingw-glib2","cpes":["cpe:/o:redhat:enterprise_linux:10"]},{"vendor":"Red Hat","product":"Red Hat Enterprise Linux 6","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"glib2","cpes":["cpe:/o:redhat:enterprise_linux:6"]},{"vendor":"Red Hat","product":"Red Hat Enterprise Linux 7","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"glib2","cpes":["cpe:/o:redhat:enterprise_linux:7"]},{"vendor":"Red Hat","product":"Red Hat Enterprise Linux 8","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"librsvg2","cpes":["cpe:/o:redhat:enterprise_linux:8"]},{"vendor":"Red Hat","product":"Red Hat Enterprise Linux 8","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"mingw-glib2","cpes":["cpe:/o:redhat:enterprise_linux:8"]},{"vendor":"Red Hat","product":"Red Hat Enterprise Linux 9","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"bootc","cpes":["cpe:/o:redhat:enterprise_linux:9"]},{"vendor":"Red Hat","product":"Red Hat Enterprise Linux 9","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"librsvg2","cpes":["cpe:/o:redhat:enterprise_linux:9"]},{"vendor":"Red Hat","product":"Red Hat Enterprise Linux 9","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"mingw-glib2","cpes":["cpe:/o:redhat:enterprise_linux:9"]}]},{"source":"0b142b55-0307-4c5a-b3c9-f314f3fb7c5e","affectedData":[{"vendor":"Siemens","product":"RUGGEDCOM RST2428P","defaultStatus":"unknown","versions":[{"version":"0","lessThan":"V3.3","versionType":"custom","status":"affected"}]},{"vendor":"Siemens","product":"SCALANCE XC-300/XR-300/XC-400/XR-500WG/XR-500 family","defaultStatus":"unknown","versions":[{"version":"0","lessThan":"V3.3","versionType":"custom","status":"affected"}]},{"vendor":"Siemens","product":"SCALANCE XCH328","defaultStatus":"unknown","versions":[{"version":"0","lessThan":"V3.3","versionType":"custom","status":"affected"}]},{"vendor":"Siemens","product":"SCALANCE XCM324","defaultStatus":"unknown","versions":[{"version":"0","lessThan":"V3.3","versionType":"custom","status":"affected"}]},{"vendor":"Siemens","product":"SCALANCE XCM328","defaultStatus":"unknown","versions":[{"version":"0","lessThan":"V3.3","versionType":"custom","status":"affected"}]},{"vendor":"Siemens","product":"SCALANCE XCM332","defaultStatus":"unknown","versions":[{"version":"0","lessThan":"V3.3","versionType":"custom","status":"affected"}]},{"vendor":"Siemens","product":"SCALANCE XRH334 (24 V DC, 8xFO, CC)","defaultStatus":"unknown","versions":[{"version":"0","lessThan":"V3.3","versionType":"custom","status":"affected"}]},{"vendor":"Siemens","product":"SCALANCE XRM334 (230 V AC, 12xFO)","defaultStatus":"unknown","versions":[{"version":"0","lessThan":"V3.3","versionType":"custom","status":"affected"}]},{"vendor":"Siemens","product":"SCALANCE XRM334 (230 V AC, 8xFO)","defaultStatus":"unknown","versions":[{"version":"0","lessThan":"V3.3","versionType":"custom","status":"affected"}]},{"vendor":"Siemens","product":"SCALANCE XRM334 (230V AC, 2x10G, 24xSFP, 8xSFP+)","defaultStatus":"unknown","versions":[{"version":"0","lessThan":"V3.3","versionType":"custom","status":"affected"}]},{"vendor":"Siemens","product":"SCALANCE XRM334 (24 V DC, 12xFO)","defaultStatus":"unknown","versions":[{"version":"0","lessThan":"V3.3","versionType":"custom","status":"affected"}]},{"vendor":"Siemens","product":"SCALANCE XRM334 (24 V DC, 8xFO)","defaultStatus":"unknown","versions":[{"version":"0","lessThan":"V3.3","versionType":"custom","status":"affected"}]},{"vendor":"Siemens","product":"SCALANCE XRM334 (24V DC, 2x10G, 24xSFP, 8xSFP+)","defaultStatus":"unknown","versions":[{"version":"0","lessThan":"V3.3","versionType":"custom","status":"affected"}]},{"vendor":"Siemens","product":"SCALANCE XRM334 (2x230 V AC, 12xFO)","defaultStatus":"unknown","versions":[{"version":"0","lessThan":"V3.3","versionType":"custom","status":"affected"}]},{"vendor":"Siemens","product":"SCALANCE XRM334 (2x230 V AC, 8xFO)","defaultStatus":"unknown","versions":[{"version":"0","lessThan":"V3.3","versionType":"custom","status":"affected"}]},{"vendor":"Siemens","product":"SCALANCE XRM334 (2x230V AC, 2x10G, 24xSFP, 8xSFP+)","defaultStatus":"unknown","versions":[{"version":"0","lessThan":"V3.3","versionType":"custom","status":"affected"}]},{"vendor":"Siemens","product":"SIMATIC S7-1500 CPU 1518-4 PN/DP MFP","defaultStatus":"unknown","versions":[{"version":"V3.1.5","lessThan":"*","versionType":"custom","status":"affected"}]},{"vendor":"Siemens","product":"SIMATIC S7-1500 CPU 1518-4 PN/DP MFP","defaultStatus":"unknown","versions":[{"version":"V3.1.5","lessThan":"*","versionType":"custom","status":"affected"}]},{"vendor":"Siemens","product":"SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP","defaultStatus":"unknown","versions":[{"version":"V3.1.5","lessThan":"*","versionType":"custom","status":"affected"}]},{"vendor":"Siemens","product":"SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP","defaultStatus":"unknown","versions":[{"version":"V3.1.5","lessThan":"*","versionType":"custom","status":"affected"}]},{"vendor":"Siemens","product":"SIPLUS S7-1500 CPU 1518-4 PN/DP MFP","defaultStatus":"unknown","versions":[{"version":"V3.1.5","lessThan":"*","versionType":"custom","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"secalert@redhat.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:L","baseScore":4.8,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"LOW"},"exploitabilityScore":2.2,"impactScore":2.5}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2025-05-06T15:09:21.791020Z","id":"CVE-2025-4373","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"secalert@redhat.com","type":"Secondary","description":[{"lang":"en","value":"CWE-124"}]}],"references":[{"url":"https://access.redhat.com/errata/RHSA-2025:10855","source":"secalert@redhat.com"},{"url":"https://access.redhat.com/errata/RHSA-2025:11140","source":"secalert@redhat.com"},{"url":"https://access.redhat.com/errata/RHSA-2025:11327","source":"secalert@redhat.com"},{"url":"https://access.redhat.com/errata/RHSA-2025:11373","source":"secalert@redhat.com"},{"url":"https://access.redhat.com/errata/RHSA-2025:11374","source":"secalert@redhat.com"},{"url":"https://access.redhat.com/errata/RHSA-2025:11662","source":"secalert@redhat.com"},{"url":"https://access.redhat.com/errata/RHSA-2025:12275","source":"secalert@redhat.com"},{"url":"https://access.redhat.com/errata/RHSA-2025:13335","source":"secalert@redhat.com"},{"url":"https://access.redhat.com/errata/RHSA-2025:14988","source":"secalert@redhat.com"},{"url":"https://access.redhat.com/errata/RHSA-2025:14989","source":"secalert@redhat.com"},{"url":"https://access.redhat.com/errata/RHSA-2025:14990","source":"secalert@redhat.com"},{"url":"https://access.redhat.com/errata/RHSA-2025:14991","source":"secalert@redhat.com"},{"url":"https://access.redhat.com/security/cve/CVE-2025-4373","source":"secalert@redhat.com"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2364265","source":"secalert@redhat.com"},{"url":"https://gitlab.gnome.org/GNOME/glib/-/issues/3677","source":"secalert@redhat.com"},{"url":"https://cert-portal.siemens.com/productcert/html/ssa-082556.html","source":"0b142b55-0307-4c5a-b3c9-f314f3fb7c5e"},{"url":"https://cert-portal.siemens.com/productcert/html/ssa-089022.html","source":"0b142b55-0307-4c5a-b3c9-f314f3fb7c5e"}]}},{"cve":{"id":"CVE-2026-2100","sourceIdentifier":"secalert@redhat.com","published":"2026-03-26T21:17:04.247","lastModified":"2026-07-19T18:16:31.763","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"A flaw was found in p11-kit. A remote attacker could exploit this vulnerability by calling the C_DeriveKey function on a remote token with specific IBM kyber or IBM btc derive mechanism parameters set to NULL. This could lead to the RPC-client attempting to return an uninitialized value, potentially resulting in a NULL dereference or undefined behavior. This issue may cause an application level denial of service or other unpredictable system states."},{"lang":"es","value":"Se encontró una falla en p11-kit. Un atacante remoto podría explotar esta vulnerabilidad al llamar a la función C_DeriveKey en un token remoto con parámetros específicos del mecanismo de derivación IBM kyber o IBM btc establecidos en NULL. Esto podría llevar al cliente RPC intentando devolver un valor no inicializado, resultando potencialmente en una desreferencia NULL o comportamiento indefinido. Este problema puede causar una denegación de servicio a nivel de aplicación o a otros estados impredecibles del sistema."}],"affected":[{"source":"secalert@redhat.com","affectedData":[{"vendor":"p11-glue","product":"p11-kit","defaultStatus":"unaffected","repo":"https://github.com/p11-glue/p11-kit","versions":[{"version":"0","lessThan":"0.26.2","versionType":"semver","status":"affected"}]},{"vendor":"Red Hat","product":"Red Hat Enterprise Linux 10","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"p11-kit","cpes":["cpe:/o:redhat:enterprise_linux:10.2"],"versions":[{"version":"0:0.26.2-1.el10","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat Enterprise Linux 9","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"p11-kit","cpes":["cpe:/a:redhat:enterprise_linux:9::appstream","cpe:/o:redhat:enterprise_linux:9::baseos"],"versions":[{"version":"0:0.26.2-1.el9","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat Enterprise Linux 9","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"p11-kit","cpes":["cpe:/a:redhat:enterprise_linux:9::appstream","cpe:/o:redhat:enterprise_linux:9::baseos"],"versions":[{"version":"0:0.26.2-1.el9","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Cost Management Metrics Operator 4","defaultStatus":"affected","collectionURL":"https://catalog.redhat.com/software/containers/","packageName":"costmanagement/costmanagement-metrics-rhel9-operator","cpes":["cpe:/a:redhat:cost_management:4::el9"],"versions":[{"version":"1780946239","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat Hardened Images","defaultStatus":"affected","collectionURL":"https://catalog.redhat.com/software/containers/","packageName":"p11-kit-main","cpes":["cpe:/a:redhat:hummingbird:1"],"versions":[{"version":"0.26.2-1.1.hum1","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat Insights proxy 1.5","defaultStatus":"affected","collectionURL":"https://catalog.redhat.com/software/containers/","packageName":"insights-proxy/insights-proxy-container-rhel9","cpes":["cpe:/a:redhat:insights_proxy:1.5::el9"],"versions":[{"version":"1780420428","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat Update Infrastructure 5","defaultStatus":"affected","collectionURL":"https://catalog.redhat.com/software/containers/","packageName":"rhui5/cds-rhel9","cpes":["cpe:/a:redhat:rhui:5::el9"],"versions":[{"version":"1779798159","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat Update Infrastructure 5","defaultStatus":"affected","collectionURL":"https://catalog.redhat.com/software/containers/","packageName":"rhui5/haproxy-rhel9","cpes":["cpe:/a:redhat:rhui:5::el9"],"versions":[{"version":"1779798164","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat Update Infrastructure 5","defaultStatus":"affected","collectionURL":"https://catalog.redhat.com/software/containers/","packageName":"rhui5/installer-rhel9","cpes":["cpe:/a:redhat:rhui:5::el9"],"versions":[{"version":"1779798165","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat Update Infrastructure 5","defaultStatus":"affected","collectionURL":"https://catalog.redhat.com/software/containers/","packageName":"rhui5/rhua-rhel9","cpes":["cpe:/a:redhat:rhui:5::el9"],"versions":[{"version":"1779798222","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat Enterprise Linux 6","defaultStatus":"unaffected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"p11-kit","cpes":["cpe:/o:redhat:enterprise_linux:6"]},{"vendor":"Red Hat","product":"Red Hat Enterprise Linux 7","defaultStatus":"unaffected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"p11-kit","cpes":["cpe:/o:redhat:enterprise_linux:7"]},{"vendor":"Red Hat","product":"Red Hat Enterprise Linux 8","defaultStatus":"unaffected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"p11-kit","cpes":["cpe:/o:redhat:enterprise_linux:8"]},{"vendor":"Red Hat","product":"Red Hat OpenShift Container Platform 4","defaultStatus":"unknown","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"openshift4/ose-hypershift-rhel9","cpes":["cpe:/a:redhat:openshift:4"]},{"vendor":"Red Hat","product":"Red Hat OpenShift Container Platform 4","defaultStatus":"unaffected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"rhcos","cpes":["cpe:/a:redhat:openshift:4"]}]}],"metrics":{"cvssMetricV31":[{"source":"secalert@redhat.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","baseScore":5.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"LOW"},"exploitabilityScore":3.9,"impactScore":1.4},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","baseScore":7.5,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"},"exploitabilityScore":3.9,"impactScore":3.6}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-03-26T20:30:34.453809Z","id":"CVE-2026-2100","options":[{"exploitation":"none"},{"automatable":"yes"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"secalert@redhat.com","type":"Secondary","description":[{"lang":"en","value":"CWE-824"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:p11-kit_project:p11-kit:-:*:*:*:*:*:*:*","matchCriteriaId":"EC8CB498-F5D5-4AB6-B33E-404C80966280"},{"vulnerable":true,"criteria":"cpe:2.3:a:redhat:hardened_images:-:*:*:*:*:*:*:*","matchCriteriaId":"87DEB507-5B64-47D7-9A50-3B87FD1E571F"},{"vulnerable":true,"criteria":"cpe:2.3:o:redhat:enterprise_linux:9.0:*:*:*:*:*:*:*","matchCriteriaId":"7F6FB57C-2BC7-487C-96DD-132683AEB35D"},{"vulnerable":true,"criteria":"cpe:2.3:o:redhat:enterprise_linux:10.0:*:*:*:*:*:*:*","matchCriteriaId":"D65C2163-CFC2-4ABB-8F4E-CB09CEBD006C"}]}]}],"references":[{"url":"https://access.redhat.com/errata/RHSA-2026:18143","source":"secalert@redhat.com"},{"url":"https://access.redhat.com/errata/RHSA-2026:18599","source":"secalert@redhat.com"},{"url":"https://access.redhat.com/errata/RHSA-2026:21275","source":"secalert@redhat.com"},{"url":"https://access.redhat.com/errata/RHSA-2026:22634","source":"secalert@redhat.com"},{"url":"https://access.redhat.com/errata/RHSA-2026:27998","source":"secalert@redhat.com"},{"url":"https://access.redhat.com/errata/RHSA-2026:7065","source":"secalert@redhat.com"},{"url":"https://access.redhat.com/security/cve/CVE-2026-2100","source":"secalert@redhat.com","tags":["Vendor Advisory"]},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2437308","source":"secalert@redhat.com","tags":["Issue Tracking","Vendor Advisory"]},{"url":"https://github.com/p11-glue/p11-kit/pull/740","source":"secalert@redhat.com","tags":["Issue Tracking","Patch"]},{"url":"https://github.com/p11-glue/p11-kit/releases/tag/0.26.2","source":"secalert@redhat.com"}]}},{"cve":{"id":"CVE-2026-63876","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-07-19T16:17:04.500","lastModified":"2026-07-19T16:17:04.500","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nserial: zs: Convert to use a platform device\n\nPrevent a crash from happening as the first serial port is initialised:\n\n  Console: switching to mono frame buffer device 160x64\n  fb0: PMAG-AA frame buffer device at tc0\n  DECstation Z85C30 serial driver version 0.10\n  CPU 0 Unable to handle kernel paging request at virtual address 0000002c, epc == 803ab00c, ra == 803aafe0\n  Oops[#1]:\n  CPU: 0 PID: 1 Comm: swapper Not tainted 6.4.0-rc3-00031-g84a9582fd203-dirty #57\n  $ 0   : 00000000 10012c00 803aaeb0 00000000\n  $ 4   : 80e12f60 80e12f50 80e12f58 81000030\n  $ 8   : 00000000 805ff37c 00000000 33433538\n  $12   : 65732030 00000006 80c2915d 6c616972\n  $16   : 80e12f00 807b7630 00000000 00000000\n  $20   : 00000004 00000348 000001a0 807623b8\n  $24   : 00000018 00000000\n  $28   : 80c24000 80c25d60 8078b148 803aafe0\n  Hi    : 00000000\n  Lo    : 00000000\n  epc   : 803ab00c serial_base_ctrl_add+0x78/0xf4\n  ra    : 803aafe0 serial_base_ctrl_add+0x4c/0xf4\n  Status: 10012c03\tKERNEL EXL IE\n  Cause : 00000008 (ExcCode 02)\n  BadVA : 0000002c\n  PrId  : 00000440 (R4400SC)\n  Modules linked in:\n  Process swapper (pid: 1, threadinfo=(ptrval), task=(ptrval), tls=00000000)\n  Stack : 80760000 00000cc0 00400044 00400040 803aa02c 80d61ab8 00000000 807b7630\n          80760000 807623b8 807b7628 803aa644 80386998 00000000 80e17780 80220f68\n          80e17780 80d61ab8 80c17d80 80e17780 80e17780 8063c798 80e17780 80383fa0\n          00000010 80e17780 00000000 80386998 807a0000 00000000 00400040 8038f848\n          807623b8 80d61ab8 00000004 80e17780 00000000 803a68e4 80c25e2c 803bb884\n          ...\n  Call Trace:\n  [<803ab00c>] serial_base_ctrl_add+0x78/0xf4\n  [<803aa644>] serial_core_register_port+0x174/0x69c\n  [<8077e9ac>] zs_init+0xc8/0xfc\n  [<800404d4>] do_one_initcall+0x40/0x2ac\n  [<8076cecc>] kernel_init_freeable+0x1e4/0x270\n  [<80605bec>] kernel_init+0x20/0x108\n  [<800431e8>] ret_from_kernel_thread+0x14/0x1c\n\n  Code: 2442aeb0  ae120024  ae0200d0 <8c67002c> 50e00001  8c670000  3c06806e  3c05806e  afb30010\n\n  ---[ end trace 0000000000000000 ]---\n\n(report at the offending commit) -- where a pointer is dereferenced that\nhas been derived from a null pointer to the port's parent device.\n\nSince no device is available with legacy probing and it's not anymore a\npreferable way to discover devices anyway, switch the driver to using a\nplatform device and use it as the port's parent device.  Update resource\nhandling accordingly and only request the actual span of addresses used\nwithin the slot, which will have had its resource already requested by\ngeneric platform device code.\n\nUse platform_driver_probe() not just because SCC devices are fixed with\nsolder on board and not straightforward to remove, but foremost because\nthe associated TTY's major device number is the same as used by the dz\ndriver and the first driver to claim it will prevent the other one from\nusing it.  Either one DZ device or some SCC devices will be present in a\ngiven system but never both at a time, and therefore we want the major\ndevice number to be claimed by the first driver to actually successfully\nbind to its device and platform_driver_probe() is a way to fulfil that.\n\nAn unfortunate consequence of the switch to a platform device is we now\nhand the console over from the bootconsole much later in the bootstrap.\nThe firmware console handler appears good enough though to work so late\nand in particular with interrupts enabled.\n\nSince there is one way only remaining to reach zs_reset() now, remove\nthe port initialisation marker as no longer needed and go through the\nchannel reset unconditionally."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["arch/mips/dec/platform.c","drivers/tty/serial/zs.c","drivers/tty/serial/zs.h"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"84a9582fd203063cd4d301204971ff2cd8327f1a","lessThan":"bb2040484f90f91b717060e1a66026cc4287bcf0","versionType":"git","status":"affected"},{"version":"84a9582fd203063cd4d301204971ff2cd8327f1a","lessThan":"6a83d5e24a84e746425cd93539130e5f7381ef47","versionType":"git","status":"affected"},{"version":"84a9582fd203063cd4d301204971ff2cd8327f1a","lessThan":"237dc8c08de3cb293b6607aaee8b13b3a671e267","versionType":"git","status":"affected"},{"version":"84a9582fd203063cd4d301204971ff2cd8327f1a","lessThan":"4dc9f1517503c883d5ce25b7ab29d177d05edc6a","versionType":"git","status":"affected"},{"version":"84a9582fd203063cd4d301204971ff2cd8327f1a","lessThan":"7cac59d08a73cb866ec51a483a6f3fe0f531947c","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["arch/mips/dec/platform.c","drivers/tty/serial/zs.c","drivers/tty/serial/zs.h"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.5","status":"affected"},{"version":"0","lessThan":"6.5","versionType":"semver","status":"unaffected"},{"version":"6.6.143","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.93","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.35","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.0.12","lessThanOrEqual":"7.0.*","versionType":"semver","status":"unaffected"},{"version":"7.1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/237dc8c08de3cb293b6607aaee8b13b3a671e267","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/4dc9f1517503c883d5ce25b7ab29d177d05edc6a","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/6a83d5e24a84e746425cd93539130e5f7381ef47","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/7cac59d08a73cb866ec51a483a6f3fe0f531947c","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/bb2040484f90f91b717060e1a66026cc4287bcf0","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-63877","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-07-19T16:17:04.653","lastModified":"2026-07-19T16:17:04.653","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nserial: dz: Convert to use a platform device\n\nPrevent a crash from happening as the first serial port is initialised:\n\n  Console: switching to colour frame buffer device 160x64\n  tgafb: SFB+ detected, rev=0x02\n  fb0: Digital ZLX-E1 frame buffer device at 0x1e000000\n  DECstation DZ serial driver version 1.04\n  CPU 0 Unable to handle kernel paging request at virtual address 000000bc, epc == 8048b3a4, ra == 80470a78\n  Oops[#1]:\n  CPU: 0 UID: 0 PID: 1 Comm: swapper/0 Not tainted 6.19.0-dirty #35 NONE\n  $ 0   : 00000000 1000ac00 00000004 804707ac\n  $ 4   : 00000000 80e20850 80e20858 81000030\n  $ 8   : 00000000 8072c81c 00000008 fefefeff\n  $12   : 6c616972 00000006 80c5917f 69726420\n  $16   : 80e20800 00000000 808f8968 80e20800\n  $20   : 00000000 807f5a90 808b0094 808d3bc8\n  $24   : 00000018 80479030\n  $28   : 80c2e000 80c2fd70 00000069 80470a78\n  Hi    : 00000004\n  Lo    : 00000000\n  epc   : 8048b3a4 __dev_fwnode+0x0/0xc\n  ra    : 80470a78 serial_base_ctrl_add+0xa0/0x168\n  Status: 1000ac04\tIEp\n  Cause : 30000008 (ExcCode 02)\n  BadVA : 000000bc\n  PrId  : 00000220 (R3000)\n  Modules linked in:\n  Process swapper/0 (pid: 1, threadinfo=(ptrval), task=(ptrval), tls=00000000)\n  Stack : 00400044 00400040 8046f4cc 00000000 808a6148 808a0000 808f8968 8086983c\n          808e0000 8046fc84 1000ac01 00000028 80e20700 802ba3f8 80e20700 80d34a94\n          80c1b900 80e20700 80e20700 80e20700 80e20700 80444650 00000000 00000000\n          00000000 807f5a90 808b0094 80447080 00400040 808e0000 80d34a94 808a6148\n          80d34a94 00000004 80e20700 00000000 8076974c 80469810 80c2fe3c 1000ac01\n          ...\n  Call Trace:\n  [<8048b3a4>] __dev_fwnode+0x0/0xc\n  [<80470a78>] serial_base_ctrl_add+0xa0/0x168\n  [<8046fc84>] serial_core_register_port+0x1c8/0x974\n  [<808c6af0>] dz_init+0x74/0xc8\n  [<800470e0>] do_one_initcall+0x44/0x2d4\n  [<808b111c>] kernel_init_freeable+0x258/0x308\n  [<8072e434>] kernel_init+0x20/0x114\n  [<80049cd0>] ret_from_kernel_thread+0x14/0x1c\n\n  Code: 27bd0018  03e00008  2402ffea <8c8200bc> 03e00008  00000000  27bdffc0  afbe0038  afb30024\n\n  ---[ end trace 0000000000000000 ]---\n\n-- where a pointer is dereferenced that has been derived from a null\npointer to the port's parent device.\n\nSince no device is available with legacy probing and it's not anymore a\npreferable way to discover devices anyway, switch the driver to using a\nplatform device and use it as the port's parent device.  Update resource\nhandling accordingly and only request the actual span of addresses used\nwithin the slot, which will have had its resource already requested by\ngeneric platform device code.\n\nUse platform_driver_probe() not just because the DZ device is fixed with\nsolder on board and not straightforward to remove, but foremost because\nthe associated TTY's major device number is the same as used by the zs\ndriver and the first driver to claim it will prevent the other one from\nusing it.  Either one DZ device or some SCC devices will be present in a\ngiven system but never both at a time, and therefore we want the major\ndevice number to be claimed by the first driver to actually successfully\nbind to its device and platform_driver_probe() is a way to fulfil that.\n\nAn unfortunate consequence of the switch to a platform device is we now\nhand the console over from the bootconsole much later in the bootstrap.\nThe firmware console handler appears good enough though to work so late\nand in particular with interrupts enabled.\n\nConversely only starting the console port so late lets the reset code\nfully utilise our delay handlers, so switch from udelay() to fsleep()\nfor transmitter draining so as to avoid busy-waiting for an excessive\namount of time."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["arch/mips/dec/platform.c","drivers/tty/serial/dz.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"84a9582fd203063cd4d301204971ff2cd8327f1a","lessThan":"c9e78361fe92fb64662fc3c8f34e2cdbb8c25bc6","versionType":"git","status":"affected"},{"version":"84a9582fd203063cd4d301204971ff2cd8327f1a","lessThan":"6f59646229490a93cda950017ad4bdfbfe770a1d","versionType":"git","status":"affected"},{"version":"84a9582fd203063cd4d301204971ff2cd8327f1a","lessThan":"2ff0401ffddaccc85f758c8259912d686d052b31","versionType":"git","status":"affected"},{"version":"84a9582fd203063cd4d301204971ff2cd8327f1a","lessThan":"5c9fb95c8d6430d11dbb7b44fbe23222585cda86","versionType":"git","status":"affected"},{"version":"84a9582fd203063cd4d301204971ff2cd8327f1a","lessThan":"5d7a49d60b8fda66da60e240fd7315232fa1754f","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["arch/mips/dec/platform.c","drivers/tty/serial/dz.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.5","status":"affected"},{"version":"0","lessThan":"6.5","versionType":"semver","status":"unaffected"},{"version":"6.6.143","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.93","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.35","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.0.12","lessThanOrEqual":"7.0.*","versionType":"semver","status":"unaffected"},{"version":"7.1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/2ff0401ffddaccc85f758c8259912d686d052b31","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/5c9fb95c8d6430d11dbb7b44fbe23222585cda86","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/5d7a49d60b8fda66da60e240fd7315232fa1754f","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/6f59646229490a93cda950017ad4bdfbfe770a1d","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/c9e78361fe92fb64662fc3c8f34e2cdbb8c25bc6","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-63878","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-07-19T16:17:04.800","lastModified":"2026-07-19T16:17:04.800","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amdgpu: check num_entries in GEM_OP GET_MAPPING_INFO\n\nkvcalloc(args->num_entries, sizeof(*vm_entries), GFP_KERNEL) at\namdgpu_gem.c:1050 uses the user-supplied num_entries directly without\nany upper bounds check. Since num_entries is a __u32 and\nsizeof(drm_amdgpu_gem_vm_entry) is 32 bytes, a large num_entries\nproduces an allocation exceeding INT_MAX, triggering\nWARNING in __kvmalloc_node_noprof(), causing a kernel WARNING,\nTAINT_WARN, and panic on CONFIG_PANIC_ON_WARN=y systems.\n\nAdd a size bounds check before we invoke the kvzalloc() to\nreject oversized num_entries early with -EINVAL.\n\n(cherry picked from commit 1fe7bf5457f6efd7be60b17e23163ba54341d73d)"}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/gpu/drm/amd/amdgpu/amdgpu_gem.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"4d82724f7f2b847eb0454b1aab5450545b39abd4","lessThan":"f059b4c493df3e54fe3ffe4658009c31864275da","versionType":"git","status":"affected"},{"version":"4d82724f7f2b847eb0454b1aab5450545b39abd4","lessThan":"967a00b8e06a7734aded23861faba9ee2462be87","versionType":"git","status":"affected"},{"version":"4d82724f7f2b847eb0454b1aab5450545b39abd4","lessThan":"a1ba4594232c87c3b8defd6f89a2e40f8b08395d","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/gpu/drm/amd/amdgpu/amdgpu_gem.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.18","status":"affected"},{"version":"0","lessThan":"6.18","versionType":"semver","status":"unaffected"},{"version":"6.18.35","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.0.12","lessThanOrEqual":"7.0.*","versionType":"semver","status":"unaffected"},{"version":"7.1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/967a00b8e06a7734aded23861faba9ee2462be87","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/a1ba4594232c87c3b8defd6f89a2e40f8b08395d","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/f059b4c493df3e54fe3ffe4658009c31864275da","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-63880","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-07-19T16:17:05.007","lastModified":"2026-07-19T16:17:05.007","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amdgpu: fix lock leak on ENOMEM in AMDGPU_GEM_OP_GET_MAPPING_INFO\n\nThe AMDGPU_GEM_OP_GET_MAPPING_INFO branch of amdgpu_gem_op_ioctl()\nholds three cleanup-tracked resources before calling kvcalloc():\nthe drm_gem_object reference from drm_gem_object_lookup(), the\ndrm_exec lock on the looked-up GEM via drm_exec_lock_obj(), and\nthe drm_exec lock on the per-process VM root page directory via\namdgpu_vm_lock_pd().  All three are released by the out_exec\nlabel that every other error path in this function jumps to.\nThe kvcalloc() failure path returns -ENOMEM directly, skipping\nout_exec and leaking all three.\n\nThe leaked per-process VM root PD dma_resv lock is the\nload-bearing leak: any subsequent operation on the same VM\n(further GEM ops, command-submission, eviction, TTM shrinker\ncallbacks) blocks on the held lock.  DRM_IOCTL_AMDGPU_GEM_OP is\nDRM_AUTH | DRM_RENDER_ALLOW, so this is an unprivileged-local\ndenial of service against the caller's GPU context, reachable\nby any process with /dev/dri/renderD* access.\n\nRoute the failure through out_exec so drm_exec_fini() and\ndrm_gem_object_put() run.\n\nReproduced on stock 7.0.0-10, Ryzen 7 5700U / Radeon Vega\n(Lucienne): the failing ioctl returns -ENOMEM and a second\nGET_MAPPING_INFO on the same fd then blocks in\ndrm_exec_lock_obj() on the leaked dma_resv.  SIGKILL on the\ncaller does not reap the task; the fd-release path during\nprocess exit goes through amdgpu_gem_object_close() ->\ndrm_exec_prepare_obj() on the same lock, leaving the task in D\nstate until the box is rebooted.  The patched kernel was not\nrebuilt and re-tested on this hardware; the fix is mechanical.\nTested on a single Lucienne / Vega box only.\n\nZiyi Guo posted an independent INT_MAX-bound check for\nargs->num_entries in the same branch [1]; the two patches are\ncomplementary and can land in either order.\n\n(cherry picked from commit b69d3256d79de15f54c322986ff4da68f1d65b0a)"}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/gpu/drm/amd/amdgpu/amdgpu_gem.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"4d82724f7f2b847eb0454b1aab5450545b39abd4","lessThan":"1eb86334e391695d4a40743b114afc15df4dc506","versionType":"git","status":"affected"},{"version":"4d82724f7f2b847eb0454b1aab5450545b39abd4","lessThan":"8f643d534ffc6f1b6182e4f3acff8f04890504b9","versionType":"git","status":"affected"},{"version":"4d82724f7f2b847eb0454b1aab5450545b39abd4","lessThan":"2e7f55eb408c3f72ee1957a0d0ad11d8648a6379","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/gpu/drm/amd/amdgpu/amdgpu_gem.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.18","status":"affected"},{"version":"0","lessThan":"6.18","versionType":"semver","status":"unaffected"},{"version":"6.18.35","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.0.12","lessThanOrEqual":"7.0.*","versionType":"semver","status":"unaffected"},{"version":"7.1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/1eb86334e391695d4a40743b114afc15df4dc506","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/2e7f55eb408c3f72ee1957a0d0ad11d8648a6379","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/8f643d534ffc6f1b6182e4f3acff8f04890504b9","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-63890","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-07-19T16:17:06.300","lastModified":"2026-07-19T16:17:06.300","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nscsi: fcoe: Reject FIP descriptors with zero fip_dlen in CVL walker\n\ndrivers/scsi/fcoe/fcoe_ctlr.c::fcoe_ctlr_recv_clr_vlink() advanced the\ndescriptor cursor by an attacker-supplied fip_dlen without ever\nrequiring dlen >= sizeof(struct fip_desc) in the default branch.  The\nnamed descriptor cases (FIP_DT_MAC, FIP_DT_NAME, FIP_DT_VN_ID) checked\ntheir per-type minimum lengths, but a FIP_DT_NON_CRITICAL descriptor\n(fip_dtype >= 128, which the standard requires receivers to silently\nignore) skipped that check entirely.\n\nAn unauthenticated L2 peer on the FCoE control VLAN could hang\nfcoe_ctlr_recv_work on an fcoe, qedf, or bnx2fc initiator indefinitely\nby emitting one FIP CVL frame whose single descriptor had fip_dtype ==\nFIP_DT_NON_CRITICAL and fip_dlen == 0: the cursor advanced zero bytes\nper iteration and the loop condition rlen >= sizeof(*desc) stayed true\nforever, blocking every subsequent FIP frame on that controller.\n\nTighten the outer dlen guard to also reject dlen < sizeof(struct\nfip_desc), so a malformed descriptor whose length cannot even cover the\ndescriptor header is rejected before the switch.  This is the same\nlower-bound the named cases already apply and is the minimum scope that\ncloses the loop."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/scsi/fcoe/fcoe_ctlr.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"97c8389d54b9665c38105ea72a428a44b97ff2f6","lessThan":"d179949d2175d2857d1c3a275a22bea58bcc5d36","versionType":"git","status":"affected"},{"version":"97c8389d54b9665c38105ea72a428a44b97ff2f6","lessThan":"fda976f7390bb5d1e9b84ef11ebb17323038e0c6","versionType":"git","status":"affected"},{"version":"97c8389d54b9665c38105ea72a428a44b97ff2f6","lessThan":"80a0cd307205236ca28aa49bc553f58edcb9bf3a","versionType":"git","status":"affected"},{"version":"97c8389d54b9665c38105ea72a428a44b97ff2f6","lessThan":"0e3c6e5a8fc15a74dfb1e0c1df9f1da73600a81a","versionType":"git","status":"affected"},{"version":"97c8389d54b9665c38105ea72a428a44b97ff2f6","lessThan":"549859a1131052b07dff11a448e9f3221a40f260","versionType":"git","status":"affected"},{"version":"97c8389d54b9665c38105ea72a428a44b97ff2f6","lessThan":"14dd80a20a72ce334adcc2d67402360527065948","versionType":"git","status":"affected"},{"version":"97c8389d54b9665c38105ea72a428a44b97ff2f6","lessThan":"d537d29d51c8b808469e5adacf3e5a0092700738","versionType":"git","status":"affected"},{"version":"97c8389d54b9665c38105ea72a428a44b97ff2f6","lessThan":"9eed1bd59937e6828b00d2f2dfef631d964f3636","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/scsi/fcoe/fcoe_ctlr.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"2.6.30","status":"affected"},{"version":"0","lessThan":"2.6.30","versionType":"semver","status":"unaffected"},{"version":"5.10.259","lessThanOrEqual":"5.10.*","versionType":"semver","status":"unaffected"},{"version":"5.15.210","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.176","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.143","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.93","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.35","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.0.12","lessThanOrEqual":"7.0.*","versionType":"semver","status":"unaffected"},{"version":"7.1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/0e3c6e5a8fc15a74dfb1e0c1df9f1da73600a81a","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/14dd80a20a72ce334adcc2d67402360527065948","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/549859a1131052b07dff11a448e9f3221a40f260","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/80a0cd307205236ca28aa49bc553f58edcb9bf3a","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/9eed1bd59937e6828b00d2f2dfef631d964f3636","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/d179949d2175d2857d1c3a275a22bea58bcc5d36","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/d537d29d51c8b808469e5adacf3e5a0092700738","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/fda976f7390bb5d1e9b84ef11ebb17323038e0c6","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-63891","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-07-19T16:17:06.440","lastModified":"2026-07-19T16:17:06.440","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nthunderbolt: property: Cap recursion depth in __tb_property_parse_dir()\n\nA DIRECTORY entry's value field is used as the dir_offset for a\nrecursive call into __tb_property_parse_dir() with no depth counter.\nA crafted peer that chains DIRECTORY entries into a back-reference\nloop drives the parser until the kernel stack is exhausted and the\nguard page fires.  Any untrusted XDomain peer (cable, dock, in-line\ninspector, adjacent host) that reaches the PROPERTIES_REQUEST\ncontrol-plane exchange can trigger this without authentication.\n\nThread a depth counter through tb_property_parse() and\n__tb_property_parse_dir(), and reject blocks that exceed\nTB_PROPERTY_MAX_DEPTH = 8.  That is comfortably larger than any\nobserved legitimate XDomain layout.\n\nOperators who do not need XDomain host-to-host discovery can disable\nthe path entirely with thunderbolt.xdomain=0 on the kernel command\nline."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/thunderbolt/property.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"cdae7c07e3e3509eaabc18c1640a55dc5b99c179","lessThan":"2b5f47a710172c962ef42d1b732b04d2ad0dce21","versionType":"git","status":"affected"},{"version":"cdae7c07e3e3509eaabc18c1640a55dc5b99c179","lessThan":"95839a67ea56ca35732aad7f711404a3127cfe2d","versionType":"git","status":"affected"},{"version":"cdae7c07e3e3509eaabc18c1640a55dc5b99c179","lessThan":"0a84ab9271936c11e84e511bb52fc5682f8b6726","versionType":"git","status":"affected"},{"version":"cdae7c07e3e3509eaabc18c1640a55dc5b99c179","lessThan":"b4621e5ef63405c317a84b711faf3bd75b3c6a94","versionType":"git","status":"affected"},{"version":"cdae7c07e3e3509eaabc18c1640a55dc5b99c179","lessThan":"f31c6d220f455b5af63590302b30e1b932d14599","versionType":"git","status":"affected"},{"version":"cdae7c07e3e3509eaabc18c1640a55dc5b99c179","lessThan":"830c8a9b467e7d3a158483d37fa7dc13892b293a","versionType":"git","status":"affected"},{"version":"cdae7c07e3e3509eaabc18c1640a55dc5b99c179","lessThan":"ed9455ef4bd9babc90f92e526abe3fb68c1a8709","versionType":"git","status":"affected"},{"version":"cdae7c07e3e3509eaabc18c1640a55dc5b99c179","lessThan":"928abe19fbf0127003abcb1ea69cabc1c897d0ab","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/thunderbolt/property.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"4.15","status":"affected"},{"version":"0","lessThan":"4.15","versionType":"semver","status":"unaffected"},{"version":"5.10.259","lessThanOrEqual":"5.10.*","versionType":"semver","status":"unaffected"},{"version":"5.15.210","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.176","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.143","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.93","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.35","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.0.12","lessThanOrEqual":"7.0.*","versionType":"semver","status":"unaffected"},{"version":"7.1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/0a84ab9271936c11e84e511bb52fc5682f8b6726","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/2b5f47a710172c962ef42d1b732b04d2ad0dce21","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/830c8a9b467e7d3a158483d37fa7dc13892b293a","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/928abe19fbf0127003abcb1ea69cabc1c897d0ab","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/95839a67ea56ca35732aad7f711404a3127cfe2d","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/b4621e5ef63405c317a84b711faf3bd75b3c6a94","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/ed9455ef4bd9babc90f92e526abe3fb68c1a8709","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/f31c6d220f455b5af63590302b30e1b932d14599","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-63892","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-07-19T16:17:06.577","lastModified":"2026-07-19T16:17:06.577","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nthunderbolt: property: Reject dir_len < 4 to prevent size_t underflow\n\nOn the non-root path, __tb_property_parse_dir() takes dir_len from\nentry->length (u16 widened to size_t).  Two distinct OOB conditions\nfollow when entry->length < 4:\n\n1. The non-root path begins with kmemdup(&block[dir_offset],\n   sizeof(*dir->uuid), ...) which always reads 4 dwords from\n   dir_offset.  tb_property_entry_valid() only enforces\n   dir_offset + entry->length <= block_len, so a crafted entry\n   with dir_offset close to the end of the property block and\n   entry->length in 0..3 passes that gate but lets the UUID copy\n   run off the block (e.g. dir_offset = 497, dir_len = 3 in a\n   500-dword block reads block[497..501]).\n\n2. After the kmemdup, content_len = dir_len - 4 underflows size_t\n   to ~SIZE_MAX, nentries becomes SIZE_MAX / 4, and the entry\n   walk runs OOB on each iteration until an entry fails\n   validation or the kernel oopses on an unmapped page.\n\nReject dir_len < 4 on the non-root path *before* the UUID kmemdup,\nwhich closes both holes.\n\nAlso move INIT_LIST_HEAD(&dir->properties) up to immediately after\nthe dir allocation so the new error-return path (and the existing\nuuid-alloc failure path) calling tb_property_free_dir() sees a\nwalkable list rather than the zero-initialized NULL next/prev that\nlist_for_each_entry_safe() would oops on."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/thunderbolt/property.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"cdae7c07e3e3509eaabc18c1640a55dc5b99c179","lessThan":"37abc4504fa19d8f9f1e87792e8a2b8fdb308e40","versionType":"git","status":"affected"},{"version":"cdae7c07e3e3509eaabc18c1640a55dc5b99c179","lessThan":"e2d4d51cf5785815fa4e91e0c019e3eb2506a84c","versionType":"git","status":"affected"},{"version":"cdae7c07e3e3509eaabc18c1640a55dc5b99c179","lessThan":"de618299190b418291609e6921557253bd417e25","versionType":"git","status":"affected"},{"version":"cdae7c07e3e3509eaabc18c1640a55dc5b99c179","lessThan":"5506c825f14d810f0690b1f4367cb7249ebb387a","versionType":"git","status":"affected"},{"version":"cdae7c07e3e3509eaabc18c1640a55dc5b99c179","lessThan":"542a13890b742099c461d70920e97b14e568f6ec","versionType":"git","status":"affected"},{"version":"cdae7c07e3e3509eaabc18c1640a55dc5b99c179","lessThan":"d548179adcc87e1bc66b17e00352a1f536e76065","versionType":"git","status":"affected"},{"version":"cdae7c07e3e3509eaabc18c1640a55dc5b99c179","lessThan":"3bec49ca55e08fb085cc4318f24b1b37eaab28cb","versionType":"git","status":"affected"},{"version":"cdae7c07e3e3509eaabc18c1640a55dc5b99c179","lessThan":"de21b59c29e31c5108ddc04210631bbfab81b997","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/thunderbolt/property.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"4.15","status":"affected"},{"version":"0","lessThan":"4.15","versionType":"semver","status":"unaffected"},{"version":"5.10.259","lessThanOrEqual":"5.10.*","versionType":"semver","status":"unaffected"},{"version":"5.15.210","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.176","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.143","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.93","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.35","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.0.12","lessThanOrEqual":"7.0.*","versionType":"semver","status":"unaffected"},{"version":"7.1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/37abc4504fa19d8f9f1e87792e8a2b8fdb308e40","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/3bec49ca55e08fb085cc4318f24b1b37eaab28cb","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/542a13890b742099c461d70920e97b14e568f6ec","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/5506c825f14d810f0690b1f4367cb7249ebb387a","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/d548179adcc87e1bc66b17e00352a1f536e76065","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/de21b59c29e31c5108ddc04210631bbfab81b997","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/de618299190b418291609e6921557253bd417e25","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/e2d4d51cf5785815fa4e91e0c019e3eb2506a84c","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-63895","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-07-19T16:17:06.990","lastModified":"2026-07-19T16:17:06.990","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nusb: gadget: f_fs: copy only received bytes on short ep0 read\n\nffs_ep0_read() allocates its control-OUT data buffer with\nkmalloc() (not kzalloc) at the Length value from the Setup\npacket, then copies that full len to userspace regardless of\nhow many bytes were actually received:\n\n    data = kmalloc(len, GFP_KERNEL);\n    ...\n    ret = __ffs_ep0_queue_wait(ffs, data, len);\n    if ((ret > 0) && (copy_to_user(buf, data, len)))\n            ret = -EFAULT;\n\n__ffs_ep0_queue_wait() returns req->actual, which on a short\ncontrol OUT transfer is strictly less than len.  The\ncopy_to_user() call still copies len bytes, so on a short OUT\nthe last (len - ret) bytes of the kmalloc() buffer --\nuninitialised slab residue -- are delivered to the FunctionFS\ndaemon.\n\nShort ep0 OUT completions are specified USB control-transfer\nbehavior and are produced by in-tree UDCs:\n\n  * dwc2 continues on req->actual < req->length for ep0 DATA OUT\n    (short-not-ok is the only ep0-OUT stall path).\n  * aspeed_udc ends ep0 OUT on rx_len < ep->ep.maxpacket.\n  * renesas_usbf logs \"ep0 short packet\" and completes the\n    request.\n  * dwc3 stalls on short IN but not on short OUT.\n\nA short ep0 OUT is therefore not evidence of a broken UDC; it is\na normal condition f_fs has to cope with.  The sibling gadgetfs\nimplementation in drivers/usb/gadget/legacy/inode.c already does\nthis correctly via min(len, dev->req->actual) before\ncopy_to_user().  This patch brings f_fs.c to the same safe\npattern rather than trimming at a defensive layer.\n\nThe bug is reached from the FunctionFS device node, which in\nreal deployments is owned by the privileged gadget daemon\n(adbd, UMS, composite gadget services, etc.); it is not\nreachable from unprivileged userspace.  Linux host stacks\nnormally reject short-wLength control OUTs before they reach\nthe gadget, so reproducing this required a build that\nbypasses that host-side check.  With the bypass in place, a\n1-byte payload on a 64-byte Setup produces 63 bytes of\nnon-canary slab residue in the daemon's read buffer.\n\nFix by copying only ret (actually received) bytes to\nuserspace."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/usb/gadget/function/f_fs.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"ddf8abd2599491cbad959c700b90ba72a5dce8d0","lessThan":"90ccf5fb63243fae1b4b3200f3310500500ecf2e","versionType":"git","status":"affected"},{"version":"ddf8abd2599491cbad959c700b90ba72a5dce8d0","lessThan":"af32dbb2ca0b3d09271ab718d13857a457fa16f2","versionType":"git","status":"affected"},{"version":"ddf8abd2599491cbad959c700b90ba72a5dce8d0","lessThan":"e835bf9a055f71874065a40780ca5560b7df8b33","versionType":"git","status":"affected"},{"version":"ddf8abd2599491cbad959c700b90ba72a5dce8d0","lessThan":"88874a19b2b093bfaaa1c0090fa536c44da8c08b","versionType":"git","status":"affected"},{"version":"ddf8abd2599491cbad959c700b90ba72a5dce8d0","lessThan":"607730a414773a7cbe3037a64a6c64e72689ff5e","versionType":"git","status":"affected"},{"version":"ddf8abd2599491cbad959c700b90ba72a5dce8d0","lessThan":"23c1f7deb9dd8447ecde749850676302aa1e2bd3","versionType":"git","status":"affected"},{"version":"ddf8abd2599491cbad959c700b90ba72a5dce8d0","lessThan":"4e036c10e7f4df5d951c69cc3697bc8e209c6d02","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/usb/gadget/function/f_fs.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"2.6.35","status":"affected"},{"version":"0","lessThan":"2.6.35","versionType":"semver","status":"unaffected"},{"version":"5.15.210","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.176","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.143","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.93","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.35","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.0.12","lessThanOrEqual":"7.0.*","versionType":"semver","status":"unaffected"},{"version":"7.1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/23c1f7deb9dd8447ecde749850676302aa1e2bd3","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/4e036c10e7f4df5d951c69cc3697bc8e209c6d02","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/607730a414773a7cbe3037a64a6c64e72689ff5e","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/88874a19b2b093bfaaa1c0090fa536c44da8c08b","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/90ccf5fb63243fae1b4b3200f3310500500ecf2e","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/af32dbb2ca0b3d09271ab718d13857a457fa16f2","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/e835bf9a055f71874065a40780ca5560b7df8b33","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-63896","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-07-19T16:17:07.130","lastModified":"2026-07-19T16:17:07.130","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nusb: gadget: composite: fix integer underflow in WebUSB GET_URL handling\n\nThe WebUSB GET_URL handler in composite_setup() narrows\nlanding_page_length to fit the host-supplied wLength using\n\n\tlanding_page_length = w_length\n\t\t- WEBUSB_URL_DESCRIPTOR_HEADER_LENGTH + landing_page_offset;\n\nIf wLength is smaller than WEBUSB_URL_DESCRIPTOR_HEADER_LENGTH the\nunsigned subtraction wraps, and the subsequent\n\n\tmemcpy(url_descriptor->URL,\n\t       cdev->landing_page + landing_page_offset,\n\t       landing_page_length - landing_page_offset);\n\nends up copying close to UINT_MAX bytes from cdev->landing_page into\ncdev->req->buf.  KASAN reports a slab-out-of-bounds in composite_setup\non the kmalloc-2k gadget_info allocation, and FORTIFY_SOURCE traps the\nmemcpy as a 4294967293-byte field-spanning write into\nurl_descriptor->URL (size 252).\n\nA USB host can reach this from a single SETUP packet against any\ngadget that has webusb/use=1 and a landingPage configured.\n\nHandle the small-wLength case before the math: when the host requested\nfewer bytes than the URL descriptor header, only the header is\nmeaningful and no URL bytes need to be copied.  Setting\nlanding_page_length to landing_page_offset makes the existing memcpy a\nno-op and leaves the descriptor returned to the host unchanged for all\nlarger wLength values."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/usb/gadget/composite.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"93c473948c588978cd55d9a3adad8b3e8057aa21","lessThan":"046870ff6b6f7b743c953c061043a9b30700d491","versionType":"git","status":"affected"},{"version":"93c473948c588978cd55d9a3adad8b3e8057aa21","lessThan":"f5869dfaa89854dcf34121036294d42d6c7acb8f","versionType":"git","status":"affected"},{"version":"93c473948c588978cd55d9a3adad8b3e8057aa21","lessThan":"f8f5a8f48c7cae3fac85e04b593bd47939f9725f","versionType":"git","status":"affected"},{"version":"93c473948c588978cd55d9a3adad8b3e8057aa21","lessThan":"a20f0ccf45708af6e063c7234c215d364b00de25","versionType":"git","status":"affected"},{"version":"93c473948c588978cd55d9a3adad8b3e8057aa21","lessThan":"6c5dbc104dadd79fc2923497c20bae759a18758c","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/usb/gadget/composite.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.3","status":"affected"},{"version":"0","lessThan":"6.3","versionType":"semver","status":"unaffected"},{"version":"6.6.143","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.93","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.35","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.0.12","lessThanOrEqual":"7.0.*","versionType":"semver","status":"unaffected"},{"version":"7.1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/046870ff6b6f7b743c953c061043a9b30700d491","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/6c5dbc104dadd79fc2923497c20bae759a18758c","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/a20f0ccf45708af6e063c7234c215d364b00de25","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/f5869dfaa89854dcf34121036294d42d6c7acb8f","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/f8f5a8f48c7cae3fac85e04b593bd47939f9725f","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-63897","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-07-19T16:17:07.243","lastModified":"2026-07-19T16:17:07.243","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nUSB: serial: mct_u232: fix missing interrupt-in transfer sanity check\n\nAdd the missing sanity check on the size of interrupt-in transfers to\navoid parsing stale or uninitialised slab data (and leaking it to user\nspace)."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/usb/serial/mct_u232.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"82b48d70bced1ec8e5f676d1fd5eccc7a44dc418","versionType":"git","status":"affected"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"8b93ee5baeef6efabee2c3381907733ad2dbc883","versionType":"git","status":"affected"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"a093f3e0c03d25a86d747a655d4b9322ffb2ed87","versionType":"git","status":"affected"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"70bb9a2661d34b93a9b83cf83e2b76289a712ef0","versionType":"git","status":"affected"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"631b8b7c456567f7a8d26f6fc354c8dd9cc9f832","versionType":"git","status":"affected"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"f06bcaba29707f060706483b2020d3cafbe98f9f","versionType":"git","status":"affected"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"ed260b56bc9fc878e5dcbb866eab8af0688e0e67","versionType":"git","status":"affected"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"245aba83e3c288e176ed037a1f6b618b09e92ed8","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/usb/serial/mct_u232.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"2.6.12","status":"affected"},{"version":"0","lessThan":"2.6.12","versionType":"semver","status":"unaffected"},{"version":"5.10.259","lessThanOrEqual":"5.10.*","versionType":"semver","status":"unaffected"},{"version":"5.15.210","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.176","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.143","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.93","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.35","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.0.12","lessThanOrEqual":"7.0.*","versionType":"semver","status":"unaffected"},{"version":"7.1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/245aba83e3c288e176ed037a1f6b618b09e92ed8","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/631b8b7c456567f7a8d26f6fc354c8dd9cc9f832","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/70bb9a2661d34b93a9b83cf83e2b76289a712ef0","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/82b48d70bced1ec8e5f676d1fd5eccc7a44dc418","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/8b93ee5baeef6efabee2c3381907733ad2dbc883","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/a093f3e0c03d25a86d747a655d4b9322ffb2ed87","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/ed260b56bc9fc878e5dcbb866eab8af0688e0e67","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/f06bcaba29707f060706483b2020d3cafbe98f9f","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-63898","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-07-19T16:17:07.370","lastModified":"2026-07-19T16:17:07.370","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nUSB: serial: mct_u232: fix memory corruption with small endpoint\n\nThe driver overrides the maximum transfer size for a specific device\nwhich only accepts 16 byte packets for its 32 byte bulk-out endpoint.\n\nMake sure to never increase the maximum transfer size to prevent slab\ncorruption should a malicious device report a smaller endpoint max\npacket size than expected."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/usb/serial/mct_u232.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"94edbbc5fe00d03cfe1d4e690d7d2cd36317a935","versionType":"git","status":"affected"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"bd2ddb3fe9052ad8703593bbec26ecc7ca92869e","versionType":"git","status":"affected"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"39e295a91e80f3b91f61c7ada2bde434dcaba20d","versionType":"git","status":"affected"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"90dbad14b109e5fdfb4934ff61e561d11ba3742d","versionType":"git","status":"affected"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"6cb48f8890f9b2051d7c34823057296a536a31c5","versionType":"git","status":"affected"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"d8fdf33d6fcfb90cbec26299baf2352c84b2d768","versionType":"git","status":"affected"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"57f332af1745014cd7e40414814ffaa6bc7d3b5b","versionType":"git","status":"affected"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"915b36d701950503c4ea0f6e314b10868e59fce3","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/usb/serial/mct_u232.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"2.6.12","status":"affected"},{"version":"0","lessThan":"2.6.12","versionType":"semver","status":"unaffected"},{"version":"5.10.259","lessThanOrEqual":"5.10.*","versionType":"semver","status":"unaffected"},{"version":"5.15.210","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.176","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.143","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.94","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.35","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.0.12","lessThanOrEqual":"7.0.*","versionType":"semver","status":"unaffected"},{"version":"7.1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/39e295a91e80f3b91f61c7ada2bde434dcaba20d","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/57f332af1745014cd7e40414814ffaa6bc7d3b5b","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/6cb48f8890f9b2051d7c34823057296a536a31c5","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/90dbad14b109e5fdfb4934ff61e561d11ba3742d","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/915b36d701950503c4ea0f6e314b10868e59fce3","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/94edbbc5fe00d03cfe1d4e690d7d2cd36317a935","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/bd2ddb3fe9052ad8703593bbec26ecc7ca92869e","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/d8fdf33d6fcfb90cbec26299baf2352c84b2d768","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-63899","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-07-19T16:17:07.497","lastModified":"2026-07-19T16:17:07.497","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nUSB: serial: mxuport: fix memory corruption with small endpoint\n\nMake sure that the bulk-out endpoint max packet size is at least eight\nbytes to avoid user-controlled slab corruption should a malicious device\nreport a smaller size."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/usb/serial/mxuport.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"ee467a1f2066d2bfa293f7c2c7f1ff7000b0a39e","lessThan":"086b858b5f5125bc9d967ea2bd825f83d9f8f29d","versionType":"git","status":"affected"},{"version":"ee467a1f2066d2bfa293f7c2c7f1ff7000b0a39e","lessThan":"2f3661eb2446e1ef593da45e01a3b21a906768ec","versionType":"git","status":"affected"},{"version":"ee467a1f2066d2bfa293f7c2c7f1ff7000b0a39e","lessThan":"ccbec56f2f9af008f1574335cc6a668f16603e47","versionType":"git","status":"affected"},{"version":"ee467a1f2066d2bfa293f7c2c7f1ff7000b0a39e","lessThan":"be3a1ed4ae51fa8dde57383277d336ce834f2cd9","versionType":"git","status":"affected"},{"version":"ee467a1f2066d2bfa293f7c2c7f1ff7000b0a39e","lessThan":"e906545641d34fb1a09a65b4b5cfdff40eb09681","versionType":"git","status":"affected"},{"version":"ee467a1f2066d2bfa293f7c2c7f1ff7000b0a39e","lessThan":"6c0cf56f00f280d72180bb6ce79741bc787a6269","versionType":"git","status":"affected"},{"version":"ee467a1f2066d2bfa293f7c2c7f1ff7000b0a39e","lessThan":"b40166b4ef96067620a0f248e74ad9658c8f680c","versionType":"git","status":"affected"},{"version":"ee467a1f2066d2bfa293f7c2c7f1ff7000b0a39e","lessThan":"4085f0dbb1ce2251c9a5938d693de6593f0ab2bd","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/usb/serial/mxuport.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"3.14","status":"affected"},{"version":"0","lessThan":"3.14","versionType":"semver","status":"unaffected"},{"version":"5.10.259","lessThanOrEqual":"5.10.*","versionType":"semver","status":"unaffected"},{"version":"5.15.210","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.176","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.143","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.93","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.35","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.0.12","lessThanOrEqual":"7.0.*","versionType":"semver","status":"unaffected"},{"version":"7.1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/086b858b5f5125bc9d967ea2bd825f83d9f8f29d","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/2f3661eb2446e1ef593da45e01a3b21a906768ec","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/4085f0dbb1ce2251c9a5938d693de6593f0ab2bd","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/6c0cf56f00f280d72180bb6ce79741bc787a6269","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/b40166b4ef96067620a0f248e74ad9658c8f680c","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/be3a1ed4ae51fa8dde57383277d336ce834f2cd9","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/ccbec56f2f9af008f1574335cc6a668f16603e47","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/e906545641d34fb1a09a65b4b5cfdff40eb09681","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-63900","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-07-19T16:17:07.623","lastModified":"2026-07-19T16:17:07.623","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nUSB: serial: keyspan: fix missing indat transfer sanity check\n\nAdd the missing sanity check on the size of usa49wg indat transfers to\navoid parsing stale or uninitialised slab data."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/usb/serial/keyspan.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"0ca1268e109acf6d71507398cb95cab2e670b654","lessThan":"bd6c5fe59f374b63173afe5cf0ab38a9a370f2c1","versionType":"git","status":"affected"},{"version":"0ca1268e109acf6d71507398cb95cab2e670b654","lessThan":"e124120e89b61a967e40dee6b5e1ecafc45c09d9","versionType":"git","status":"affected"},{"version":"0ca1268e109acf6d71507398cb95cab2e670b654","lessThan":"41d9673941eebdde62ee73848fcfe4ae1105c979","versionType":"git","status":"affected"},{"version":"0ca1268e109acf6d71507398cb95cab2e670b654","lessThan":"0bde5431037a076ff3750da2165fd77a6f5ff058","versionType":"git","status":"affected"},{"version":"0ca1268e109acf6d71507398cb95cab2e670b654","lessThan":"3759a40738b83bb61699c85f063202b514b94f77","versionType":"git","status":"affected"},{"version":"0ca1268e109acf6d71507398cb95cab2e670b654","lessThan":"ea2b792330b44b6d7ce671c3e1d59d0c121f7ed1","versionType":"git","status":"affected"},{"version":"0ca1268e109acf6d71507398cb95cab2e670b654","lessThan":"f7f566ad7519c7ca3bc9071350002940a2b0e22a","versionType":"git","status":"affected"},{"version":"0ca1268e109acf6d71507398cb95cab2e670b654","lessThan":"ab8336a7e414f018430aa1af3a46944032f7ff96","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/usb/serial/keyspan.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"2.6.23","status":"affected"},{"version":"0","lessThan":"2.6.23","versionType":"semver","status":"unaffected"},{"version":"5.10.259","lessThanOrEqual":"5.10.*","versionType":"semver","status":"unaffected"},{"version":"5.15.210","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.176","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.143","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.93","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.35","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.0.12","lessThanOrEqual":"7.0.*","versionType":"semver","status":"unaffected"},{"version":"7.1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/0bde5431037a076ff3750da2165fd77a6f5ff058","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/3759a40738b83bb61699c85f063202b514b94f77","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/41d9673941eebdde62ee73848fcfe4ae1105c979","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/ab8336a7e414f018430aa1af3a46944032f7ff96","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/bd6c5fe59f374b63173afe5cf0ab38a9a370f2c1","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/e124120e89b61a967e40dee6b5e1ecafc45c09d9","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/ea2b792330b44b6d7ce671c3e1d59d0c121f7ed1","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/f7f566ad7519c7ca3bc9071350002940a2b0e22a","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-63901","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-07-19T16:17:07.743","lastModified":"2026-07-19T16:17:07.743","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nUSB: serial: digi_acceleport: fix memory corruption with small endpoints\n\nAdd the missing bulk-out buffer size sanity checks to avoid\nout-of-bounds memory accesses or slab corruption should a malicious\ndevice report smaller buffers than expected."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/usb/serial/digi_acceleport.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"fd34198c2e5d164b57a7dcd4692626fece319225","versionType":"git","status":"affected"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"25b93d0f229a115ab120106f37b9454170d4cfd4","versionType":"git","status":"affected"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"6ab1e9ae099577a1019312088309ecbad2da9a91","versionType":"git","status":"affected"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"8a65db5edd7b63365e9c5b7d9f4b8f314696dc49","versionType":"git","status":"affected"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"41b645e791099f0038225da5e2ca3ca31f00d435","versionType":"git","status":"affected"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"062dcc0b324afd03b1406f157190804f105718bb","versionType":"git","status":"affected"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"9469419b12a100e7e2ccdda64ab45b8368456c8a","versionType":"git","status":"affected"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"cb3560e8eab1dfa1cac1ed52631adf8ec6ff2cd5","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/usb/serial/digi_acceleport.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"2.6.12","status":"affected"},{"version":"0","lessThan":"2.6.12","versionType":"semver","status":"unaffected"},{"version":"5.10.259","lessThanOrEqual":"5.10.*","versionType":"semver","status":"unaffected"},{"version":"5.15.210","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.176","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.143","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.93","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.35","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.0.12","lessThanOrEqual":"7.0.*","versionType":"semver","status":"unaffected"},{"version":"7.1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/062dcc0b324afd03b1406f157190804f105718bb","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/25b93d0f229a115ab120106f37b9454170d4cfd4","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/41b645e791099f0038225da5e2ca3ca31f00d435","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/6ab1e9ae099577a1019312088309ecbad2da9a91","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/8a65db5edd7b63365e9c5b7d9f4b8f314696dc49","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/9469419b12a100e7e2ccdda64ab45b8368456c8a","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/cb3560e8eab1dfa1cac1ed52631adf8ec6ff2cd5","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/fd34198c2e5d164b57a7dcd4692626fece319225","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-63902","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-07-19T16:17:07.867","lastModified":"2026-07-19T16:17:07.867","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nUSB: serial: cypress_m8: validate interrupt packet headers\n\ncypress_read_int_callback() parses the interrupt-in buffer according to\nthe selected Cypress packet format. Format 1 has a two-byte status/count\nheader and format 2 has a one-byte combined status/count header. The\nusb-serial core sizes the interrupt-in buffer from the endpoint\ndescriptor's wMaxPacketSize, and successful interrupt transfers can\ncomplete short when URB_SHORT_NOT_OK is not set.\n\nCheck that the completed packet contains the selected header before\nreading it. Malformed short reports are ignored and the interrupt URB is\nresubmitted through the existing retry path, preventing out-of-bounds\nheader-byte reads.\n\nKASAN report as below:\nKASAN slab-out-of-bounds in cypress_read_int_callback+0x240/0x7f0\nRead of size 1\nCall trace:\n  cypress_read_int_callback() (drivers/usb/serial/cypress_m8.c:1009)\n  __usb_hcd_giveback_urb()\n  dummy_timer()\n\n[ johan: use constants in header length sanity checks ]"}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/usb/serial/cypress_m8.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"3416eaa1f8f8d516b77de514e14cf8da256d28fb","lessThan":"fcef31a5a85ccf3c313449a866ec6ed7e4132425","versionType":"git","status":"affected"},{"version":"3416eaa1f8f8d516b77de514e14cf8da256d28fb","lessThan":"aaa66708bfb1dca2acd219d1c1582f9f6d5492cb","versionType":"git","status":"affected"},{"version":"3416eaa1f8f8d516b77de514e14cf8da256d28fb","lessThan":"44f9bab8df7750a1e2a4d6cc22d7c9c2dc096aed","versionType":"git","status":"affected"},{"version":"3416eaa1f8f8d516b77de514e14cf8da256d28fb","lessThan":"be50533fe7068e86eb7adb81988e6d6a3f6dfe53","versionType":"git","status":"affected"},{"version":"3416eaa1f8f8d516b77de514e14cf8da256d28fb","lessThan":"90664556916de22467097d4c8ceb716d597a5c32","versionType":"git","status":"affected"},{"version":"3416eaa1f8f8d516b77de514e14cf8da256d28fb","lessThan":"ae03453f2c809ca3cf73753269fa6184dea7160f","versionType":"git","status":"affected"},{"version":"3416eaa1f8f8d516b77de514e14cf8da256d28fb","lessThan":"4a4cb0021ebe1fcadb52e04d19ed8d71470a530b","versionType":"git","status":"affected"},{"version":"3416eaa1f8f8d516b77de514e14cf8da256d28fb","lessThan":"9f9bfc80c67f35a275820da7e83a35dface08281","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/usb/serial/cypress_m8.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"2.6.26","status":"affected"},{"version":"0","lessThan":"2.6.26","versionType":"semver","status":"unaffected"},{"version":"5.10.259","lessThanOrEqual":"5.10.*","versionType":"semver","status":"unaffected"},{"version":"5.15.210","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.176","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.143","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.93","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.35","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.0.12","lessThanOrEqual":"7.0.*","versionType":"semver","status":"unaffected"},{"version":"7.1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/44f9bab8df7750a1e2a4d6cc22d7c9c2dc096aed","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/4a4cb0021ebe1fcadb52e04d19ed8d71470a530b","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/90664556916de22467097d4c8ceb716d597a5c32","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/9f9bfc80c67f35a275820da7e83a35dface08281","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/aaa66708bfb1dca2acd219d1c1582f9f6d5492cb","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/ae03453f2c809ca3cf73753269fa6184dea7160f","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/be50533fe7068e86eb7adb81988e6d6a3f6dfe53","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/fcef31a5a85ccf3c313449a866ec6ed7e4132425","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-63903","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-07-19T16:17:08.000","lastModified":"2026-07-19T16:17:08.000","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nUSB: serial: belkin_sa: validate interrupt status length\n\nThe Belkin interrupt callback treats interrupt data as a four-byte\nstatus report and reads LSR/MSR fields at offsets 2 and 3. The\ninterrupt-in buffer length is derived from endpoint wMaxPacketSize, and\nshort interrupt transfers may complete successfully with a smaller\nactual_length.\n\nCheck the completed interrupt packet length before parsing status\nfields so short interrupt endpoints and short successful packets are\nignored instead of causing out-of-bounds or stale status-byte reads.\n\nKASAN report as below:\n\nBUG: KASAN: slab-out-of-bounds in belkin_sa_read_int_callback()\nRead of size 1\nCall trace:\n  belkin_sa_read_int_callback() (drivers/usb/serial/belkin_sa.c:202)\n  __usb_hcd_giveback_urb() (drivers/usb/core/hcd.c:1630)\n  dummy_timer() (?:?)"}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/usb/serial/belkin_sa.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"f1617539ab90e67da788959bfd314076f093a11a","versionType":"git","status":"affected"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"f361359a952da15e70e693c2d7dca5c5843eae3e","versionType":"git","status":"affected"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"37e54d1b986df35c936d81e5b59a7aa3ec6938f0","versionType":"git","status":"affected"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"ffb739a49186ea784bbd9cb91b647f062395b419","versionType":"git","status":"affected"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"6a4602221cba7a738442328d66a2f0b1c9bf6e17","versionType":"git","status":"affected"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"22823a319fb2afdf02cacafbed8b613b757efbc8","versionType":"git","status":"affected"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"db1e7eb6203d534dad64cac2c793b69e561e657b","versionType":"git","status":"affected"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"4ce058df2ee02cc2a0f0fd5cd64ce6f1482a0b65","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/usb/serial/belkin_sa.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"2.6.12","status":"affected"},{"version":"0","lessThan":"2.6.12","versionType":"semver","status":"unaffected"},{"version":"5.10.259","lessThanOrEqual":"5.10.*","versionType":"semver","status":"unaffected"},{"version":"5.15.210","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.176","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.143","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.93","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.35","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.0.12","lessThanOrEqual":"7.0.*","versionType":"semver","status":"unaffected"},{"version":"7.1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/22823a319fb2afdf02cacafbed8b613b757efbc8","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/37e54d1b986df35c936d81e5b59a7aa3ec6938f0","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/4ce058df2ee02cc2a0f0fd5cd64ce6f1482a0b65","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/6a4602221cba7a738442328d66a2f0b1c9bf6e17","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/db1e7eb6203d534dad64cac2c793b69e561e657b","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/f1617539ab90e67da788959bfd314076f093a11a","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/f361359a952da15e70e693c2d7dca5c5843eae3e","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/ffb739a49186ea784bbd9cb91b647f062395b419","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-63904","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-07-19T16:17:08.130","lastModified":"2026-07-19T16:17:08.130","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nusb: usbtmc: check URB actual_length for interrupt-IN notifications\n\nUSBTMC devices can use an optional interrupt endpoint for notification\nmessages. These typically contain two-byte headers indicating the\npayload format, but the driver does not check if these headers are\npresent before accessing the data buffers. In cases where the URB\nactual_length is not enough to fit these headers, the driver will either\ncause an out-of-bounds read, or consume stale leftover data from a\nprevious notification.\n\nFix by checking if actual_data contains enough bytes for the headers,\notherwise resubmit URB to the interrupt endpoint."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/usb/class/usbtmc.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"dbf3e7f654c0f06a932b8fcafac78de9d0b81d68","lessThan":"e794bd67b3faf98af46f958897f6b91412c7d2a9","versionType":"git","status":"affected"},{"version":"dbf3e7f654c0f06a932b8fcafac78de9d0b81d68","lessThan":"e3eec3005de44e7f37d8d7724be636446516ab42","versionType":"git","status":"affected"},{"version":"dbf3e7f654c0f06a932b8fcafac78de9d0b81d68","lessThan":"ae87f505917e703ae3b487d9663d78826ff43608","versionType":"git","status":"affected"},{"version":"dbf3e7f654c0f06a932b8fcafac78de9d0b81d68","lessThan":"5de7df75ef3a2756b25fe3d582a4a2970444fe5a","versionType":"git","status":"affected"},{"version":"dbf3e7f654c0f06a932b8fcafac78de9d0b81d68","lessThan":"69020fa089f1bf0e1a10a15265f31b143a846409","versionType":"git","status":"affected"},{"version":"dbf3e7f654c0f06a932b8fcafac78de9d0b81d68","lessThan":"75f6d3da2cc646983f41807ef98851569c12bca9","versionType":"git","status":"affected"},{"version":"dbf3e7f654c0f06a932b8fcafac78de9d0b81d68","lessThan":"f141b01eaa58ac7e323931d670318aa247bff087","versionType":"git","status":"affected"},{"version":"dbf3e7f654c0f06a932b8fcafac78de9d0b81d68","lessThan":"52f2ad3f7e5eb3b5908e1d685d4342519dc9cfcd","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/usb/class/usbtmc.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"4.6","status":"affected"},{"version":"0","lessThan":"4.6","versionType":"semver","status":"unaffected"},{"version":"5.10.259","lessThanOrEqual":"5.10.*","versionType":"semver","status":"unaffected"},{"version":"5.15.210","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.176","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.143","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.93","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.35","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.0.12","lessThanOrEqual":"7.0.*","versionType":"semver","status":"unaffected"},{"version":"7.1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/52f2ad3f7e5eb3b5908e1d685d4342519dc9cfcd","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/5de7df75ef3a2756b25fe3d582a4a2970444fe5a","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/69020fa089f1bf0e1a10a15265f31b143a846409","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/75f6d3da2cc646983f41807ef98851569c12bca9","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/ae87f505917e703ae3b487d9663d78826ff43608","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/e3eec3005de44e7f37d8d7724be636446516ab42","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/e794bd67b3faf98af46f958897f6b91412c7d2a9","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/f141b01eaa58ac7e323931d670318aa247bff087","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-63905","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-07-19T16:17:08.260","lastModified":"2026-07-19T16:17:08.260","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nusbip: vudc: Fix use after free bug in vudc_remove due to race condition\n\nThis patch follows up Zheng Wang's 2023 report of a use-after-free in\nvudc_remove(). The original thread stalled on Shuah Khan's request for\nruntime testing of the unplug/unbind path. This patch supplies that\ntesting and keeps Zheng's original fix shape.\n\nIn vudc_probe(), v_init_timer() binds udc->tr_timer.timer to v_timer().\nusbip_sockfd_store() starts the timer via v_start_timer()/v_kick_timer().\nvudc_remove() can then free the containing struct vudc while the timer is\nstill pending or executing.\n\nKASAN confirms the race on an unpatched x86_64 QEMU guest with\nCONFIG_KASAN=y, CONFIG_USBIP_VUDC=y, CONFIG_USB_ZERO=y, and a tight loop\nthat repeatedly writes a socket fd to usbip_sockfd, closes the socket\npair, and unbinds/rebinds usbip-vudc.0:\n\n  BUG: KASAN: slab-use-after-free in __run_timer_base.part.0+0x8ba/0x8e0\n  Write of size 8 at addr ffff888001b80740 by task trigger_and_unb/239\n  Allocated by task 239:\n    vudc_probe+0x4d/0xaa0\n  Freed by task 239:\n    kfree+0x18f/0x520\n    device_release_driver_internal+0x388/0x540\n    unbind_store+0xd9/0x100\n\nThis lands in the timer core rather than v_timer() itself because the\nembedded timer_list is being walked after its containing struct vudc has\nalready been freed. The underlying lifetime bug is the same one Zheng\nreported.\n\nWith v_stop_timer() called from vudc_remove() and the timer deleted\nsynchronously, the same harness completed 5000 bind/unbind iterations\nwith no KASAN report."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/usb/usbip/vudc_dev.c","drivers/usb/usbip/vudc_transfer.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"b6a0ca11186759ad7045d68a5447b1e89f658384","lessThan":"61704e5cf9cd7464b510eb606e7e2978b1160a64","versionType":"git","status":"affected"},{"version":"b6a0ca11186759ad7045d68a5447b1e89f658384","lessThan":"dcc1c90b28b28b7c493547506297e78653f81952","versionType":"git","status":"affected"},{"version":"b6a0ca11186759ad7045d68a5447b1e89f658384","lessThan":"1036ac6148995feaf486014d32bf26bf993c06a9","versionType":"git","status":"affected"},{"version":"b6a0ca11186759ad7045d68a5447b1e89f658384","lessThan":"a0638db2340ee053ab0450656a763fd111475e54","versionType":"git","status":"affected"},{"version":"b6a0ca11186759ad7045d68a5447b1e89f658384","lessThan":"d07ed707467ce05ea9c03412d0c5ee9d0fe386a6","versionType":"git","status":"affected"},{"version":"b6a0ca11186759ad7045d68a5447b1e89f658384","lessThan":"88d459e5b5a46da1ef9fd6f52d9439343edeec88","versionType":"git","status":"affected"},{"version":"b6a0ca11186759ad7045d68a5447b1e89f658384","lessThan":"207bf80362df3fce8ebc9723351dcb1bc6d9ed0f","versionType":"git","status":"affected"},{"version":"b6a0ca11186759ad7045d68a5447b1e89f658384","lessThan":"d96209626a29ea64666be98c30b30ac82e5f1be6","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/usb/usbip/vudc_dev.c","drivers/usb/usbip/vudc_transfer.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"4.7","status":"affected"},{"version":"0","lessThan":"4.7","versionType":"semver","status":"unaffected"},{"version":"5.10.259","lessThanOrEqual":"5.10.*","versionType":"semver","status":"unaffected"},{"version":"5.15.210","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.176","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.143","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.93","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.35","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.0.12","lessThanOrEqual":"7.0.*","versionType":"semver","status":"unaffected"},{"version":"7.1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/1036ac6148995feaf486014d32bf26bf993c06a9","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/207bf80362df3fce8ebc9723351dcb1bc6d9ed0f","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/61704e5cf9cd7464b510eb606e7e2978b1160a64","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/88d459e5b5a46da1ef9fd6f52d9439343edeec88","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/a0638db2340ee053ab0450656a763fd111475e54","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/d07ed707467ce05ea9c03412d0c5ee9d0fe386a6","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/d96209626a29ea64666be98c30b30ac82e5f1be6","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/dcc1c90b28b28b7c493547506297e78653f81952","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-63907","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-07-19T16:17:08.517","lastModified":"2026-07-19T16:17:08.517","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nuio: uio_pci_generic_sva: fix double free of devm_kzalloc() memory\n\nuio_pci_sva allocates struct uio_pci_sva_dev with devm_kzalloc() in\nprobe(), but then calls kfree(udev) both on the probe() error path\n(label out_free) and again in remove().\n\nBecause devm_kzalloc() allocations are devres-managed and are freed\nautomatically when the device is detached (including after a failing\nprobe() and during driver unbind), the explicit kfree() can lead to a\ndouble free.\n\nIf probe() fails after devm_kzalloc(), the error path frees udev and\ndevres cleanup will free it again when the core unwinds the partially\nbound device. On normal driver removal, remove() frees udev and devres\nwill free it again when the device is detached.\n\nThis issue was identified by a static analysis tool I developed and\nconfirmed by manual review. Fix by removing the manual kfree() calls\nand dropping the now-unused label."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/uio/uio_pci_generic_sva.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"3397c3cd859a2c51962ad032dcf97961d42f9db2","lessThan":"e344865bfca4eb37ed8d7ac5917226e49fcec7ce","versionType":"git","status":"affected"},{"version":"3397c3cd859a2c51962ad032dcf97961d42f9db2","lessThan":"f74c8696f14149d5e43cc28b015326a759c48f00","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/uio/uio_pci_generic_sva.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.19","status":"affected"},{"version":"0","lessThan":"6.19","versionType":"semver","status":"unaffected"},{"version":"7.0.12","lessThanOrEqual":"7.0.*","versionType":"semver","status":"unaffected"},{"version":"7.1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/e344865bfca4eb37ed8d7ac5917226e49fcec7ce","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/f74c8696f14149d5e43cc28b015326a759c48f00","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-63908","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-07-19T16:17:08.620","lastModified":"2026-07-19T16:17:08.620","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nInput: atmel_mxt_ts - fix boundary check in mxt_prepare_cfg_mem\n\nWhen a configuration file provides an object size that is larger than the\ndriver's known mxt_obj_size(object), the driver intends to discard the\nextra bytes.\n\nThe loop iterates using for (i = 0; i < size; i++). Inside the loop, the\ncondition to skip processing extra bytes is:\n\n    if (i > mxt_obj_size(object))\n        continue;\n\nSince i is a 0-based index, the valid indices for the object are 0 through\nmxt_obj_size(object) - 1.\n\nWhen i == mxt_obj_size(object), the condition evaluates to false, and the\ncode processes the byte instead of discarding it.\n\nThis causes the code to calculate byte_offset = reg + i - cfg->start_ofs\nand writes the byte there, overwriting exactly one byte of the adjacent\ninstance or object.\n\nUpdate the boundary check to skip extra bytes correctly by using >=."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/input/touchscreen/atmel_mxt_ts.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"50a77c658b80e7e3303e3bcec195b30e2b62d513","lessThan":"862a1a32b5190241fce7a7d20229539a3926f31e","versionType":"git","status":"affected"},{"version":"50a77c658b80e7e3303e3bcec195b30e2b62d513","lessThan":"5c3681c3abc35cfac6b702251382312c60d96bc2","versionType":"git","status":"affected"},{"version":"50a77c658b80e7e3303e3bcec195b30e2b62d513","lessThan":"1017e1c6c6c49cccbcda9bbcfa49e50b0b6dad39","versionType":"git","status":"affected"},{"version":"50a77c658b80e7e3303e3bcec195b30e2b62d513","lessThan":"e9b62996ba537774f68fecfd7eecb5aec1713952","versionType":"git","status":"affected"},{"version":"50a77c658b80e7e3303e3bcec195b30e2b62d513","lessThan":"ae92e334544263a02d9f99e18385e718c44392c9","versionType":"git","status":"affected"},{"version":"50a77c658b80e7e3303e3bcec195b30e2b62d513","lessThan":"7f95f4792c0dc767fcb8e405391e779ab419d55a","versionType":"git","status":"affected"},{"version":"50a77c658b80e7e3303e3bcec195b30e2b62d513","lessThan":"6c6b989b4ebf22b086fdfcac2163b5cb55e34d8f","versionType":"git","status":"affected"},{"version":"50a77c658b80e7e3303e3bcec195b30e2b62d513","lessThan":"baa0210fb6a9dc3882509a9411b6d284d88fe30e","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/input/touchscreen/atmel_mxt_ts.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"3.17","status":"affected"},{"version":"0","lessThan":"3.17","versionType":"semver","status":"unaffected"},{"version":"5.10.259","lessThanOrEqual":"5.10.*","versionType":"semver","status":"unaffected"},{"version":"5.15.210","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.176","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.143","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.93","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.35","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.0.12","lessThanOrEqual":"7.0.*","versionType":"semver","status":"unaffected"},{"version":"7.1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/1017e1c6c6c49cccbcda9bbcfa49e50b0b6dad39","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/5c3681c3abc35cfac6b702251382312c60d96bc2","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/6c6b989b4ebf22b086fdfcac2163b5cb55e34d8f","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/7f95f4792c0dc767fcb8e405391e779ab419d55a","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/862a1a32b5190241fce7a7d20229539a3926f31e","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/ae92e334544263a02d9f99e18385e718c44392c9","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/baa0210fb6a9dc3882509a9411b6d284d88fe30e","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/e9b62996ba537774f68fecfd7eecb5aec1713952","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-63928","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-07-19T16:17:11.163","lastModified":"2026-07-19T16:17:11.163","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nUSB: serial: omninet: fix memory corruption with small endpoint\n\nMake sure that the bulk-out buffers are at least as large as the\nhardcoded transfer size to avoid user-controlled slab corruption should\na malicious device report a smaller endpoint max packet size than\nexpected."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/usb/serial/omninet.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"180996f0ca774001944e4afa452d569ba2f6455c","versionType":"git","status":"affected"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"b496e25ead5976bce2891dacaed09beb53a54f9f","versionType":"git","status":"affected"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"4e7d32189d6219beb7db37cd0ea36b6bac7dfedb","versionType":"git","status":"affected"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"9a3860454bdfb765f936965e975c594352602ffc","versionType":"git","status":"affected"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"0bda1893e4cc4ad2b7dcdbaca246f2af688c6c2a","versionType":"git","status":"affected"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"0fee0ccac29e088d4bfab7e2d075725dcecd803d","versionType":"git","status":"affected"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"f34cf2928387fba01a78381f3258c7e1428897d9","versionType":"git","status":"affected"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"60df93d30f9bdd27db17c4d80ed80ef718d7226b","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/usb/serial/omninet.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"2.6.12","status":"affected"},{"version":"0","lessThan":"2.6.12","versionType":"semver","status":"unaffected"},{"version":"5.10.259","lessThanOrEqual":"5.10.*","versionType":"semver","status":"unaffected"},{"version":"5.15.210","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.176","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.143","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.93","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.35","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.0.12","lessThanOrEqual":"7.0.*","versionType":"semver","status":"unaffected"},{"version":"7.1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/0bda1893e4cc4ad2b7dcdbaca246f2af688c6c2a","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/0fee0ccac29e088d4bfab7e2d075725dcecd803d","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/180996f0ca774001944e4afa452d569ba2f6455c","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/4e7d32189d6219beb7db37cd0ea36b6bac7dfedb","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/60df93d30f9bdd27db17c4d80ed80ef718d7226b","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/9a3860454bdfb765f936965e975c594352602ffc","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/b496e25ead5976bce2891dacaed09beb53a54f9f","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/f34cf2928387fba01a78381f3258c7e1428897d9","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-63929","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-07-19T16:17:11.277","lastModified":"2026-07-19T16:17:11.277","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\niio: buffer: Fix DMA fence leak in iio_buffer_enqueue_dmabuf()\n\niio_buffer_enqueue_dmabuf() allocates a struct iio_dma_fence (104 bytes,\nkmalloc-128) via kmalloc_obj()+dma_fence_init(), which sets the initial\nkref to 1.  It then calls dma_resv_add_fence() which takes a second\nreference (kref=2), and stores a raw pointer in block->fence.\n\nOn the success path the function returns without calling dma_fence_put()\nto release the initial reference, so every buffer enqueue permanently\nleaks one kmalloc-128 allocation.\n\nThe iio_buffer_cleanup() work item only releases the temporary reference\ntaken during completion signalling by iio_buffer_signal_dmabuf_done();\nthe initial reference from dma_fence_init() is never released.\n\nWith four iio_rwdev instances at 240kHz and 512 samples per buffer,\nthis produces ~1875 kmalloc-128 allocations per second matching the\nobserved slab growth exactly. A test with ftrace confirmed that the\ndma_fence_destroy event was never triggered.\n\nFix by calling dma_fence_put() after dma_resv_add_fence(), transferring\nownership of the fence to the DMA reservation object. The DMA fence then\ngets properly discarded after being signalled."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/iio/industrialio-buffer.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"3e26d9f08fbe0b73e951a5e810fdb7a332b7e37f","lessThan":"9678aeed8b77d495a417dd057d479f3733094019","versionType":"git","status":"affected"},{"version":"3e26d9f08fbe0b73e951a5e810fdb7a332b7e37f","lessThan":"3412a95afaa5d3262008dfc34f3c7be33d8151dc","versionType":"git","status":"affected"},{"version":"3e26d9f08fbe0b73e951a5e810fdb7a332b7e37f","lessThan":"96cdeaba6a008503455b78a9641c05c2a886a7ec","versionType":"git","status":"affected"},{"version":"3e26d9f08fbe0b73e951a5e810fdb7a332b7e37f","lessThan":"a093999355084bdbfe6e97f1dd232e58a1525f0b","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/iio/industrialio-buffer.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.11","status":"affected"},{"version":"0","lessThan":"6.11","versionType":"semver","status":"unaffected"},{"version":"6.12.93","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.35","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.0.12","lessThanOrEqual":"7.0.*","versionType":"semver","status":"unaffected"},{"version":"7.1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/3412a95afaa5d3262008dfc34f3c7be33d8151dc","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/9678aeed8b77d495a417dd057d479f3733094019","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/96cdeaba6a008503455b78a9641c05c2a886a7ec","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/a093999355084bdbfe6e97f1dd232e58a1525f0b","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-63931","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-07-19T16:17:11.507","lastModified":"2026-07-19T16:17:11.507","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\niio: chemical: scd30: fix division by zero in write_raw\n\nAdd a zero check for val2 before using it as a divisor when setting the\nsampling frequency. A user writing a zero fractional part to the\nsampling_frequency sysfs attribute triggers a division by zero in the\nkernel."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/iio/chemical/scd30_core.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"64b3d8b1b0f5c16c19045785e4da8391ae35ec99","lessThan":"4748bce423a363bb8a85a624faeb8f54fe331611","versionType":"git","status":"affected"},{"version":"64b3d8b1b0f5c16c19045785e4da8391ae35ec99","lessThan":"6308b812acdcac38cbfe1af0b1524c3375f408a5","versionType":"git","status":"affected"},{"version":"64b3d8b1b0f5c16c19045785e4da8391ae35ec99","lessThan":"c7a740bf75554b051fabb17596ca6e483d6e6d90","versionType":"git","status":"affected"},{"version":"64b3d8b1b0f5c16c19045785e4da8391ae35ec99","lessThan":"e85bc501947f5ae16dd9adc01162b76d55ab7962","versionType":"git","status":"affected"},{"version":"64b3d8b1b0f5c16c19045785e4da8391ae35ec99","lessThan":"d98c2e69aab905d1b19a69ffe584efa46a9efd42","versionType":"git","status":"affected"},{"version":"64b3d8b1b0f5c16c19045785e4da8391ae35ec99","lessThan":"5e4d34092a5ebfbc3a45a180c76ecb1cdbbedd53","versionType":"git","status":"affected"},{"version":"64b3d8b1b0f5c16c19045785e4da8391ae35ec99","lessThan":"2c50c017df97bfb425038efdfb8514c7bcd08564","versionType":"git","status":"affected"},{"version":"64b3d8b1b0f5c16c19045785e4da8391ae35ec99","lessThan":"5aba4f94b225617a55fed442a70329b2ee19c0a5","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/iio/chemical/scd30_core.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"5.9","status":"affected"},{"version":"0","lessThan":"5.9","versionType":"semver","status":"unaffected"},{"version":"5.10.259","lessThanOrEqual":"5.10.*","versionType":"semver","status":"unaffected"},{"version":"5.15.210","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.176","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.143","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.93","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.35","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.0.12","lessThanOrEqual":"7.0.*","versionType":"semver","status":"unaffected"},{"version":"7.1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/2c50c017df97bfb425038efdfb8514c7bcd08564","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/4748bce423a363bb8a85a624faeb8f54fe331611","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/5aba4f94b225617a55fed442a70329b2ee19c0a5","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/5e4d34092a5ebfbc3a45a180c76ecb1cdbbedd53","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/6308b812acdcac38cbfe1af0b1524c3375f408a5","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/c7a740bf75554b051fabb17596ca6e483d6e6d90","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/d98c2e69aab905d1b19a69ffe584efa46a9efd42","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/e85bc501947f5ae16dd9adc01162b76d55ab7962","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-63932","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-07-19T16:17:11.633","lastModified":"2026-07-19T16:17:11.633","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\niio: chemical: mhz19b: reject oversized serial replies\n\nmhz19b_receive_buf() appends each serdev chunk into the fixed\nMHZ19B_CMD_SIZE receive buffer and advances buf_idx by len without\nchecking that the chunk fits in the remaining space. A large callback\ncan therefore overflow st->buf before the command path validates the\nreply.\n\nReset the reply state before each command and reject oversized serial\nreplies before copying them into the fixed buffer. When an oversized\nreply is detected, wake the waiter and report -EMSGSIZE instead of\noverwriting st->buf."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/iio/chemical/mhz19b.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"4572a70b3681e38055c78d12fb68cd147bdbee7d","lessThan":"a5a05410cb34bfa486d63684cdc1f87a3b13f20a","versionType":"git","status":"affected"},{"version":"4572a70b3681e38055c78d12fb68cd147bdbee7d","lessThan":"ea69e7a6efa88ef32090a91064c362738cc19ddd","versionType":"git","status":"affected"},{"version":"4572a70b3681e38055c78d12fb68cd147bdbee7d","lessThan":"673478bc29cf72010faaf293c1c8c667393335a0","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/iio/chemical/mhz19b.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.16","status":"affected"},{"version":"0","lessThan":"6.16","versionType":"semver","status":"unaffected"},{"version":"6.18.35","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.0.12","lessThanOrEqual":"7.0.*","versionType":"semver","status":"unaffected"},{"version":"7.1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/673478bc29cf72010faaf293c1c8c667393335a0","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/a5a05410cb34bfa486d63684cdc1f87a3b13f20a","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/ea69e7a6efa88ef32090a91064c362738cc19ddd","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-63933","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-07-19T16:17:11.737","lastModified":"2026-07-19T16:17:11.737","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\niio: gyro: adis16260: fix division by zero in write_raw\n\nAdd a validation check for the sampling frequency value before using it\nas a divisor. A user writing zero to the sampling_frequency sysfs\nattribute triggers a division by zero in the kernel."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/iio/gyro/adis16260.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"089a41985c6c7e69c8fe043c0dd397da628254f5","lessThan":"d2b83995759cfe5d06567bbcb600fe16d4048da3","versionType":"git","status":"affected"},{"version":"089a41985c6c7e69c8fe043c0dd397da628254f5","lessThan":"19eb8565c4500f9af17ec65eaf952365e2893351","versionType":"git","status":"affected"},{"version":"089a41985c6c7e69c8fe043c0dd397da628254f5","lessThan":"59f80b945f2ca645064074d8507785c26ea16d2d","versionType":"git","status":"affected"},{"version":"089a41985c6c7e69c8fe043c0dd397da628254f5","lessThan":"86298fb6829cab983910810959f85d4b4fd0f5c1","versionType":"git","status":"affected"},{"version":"089a41985c6c7e69c8fe043c0dd397da628254f5","lessThan":"aa8a5e118e97d2cfd0da5ea4f8f0f488efdea4b0","versionType":"git","status":"affected"},{"version":"089a41985c6c7e69c8fe043c0dd397da628254f5","lessThan":"aaf9d640e9ae1172d0a9c659ecb245a50a10850a","versionType":"git","status":"affected"},{"version":"089a41985c6c7e69c8fe043c0dd397da628254f5","lessThan":"5a42e39606b9bd6b40ed02bdfd04fe179d6173f4","versionType":"git","status":"affected"},{"version":"089a41985c6c7e69c8fe043c0dd397da628254f5","lessThan":"761e8b489e6cf166c574034b70637f8a7eadd0ee","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/iio/gyro/adis16260.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"2.6.35","status":"affected"},{"version":"0","lessThan":"2.6.35","versionType":"semver","status":"unaffected"},{"version":"5.10.259","lessThanOrEqual":"5.10.*","versionType":"semver","status":"unaffected"},{"version":"5.15.210","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.176","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.143","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.93","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.35","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.0.12","lessThanOrEqual":"7.0.*","versionType":"semver","status":"unaffected"},{"version":"7.1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/19eb8565c4500f9af17ec65eaf952365e2893351","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/59f80b945f2ca645064074d8507785c26ea16d2d","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/5a42e39606b9bd6b40ed02bdfd04fe179d6173f4","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/761e8b489e6cf166c574034b70637f8a7eadd0ee","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/86298fb6829cab983910810959f85d4b4fd0f5c1","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/aa8a5e118e97d2cfd0da5ea4f8f0f488efdea4b0","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/aaf9d640e9ae1172d0a9c659ecb245a50a10850a","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/d2b83995759cfe5d06567bbcb600fe16d4048da3","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-63934","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-07-19T16:17:11.857","lastModified":"2026-07-19T16:17:11.857","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\niio: gyro: itg3200: fix i2c read into the wrong stack location\n\nitg3200_read_all_channels() takes `__be16 *buf' as a parameter and\nfills the i2c_msg destination as `(char *)&buf'. Since `buf' is the\nparameter (a pointer), `&buf' is the address of the local pointer\nslot on the stack of itg3200_read_all_channels(), not the address\nof the caller's scan buffer. The (char *) cast hides the type\nmismatch.\n\ni2c_transfer() therefore writes ITG3200_SCAN_ELEMENTS * sizeof(s16)\n= 8 bytes into the parameter's stack slot, which is discarded when\nthe function returns. The caller's scan buffer in\nitg3200_trigger_handler() is never written to, so\niio_push_to_buffers_with_timestamp() pushes uninitialised stack\ncontents to userspace via /dev/iio:deviceX every scan -- both a\nfunctional bug (no actual gyroscope or temperature data is\ndelivered through the triggered buffer) and an information leak.\n\nThe non-buffered read_raw() path is unaffected: it goes through\nitg3200_read_reg_s16() which uses `&out' on a local s16 value,\nwhere that is correct.\n\nDrop the spurious `&' so the i2c read writes into the caller's\nbuffer."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/iio/gyro/itg3200_buffer.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"9dbf091da080508e9f632d307f357beb79a0766b","lessThan":"90e809376b0f0d1ddec2eec954aecdd2a5b40b0e","versionType":"git","status":"affected"},{"version":"9dbf091da080508e9f632d307f357beb79a0766b","lessThan":"8654b5e2617819ff4f7c78071dfd0275e971a9b6","versionType":"git","status":"affected"},{"version":"9dbf091da080508e9f632d307f357beb79a0766b","lessThan":"b64dd5f3b38911054cbcc570df617e3e8e75e562","versionType":"git","status":"affected"},{"version":"9dbf091da080508e9f632d307f357beb79a0766b","lessThan":"31bbd4b87dd6701fa10e03ba7f6268e49e178d16","versionType":"git","status":"affected"},{"version":"9dbf091da080508e9f632d307f357beb79a0766b","lessThan":"63203bd072b613c18c237b906b1c9d2dc4527337","versionType":"git","status":"affected"},{"version":"9dbf091da080508e9f632d307f357beb79a0766b","lessThan":"15a0b3f33ffb6c78b3de6f69b026ceb09b973dd1","versionType":"git","status":"affected"},{"version":"9dbf091da080508e9f632d307f357beb79a0766b","lessThan":"cfc3283859cfdeacadf80d5e6880bdf871ffeaa6","versionType":"git","status":"affected"},{"version":"9dbf091da080508e9f632d307f357beb79a0766b","lessThan":"6bdc3023d62ed5c7d591f0eb27a5adb37fb892ae","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/iio/gyro/itg3200_buffer.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"3.9","status":"affected"},{"version":"0","lessThan":"3.9","versionType":"semver","status":"unaffected"},{"version":"5.10.259","lessThanOrEqual":"5.10.*","versionType":"semver","status":"unaffected"},{"version":"5.15.210","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.176","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.143","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.93","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.35","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.0.12","lessThanOrEqual":"7.0.*","versionType":"semver","status":"unaffected"},{"version":"7.1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/15a0b3f33ffb6c78b3de6f69b026ceb09b973dd1","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/31bbd4b87dd6701fa10e03ba7f6268e49e178d16","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/63203bd072b613c18c237b906b1c9d2dc4527337","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/6bdc3023d62ed5c7d591f0eb27a5adb37fb892ae","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/8654b5e2617819ff4f7c78071dfd0275e971a9b6","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/90e809376b0f0d1ddec2eec954aecdd2a5b40b0e","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/b64dd5f3b38911054cbcc570df617e3e8e75e562","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/cfc3283859cfdeacadf80d5e6880bdf871ffeaa6","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-63935","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-07-19T16:17:11.987","lastModified":"2026-07-19T16:17:11.987","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\niio: adc: nxp-sar-adc: fix division by zero in write_raw\n\nAdd a validation check for the sampling frequency value before using it\nas a divisor. A user writing zero or a negative value to the\nsampling_frequency sysfs attribute triggers a division by zero in the\nkernel.\n\nAlso prevent unsigned integer underflow when the computed cycle count is\nsmaller than NXP_SAR_ADC_CONV_TIME, which would wrap the u32 inpsamp to\na huge value."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/iio/adc/nxp-sar-adc.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"4434072a893e4864519c167947083ff3e4cc2d95","lessThan":"cb6ea15e7d3c7518f806975a06b7d4c0a26402ea","versionType":"git","status":"affected"},{"version":"4434072a893e4864519c167947083ff3e4cc2d95","lessThan":"a9aba21a539c668a66b58eeb08ad3909e5a54c2a","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/iio/adc/nxp-sar-adc.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"7.0","status":"affected"},{"version":"0","lessThan":"7.0","versionType":"semver","status":"unaffected"},{"version":"7.0.12","lessThanOrEqual":"7.0.*","versionType":"semver","status":"unaffected"},{"version":"7.1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/a9aba21a539c668a66b58eeb08ad3909e5a54c2a","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/cb6ea15e7d3c7518f806975a06b7d4c0a26402ea","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-63936","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-07-19T16:17:12.080","lastModified":"2026-07-19T16:17:12.080","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\niio: adc: mt6359: fix unchecked return value in mt6358_read_imp\n\nIn mt6358_read_imp(), the variable val_v is passed to regmap_read()\nbut the return value is not checked. If the read fails, val_v remains\nuninitialized and its random stack content is subsequently reported\nas a measurement result.\n\nInitialize val_v to zero to ensure a predictable value is reported\nin case of bus failure and to prevent potential stack data leakage.\nThis also satisfies static analyzers that might otherwise flag the\nvariable as used uninitialized."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/iio/adc/mt6359-auxadc.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"3587914bf61df7924933530353d840378cdc4973","lessThan":"6258bfec51e894ea97b8e69f3cde7af269b37de9","versionType":"git","status":"affected"},{"version":"3587914bf61df7924933530353d840378cdc4973","lessThan":"944082fdb0284a31c0b37a88c8a1d4404da3a6d9","versionType":"git","status":"affected"},{"version":"3587914bf61df7924933530353d840378cdc4973","lessThan":"a72f8e51d6ee66c255a8a93a4421b8a538d112a8","versionType":"git","status":"affected"},{"version":"3587914bf61df7924933530353d840378cdc4973","lessThan":"f9bbd943c34a9ad60e593a4b99ce2394e4e2381b","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/iio/adc/mt6359-auxadc.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.11","status":"affected"},{"version":"0","lessThan":"6.11","versionType":"semver","status":"unaffected"},{"version":"6.12.93","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.35","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.0.12","lessThanOrEqual":"7.0.*","versionType":"semver","status":"unaffected"},{"version":"7.1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/6258bfec51e894ea97b8e69f3cde7af269b37de9","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/944082fdb0284a31c0b37a88c8a1d4404da3a6d9","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/a72f8e51d6ee66c255a8a93a4421b8a538d112a8","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/f9bbd943c34a9ad60e593a4b99ce2394e4e2381b","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-63943","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-07-19T16:17:12.880","lastModified":"2026-07-19T16:17:12.880","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nInput: xpad - fix out-of-bounds access for Share button\n\nxpadone_process_packet() receives len directly from urb->actual_length\nand uses it to index the share-button byte at data[len - 18] or\ndata[len - 26]. Since both len and data[0] are under the device's\ncontrol, a broken controller can send a GIP_CMD_INPUT packet with\nactual_length < 18 (e.g. 5 bytes) and reach this code path, causing\naccesses beyond the actual array.\n\nFix this by calculating the offset and checking bounds against the\npacket length."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/input/joystick/xpad.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"cbc82e7db16d59c301457312a624a7de2c03cd4a","lessThan":"bcfb4833cd4078a1a356ef451838b75cd233099e","versionType":"git","status":"affected"},{"version":"302a0cd0bbc450998429a3f4267970a4b93251a8","lessThan":"37ec54abfdd63a63fd50734a9c4e4cbc1e5795af","versionType":"git","status":"affected"},{"version":"4ef46367073b107ec22f46fe5f12176e87c238e8","lessThan":"9749db57233b396353ad5dee81eec9d9880c9246","versionType":"git","status":"affected"},{"version":"4ef46367073b107ec22f46fe5f12176e87c238e8","lessThan":"6346b0895b574ce45f3747b9c508c72f70e6abef","versionType":"git","status":"affected"},{"version":"4ef46367073b107ec22f46fe5f12176e87c238e8","lessThan":"6cdc46b38cf146ce81d4831b6472dbf7731849a2","versionType":"git","status":"affected"},{"version":"a7e3ddd1d9a3d0b26465ed01d464e3c05479ebc8","versionType":"git","status":"affected"},{"version":"6.6.91","lessThan":"6.6.143","versionType":"semver","status":"affected"},{"version":"6.12.29","lessThan":"6.12.93","versionType":"semver","status":"affected"},{"version":"6.14.7","lessThan":"6.15","versionType":"semver","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/input/joystick/xpad.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.15","status":"affected"},{"version":"0","lessThan":"6.15","versionType":"semver","status":"unaffected"},{"version":"6.6.143","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.93","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.35","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.0.12","lessThanOrEqual":"7.0.*","versionType":"semver","status":"unaffected"},{"version":"7.1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/37ec54abfdd63a63fd50734a9c4e4cbc1e5795af","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/6346b0895b574ce45f3747b9c508c72f70e6abef","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/6cdc46b38cf146ce81d4831b6472dbf7731849a2","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/9749db57233b396353ad5dee81eec9d9880c9246","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/bcfb4833cd4078a1a356ef451838b75cd233099e","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-63948","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-07-19T16:17:13.460","lastModified":"2026-07-19T16:17:13.460","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nBluetooth: L2CAP: fix chan ref leak in l2cap_chan_timeout() on !conn\n\n__set_chan_timer() takes a l2cap_chan reference via l2cap_chan_hold()\nbefore scheduling the delayed work.  The normal path in\nl2cap_chan_timeout() drops this reference with l2cap_chan_put() at the\nend, but the early return when chan->conn is NULL skips the put,\nleaking the reference.\n\nAdd the missing l2cap_chan_put() before the early return."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["net/bluetooth/l2cap_core.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"06acb75e7ed600d0bbf7bff5628aa8f24a97978c","lessThan":"50f1bcaaaa3a80bb1c3472044bc146e8d49d51ee","versionType":"git","status":"affected"},{"version":"e97e16433eb4533083b096a3824b93a5ca3aee79","lessThan":"b5c59a5b469e2a809a2d57eda4ded94235971060","versionType":"git","status":"affected"},{"version":"8960ff650aec70485b40771cd8e6e8c4cb467d33","lessThan":"8894c2010435a56ce7c6c2a8785860c13554df2f","versionType":"git","status":"affected"},{"version":"955b5b6c54d95b5e7444dfc81c95c8e013f27ac0","lessThan":"63cd225cc13d782a85e2a73c04d0d350153eada1","versionType":"git","status":"affected"},{"version":"adf0398cee86643b8eacde95f17d073d022f782c","lessThan":"107c826e4ef9ec5ad8f60e6fe64d8d5325ba508f","versionType":"git","status":"affected"},{"version":"adf0398cee86643b8eacde95f17d073d022f782c","lessThan":"e8a5baff5be273ca07771fd2b9bb1f2a4152917b","versionType":"git","status":"affected"},{"version":"adf0398cee86643b8eacde95f17d073d022f782c","lessThan":"08d81fe96f80a8e20c7acb573b6a45d901fcf2cd","versionType":"git","status":"affected"},{"version":"adf0398cee86643b8eacde95f17d073d022f782c","lessThan":"9dbd84990394c51f5cee1e8871bb5ff8af5ed939","versionType":"git","status":"affected"},{"version":"e137e2ba96e51902dc2878131823a96bf8e638ae","versionType":"git","status":"affected"},{"version":"6466ee65e5b27161c846c73ef407f49dfa1bd1d9","versionType":"git","status":"affected"},{"version":"eb86f955488c39526534211f2610e48a5cf8ead4","versionType":"git","status":"affected"},{"version":"5.10.217","lessThan":"5.10.259","versionType":"semver","status":"affected"},{"version":"5.15.159","lessThan":"5.15.210","versionType":"semver","status":"affected"},{"version":"6.1.91","lessThan":"6.1.176","versionType":"semver","status":"affected"},{"version":"6.6.31","lessThan":"6.6.143","versionType":"semver","status":"affected"},{"version":"4.19.314","lessThan":"4.20","versionType":"semver","status":"affected"},{"version":"5.4.276","lessThan":"5.5","versionType":"semver","status":"affected"},{"version":"6.8.10","lessThan":"6.9","versionType":"semver","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["net/bluetooth/l2cap_core.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.9","status":"affected"},{"version":"0","lessThan":"6.9","versionType":"semver","status":"unaffected"},{"version":"5.10.259","lessThanOrEqual":"5.10.*","versionType":"semver","status":"unaffected"},{"version":"5.15.210","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.176","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.143","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.93","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.35","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.0.12","lessThanOrEqual":"7.0.*","versionType":"semver","status":"unaffected"},{"version":"7.1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/08d81fe96f80a8e20c7acb573b6a45d901fcf2cd","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/107c826e4ef9ec5ad8f60e6fe64d8d5325ba508f","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/50f1bcaaaa3a80bb1c3472044bc146e8d49d51ee","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/63cd225cc13d782a85e2a73c04d0d350153eada1","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/8894c2010435a56ce7c6c2a8785860c13554df2f","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/9dbd84990394c51f5cee1e8871bb5ff8af5ed939","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/b5c59a5b469e2a809a2d57eda4ded94235971060","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/e8a5baff5be273ca07771fd2b9bb1f2a4152917b","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-63949","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-07-19T16:17:13.600","lastModified":"2026-07-19T16:17:13.600","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nauxdisplay: line-display: fix OOB read on zero-length message_store()\n\nlinedisp_display() unconditionally reads msg[count - 1] before\nchecking whether count is zero, so a write of zero bytes to the\nmessage sysfs attribute hits msg[-1]:\n\n\twrite(fd, \"\", 0);\n\n\t-> message_store(..., buf, count=0)\n\t   -> linedisp_display(linedisp, buf, count=0)\n\t      -> msg[count - 1] == '\\n'  ; OOB read\n\nThe kernfs write buffer for that store is a 1-byte allocation\n(kernfs_fop_write_iter() does kmalloc(len + 1) with len == 0),\nso msg[-1] is a 1-byte read before the slab object. On a\nKASAN-enabled kernel this trips an out-of-bounds report and\npanics; on stock kernels it silently reads adjacent slab data\nand, if that byte happens to be '\\n', the following count--\nwraps ssize_t 0 to -1 and is then passed to kmemdup_nul().\n\nlinedisp_display() is reached from the message_store() sysfs\ncallback (drivers/auxdisplay/line-display.c message attribute,\nmode 0644) and from the in-tree initial-message setup with\ncount == -1, so the OOB path is only userspace-triggerable via\nzero-byte writes; vfs_write() does not short-circuit on\ncount == 0 and kernfs_fop_write_iter() dispatches the store\ncallback regardless.\n\nGuard the trailing-newline trim with a count check. The\nexisting if (!count) block then takes the clear-display path\nunchanged.\n\nAffects every auxdisplay driver that registers via\nlinedisp_register() / linedisp_attach(): ht16k33, max6959,\nimg-ascii-lcd, seg-led-gpio."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/auxdisplay/line-display.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"7e76aece6f036cb7ada4858d6aa73825bfe22983","lessThan":"ca5b0781946d5083ceafa752141f47f085853620","versionType":"git","status":"affected"},{"version":"7e76aece6f036cb7ada4858d6aa73825bfe22983","lessThan":"8776032fe989a9b5fc77f2de5e03e4adb44c630e","versionType":"git","status":"affected"},{"version":"7e76aece6f036cb7ada4858d6aa73825bfe22983","lessThan":"3859960daeb9b7b39b9847b5b0113bc6081eb735","versionType":"git","status":"affected"},{"version":"7e76aece6f036cb7ada4858d6aa73825bfe22983","lessThan":"197476b126010bac1b3199833c6966cd6f54c2a9","versionType":"git","status":"affected"},{"version":"7e76aece6f036cb7ada4858d6aa73825bfe22983","lessThan":"6ad4f75ef9f3372fce8cad494e789ac6a5507bef","versionType":"git","status":"affected"},{"version":"7e76aece6f036cb7ada4858d6aa73825bfe22983","lessThan":"a7511dcd9dd4bc55d123f9b800c8a4ed2662e5c6","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/auxdisplay/line-display.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"5.16","status":"affected"},{"version":"0","lessThan":"5.16","versionType":"semver","status":"unaffected"},{"version":"6.1.176","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.143","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.93","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.35","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.0.12","lessThanOrEqual":"7.0.*","versionType":"semver","status":"unaffected"},{"version":"7.1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/197476b126010bac1b3199833c6966cd6f54c2a9","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/3859960daeb9b7b39b9847b5b0113bc6081eb735","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/6ad4f75ef9f3372fce8cad494e789ac6a5507bef","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/8776032fe989a9b5fc77f2de5e03e4adb44c630e","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/a7511dcd9dd4bc55d123f9b800c8a4ed2662e5c6","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/ca5b0781946d5083ceafa752141f47f085853620","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-63953","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-07-19T16:17:14.060","lastModified":"2026-07-19T16:17:14.060","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nmm/migrate_device: fix pgtable leak in migrate_vma_insert_huge_pmd_page\n\nWhen migrate_vma_insert_huge_pmd_page() jumps to unlock_abort due\nto a PMD check failure, the pgtable allocated earlier via\npte_alloc_one() is never freed, causing a memory leak.\n\nAdded free_abort label to release the pgtable in error path."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["mm/migrate_device.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"a30b48bf1b244f11bf9b6d20cdccfe0c2264130c","lessThan":"24861d04f197bb651e9dfb211978271c15f75a98","versionType":"git","status":"affected"},{"version":"a30b48bf1b244f11bf9b6d20cdccfe0c2264130c","lessThan":"2c6f81d58741349298f51ff697d988cb42881453","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["mm/migrate_device.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.19","status":"affected"},{"version":"0","lessThan":"6.19","versionType":"semver","status":"unaffected"},{"version":"7.0.12","lessThanOrEqual":"7.0.*","versionType":"semver","status":"unaffected"},{"version":"7.1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/24861d04f197bb651e9dfb211978271c15f75a98","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/2c6f81d58741349298f51ff697d988cb42881453","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-63956","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-07-19T16:17:14.410","lastModified":"2026-07-19T16:17:14.410","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nUSB: serial: cypress_m8: fix memory corruption with small endpoint\n\nMake sure that the interrupt-out endpoint max packet size is at least\neight bytes to avoid user-controlled slab corruption or NULL-pointer\ndereference should a malicious device report a smaller size."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/usb/serial/cypress_m8.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"3416eaa1f8f8d516b77de514e14cf8da256d28fb","lessThan":"4fcb22218f0a7229b7ce3b3952fb644def293fa5","versionType":"git","status":"affected"},{"version":"3416eaa1f8f8d516b77de514e14cf8da256d28fb","lessThan":"ad3d1628a46134276546d7a12fedf04be9979158","versionType":"git","status":"affected"},{"version":"3416eaa1f8f8d516b77de514e14cf8da256d28fb","lessThan":"52e18ae0c47c5c89e18fcd8022f287f7cc8802ec","versionType":"git","status":"affected"},{"version":"3416eaa1f8f8d516b77de514e14cf8da256d28fb","lessThan":"4bcaa59f403dbde6328604a500d65ee8d40975d9","versionType":"git","status":"affected"},{"version":"3416eaa1f8f8d516b77de514e14cf8da256d28fb","lessThan":"1ef25704bd3b625fd151c09feee459479f71ee64","versionType":"git","status":"affected"},{"version":"3416eaa1f8f8d516b77de514e14cf8da256d28fb","lessThan":"284105c40fc31fff90cdab8a0377aaeb92f87f0e","versionType":"git","status":"affected"},{"version":"3416eaa1f8f8d516b77de514e14cf8da256d28fb","lessThan":"6c13f3bb652bc8665e709ba07122612586aea648","versionType":"git","status":"affected"},{"version":"3416eaa1f8f8d516b77de514e14cf8da256d28fb","lessThan":"e1a9d791fd66ab2431b9e6f6f835823809869047","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/usb/serial/cypress_m8.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"2.6.26","status":"affected"},{"version":"0","lessThan":"2.6.26","versionType":"semver","status":"unaffected"},{"version":"5.10.259","lessThanOrEqual":"5.10.*","versionType":"semver","status":"unaffected"},{"version":"5.15.210","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.176","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.143","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.93","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.35","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.0.12","lessThanOrEqual":"7.0.*","versionType":"semver","status":"unaffected"},{"version":"7.1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/1ef25704bd3b625fd151c09feee459479f71ee64","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/284105c40fc31fff90cdab8a0377aaeb92f87f0e","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/4bcaa59f403dbde6328604a500d65ee8d40975d9","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/4fcb22218f0a7229b7ce3b3952fb644def293fa5","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/52e18ae0c47c5c89e18fcd8022f287f7cc8802ec","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/6c13f3bb652bc8665e709ba07122612586aea648","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/ad3d1628a46134276546d7a12fedf04be9979158","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/e1a9d791fd66ab2431b9e6f6f835823809869047","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-63957","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-07-19T16:17:14.533","lastModified":"2026-07-19T16:17:14.533","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nUSB: serial: safe_serial: fix memory corruption with small endpoint\n\nMake sure that the bulk-out buffer size is at least eight bytes to avoid\nuser-controlled slab corruption in \"safe\" mode should a malicious device\nreport a smaller size."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/usb/serial/safe_serial.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"e3a1d6eee25dc96b1d2db0ecd9d8741e92056476","versionType":"git","status":"affected"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"c7336c0fba5c959249f3d793d33076b992ec3ee4","versionType":"git","status":"affected"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"161ea0e5236f5f051d2d85d6c54dd08ee9dc7ba4","versionType":"git","status":"affected"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"9b3145b3001fb24de1da72d1deb0bea70e5a078b","versionType":"git","status":"affected"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"a550ed2117ca4709d38f713933ff924a83942e41","versionType":"git","status":"affected"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"f793b67d41e5fab719c5a90baa77cbd2fe259517","versionType":"git","status":"affected"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"857b3cc73f91871ae4433f8b97c4670b78f8dc96","versionType":"git","status":"affected"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"438061ed1ad85e6743e2dce826671772d81089ec","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/usb/serial/safe_serial.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"2.6.12","status":"affected"},{"version":"0","lessThan":"2.6.12","versionType":"semver","status":"unaffected"},{"version":"5.10.259","lessThanOrEqual":"5.10.*","versionType":"semver","status":"unaffected"},{"version":"5.15.210","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.176","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.143","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.93","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.35","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.0.12","lessThanOrEqual":"7.0.*","versionType":"semver","status":"unaffected"},{"version":"7.1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/161ea0e5236f5f051d2d85d6c54dd08ee9dc7ba4","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/438061ed1ad85e6743e2dce826671772d81089ec","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/857b3cc73f91871ae4433f8b97c4670b78f8dc96","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/9b3145b3001fb24de1da72d1deb0bea70e5a078b","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/a550ed2117ca4709d38f713933ff924a83942e41","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/c7336c0fba5c959249f3d793d33076b992ec3ee4","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/e3a1d6eee25dc96b1d2db0ecd9d8741e92056476","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/f793b67d41e5fab719c5a90baa77cbd2fe259517","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-63965","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-07-19T16:17:15.500","lastModified":"2026-07-19T16:17:15.500","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\niio: pressure: bmp280: fix stack leak in bmp580 trigger handler\n\nbmp580_trigger_handler() declares its scan buffer on the stack without\nan initializer and then memcpy()s 3 bytes of 24-bit sensor data into\neach 4-byte __le32 field.  The high byte of comp_temp and comp_press is\nleft uninitialized, and the channel storagebits is 32, so two bytes of\nstack are pushed to userspace per scan.\n\nThis is a regression from when the buffer lived in the private data, the\nmove to a stack-local struct dropped the implicit zeroing.\nbme280_trigger_handler() was fixed up to handle this bug, but this\ndriver was not fixed because there was no padding hole, but rather a\nshort-fill issue.\n\nFix this all by just zero-initializing the structure on the stack."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/iio/pressure/bmp280-core.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"872c8014e05ed47b8a7c0f5ba4311279a637150b","lessThan":"a58400f58f82f3d8de9c067aa7cda690228c1ecc","versionType":"git","status":"affected"},{"version":"872c8014e05ed47b8a7c0f5ba4311279a637150b","lessThan":"58dfb6fe9dc80270cf7cc014837af4cbf928e3aa","versionType":"git","status":"affected"},{"version":"872c8014e05ed47b8a7c0f5ba4311279a637150b","lessThan":"387c86b582e0782ab332e7bfcd4e6e3f93922961","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/iio/pressure/bmp280-core.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.16","status":"affected"},{"version":"0","lessThan":"6.16","versionType":"semver","status":"unaffected"},{"version":"6.18.35","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.0.12","lessThanOrEqual":"7.0.*","versionType":"semver","status":"unaffected"},{"version":"7.1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/387c86b582e0782ab332e7bfcd4e6e3f93922961","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/58dfb6fe9dc80270cf7cc014837af4cbf928e3aa","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/a58400f58f82f3d8de9c067aa7cda690228c1ecc","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-63966","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-07-19T16:17:15.600","lastModified":"2026-07-19T16:17:15.600","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\niio: imu: adis16550: fix stack leak in trigger handler\n\nadis16550_trigger_handler() declares the scan data array on the stack\nwithout initializing it.  The memcpy() at the bottom fills only the\nfirst 28 bytes (TEMP + 6 channels of GYRO/ACCEL data), and\niio_push_to_buffers_with_timestamp() writes the s64 timestamp at the\n8-byte-aligned offset 32.  Bytes 28-31 remain uninitialized stack data\nwhich leaks to userspace on ever trigger.\n\nFix this all by just zero-initializing the structure on the stack."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/iio/imu/adis16550.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"e4570f4bb231f01e32d44fd38841665f340d6914","lessThan":"ce582b22dd2ff15ac99101c22ec1559d1febe2ff","versionType":"git","status":"affected"},{"version":"e4570f4bb231f01e32d44fd38841665f340d6914","lessThan":"c2c255444392872cbbf46d640cb3a938e8000309","versionType":"git","status":"affected"},{"version":"e4570f4bb231f01e32d44fd38841665f340d6914","lessThan":"474f8928d50b09f7dcf507049f08732640b88b49","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/iio/imu/adis16550.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.15","status":"affected"},{"version":"0","lessThan":"6.15","versionType":"semver","status":"unaffected"},{"version":"6.18.35","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.0.12","lessThanOrEqual":"7.0.*","versionType":"semver","status":"unaffected"},{"version":"7.1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/474f8928d50b09f7dcf507049f08732640b88b49","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/c2c255444392872cbbf46d640cb3a938e8000309","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/ce582b22dd2ff15ac99101c22ec1559d1febe2ff","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-63967","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-07-19T16:17:15.700","lastModified":"2026-07-19T16:17:15.700","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\niio: imu: st_lsm6dsx: fix stack leak in tagged FIFO buffer\n\nThe tagged FIFO path declares iio_buff on the stack with __aligned(8)\nbut no initializer, but there is a hole in the structure, which will\nthen leak to userspace as ST_LSM6DSX_SAMPLE_SIZE bytes (6) will be\ncopied, but the space between that and the timestamp are not\ninitialized.\n\nCommit c14edb4d0bdc (\"iio:imu:st_lsm6dsx Fix alignment and data leak\nissues\") moved the untagged FIFO path to a kzalloc'd buffer in hw->scan,\nbut for the tagged path it only added the alignment qualifier and not\nthe initializer :(\n\nFix this by just zero-initializing the structure on the stack."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/iio/imu/st_lsm6dsx/st_lsm6dsx_buffer.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"c14edb4d0bdc53f969ea84c7f384472c28b1a9f8","lessThan":"ff8d3c088b77b11782f2c3b97e37425be050e8de","versionType":"git","status":"affected"},{"version":"c14edb4d0bdc53f969ea84c7f384472c28b1a9f8","lessThan":"fe1a7f99e72ebd2880515332b79b8c256be22aca","versionType":"git","status":"affected"},{"version":"c14edb4d0bdc53f969ea84c7f384472c28b1a9f8","lessThan":"babf1943a40bb5669db57d30ca16c22504b18e07","versionType":"git","status":"affected"},{"version":"c14edb4d0bdc53f969ea84c7f384472c28b1a9f8","lessThan":"d42ac0bfb6a16617c62a59d53706579c7fadbfa6","versionType":"git","status":"affected"},{"version":"c14edb4d0bdc53f969ea84c7f384472c28b1a9f8","lessThan":"3147b303b8c7d9f91da4b849ece33b45048f5eaf","versionType":"git","status":"affected"},{"version":"c14edb4d0bdc53f969ea84c7f384472c28b1a9f8","lessThan":"e6bb3a49c5f9de870ea95e69775df785728e3366","versionType":"git","status":"affected"},{"version":"c14edb4d0bdc53f969ea84c7f384472c28b1a9f8","lessThan":"890d0312d5f94be43eac21f5a34d3bccc60d051b","versionType":"git","status":"affected"},{"version":"c14edb4d0bdc53f969ea84c7f384472c28b1a9f8","lessThan":"c9d8e9adaa63150ef7e833480b799d0bab83a276","versionType":"git","status":"affected"},{"version":"a42ca3b182ccb766666a0be1053921cba190e2de","versionType":"git","status":"affected"},{"version":"5.9.5","lessThan":"5.10","versionType":"semver","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/iio/imu/st_lsm6dsx/st_lsm6dsx_buffer.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"5.10","status":"affected"},{"version":"0","lessThan":"5.10","versionType":"semver","status":"unaffected"},{"version":"5.10.259","lessThanOrEqual":"5.10.*","versionType":"semver","status":"unaffected"},{"version":"5.15.210","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.176","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.143","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.93","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.35","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.0.12","lessThanOrEqual":"7.0.*","versionType":"semver","status":"unaffected"},{"version":"7.1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/3147b303b8c7d9f91da4b849ece33b45048f5eaf","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/890d0312d5f94be43eac21f5a34d3bccc60d051b","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/babf1943a40bb5669db57d30ca16c22504b18e07","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/c9d8e9adaa63150ef7e833480b799d0bab83a276","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/d42ac0bfb6a16617c62a59d53706579c7fadbfa6","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/e6bb3a49c5f9de870ea95e69775df785728e3366","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/fe1a7f99e72ebd2880515332b79b8c256be22aca","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/ff8d3c088b77b11782f2c3b97e37425be050e8de","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-63969","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-07-19T16:17:15.947","lastModified":"2026-07-19T16:17:15.947","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nipv6: fix possible infinite loop in rt6_fill_node()\n\nSashiko reported this issue [1]. Apply the same fix as\ncommit f8d8ce1b515a (\"ipv6: fix possible infinite loop in fib6_info_uses_dev()\").\n\nWriters holding tb6_lock can list_del_rcu(&rt->fib6_siblings)\nwithout waiting for RCU readers; rt->fib6_siblings.next then still\npoints into the old ring and this softirq-side walker never reaches\n&rt->fib6_siblings, causing a CPU stall. fib6_del_route() always\nWRITE_ONCE()s rt->fib6_nsiblings to 0 before list_del_rcu(), so an\ninside-loop check is a reliable detach signal.\n\n[1] https://sashiko.dev/#/patchset/20260526020227.4857-1-jiayuan.chen%40linux.dev"}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["net/ipv6/route.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"d0ec61c9f3583b76aebdbb271f5c0d3fcccd48b2","lessThan":"b014a63d2f2c2c767762b548381882dfb1655529","versionType":"git","status":"affected"},{"version":"52da02521ede55fb86546c3fffd9377b3261b91f","lessThan":"279853aec9f58d5cd723e6e5617c1c3337b30383","versionType":"git","status":"affected"},{"version":"34a949e7a0869dfa31a40416d2a56973fae1807b","lessThan":"c65b1f60237daac7c56c2652e064cc566a45dc81","versionType":"git","status":"affected"},{"version":"d9ccb18f83ea2bb654289b6ecf014fd267cc988b","lessThan":"dc36a04621dcc2447dae428709207810b6c06e14","versionType":"git","status":"affected"},{"version":"d9ccb18f83ea2bb654289b6ecf014fd267cc988b","lessThan":"5e40de719ee76b8d96e2556ce36dbd3bd07bf37d","versionType":"git","status":"affected"},{"version":"d9ccb18f83ea2bb654289b6ecf014fd267cc988b","lessThan":"9f72412bcf60144f252b0d6205106abf14344abc","versionType":"git","status":"affected"},{"version":"11edcd026012ac18acee0f1514db3ed1b160fc6f","versionType":"git","status":"affected"},{"version":"6.1.128","lessThan":"6.1.176","versionType":"semver","status":"affected"},{"version":"6.6.75","lessThan":"6.6.143","versionType":"semver","status":"affected"},{"version":"6.12.2","lessThan":"6.12.93","versionType":"semver","status":"affected"},{"version":"6.11.11","lessThan":"6.12","versionType":"semver","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["net/ipv6/route.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.13","status":"affected"},{"version":"0","lessThan":"6.13","versionType":"semver","status":"unaffected"},{"version":"6.1.176","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.143","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.93","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.35","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.0.12","lessThanOrEqual":"7.0.*","versionType":"semver","status":"unaffected"},{"version":"7.1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/279853aec9f58d5cd723e6e5617c1c3337b30383","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/5e40de719ee76b8d96e2556ce36dbd3bd07bf37d","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/9f72412bcf60144f252b0d6205106abf14344abc","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/b014a63d2f2c2c767762b548381882dfb1655529","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/c65b1f60237daac7c56c2652e064cc566a45dc81","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/dc36a04621dcc2447dae428709207810b6c06e14","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-63973","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-07-19T16:17:16.383","lastModified":"2026-07-19T16:17:16.383","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nnet: mana: Add NULL guards in teardown path to prevent panic on attach failure\n\nWhen queue allocation fails partway through, the error cleanup frees\nand NULLs apc->tx_qp and apc->rxqs. Multiple teardown paths such as\nmana_remove(), mana_change_mtu() recovery, and internal error handling\nin mana_alloc_queues() can subsequently call into functions that\ndereference these pointers without NULL checks:\n\n- mana_chn_setxdp() dereferences apc->rxqs[0], causing a NULL pointer\n  dereference panic (CR2: 0000000000000000 at mana_chn_setxdp+0x26).\n- mana_destroy_vport() iterates apc->rxqs without a NULL check.\n- mana_fence_rqs() iterates apc->rxqs without a NULL check.\n- mana_dealloc_queues() iterates apc->tx_qp without a NULL check.\n\nAdd NULL guards for apc->rxqs in mana_fence_rqs(),\nmana_destroy_vport(), and before the mana_chn_setxdp() call. Add a\nNULL guard for apc->tx_qp in mana_dealloc_queues() to skip TX queue\ndraining when TX queues were never allocated or already freed."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/net/ethernet/microsoft/mana/mana_en.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"ca9c54d2d6a5ab2430c4eda364c77125d62e5e0f","lessThan":"da7e4a1aaf397af6a094f640c92d6bc7564c10db","versionType":"git","status":"affected"},{"version":"ca9c54d2d6a5ab2430c4eda364c77125d62e5e0f","lessThan":"95e414f8324385771bdfd6d497a01d5593813ccb","versionType":"git","status":"affected"},{"version":"ca9c54d2d6a5ab2430c4eda364c77125d62e5e0f","lessThan":"26a96fa81496afe7d162d172ccdc8cb9dbc685d2","versionType":"git","status":"affected"},{"version":"ca9c54d2d6a5ab2430c4eda364c77125d62e5e0f","lessThan":"da87896f34e0a51489811d1a684e2953099ca98f","versionType":"git","status":"affected"},{"version":"ca9c54d2d6a5ab2430c4eda364c77125d62e5e0f","lessThan":"0a9c520fdcb1cb2e79c163c12d359b5e1ee40007","versionType":"git","status":"affected"},{"version":"ca9c54d2d6a5ab2430c4eda364c77125d62e5e0f","lessThan":"17bfe0a8c014ee1d542ad352cd6a0a505361664a","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/net/ethernet/microsoft/mana/mana_en.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"5.13","status":"affected"},{"version":"0","lessThan":"5.13","versionType":"semver","status":"unaffected"},{"version":"6.1.176","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.143","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.93","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.35","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.0.12","lessThanOrEqual":"7.0.*","versionType":"semver","status":"unaffected"},{"version":"7.1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/0a9c520fdcb1cb2e79c163c12d359b5e1ee40007","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/17bfe0a8c014ee1d542ad352cd6a0a505361664a","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/26a96fa81496afe7d162d172ccdc8cb9dbc685d2","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/95e414f8324385771bdfd6d497a01d5593813ccb","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/da7e4a1aaf397af6a094f640c92d6bc7564c10db","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/da87896f34e0a51489811d1a684e2953099ca98f","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-63981","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-07-19T16:17:17.283","lastModified":"2026-07-19T16:17:17.283","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nnet/sched: act_mirred: Fix blockcast recursion bypass leading to stack overflow\n\ntcf_mirred_act() checks sched_mirred_nest against MIRRED_NEST_LIMIT (4)\nto prevent deep recursion.  However, when the action uses blockcast\n(tcfm_blockid != 0), the function returns at the tcf_blockcast() call\nBEFORE reaching the counter increment.  As a result, the recursion\ncounter never advances and the limit check is entirely bypassed.\n\nWhen two devices share a TC egress block with a mirred blockcast rule,\na packet egressing on device A is mirrored to device B via blockcast;\ndevice B's egress TC re-enters tcf_mirred_act() via blockcast and\nmirrors back to A, creating an unbounded recursion loop:\n\n  tcf_mirred_act -> tcf_blockcast -> tcf_mirred_to_dev -> dev_queue_xmit\n  -> sch_handle_egress -> tcf_classify -> tcf_mirred_act -> (repeat)\n\nThis recursion continues until the kernel stack overflows.\n\nThe bug is reachable from an unprivileged user via\nunshare(CLONE_NEWUSER | CLONE_NEWNET): user namespaces grant\nCAP_NET_ADMIN in the new network namespace, which is sufficient to\ncreate dummy devices, attach clsact qdiscs with shared blocks, and\ninstall mirred blockcast filters.\n\n BUG: TASK stack guard page was hit at ffffc90000b7fff8\n Oops: stack guard page: 0000 [#1] SMP KASAN NOPTI\n CPU: 2 UID: 1000 PID: 169 Comm: poc Not tainted 7.0.0-rc7-next-20260410\n RIP: 0010:xas_find+0x17/0x480\n Call Trace:\n  xa_find+0x17b/0x1d0\n  tcf_mirred_act+0x640/0x1060\n  tcf_action_exec+0x400/0x530\n  basic_classify+0x128/0x1d0\n  tcf_classify+0xd83/0x1150\n  tc_run+0x328/0x620\n  __dev_queue_xmit+0x797/0x3100\n  tcf_mirred_to_dev+0x7b1/0xf70\n  tcf_mirred_act+0x68a/0x1060\n  [repeating ~30+ times until stack overflow]\n Kernel panic - not syncing: Fatal exception in interrupt\n\nFix this by incrementing sched_mirred_nest before calling\ntcf_blockcast() and decrementing it on return, mirroring the\nnon-blockcast path.  This ensures subsequent recursive entries see the\nupdated counter and are correctly limited by MIRRED_NEST_LIMIT."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["net/sched/act_mirred.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"906736728cea480a85803c67fafb1b0e78491922","lessThan":"25fc9352590f5ef21ebf290432bd768b336693bc","versionType":"git","status":"affected"},{"version":"fe946a751d9b52b7c45ca34899723b314b79b249","lessThan":"34457de389fb64a01fdcc71177dfebe65fd2d362","versionType":"git","status":"affected"},{"version":"fe946a751d9b52b7c45ca34899723b314b79b249","lessThan":"a005fa5d7502eefec7ee6e1c01adadc06de2f9ad","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["net/sched/act_mirred.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.19","status":"affected"},{"version":"0","lessThan":"6.19","versionType":"semver","status":"unaffected"},{"version":"7.0.12","lessThanOrEqual":"7.0.*","versionType":"semver","status":"unaffected"},{"version":"7.1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/25fc9352590f5ef21ebf290432bd768b336693bc","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/34457de389fb64a01fdcc71177dfebe65fd2d362","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/a005fa5d7502eefec7ee6e1c01adadc06de2f9ad","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-63982","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-07-19T16:17:17.390","lastModified":"2026-07-19T16:17:17.390","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nnet/sched: Fix ethx:ingress -> ethy:egress -> ethx:ingress mirred loop\n\nWhen mirred redirects to ingress (from either ingress or egress) the loop\nstate from sched_mirred_dev array dev is lost because of 1) the packet\ndeferral into the backlog and 2) the fact the sched_mirred_dev array is\ncleared. In such cases, if there was a loop we won't discover it.\n\nHere's a simple test to reproduce:\nip a add dev port0 10.10.10.11/24\n\ntc qdisc add dev port0 clsact\ntc filter add dev port0 egress protocol ip \\\n   prio 10 matchall action mirred ingress redirect dev port1\n\ntc qdisc add dev port1 clsact\ntc filter add dev port1 ingress protocol ip \\\n   prio 10 matchall action mirred egress redirect dev port0\n\nping -c 1 -W0.01 10.10.10.10"}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["net/sched/act_mirred.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"906736728cea480a85803c67fafb1b0e78491922","lessThan":"66f4607fe788fc7d81bce0e2f7b3726ed2f71284","versionType":"git","status":"affected"},{"version":"fe946a751d9b52b7c45ca34899723b314b79b249","lessThan":"45ac526a0d5733c3695946bd84ec57f24d8f5e66","versionType":"git","status":"affected"},{"version":"fe946a751d9b52b7c45ca34899723b314b79b249","lessThan":"db875221ab08d213a83bf30196ae8b64d55a3403","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["net/sched/act_mirred.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.19","status":"affected"},{"version":"0","lessThan":"6.19","versionType":"semver","status":"unaffected"},{"version":"7.0.12","lessThanOrEqual":"7.0.*","versionType":"semver","status":"unaffected"},{"version":"7.1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/45ac526a0d5733c3695946bd84ec57f24d8f5e66","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/66f4607fe788fc7d81bce0e2f7b3726ed2f71284","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/db875221ab08d213a83bf30196ae8b64d55a3403","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-63983","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-07-19T16:17:17.490","lastModified":"2026-07-19T16:17:17.490","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nnet/sched: fix packet loop on netem when duplicate is on\n\nWhen netem duplicates a packet it re-enqueues the copy at the root qdisc.\nIf another netem sits in the tree the copy can be duplicated\nagain, recursing until the stack or memory is exhausted.\n\nThe original duplication guard temporarily zeroed q->duplicate around\nthe re-enqueue, but that does not cover all cases because it is\nper-qdisc state shared across all concurrent enqueue paths\nand is not safe without additional locking.\n\nUse the skb tc_depth field introduced in an earlier patch:\n - increment it on the duplicate before re-enqueue\n - skip duplication for any skb whose tc_depth is already non-zero.\n\nThis marks the packet itself rather than mutating qdisc state,\ntherefore it is safe regardless of tree topology or concurrency."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["net/sched/sch_netem.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"0afb51e72855971dba83b3c6b70c547c2d1161fd","lessThan":"1a298a514ce766c6d0c232991a390fec67af81ad","versionType":"git","status":"affected"},{"version":"0afb51e72855971dba83b3c6b70c547c2d1161fd","lessThan":"cfb2616042767ab31260d4f39190c381bec8b12e","versionType":"git","status":"affected"},{"version":"0afb51e72855971dba83b3c6b70c547c2d1161fd","lessThan":"9552b11e3edabc97cfcd9f29103d5afbce7ae183","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["net/sched/sch_netem.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"2.6.12","status":"affected"},{"version":"0","lessThan":"2.6.12","versionType":"semver","status":"unaffected"},{"version":"6.12.93","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"7.0.12","lessThanOrEqual":"7.0.*","versionType":"semver","status":"unaffected"},{"version":"7.1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/1a298a514ce766c6d0c232991a390fec67af81ad","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/9552b11e3edabc97cfcd9f29103d5afbce7ae183","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/cfb2616042767ab31260d4f39190c381bec8b12e","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-63986","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-07-19T16:17:17.847","lastModified":"2026-07-19T16:17:17.847","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nethtool: tsinfo: don't pass ERR_PTR to genlmsg_cancel on prepare failure\n\nThe goto err label leads to:\n\n\tgenlmsg_cancel(skb, ehdr);\n\treturn ret;\n\nIf ethnl_tsinfo_prepare_dump() failed, it has not started a genlmsg.\nThere's nothing to cancel, and passing an error pointer to\ngenlmsg_cancel() would cause a crash."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["net/ethtool/tsinfo.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"b9e3f7dc9ed95daeb83cfa45b821cacaa01aa906","lessThan":"2008f9bb1ede9b688624a241228b8e54fc74f0f6","versionType":"git","status":"affected"},{"version":"b9e3f7dc9ed95daeb83cfa45b821cacaa01aa906","lessThan":"d0d2c5ccd1de28368cebeef74d9c530a60eff9a5","versionType":"git","status":"affected"},{"version":"b9e3f7dc9ed95daeb83cfa45b821cacaa01aa906","lessThan":"c3fc9976f686f9a95baf87db9d387f218fd65394","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["net/ethtool/tsinfo.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.14","status":"affected"},{"version":"0","lessThan":"6.14","versionType":"semver","status":"unaffected"},{"version":"6.18.35","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.0.12","lessThanOrEqual":"7.0.*","versionType":"semver","status":"unaffected"},{"version":"7.1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/2008f9bb1ede9b688624a241228b8e54fc74f0f6","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/c3fc9976f686f9a95baf87db9d387f218fd65394","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/d0d2c5ccd1de28368cebeef74d9c530a60eff9a5","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-63988","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-07-19T16:17:18.060","lastModified":"2026-07-19T16:17:18.060","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nbridge: Fix sleep in atomic context in sysfs path\n\nSince the start of the git history, brport_store() always acquired the\nbridge lock. Back then this decision made sense: The bridge lock\nprotects the STP state of the bridge and its ports and at that time the\nfunction was only used by two STP related attributes (cost and\npriority).\n\nNowadays, brport_store() processes a lot more attributes and most of\nthem do not need the bridge lock:\n\n* Bridge flags: Only require RTNL. Read locklessly by the data path.\n  Annotations can be added in net-next.\n\n* FDB port flushing: Only requires the FDB lock.\n\n* Multicast attributes: Only require the multicast lock.\n\n* Group forward mask: Only requires RTNL. Read locklessly by the data\n  path. Annotations can be added in net-next.\n\n* Backup port: Only requires RTNL. Read locklessly by the data path.\n\nThis is a problem as the bridge calls dev_set_promiscuity() when certain\nbridge port flags change and this function can sleep since the commit\ncited below, resulting in a splat such as [1].\n\nFix this by reducing the scope of the bridge lock and only take it when\nprocessing the two STP related attributes that require it. Remove the\nnow stale comment from br_switchdev_set_port_flag(). The\nSWITCHDEV_F_DEFER flag can be removed in net-next.\n\n[1]\nBUG: sleeping function called from invalid context at net/core/dev_addr_lists.c:1262\nin_atomic(): 1, irqs_disabled(): 0, non_block: 0, pid: 372, name: bash\npreempt_count: 201, expected: 0\nRCU nest depth: 0, expected: 0\n5 locks held by bash/372:\n#0: ffff88810c51c3f0 (sb_writers#7){.+.+}-{0:0}, at: ksys_write (fs/read_write.c:740)\n#1: ffff888115ce9480 (&of->mutex){+.+.}-{4:4}, at: kernfs_fop_write_iter (fs/kernfs/file.c:343)\n#2: ffff88810b9fd330 (kn->active#37){.+.+}-{0:0}, at: kernfs_fop_write_iter (fs/kernfs/file.c:80 fs/kernfs/file.c:344)\n#3: ffffffffa59473a0 (rtnl_mutex){+.+.}-{4:4}, at: brport_store (net/bridge/br_sysfs_if.c:326)\n#4: ffff8881099d2d58 (&br->lock){+...}-{3:3}, at: brport_store (./include/linux/spinlock.h:348 net/bridge/br_sysfs_if.c:345)\nPreemption disabled at:\n 0x0\nHardware name: Bochs Bochs, BIOS Bochs 01/01/2011\nCall Trace:\n<TASK>\ndump_stack_lvl (lib/dump_stack.c:94 lib/dump_stack.c:120)\n__might_resched.cold (kernel/sched/core.c:9163)\nnetif_rx_mode_run (net/core/dev_addr_lists.c:1262)\nnetif_rx_mode_sync (net/core/dev_addr_lists.c:1428)\ndev_set_promiscuity (net/core/dev_api.c:289)\nbr_manage_promisc (net/bridge/br_if.c:135 net/bridge/br_if.c:172)\nbr_port_flags_change (net/bridge/br_if.c:242 net/bridge/br_if.c:747)\nstore_learning (net/bridge/br_sysfs_if.c:79 net/bridge/br_sysfs_if.c:235)\nbrport_store (net/bridge/br_sysfs_if.c:346)\nkernfs_fop_write_iter (fs/kernfs/file.c:352)\nnew_sync_write (fs/read_write.c:595)\nvfs_write (fs/read_write.c:688)\nksys_write (fs/read_write.c:740)\ndo_syscall_64 (arch/x86/entry/syscall_64.c:63 arch/x86/entry/syscall_64.c:94)\nentry_SYSCALL_64_after_hwframe (arch/x86/entry/entry_64.S:121)"}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["net/bridge/br_switchdev.c","net/bridge/br_sysfs_if.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"78cd408356fe3edbac66598772fd347bf3e32c1f","lessThan":"e976e3f2f2005c6267089a1a3b6344f234a59a55","versionType":"git","status":"affected"},{"version":"78cd408356fe3edbac66598772fd347bf3e32c1f","lessThan":"2f9cb30d97e45686f3119fff3b30f12259950910","versionType":"git","status":"affected"},{"version":"78cd408356fe3edbac66598772fd347bf3e32c1f","lessThan":"6d34594cc619d0d4b07d5afcad8b5984f3526dcf","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["net/bridge/br_switchdev.c","net/bridge/br_sysfs_if.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.15","status":"affected"},{"version":"0","lessThan":"6.15","versionType":"semver","status":"unaffected"},{"version":"6.18.35","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.0.12","lessThanOrEqual":"7.0.*","versionType":"semver","status":"unaffected"},{"version":"7.1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/2f9cb30d97e45686f3119fff3b30f12259950910","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/6d34594cc619d0d4b07d5afcad8b5984f3526dcf","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/e976e3f2f2005c6267089a1a3b6344f234a59a55","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-63989","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-07-19T16:17:18.260","lastModified":"2026-07-19T16:17:18.260","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nbridge: Fix sleep in atomic context in netlink path\n\nSince the introduction of the netlink configuration path for bridge\nports in commit 25c71c75ac87 (\"bridge: bridge port parameters over\nnetlink\"), br_setport() was always called with the bridge lock held\naround it. Back then this decision made sense: The bridge lock protects\nthe STP state of the bridge and its ports and at that time the function\nonly processed three STP related netlink attributes (cost, priority and\nstate).\n\nNowadays, br_setport() processes a lot more attributes and most of them\ndo not need the bridge lock:\n\n* Bridge flags: Only require RTNL. Read locklessly by the data path.\n  Annotations can be added in net-next.\n\n* FDB port flushing: Only requires the FDB lock.\n\n* Multicast attributes: Only require the multicast lock.\n\n* Group forward mask: Only requires RTNL. Read locklessly by the data\n  path. Annotations can be added in net-next.\n\n* Backup port and NHID: Only require RTNL. Read locklessly by the data\n  path.\n\nThis is a problem as the bridge calls dev_set_promiscuity() when certain\nbridge port flags change and this function can sleep since the commit\ncited below, resulting in a splat such as [1].\n\nFix this by reducing the scope of the bridge lock and only take it when\nprocessing the three STP related attributes that require it. This is\nconsistent with the multicast attributes where each attribute acquires\nthe multicast lock instead of having one critical section for all\nrelevant attributes.\n\n[1]\nBUG: sleeping function called from invalid context at net/core/dev_addr_lists.c:1262\nin_atomic(): 1, irqs_disabled(): 0, non_block: 0, pid: 356, name: bridge\npreempt_count: 201, expected: 0\nRCU nest depth: 0, expected: 0\n2 locks held by bridge/356:\n#0: ffffffff919473a0 (rtnl_mutex){+.+.}-{4:4}, at: rtnetlink_rcv_msg (net/core/rtnetlink.c:80 net/core/rtnetlink.c:7002)\n#1: ffff888115072d58 (&br->lock){+...}-{3:3}, at: br_setlink (./include/linux/spinlock.h:348 net/bridge/br_netlink.c:1117)\nPreemption disabled at:\n 0x0\nHardware name: Bochs Bochs, BIOS Bochs 01/01/2011\nCall Trace:\n<TASK>\ndump_stack_lvl (lib/dump_stack.c:94 lib/dump_stack.c:120)\n__might_resched.cold (kernel/sched/core.c:9163)\nnetif_rx_mode_run (net/core/dev_addr_lists.c:1262)\nnetif_rx_mode_sync (net/core/dev_addr_lists.c:1428)\ndev_set_promiscuity (net/core/dev_api.c:289)\nbr_manage_promisc (net/bridge/br_if.c:135 net/bridge/br_if.c:172)\nbr_port_flags_change (net/bridge/br_if.c:242 net/bridge/br_if.c:747)\nbr_setport (net/bridge/br_netlink.c:1000)\nbr_setlink (net/bridge/br_netlink.c:1118)\nrtnl_bridge_setlink (net/core/rtnetlink.c:5572)\nrtnetlink_rcv_msg (net/core/rtnetlink.c:7005)\nnetlink_rcv_skb (net/netlink/af_netlink.c:2550)\nnetlink_unicast (net/netlink/af_netlink.c:1318 net/netlink/af_netlink.c:1344)\nnetlink_sendmsg (net/netlink/af_netlink.c:1894)\n__sock_sendmsg (net/socket.c:787 (discriminator 4) net/socket.c:802 (discriminator 4))\n____sys_sendmsg (net/socket.c:2698)\n___sys_sendmsg (net/socket.c:2752)\n__sys_sendmsg (net/socket.c:2784)\ndo_syscall_64 (arch/x86/entry/syscall_64.c:63 arch/x86/entry/syscall_64.c:94)\nentry_SYSCALL_64_after_hwframe (arch/x86/entry/entry_64.S:121)"}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["net/bridge/br_netlink.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"78cd408356fe3edbac66598772fd347bf3e32c1f","lessThan":"c9c2e609e8397bb57b4d73675f33a99183c4a0bd","versionType":"git","status":"affected"},{"version":"78cd408356fe3edbac66598772fd347bf3e32c1f","lessThan":"803d39accfbdf223ccbb49684d5b5069b4c44586","versionType":"git","status":"affected"},{"version":"78cd408356fe3edbac66598772fd347bf3e32c1f","lessThan":"5eec4427b89c2fb2beac54920101e55a2f1c0c21","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["net/bridge/br_netlink.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.15","status":"affected"},{"version":"0","lessThan":"6.15","versionType":"semver","status":"unaffected"},{"version":"6.18.35","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.0.12","lessThanOrEqual":"7.0.*","versionType":"semver","status":"unaffected"},{"version":"7.1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/5eec4427b89c2fb2beac54920101e55a2f1c0c21","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/803d39accfbdf223ccbb49684d5b5069b4c44586","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/c9c2e609e8397bb57b4d73675f33a99183c4a0bd","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-63990","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-07-19T16:17:18.610","lastModified":"2026-07-19T16:17:18.610","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nbonding: refuse to enslave CAN devices\n\nsyzbot reported a kernel paging request crash in\ncan_rx_unregister() inside net/can/af_can.c. The crash occurs\nbecause a virtual CAN device (vxcan) is being enslaved to a\nbonding master.\n\nDuring the enslavement process, the bonding driver mutates\nand modifies the network device states to fit an Ethernet-like\naggregation model. However, CAN devices operate on a completely\ndifferent Layer 2 architecture, relying on the CAN mid-layer\nprivate data structure (can_ml_priv) instead of standard\nEthernet structures. Since bonding does not initialize or\nmaintain these CAN structures, subsequent operations on the\nhalf-enslaved interface (such as closing associated sockets\nvia isotp_release) lead to a null-pointer dereference when\naccessing the CAN receiver lists.\n\nBonding CAN interfaces is architecturally invalid as CAN lacks\nMAC addresses, ARP capabilities, and standard Ethernet\nlink-layer mechanisms. While generic loopback devices are\nblocked globally in net/core/dev.c, virtual CAN devices\nbypass this check because they do not carry the IFF_LOOPBACK\nflag, despite acting as local software-loopbacks.\n\nFix this by explicitly blocking network devices of type\nARPHRD_CAN from being enslaved at the very beginning of\nbond_enslave(). This prevents illegal state mutations,\neliminates the resulting KASAN crashes, and avoids potential\nmemory leaks from incomplete socket cleanups.\n\nAs the CAN support has been added a long time after bonding\nthe Fixes-tag points to the introduction of ARPHRD_CAN that\nwould have needed a specific handling in bonding_main.c."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/net/bonding/bond_main.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"cd05acfe65ed2cf2db683fa9a6adb8d35635263b","lessThan":"69b78b5f3033272e53a2dc2dad675962654a5b38","versionType":"git","status":"affected"},{"version":"cd05acfe65ed2cf2db683fa9a6adb8d35635263b","lessThan":"41e8478c4cd896d3abbe33d41afc90c84ac66602","versionType":"git","status":"affected"},{"version":"cd05acfe65ed2cf2db683fa9a6adb8d35635263b","lessThan":"f4d78a81f57df82e9d82a2c07471fed1a1235893","versionType":"git","status":"affected"},{"version":"cd05acfe65ed2cf2db683fa9a6adb8d35635263b","lessThan":"02f1c87ded33b43d48b4a1d665da15f2157b30d8","versionType":"git","status":"affected"},{"version":"cd05acfe65ed2cf2db683fa9a6adb8d35635263b","lessThan":"9ea8a648d9120f7652bcde1ce2c4ad66871af707","versionType":"git","status":"affected"},{"version":"cd05acfe65ed2cf2db683fa9a6adb8d35635263b","lessThan":"563090e5d450c665f70d955a39f9587afc7842eb","versionType":"git","status":"affected"},{"version":"cd05acfe65ed2cf2db683fa9a6adb8d35635263b","lessThan":"8ba68464e4787b6a7ec938826e16124df20fd23d","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/net/bonding/bond_main.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"2.6.25","status":"affected"},{"version":"0","lessThan":"2.6.25","versionType":"semver","status":"unaffected"},{"version":"5.15.210","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.176","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.143","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.93","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.35","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.0.12","lessThanOrEqual":"7.0.*","versionType":"semver","status":"unaffected"},{"version":"7.1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/02f1c87ded33b43d48b4a1d665da15f2157b30d8","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/41e8478c4cd896d3abbe33d41afc90c84ac66602","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/563090e5d450c665f70d955a39f9587afc7842eb","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/69b78b5f3033272e53a2dc2dad675962654a5b38","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/8ba68464e4787b6a7ec938826e16124df20fd23d","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/9ea8a648d9120f7652bcde1ce2c4ad66871af707","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/f4d78a81f57df82e9d82a2c07471fed1a1235893","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-63991","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-07-19T16:17:37.783","lastModified":"2026-07-19T16:17:37.783","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nBluetooth: 6lowpan: check skb_clone() return value in send_mcast_pkt()\n\nThe skb_clone() function can return NULL if memory allocation fails.\nsend_mcast_pkt() calls skb_clone() without checking the return value, which\ncan lead to a NULL pointer dereference in send_pkt() when it dereferences\nskb->data.\nAdd a NULL check after skb_clone() and skip the peer if the clone fails."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["net/bluetooth/6lowpan.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"18722c247023035b9e2e2a08a887adec2a9a6e49","lessThan":"9afcb5ea080af13aab37930da627db43bd277665","versionType":"git","status":"affected"},{"version":"18722c247023035b9e2e2a08a887adec2a9a6e49","lessThan":"9903a04becf059e44cccf625e23689b7d4378384","versionType":"git","status":"affected"},{"version":"18722c247023035b9e2e2a08a887adec2a9a6e49","lessThan":"d630c4b25f36e0e68461561e4c70957ec37fdedd","versionType":"git","status":"affected"},{"version":"18722c247023035b9e2e2a08a887adec2a9a6e49","lessThan":"b06203ac5f12929d79146bb9f063c2af1d679e63","versionType":"git","status":"affected"},{"version":"18722c247023035b9e2e2a08a887adec2a9a6e49","lessThan":"3d5d81d294ba09487c86bc4ba33dc4a4bec5d215","versionType":"git","status":"affected"},{"version":"18722c247023035b9e2e2a08a887adec2a9a6e49","lessThan":"e673889a35a5e4c586d0fae67d8755ca4367d3e2","versionType":"git","status":"affected"},{"version":"18722c247023035b9e2e2a08a887adec2a9a6e49","lessThan":"2061d080a013c0ec0a56162cd501fb36d2befc26","versionType":"git","status":"affected"},{"version":"18722c247023035b9e2e2a08a887adec2a9a6e49","lessThan":"3c40d381ce04f9575a5d8b542898183c3b4b38dc","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["net/bluetooth/6lowpan.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"3.14","status":"affected"},{"version":"0","lessThan":"3.14","versionType":"semver","status":"unaffected"},{"version":"5.10.259","lessThanOrEqual":"5.10.*","versionType":"semver","status":"unaffected"},{"version":"5.15.210","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.176","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.143","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.93","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.35","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.0.12","lessThanOrEqual":"7.0.*","versionType":"semver","status":"unaffected"},{"version":"7.1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/2061d080a013c0ec0a56162cd501fb36d2befc26","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/3c40d381ce04f9575a5d8b542898183c3b4b38dc","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/3d5d81d294ba09487c86bc4ba33dc4a4bec5d215","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/9903a04becf059e44cccf625e23689b7d4378384","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/9afcb5ea080af13aab37930da627db43bd277665","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/b06203ac5f12929d79146bb9f063c2af1d679e63","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/d630c4b25f36e0e68461561e4c70957ec37fdedd","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/e673889a35a5e4c586d0fae67d8755ca4367d3e2","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-63997","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-07-19T16:17:39.270","lastModified":"2026-07-19T16:17:39.270","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nethtool: module: avoid leaking a netdev ref on module flash errors\n\nmodule_flash_fw_schedule() is missing undo for setting\nthe \"in_progress\" flag and taking the netdev reference.\nDelay taking these, the device can't disappear while\nwe are holding rtnl_lock."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["net/ethtool/module.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"32b4c8b53ee7799e34a2b1634d32d3ce1e36c44e","lessThan":"f7b4513e77f9571dc1041a798b93b5c4a4bfc191","versionType":"git","status":"affected"},{"version":"32b4c8b53ee7799e34a2b1634d32d3ce1e36c44e","lessThan":"61848c83b9132ab839809fe415ba7802a0aca4f6","versionType":"git","status":"affected"},{"version":"32b4c8b53ee7799e34a2b1634d32d3ce1e36c44e","lessThan":"956b134d917fd7e014dc7e39a9b7610c04fcc9ba","versionType":"git","status":"affected"},{"version":"32b4c8b53ee7799e34a2b1634d32d3ce1e36c44e","lessThan":"fb7f511d62692661846c47f199e0afe25c2982db","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["net/ethtool/module.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.11","status":"affected"},{"version":"0","lessThan":"6.11","versionType":"semver","status":"unaffected"},{"version":"6.12.93","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.35","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.0.12","lessThanOrEqual":"7.0.*","versionType":"semver","status":"unaffected"},{"version":"7.1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/61848c83b9132ab839809fe415ba7802a0aca4f6","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/956b134d917fd7e014dc7e39a9b7610c04fcc9ba","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/f7b4513e77f9571dc1041a798b93b5c4a4bfc191","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/fb7f511d62692661846c47f199e0afe25c2982db","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-63998","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-07-19T16:17:39.370","lastModified":"2026-07-19T16:17:39.370","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nethtool: module: call ethnl_ops_complete() on module flash errors\n\nWhen validate() fails we are skipping over ethnl_ops_complete()\neven tho we already called ethnl_ops_begin()."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["net/ethtool/module.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"32b4c8b53ee7799e34a2b1634d32d3ce1e36c44e","lessThan":"d9defbf8b62bde89e206d74c2a2b445b9ed66108","versionType":"git","status":"affected"},{"version":"32b4c8b53ee7799e34a2b1634d32d3ce1e36c44e","lessThan":"e96ef1a40dda5b637b1911cd950b11e9848de939","versionType":"git","status":"affected"},{"version":"32b4c8b53ee7799e34a2b1634d32d3ce1e36c44e","lessThan":"84371fb58423f997939aacdcbc02d128d76a54e5","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["net/ethtool/module.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.11","status":"affected"},{"version":"0","lessThan":"6.11","versionType":"semver","status":"unaffected"},{"version":"6.18.35","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.0.12","lessThanOrEqual":"7.0.*","versionType":"semver","status":"unaffected"},{"version":"7.1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/84371fb58423f997939aacdcbc02d128d76a54e5","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/d9defbf8b62bde89e206d74c2a2b445b9ed66108","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/e96ef1a40dda5b637b1911cd950b11e9848de939","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-63999","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-07-19T16:17:39.477","lastModified":"2026-07-19T16:17:39.477","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nethtool: rss: fix indir_table and hkey leak on get_rxfh failure\n\nrss_prepare_get() allocates the indirection table and hash key buffer\nvia rss_get_data_alloc(), then calls ops->get_rxfh() to populate them.\nIf get_rxfh() fails, the function returns an error without freeing\nthe allocation."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["net/ethtool/rss.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"4f038a6a02d20859a3479293cbf172b0f14cbdd6","lessThan":"33d05c22d6f227c5ae171c46df2f6f8bf48047ea","versionType":"git","status":"affected"},{"version":"4f038a6a02d20859a3479293cbf172b0f14cbdd6","lessThan":"80d95d92f828cfcace955d673637d944178b435f","versionType":"git","status":"affected"},{"version":"4f038a6a02d20859a3479293cbf172b0f14cbdd6","lessThan":"266297692f97008ca48bc311775c087c59bd7fe3","versionType":"git","status":"affected"},{"version":"81a5174e64ce4fb7b7a2f6499b835c904c9451ee","versionType":"git","status":"affected"},{"version":"ec9faff49a4ea27731de39cb887b7e590e93157b","versionType":"git","status":"affected"},{"version":"c5ed0eaddcbda56079091fc3876b140a6e70a548","versionType":"git","status":"affected"},{"version":"a065b996052656a65afc51ad82336dc55ae4c72f","versionType":"git","status":"affected"},{"version":"adee9db710a6117b978a25ed4153846b7c56ec9a","versionType":"git","status":"affected"},{"version":"5eb3fdc4b6281b29e830300c866a36d90442b1f0","versionType":"git","status":"affected"},{"version":"5.15.181","lessThan":"5.16","versionType":"semver","status":"affected"},{"version":"6.1.135","lessThan":"6.2","versionType":"semver","status":"affected"},{"version":"6.6.88","lessThan":"6.7","versionType":"semver","status":"affected"},{"version":"6.12.24","lessThan":"6.13","versionType":"semver","status":"affected"},{"version":"6.13.12","lessThan":"6.14","versionType":"semver","status":"affected"},{"version":"6.14.3","lessThan":"6.15","versionType":"semver","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["net/ethtool/rss.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.15","status":"affected"},{"version":"0","lessThan":"6.15","versionType":"semver","status":"unaffected"},{"version":"6.18.35","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.0.12","lessThanOrEqual":"7.0.*","versionType":"semver","status":"unaffected"},{"version":"7.1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/266297692f97008ca48bc311775c087c59bd7fe3","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/33d05c22d6f227c5ae171c46df2f6f8bf48047ea","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/80d95d92f828cfcace955d673637d944178b435f","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-64001","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-07-19T16:17:39.700","lastModified":"2026-07-19T16:17:39.700","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nALSA: pcm: oss: Fix setup list UAF on proc write error\n\nsnd_pcm_oss_proc_write() links a newly allocated setup entry into the\nOSS setup list before duplicating the task name. If the task-name\nallocation fails, the error path frees the already linked entry and\nleaves setup_list pointing at freed memory.\n\nA later OSS device open can then walk the stale list entry in\nsnd_pcm_oss_look_for_setup() and dereference freed memory.\n\nAllocate the task name and initialize the setup entry before publishing\nthe entry on setup_list. Also fetch the initial proc read iterator only\nafter taking setup_mutex, so all setup_list traversal follows the same\nlist lifetime rules."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["sound/core/oss/pcm_oss.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"060d77b9c04acd7aef60790398a53f731db8c8fe","lessThan":"8be4efd0dc0093eb7a02ad1aac936bca2a1f04ce","versionType":"git","status":"affected"},{"version":"060d77b9c04acd7aef60790398a53f731db8c8fe","lessThan":"e13922bb97b4e6f94f8ac02d034f2d4bd65eeb3c","versionType":"git","status":"affected"},{"version":"060d77b9c04acd7aef60790398a53f731db8c8fe","lessThan":"be387230dc22d870afd0e5d35912b07c2bc323bd","versionType":"git","status":"affected"},{"version":"060d77b9c04acd7aef60790398a53f731db8c8fe","lessThan":"4cc54bdd54b337e77115be5b55577d1c58608eae","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["sound/core/oss/pcm_oss.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"2.6.17","status":"affected"},{"version":"0","lessThan":"2.6.17","versionType":"semver","status":"unaffected"},{"version":"6.12.93","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.35","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.0.12","lessThanOrEqual":"7.0.*","versionType":"semver","status":"unaffected"},{"version":"7.1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/4cc54bdd54b337e77115be5b55577d1c58608eae","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/8be4efd0dc0093eb7a02ad1aac936bca2a1f04ce","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/be387230dc22d870afd0e5d35912b07c2bc323bd","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/e13922bb97b4e6f94f8ac02d034f2d4bd65eeb3c","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-64006","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-07-19T16:17:40.297","lastModified":"2026-07-19T16:17:40.297","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nnetfilter: nf_tables: fix dst corruption in same register operation\n\nFor lshift and rshift, the shift operations are performed in a loop over\n32-bit words. The loop calculates the shifted value and write it to dst,\nand then immediately reads from src to calculate the carry for the next\niteration. Because src and dst could point to the same memory location,\nthe carry is incorrectly calculated using the newly modified dst value\ninstead of the original src value.\n\nAdding a temporary local variable to cache the original value before\nwriting to dst and using it for the carry calculation solves the\nproblem. In addition, partial overlap is rejected from control plane for\nall kind of operations including byteorder. This was tested with the\nfollowing bytecode:\n\ntable test_table ip flags 0 use 1 handle 1\nip test_table test_chain use 3 type filter hook input prio 0 policy accept packets 0 bytes 0 flags 1\nip test_table test_chain 2\n  [ immediate reg 1 0x44332211 0x88776655 ]\n  [ bitwise reg 1 = ( reg 1 << 0x08000000 ) ]\n  [ cmp eq reg 1 0x66443322 0x00887766 ]\n  [ counter pkts 0 bytes 0 ]\nip test_table test_chain 4 3\n  [ immediate reg 1 0x44332211 0x88776655 ]\n  [ bitwise reg 1 = ( reg 1 << 0x08000000 ) ]\n  [ cmp eq reg 1 0x55443322 0x00887766 ]\n  [ counter pkts 21794 bytes 1917798 ]"}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["include/net/netfilter/nf_tables.h","net/netfilter/nft_bitwise.c","net/netfilter/nft_byteorder.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"567d746b55bc66d3800c9ae91d50f0c5deb2fd93","lessThan":"b80ef316e978de2ef81d5bee9c19800b4cf96fb8","versionType":"git","status":"affected"},{"version":"567d746b55bc66d3800c9ae91d50f0c5deb2fd93","lessThan":"96bea2a7baac4a1137c188dc7610184487ab30a7","versionType":"git","status":"affected"},{"version":"567d746b55bc66d3800c9ae91d50f0c5deb2fd93","lessThan":"a391afe74398b70107f111aa731eab608624949d","versionType":"git","status":"affected"},{"version":"567d746b55bc66d3800c9ae91d50f0c5deb2fd93","lessThan":"18014147d3ee7831dce53fe65d7fc8d428b02552","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["include/net/netfilter/nf_tables.h","net/netfilter/nft_bitwise.c","net/netfilter/nft_byteorder.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"5.6","status":"affected"},{"version":"0","lessThan":"5.6","versionType":"semver","status":"unaffected"},{"version":"6.6.143","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.18.35","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.0.12","lessThanOrEqual":"7.0.*","versionType":"semver","status":"unaffected"},{"version":"7.1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/18014147d3ee7831dce53fe65d7fc8d428b02552","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/96bea2a7baac4a1137c188dc7610184487ab30a7","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/a391afe74398b70107f111aa731eab608624949d","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/b80ef316e978de2ef81d5bee9c19800b4cf96fb8","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-64012","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-07-19T16:17:41.060","lastModified":"2026-07-19T16:17:41.060","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nnet/sched: sch_sfb: Replace direct dequeue call with peek and qdisc_dequeue_peeked\n\nWhen sfb has children (eg qfq qdisc) whose peek() callback is\nqdisc_peek_dequeued(), we could get a kernel panic. When the parent of such\nqdiscs (eg illustrated in patch #3 as tbf) wants to retrieve an skb from\nits child (sfb in this case), it will do the following:\n 1a. do a peek() - and when sensing there's an skb the child can offer, then\n     - the child in this case(sfb) calls its child's (qfq) peek.\n        qfq does the right thing and will return the gso_skb queue packet.\n        Note: if there wasnt a gso_skb entry then qfq will store it there.\n 1b. invoke a dequeue() on the child (sfb). And herein lies the problem.\n     - sfb will call the child's dequeue() which will essentially just\n       try to grab something of qfq's queue.\n\n[  127.594489][  T453] KASAN: null-ptr-deref in range [0x0000000000000048-0x000000000000004f]\n[  127.594741][  T453] CPU: 2 UID: 0 PID: 453 Comm: ping Not tainted 7.1.0-rc1-00035-gac961974495b-dirty #793 PREEMPT(full)\n[  127.595059][  T453] Hardware name: Bochs Bochs, BIOS Bochs 01/01/2011\n[  127.595254][  T453] RIP: 0010:qfq_dequeue+0x35c/0x1650 [sch_qfq]\n[  127.595461][  T453] Code: 00 fc ff df 80 3c 02 00 0f 85 17 0e 00 00 4c 8d 73 48 48 89 9d b8 02 00 00 48 b8 00 00 00 00 00 fc ff df 4c 89 f2 48 c1 ea 03 <80> 3c 02 00 0f 85 76 0c 00 00 48 b8 00 00 00 00 00 fc ff df 4c 8b\n[  127.596081][  T453] RSP: 0018:ffff88810e5af440 EFLAGS: 00010216\n[  127.596337][  T453] RAX: dffffc0000000000 RBX: 0000000000000000 RCX: dffffc0000000000\n[  127.596623][  T453] RDX: 0000000000000009 RSI: 0000001880000000 RDI: ffff888104fd82b0\n[  127.596917][  T453] RBP: ffff888104fd8000 R08: ffff888104fd8280 R09: 1ffff110211893a3\n[  127.597165][  T453] R10: 1ffff110211893a6 R11: 1ffff110211893a7 R12: 0000001880000000\n[  127.597404][  T453] R13: ffff888104fd82b8 R14: 0000000000000048 R15: 0000000040000000\n[  127.597644][  T453] FS:  00007fc380cbfc40(0000) GS:ffff88816f2a8000(0000) knlGS:0000000000000000\n[  127.597956][  T453] CS:  0010 DS: 0000 ES: 0000 CR0: 0000000080050033\n[  127.598160][  T453] CR2: 00005610aa9890a8 CR3: 000000010369e000 CR4: 0000000000750ef0\n[  127.598390][  T453] PKRU: 55555554\n[  127.598509][  T453] Call Trace:\n[  127.598629][  T453]  <TASK>\n[  127.598718][  T453]  ? mark_held_locks+0x40/0x70\n[  127.598890][  T453]  ? srso_alias_return_thunk+0x5/0xfbef5\n[  127.599053][  T453]  sfb_dequeue+0x88/0x4d0\n[  127.599174][  T453]  ? ktime_get+0x137/0x230\n[  127.599328][  T453]  ? srso_alias_return_thunk+0x5/0xfbef5\n[  127.599480][  T453]  ? qdisc_peek_dequeued+0x7b/0x350 [sch_qfq]\n[  127.599670][  T453]  ? srso_alias_return_thunk+0x5/0xfbef5\n[  127.599831][  T453]  tbf_dequeue+0x6b1/0x1098 [sch_tbf]\n[  127.599988][  T453]  __qdisc_run+0x169/0x1900\n\nThe right thing to do in #1b is to grab the skb off gso_skb queue.\nThis patchset fixes that issue by changing #1b to use qdisc_dequeue_peeked()\nmethod instead."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["net/sched/sch_sfb.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"e13e02a3c68d899169c78d9a18689bd73491d59a","lessThan":"e5ea51e5f3fbba41d50cd84a530f33bc1c8f4d57","versionType":"git","status":"affected"},{"version":"e13e02a3c68d899169c78d9a18689bd73491d59a","lessThan":"1e70274d3b81de28973bcdbce40a512bcb181ff9","versionType":"git","status":"affected"},{"version":"e13e02a3c68d899169c78d9a18689bd73491d59a","lessThan":"e125f5980b730c67c92a30cf150ec8c3d6777318","versionType":"git","status":"affected"},{"version":"e13e02a3c68d899169c78d9a18689bd73491d59a","lessThan":"6c153d97c100f5b282c424101d8ff63122306997","versionType":"git","status":"affected"},{"version":"e13e02a3c68d899169c78d9a18689bd73491d59a","lessThan":"84bfbfc0c48731bcce74cdf4f9c497547ec525e0","versionType":"git","status":"affected"},{"version":"e13e02a3c68d899169c78d9a18689bd73491d59a","lessThan":"dbc560858da8b77dd9e4ef0cd93d421e0e4d7e0e","versionType":"git","status":"affected"},{"version":"e13e02a3c68d899169c78d9a18689bd73491d59a","lessThan":"9ad3288632c859cf84183199832d822e7a70bdae","versionType":"git","status":"affected"},{"version":"e13e02a3c68d899169c78d9a18689bd73491d59a","lessThan":"1b9bc71153b01dbde8045b9edede4240f4f5520e","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["net/sched/sch_sfb.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"2.6.39","status":"affected"},{"version":"0","lessThan":"2.6.39","versionType":"semver","status":"unaffected"},{"version":"5.10.259","lessThanOrEqual":"5.10.*","versionType":"semver","status":"unaffected"},{"version":"5.15.210","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.176","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.143","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.93","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.35","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.0.12","lessThanOrEqual":"7.0.*","versionType":"semver","status":"unaffected"},{"version":"7.1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/1b9bc71153b01dbde8045b9edede4240f4f5520e","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/1e70274d3b81de28973bcdbce40a512bcb181ff9","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/6c153d97c100f5b282c424101d8ff63122306997","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/84bfbfc0c48731bcce74cdf4f9c497547ec525e0","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/9ad3288632c859cf84183199832d822e7a70bdae","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/dbc560858da8b77dd9e4ef0cd93d421e0e4d7e0e","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/e125f5980b730c67c92a30cf150ec8c3d6777318","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/e5ea51e5f3fbba41d50cd84a530f33bc1c8f4d57","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-64013","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-07-19T16:17:41.220","lastModified":"2026-07-19T16:17:41.220","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nACPI: button: Fix ACPI GPE handler leak during removal\n\nCommit a7e23ec17fee (\"ACPI: button: Install notifier for system events\nas well\") changed the ACPI notify handler type for ACPI buttons to\nACPI_ALL_NOTIFY, but it forgot to update acpi_button_remove() to reflect\nthat change.  This leads to leaking the notify handler past driver\nremoval, which may cause a kernel crash to occur if ACPI notify on\nthe given device is triggered after removing the driver, and causes a\nsubsequent probe of the given device with the same driver to fail.\n\nAddress this by updating the acpi_remove_notify_handler() call in\nacpi_button_remove() as appropriate."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/acpi/button.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"a7e23ec17feecc7bac0d500cea900cace7b50129","lessThan":"614cb8c26c5aa53196ee9b211b76ee618b147d32","versionType":"git","status":"affected"},{"version":"a7e23ec17feecc7bac0d500cea900cace7b50129","lessThan":"fe80251152fed5b185f795ef2cd9f7fe9c3162e0","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/acpi/button.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.15","status":"affected"},{"version":"0","lessThan":"6.15","versionType":"semver","status":"unaffected"},{"version":"7.0.12","lessThanOrEqual":"7.0.*","versionType":"semver","status":"unaffected"},{"version":"7.1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/614cb8c26c5aa53196ee9b211b76ee618b147d32","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/fe80251152fed5b185f795ef2cd9f7fe9c3162e0","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-64014","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-07-19T16:17:41.320","lastModified":"2026-07-19T16:17:41.320","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nInput: usbtouchscreen - clamp NEXIO data_len/x_len to URB buffer size\n\nnexio_read_data() pulls data_len and x_len from a packed __be16 header\nin the device's interrupt packet and then walks packet->data[0..x_len)\nand packet->data[x_len..data_len) comparing each byte against a\nthreshold.\n\nBoth fields are 16-bit on the wire (max 65535).  The existing\nadjustments shave at most 0x100 / 0x80 off, so the loop bound can still\nreach roughly 0xfeff.  The URB transfer buffer for NEXIO is rept_size\n(1024) bytes from usb_alloc_coherent(), with the first 7 occupied by the\npacked header — so packet->data[] has 1017 valid bytes.  read_data()\ncallbacks are not given urb->actual_length, and nothing else bounds the\nwalk.\n\nA device that lies about its length can get a ~64 KiB out-of-bounds read\npast the coherent DMA allocation.  The first index whose byte exceeds\nNEXIO_THRESHOLD lands in begin_x / begin_y and from there into the\nreported touch coordinates, so adjacent kernel memory contents leak to\nuserspace as ABS_X / ABS_Y events.  Far enough out, the read can also\nhit an unmapped page and fault.\n\nFix this all by clamping data_len to the buffer's data[] capacity and\nx_len to data_len."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/input/touchscreen/usbtouchscreen.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"5197424cdcccd2b0b1922babb93969b2515c43ce","lessThan":"45c829e5eb3b974282bae50b7cca2cc891f74f0b","versionType":"git","status":"affected"},{"version":"5197424cdcccd2b0b1922babb93969b2515c43ce","lessThan":"e7cdcb266ba06d8480809b78ab8bb2bf8ff51ccb","versionType":"git","status":"affected"},{"version":"5197424cdcccd2b0b1922babb93969b2515c43ce","lessThan":"95f47331dfde243f93e679ce70bd0c24b37c683d","versionType":"git","status":"affected"},{"version":"5197424cdcccd2b0b1922babb93969b2515c43ce","lessThan":"d883312061ccde8c536595998aaf687ec070077c","versionType":"git","status":"affected"},{"version":"5197424cdcccd2b0b1922babb93969b2515c43ce","lessThan":"103d2de9f505f56da173e43f12dba62f92620278","versionType":"git","status":"affected"},{"version":"5197424cdcccd2b0b1922babb93969b2515c43ce","lessThan":"0ca809ea8e0355299266c46e5f1755040aa8dcf3","versionType":"git","status":"affected"},{"version":"5197424cdcccd2b0b1922babb93969b2515c43ce","lessThan":"7585b6aa55d8ac85ad22f522e1059f93507727b6","versionType":"git","status":"affected"},{"version":"5197424cdcccd2b0b1922babb93969b2515c43ce","lessThan":"2905281cbda52ec9df540113b35b835feb5fafd3","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/input/touchscreen/usbtouchscreen.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"2.6.34","status":"affected"},{"version":"0","lessThan":"2.6.34","versionType":"semver","status":"unaffected"},{"version":"5.10.259","lessThanOrEqual":"5.10.*","versionType":"semver","status":"unaffected"},{"version":"5.15.210","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.176","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.143","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.93","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.35","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.0.12","lessThanOrEqual":"7.0.*","versionType":"semver","status":"unaffected"},{"version":"7.1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/0ca809ea8e0355299266c46e5f1755040aa8dcf3","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/103d2de9f505f56da173e43f12dba62f92620278","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/2905281cbda52ec9df540113b35b835feb5fafd3","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/45c829e5eb3b974282bae50b7cca2cc891f74f0b","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/7585b6aa55d8ac85ad22f522e1059f93507727b6","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/95f47331dfde243f93e679ce70bd0c24b37c683d","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/d883312061ccde8c536595998aaf687ec070077c","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/e7cdcb266ba06d8480809b78ab8bb2bf8ff51ccb","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-64019","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-07-19T16:17:41.907","lastModified":"2026-07-19T16:17:41.907","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nnvme-pci: fix dma mapping leak on data setup error\n\nWe're leaking the initial DMA mapping during iteration if we fail to\nallocate the tracking descriptor for both PRP and SGL. Unmap the\niterator directly; we can't use the existing unmap helper because it\ndepends on the tracking descriptor being successfully allocated, so a\nnew one for an in-use iterator is provided.\n\nThe mappings were also leaking when the driver detects an invalid\nbio_vec when mapping PRPs, so fix that too."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/nvme/host/pci.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"7ce3c1dd78fca86ea8b9aee370db10c7a8cfc3c2","lessThan":"e50db059ec8e63bc50b1cc039e2502cb5ea75a70","versionType":"git","status":"affected"},{"version":"7ce3c1dd78fca86ea8b9aee370db10c7a8cfc3c2","lessThan":"1bf86336e4b6cf40873fda47a7fe191446864937","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/nvme/host/pci.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.17","status":"affected"},{"version":"0","lessThan":"6.17","versionType":"semver","status":"unaffected"},{"version":"7.0.11","lessThanOrEqual":"7.0.*","versionType":"semver","status":"unaffected"},{"version":"7.1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/1bf86336e4b6cf40873fda47a7fe191446864937","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/e50db059ec8e63bc50b1cc039e2502cb5ea75a70","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-64021","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-07-19T16:17:42.107","lastModified":"2026-07-19T16:17:42.107","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/xe/oa: Fix exec_queue leak on width check in stream open\n\nIn xe_oa_stream_open_ioctl(), when param.exec_q->width > 1 the\nfunction returns -EOPNOTSUPP directly, skipping the existing\nerr_exec_q cleanup path. The exec_queue reference obtained by\nxe_exec_queue_lookup() is leaked.\n\nThe exec queue holds a reference on the xe_file, which is only\ndropped during queue teardown. The leaked lookup ref is not on\nthe file's exec_queue xarray, so file close cannot release it.\nThis keeps both the exec queue and the file private state pinned\nindefinitely.\n\nJump to err_exec_q instead of returning directly so the reference\nis released.\n\n(cherry picked from commit 339fa0be9e4a5d69fa47e91f4a36574224fb478f)"}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/gpu/drm/xe/xe_oa.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"f0ed39830e6064d62f9c5393505677a26569bb56","lessThan":"04ef7592eaadd9ca8f8f66e76452f73525cff819","versionType":"git","status":"affected"},{"version":"f0ed39830e6064d62f9c5393505677a26569bb56","lessThan":"4b0c4f0c1b133d4bfa31c167200bcda646873328","versionType":"git","status":"affected"},{"version":"f0ed39830e6064d62f9c5393505677a26569bb56","lessThan":"4d25342543c01310fc4e0cba7cb17c775e2421e2","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/gpu/drm/xe/xe_oa.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.13","status":"affected"},{"version":"0","lessThan":"6.13","versionType":"semver","status":"unaffected"},{"version":"6.18.34","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.0.11","lessThanOrEqual":"7.0.*","versionType":"semver","status":"unaffected"},{"version":"7.1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/04ef7592eaadd9ca8f8f66e76452f73525cff819","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/4b0c4f0c1b133d4bfa31c167200bcda646873328","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/4d25342543c01310fc4e0cba7cb17c775e2421e2","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-64022","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-07-19T16:17:42.210","lastModified":"2026-07-19T16:17:42.210","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\ngpio: aggregator: remove the software node when deactivating the aggregator\n\nThe dynamic software node we create for the aggregator platform device\nwhen using configfs is leaked when the device is deactivated. Destroy it\nas the last step in the tear-down path."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/gpio/gpio-aggregator.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"86f162e73d2d81ef6d819c06a3b6c2fda77a79b8","lessThan":"3e657619cf7258cb53b1beaf0d02998297695cde","versionType":"git","status":"affected"},{"version":"86f162e73d2d81ef6d819c06a3b6c2fda77a79b8","lessThan":"9870ea9a4a25abef3e7af3445bfce2472528a546","versionType":"git","status":"affected"},{"version":"86f162e73d2d81ef6d819c06a3b6c2fda77a79b8","lessThan":"61fef83f239ecace1cce716135762a2d9b7b1fc6","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/gpio/gpio-aggregator.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.16","status":"affected"},{"version":"0","lessThan":"6.16","versionType":"semver","status":"unaffected"},{"version":"6.18.34","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.0.11","lessThanOrEqual":"7.0.*","versionType":"semver","status":"unaffected"},{"version":"7.1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/3e657619cf7258cb53b1beaf0d02998297695cde","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/61fef83f239ecace1cce716135762a2d9b7b1fc6","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/9870ea9a4a25abef3e7af3445bfce2472528a546","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-64028","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-07-19T16:17:42.877","lastModified":"2026-07-19T16:17:42.877","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\ntracing: Avoid NULL return from hist_field_name() on truncation\n\nhist_field_name() returns \"\" everywhere except the fully-qualified\nVAR_REF/EXPR case, where snprintf() truncation returns NULL early\nand bypasses the bottom NULL->\"\" guard. Callers don't expect NULL:\nstrcat(expr, hist_field_name(field, 0)) at trace_events_hist.c:1758\nand the strcmp() in the sort-key match loop at :4804 both deref it.\n\nsystem and event_name are bounded by MAX_EVENT_NAME_LEN, but the\nfield name on a VAR_REF is kstrdup'd from a histogram variable\nname parsed out of the trigger string and has no length cap, so\na long enough var name in a fully qualified reference can reach\nthe truncation path.\n\nKeep the length check but leave field_name as \"\" on overflow."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["kernel/trace/trace_events_hist.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"2e8578364061c4e88ae33bc20c2d6f64f365f6a2","lessThan":"e3f5d42cdc2f167719564693675f1eead81378ea","versionType":"git","status":"affected"},{"version":"dfd1cd57ee6067301841b7b0967c70f910a51150","lessThan":"37377b39ff86dacbc533275c1155210d4fd5dc91","versionType":"git","status":"affected"},{"version":"e5c223f46c2e0691461dd97510c15e1f77148872","lessThan":"0402a1d3ddec565132867337ed44514a09d84728","versionType":"git","status":"affected"},{"version":"9399a92989354e34086f9a5c379493217df83c5e","lessThan":"e91687643c440ca3997d67646e6f80b92edc6703","versionType":"git","status":"affected"},{"version":"3cb6cb9c5a547a1979ad74f38eefe8e3687d96e0","lessThan":"be4e99038c1603fa6b329d8ee3e364825e17c353","versionType":"git","status":"affected"},{"version":"0402c60abe769098d77f3b3bd1e29a97922b614b","lessThan":"d6c8b3ebdcdb12b59ad4212acb137cc56cae453d","versionType":"git","status":"affected"},{"version":"6929e650db8451a9975ac0a631ba2d6e5d1e80ba","lessThan":"915c1254fe0788abddc31095b360e9dc98907a34","versionType":"git","status":"affected"},{"version":"5ec1d1e97de134beed3a5b08235a60fc1c51af96","lessThan":"576ec047d20b368b43c4d5db98c4f2e0f3c101ec","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["kernel/trace/trace_events_hist.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.6.141","lessThan":"6.6.142","versionType":"semver","status":"affected"},{"version":"6.12.91","lessThan":"6.12.92","versionType":"semver","status":"affected"},{"version":"6.18.33","lessThan":"6.18.34","versionType":"semver","status":"affected"},{"version":"7.0.10","lessThan":"7.0.11","versionType":"semver","status":"affected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/0402a1d3ddec565132867337ed44514a09d84728","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/37377b39ff86dacbc533275c1155210d4fd5dc91","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/576ec047d20b368b43c4d5db98c4f2e0f3c101ec","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/915c1254fe0788abddc31095b360e9dc98907a34","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/be4e99038c1603fa6b329d8ee3e364825e17c353","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/d6c8b3ebdcdb12b59ad4212acb137cc56cae453d","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/e3f5d42cdc2f167719564693675f1eead81378ea","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/e91687643c440ca3997d67646e6f80b92edc6703","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-64038","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-07-19T16:17:44.053","lastModified":"2026-07-19T16:17:44.053","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nhwmon: (lm90) Stop work before releasing hwmon device\n\nSashiko reports:\n\nIn lm90_probe(), the devm action to cancel the alert_work and report_work\n(lm90_restore_conf) is registered in lm90_init_client() before\ndevm_hwmon_device_register_with_info() is called.\n\nBecause devm executes cleanup actions in reverse order during module\nunbind or probe failure, the hwmon device is unregistered and freed first.\n\nIf lm90_alert_work() or lm90_report_alarms() runs in the window between\nthe hwmon device being freed and the delayed works being cancelled,\nlm90_update_alarms() will dereference the freed data->hwmon_dev here.\n\nFix the problem by canceling the workers separately after registering\nthe hwmon device and before registering the interrupt handler. This ensures\nthat the workers are canceled after interrupts are disabled and before\nthe hwmon device is released. Add \"shutdown\" flag to indicate that device\nshutdown is in progress to prevent workers from being re-armed."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/hwmon/lm90.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"f6d0775119fb905fb02eafa98d575cf8ee792d46","lessThan":"c98107817b0f6cdf51adc5e84e75c39ee25d8b28","versionType":"git","status":"affected"},{"version":"f6d0775119fb905fb02eafa98d575cf8ee792d46","lessThan":"479e297526aeb19c745eac5c1897f455f83dc5f8","versionType":"git","status":"affected"},{"version":"f6d0775119fb905fb02eafa98d575cf8ee792d46","lessThan":"b09a45601094c7f4ec4db8090b825fa61e169d93","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/hwmon/lm90.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.0","status":"affected"},{"version":"0","lessThan":"6.0","versionType":"semver","status":"unaffected"},{"version":"6.18.34","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.0.11","lessThanOrEqual":"7.0.*","versionType":"semver","status":"unaffected"},{"version":"7.1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/479e297526aeb19c745eac5c1897f455f83dc5f8","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/b09a45601094c7f4ec4db8090b825fa61e169d93","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/c98107817b0f6cdf51adc5e84e75c39ee25d8b28","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-64040","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-07-19T16:17:44.270","lastModified":"2026-07-19T16:17:44.270","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\ncachefiles: Fix error return when vfs_mkdir() fails\n\nWhen vfs_mkdir() fails, the error code is not extracted from the\nreturned error pointer. This causes mkdir_error to be reached with\nret=0, which leads to returning ERR_PTR(0) (NULL) instead of a\nproper error pointer.\n\nFix this by extracting the error code from the error pointer when\nvfs_mkdir() fails."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["fs/cachefiles/namei.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"406fad7698f5bf21ab6b5ca195bf4b9e0b3990ed","lessThan":"0940108d27c6995e02819ff832be11892f0b208b","versionType":"git","status":"affected"},{"version":"406fad7698f5bf21ab6b5ca195bf4b9e0b3990ed","lessThan":"8a220d1c312c66194f4a33dd52d1fba42bc2b341","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["fs/cachefiles/namei.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.15","status":"affected"},{"version":"0","lessThan":"6.15","versionType":"semver","status":"unaffected"},{"version":"7.0.11","lessThanOrEqual":"7.0.*","versionType":"semver","status":"unaffected"},{"version":"7.1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/0940108d27c6995e02819ff832be11892f0b208b","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/8a220d1c312c66194f4a33dd52d1fba42bc2b341","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-64043","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-07-19T16:17:44.580","lastModified":"2026-07-19T16:17:44.580","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\novpn: fix race between deleting interface and adding new peer\n\nWhile deleting an existing ovpn interface, there is a very\nnarrow window where adding a new peer via netlink may cause\nthe netdevice to hang and prevent its unregistration.\n\nIt may happen during ovpn_dellink(), when all existing peers are\nfreed and the device is queued for deregistration, but a\nCMD_PEER_NEW message comes in adding a new peer that takes again\na reference to the netdev.\n\nAt this point there is no way to release the device because we are\nunder the assumption that all peers were already released.\n\nFix the race condition by releasing all peers in ndo_uninit(),\nwhen the netdevice has already been removed from the netdev\nlist.\n\nAlso ovpn_peer_add() has now an extra check that forces the\nfunction to bail out if the device reg_state is not REGISTERED.\nThis way any incoming CMD_PEER_NEW racing with the interface\ndeletion routine will simply stop before adding the peer.\n\nNote that the above check happens while holding the netdev_lock\nto prevent racing netdev state changes.\n\novpn_dellink() is now empty and can be removed."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/net/ovpn/main.c","drivers/net/ovpn/peer.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"80747caef33d77f5c1b3d24644e6d7dae69066b5","lessThan":"097d62df38314c14b88fab9096f3461baf158e2b","versionType":"git","status":"affected"},{"version":"80747caef33d77f5c1b3d24644e6d7dae69066b5","lessThan":"de9fec2a6645f5b4d23398cd870a33e2703728d9","versionType":"git","status":"affected"},{"version":"80747caef33d77f5c1b3d24644e6d7dae69066b5","lessThan":"982422b11e6f95f766a8cd2c2b1cbdb77e234a61","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/net/ovpn/main.c","drivers/net/ovpn/peer.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.16","status":"affected"},{"version":"0","lessThan":"6.16","versionType":"semver","status":"unaffected"},{"version":"6.18.34","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.0.11","lessThanOrEqual":"7.0.*","versionType":"semver","status":"unaffected"},{"version":"7.1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/097d62df38314c14b88fab9096f3461baf158e2b","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/982422b11e6f95f766a8cd2c2b1cbdb77e234a61","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/de9fec2a6645f5b4d23398cd870a33e2703728d9","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-64049","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-07-19T16:17:45.310","lastModified":"2026-07-19T16:17:45.310","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/msm/adreno: fix userspace-triggered crash on a2xx-a4xx\n\nBefore a5xx Adreno driver will not try fetching UBWC params (because\nthose generations didn't support UBWC anyway), however it's still\npossible to query UBWC-related params from the userspace, triggering\npossible NULL pointer dereference. Check for UBWC config in\nadreno_get_param() and return sane defaults if there is none.\n\nPatchwork: https://patchwork.freedesktop.org/patch/717778/"}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/gpu/drm/msm/adreno/adreno_gpu.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"a452510aad53f665eb422784ff525c4889aa246f","lessThan":"eea43d5ed45089705bc5d70971c39076962d5951","versionType":"git","status":"affected"},{"version":"a452510aad53f665eb422784ff525c4889aa246f","lessThan":"22fc33d9b67694b24e0deb3f08c622464338cecb","versionType":"git","status":"affected"},{"version":"a452510aad53f665eb422784ff525c4889aa246f","lessThan":"2b4abf879360ea00a9e2b46d2d15dcdbc0687eed","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/gpu/drm/msm/adreno/adreno_gpu.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.17","status":"affected"},{"version":"0","lessThan":"6.17","versionType":"semver","status":"unaffected"},{"version":"6.18.34","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.0.11","lessThanOrEqual":"7.0.*","versionType":"semver","status":"unaffected"},{"version":"7.1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/22fc33d9b67694b24e0deb3f08c622464338cecb","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/2b4abf879360ea00a9e2b46d2d15dcdbc0687eed","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/eea43d5ed45089705bc5d70971c39076962d5951","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-64052","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-07-19T16:17:45.623","lastModified":"2026-07-19T16:17:45.623","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nblock: bio-integrity: Fix null-ptr-deref in bio_integrity_map_user()\n\npin_user_pages_fast() can partially succeed and return the number of\npages that were actually pinned. However, the bio_integrity_map_user()\ndoes not handle this partial pinning. This leads to a general protection\nfault since bvec_from_pages() dereferences an unpinned page address,\nwhich is 0.\n\nTo fix this, add a check to verify that all requested memory is pinned.\nIf partial pinning occurs, unpin the memory and return -EFAULT.\n\nKernel Oops:\n\nOops: general protection fault, probably for non-canonical address 0xdffffc0000000001: 0000 [#1] SMP KASAN NOPTI\nKASAN: null-ptr-deref in range [0x0000000000000008-0x000000000000000f]\nCPU: 0 UID: 0 PID: 1061 Comm: nvme-passthroug Not tainted 7.0.0-11783-g90957f9314e8-dirty #16 PREEMPT(lazy)\nHardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS rel-1.17.0-0-gb52ca86e094d-prebuilt.qemu.org 04/01/2014\nRIP: 0010:bio_integrity_map_user.cold+0x1b0/0x9d6"}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["block/bio-integrity.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"492c5d455969fc2e829f26ed4c83487b068f0dd7","lessThan":"77c059f41e9395793917d067476f549a911d77d3","versionType":"git","status":"affected"},{"version":"492c5d455969fc2e829f26ed4c83487b068f0dd7","lessThan":"76410790f1491c8e06a451045ae223a61c652455","versionType":"git","status":"affected"},{"version":"492c5d455969fc2e829f26ed4c83487b068f0dd7","lessThan":"8fa244738641d95ea4d70e6f9a62778bba42a5b7","versionType":"git","status":"affected"},{"version":"492c5d455969fc2e829f26ed4c83487b068f0dd7","lessThan":"8582792cf23b3d94674d4d838f7cde9a28d0fcaf","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["block/bio-integrity.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.8","status":"affected"},{"version":"0","lessThan":"6.8","versionType":"semver","status":"unaffected"},{"version":"6.12.92","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.34","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.0.11","lessThanOrEqual":"7.0.*","versionType":"semver","status":"unaffected"},{"version":"7.1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/76410790f1491c8e06a451045ae223a61c652455","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/77c059f41e9395793917d067476f549a911d77d3","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/8582792cf23b3d94674d4d838f7cde9a28d0fcaf","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/8fa244738641d95ea4d70e6f9a62778bba42a5b7","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-64054","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-07-19T16:17:45.830","lastModified":"2026-07-19T16:17:45.830","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nnet: shaper: reject duplicate leaves in GROUP request\n\nnet_shaper_nl_group_doit() does not deduplicate NET_SHAPER_A_LEAVES\nentries. When userspace supplies the same leaf handle twice, the same\nold-parent pointer lands twice in old_nodes[]. The cleanup loop double\nfrees the parent. Of course the same parent may still be in old_nodes[]\ntwice if we are moving multiple of its leaves.\n\nNote that this patch also implicitly fixes the fact that the\ni >= leaves_count path forgets to set ret."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["net/shaper/shaper.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"5d5d4700e75d861e83bf18eb6bf66ff90f85fe4e","lessThan":"5098b223f0f0c5c18a3884a8b0ea5bd4a0c7bd75","versionType":"git","status":"affected"},{"version":"5d5d4700e75d861e83bf18eb6bf66ff90f85fe4e","lessThan":"31767bf852b59f05125b58a17007e4cd1ea9eb2e","versionType":"git","status":"affected"},{"version":"5d5d4700e75d861e83bf18eb6bf66ff90f85fe4e","lessThan":"a9a2fa1da619f276580b0d4c5d12efac89e8642b","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["net/shaper/shaper.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.13","status":"affected"},{"version":"0","lessThan":"6.13","versionType":"semver","status":"unaffected"},{"version":"6.18.34","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.0.11","lessThanOrEqual":"7.0.*","versionType":"semver","status":"unaffected"},{"version":"7.1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/31767bf852b59f05125b58a17007e4cd1ea9eb2e","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/5098b223f0f0c5c18a3884a8b0ea5bd4a0c7bd75","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/a9a2fa1da619f276580b0d4c5d12efac89e8642b","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-64059","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-07-19T16:17:46.407","lastModified":"2026-07-19T16:17:46.407","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nnetfs: Fix folio->private handling in netfs_perform_write()\n\nUnder some circumstances, netfs_perform_write() doesn't correctly\nmanipulate folio->private between NULL, NETFS_FOLIO_COPY_TO_CACHE, pointing\nto a group and pointing to a netfs_folio struct, leading to potential\nmultiple attachments of private data with associated folio ref leaks and\nalso leaks of netfs_folio structs or netfs_group refs.\n\nFix this by consolidating the place at which a folio is marked uptodate in\none place and having that look at what's attached to folio->private and\ndecide how to clean it up and then set the new group.  Also, the content\nshouldn't be flushed if group is NULL, even if a group is specified in the\nnetfs_group parameter, as that would be the case for a new folio.  A\nfilesystem should always specify netfs_group or never specify netfs_group.\n\nThe Sashiko auto-review tool noted that it was theoretically possible that\nthe fpos >= ctx->zero_point section might leak if it modified a streaming\nwrite folio.  This is unlikely, but with a network filesystem, third party\nchanges can happen.  It also pointed out that __netfs_set_group() would\nleak if called multiple times on the same folio from the \"whole folio\nmodify section\"."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["fs/netfs/buffered_write.c","include/trace/events/netfs.h"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"8f52de0077ba3bf41e5d53d67a185700f41efce7","lessThan":"7f040243c74d72b45b22246c7d9e621fbeab44ac","versionType":"git","status":"affected"},{"version":"8f52de0077ba3bf41e5d53d67a185700f41efce7","lessThan":"551b5c71ee312ca7646ddb605231c1016e8cbb18","versionType":"git","status":"affected"},{"version":"8f52de0077ba3bf41e5d53d67a185700f41efce7","lessThan":"0969ea8370bad0e4fb6131b6a7bed9e7ec522ac7","versionType":"git","status":"affected"},{"version":"8f52de0077ba3bf41e5d53d67a185700f41efce7","lessThan":"ccde2ac757c713535b224233a296de40efe5212d","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["fs/netfs/buffered_write.c","include/trace/events/netfs.h"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.12","status":"affected"},{"version":"0","lessThan":"6.12","versionType":"semver","status":"unaffected"},{"version":"6.12.92","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.34","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.0.11","lessThanOrEqual":"7.0.*","versionType":"semver","status":"unaffected"},{"version":"7.1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/0969ea8370bad0e4fb6131b6a7bed9e7ec522ac7","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/551b5c71ee312ca7646ddb605231c1016e8cbb18","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/7f040243c74d72b45b22246c7d9e621fbeab44ac","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/ccde2ac757c713535b224233a296de40efe5212d","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-64060","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-07-19T16:17:46.513","lastModified":"2026-07-19T16:17:46.513","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nnetfs: Fix leak of request in netfs_write_begin() error handling\n\nFix netfs_write_begin() to not leak our ref on the request in the event\nthat we get an error from netfs_wait_for_read()."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["fs/netfs/buffered_read.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"4090b31422a6f24dfe701e31ffec7ba5804a7e2f","lessThan":"22ae28aae43623be235ff455558cdd13fbe2daeb","versionType":"git","status":"affected"},{"version":"4090b31422a6f24dfe701e31ffec7ba5804a7e2f","lessThan":"28686d6d8b60dc5bbae9ef6023ab2051d6c66cdf","versionType":"git","status":"affected"},{"version":"4090b31422a6f24dfe701e31ffec7ba5804a7e2f","lessThan":"5046a34f0643441f05b0253ea64e1a3af87efe14","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["fs/netfs/buffered_read.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"5.18","status":"affected"},{"version":"0","lessThan":"5.18","versionType":"semver","status":"unaffected"},{"version":"6.18.34","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.0.11","lessThanOrEqual":"7.0.*","versionType":"semver","status":"unaffected"},{"version":"7.1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/22ae28aae43623be235ff455558cdd13fbe2daeb","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/28686d6d8b60dc5bbae9ef6023ab2051d6c66cdf","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/5046a34f0643441f05b0253ea64e1a3af87efe14","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-64062","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-07-19T16:17:46.720","lastModified":"2026-07-19T16:17:46.720","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nnetfs: Fix potential deadlock in write-through mode\n\nFix netfs_advance_writethrough() to always unlock the supplied folio and to\nmark it dirty if it isn't yet written to the end.  Unfortunately, it can't\nbe marked for writeback until the folio is done with as that may cause a\ndeadlock against mmapped reads and writes.\n\nEven though it has been marked dirty, premature writeback can't occur as\nthe caller is holding both inode->i_rwsem (which will prevent concurrent\ntruncation, fallocation, DIO and other writes) and ictx->wb_lock (which\nwill cause flushing to wait and writeback to skip or wait).\n\nNote that this may be easier to deal with once the queuing of folios is\nsplit from the generation of subrequests."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["fs/netfs/write_issue.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"288ace2f57c9d06dd2e42bd80d03747d879a4068","lessThan":"1468f39243ccb155b6d97f9a9932f610d1205d75","versionType":"git","status":"affected"},{"version":"288ace2f57c9d06dd2e42bd80d03747d879a4068","lessThan":"003aa0dd26c964025acd6d1213bcdbd674db2ca9","versionType":"git","status":"affected"},{"version":"288ace2f57c9d06dd2e42bd80d03747d879a4068","lessThan":"e40e9cbf3ee4d30ee9a97bd128c85500b6ad0da1","versionType":"git","status":"affected"},{"version":"288ace2f57c9d06dd2e42bd80d03747d879a4068","lessThan":"b6a4ae1634b3ad2aaa05222e53d36da532852faf","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["fs/netfs/write_issue.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.10","status":"affected"},{"version":"0","lessThan":"6.10","versionType":"semver","status":"unaffected"},{"version":"6.12.92","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.34","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.0.11","lessThanOrEqual":"7.0.*","versionType":"semver","status":"unaffected"},{"version":"7.1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/003aa0dd26c964025acd6d1213bcdbd674db2ca9","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/1468f39243ccb155b6d97f9a9932f610d1205d75","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/b6a4ae1634b3ad2aaa05222e53d36da532852faf","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/e40e9cbf3ee4d30ee9a97bd128c85500b6ad0da1","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-64063","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-07-19T16:17:46.820","lastModified":"2026-07-19T16:17:46.820","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nnetfs: Fix streaming write being overwritten\n\nIn order to avoid reading whilst writing, netfslib will allow \"streaming\nwrites\" in which dirty data is stored directly into folios without reading\nthem first.  Such folios are marked dirty but may not be marked uptodate.\nIf a folio is entirely written by a streaming write, uptodate will be set,\notherwise it will have a netfs_folio struct attached to ->private recording\nthe dirty region.\n\nIn the event that a partially written streaming write page is to be\noverwritten entirely by a single write(), netfs_perform_write() will try to\ncopy over it, but doesn't discard the netfs_folio if it succeeds; further,\nit doesn't correctly handle a partial copy that overwrites some of the\ndirty data.\n\nFix this by the following:\n\n (1) If the folio is successfully overwritten, free the netfs_folio struct\n     before marking the page uptodate.\n\n (2) If the copy to the folio partially fails, but short of the dirty data,\n     just ignore the copy.\n\n (3) If the copy partially fails and overwrites some of the dirty data,\n     accept the copy, update the netfs_folio struct to record the new data.\n     If the folio is now filled, free the netfs_folio and set uptodate,\n     otherwise return a partial write.\n\nFound with:\n\n\tfsx -q -N 1000000 -p 10000 -o 128000 -l 600000 \\\n\t  /xfstest.test/junk --replay-ops=junk.fsxops\n\nusing the following as junk.fsxops:\n\n\ttruncate 0x0 0 0x927c0\n\twrite 0x63fb8 0x53c8 0\n\tcopy_range 0xb704 0x19b9 0x24429 0x79380\n\twrite 0x2402b 0x144a2 0x90660 *\n\twrite 0x204d5 0x140a0 0x927c0 *\n\tcopy_range 0x1f72c 0x137d0 0x7a906 0x927c0 *\n\tread 0x00000 0x20000 0x9157c\n\tread 0x20000 0x20000 0x9157c\n\tread 0x40000 0x20000 0x9157c\n\tread 0x60000 0x20000 0x9157c\n\tread 0x7e1a0 0xcfb9 0x9157c\n\non cifs with the default cache option.\n\nIt shows folio 0x24 misbehaving if the FMODE_READ check is commented out in\nnetfs_perform_write():\n\n\t\tif (//(file->f_mode & FMODE_READ) ||\n\t\t    netfs_is_cache_enabled(ctx)) {\n\nand no fscache.  This was initially found with the generic/522 xfstest."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["fs/netfs/buffered_write.c","include/trace/events/netfs.h"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"8f52de0077ba3bf41e5d53d67a185700f41efce7","lessThan":"20195925c768626dc901a4781a51e508702c88ad","versionType":"git","status":"affected"},{"version":"8f52de0077ba3bf41e5d53d67a185700f41efce7","lessThan":"ef9b521212e4863814ef7dfe19889abaf55ca840","versionType":"git","status":"affected"},{"version":"8f52de0077ba3bf41e5d53d67a185700f41efce7","lessThan":"cdae00e8e215d95911d95f100599e187b6560de5","versionType":"git","status":"affected"},{"version":"8f52de0077ba3bf41e5d53d67a185700f41efce7","lessThan":"7b4dcf1b9455a6e52ac7478b4057dbe10359576d","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["fs/netfs/buffered_write.c","include/trace/events/netfs.h"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.12","status":"affected"},{"version":"0","lessThan":"6.12","versionType":"semver","status":"unaffected"},{"version":"6.12.92","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.34","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.0.11","lessThanOrEqual":"7.0.*","versionType":"semver","status":"unaffected"},{"version":"7.1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/20195925c768626dc901a4781a51e508702c88ad","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/7b4dcf1b9455a6e52ac7478b4057dbe10359576d","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/cdae00e8e215d95911d95f100599e187b6560de5","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/ef9b521212e4863814ef7dfe19889abaf55ca840","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-64064","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-07-19T16:17:46.937","lastModified":"2026-07-19T16:17:46.937","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nnetfs: Fix netfs_invalidate_folio() to clear dirty bit if all changes gone\n\nIf a streaming write is made, this will leave the relevant modified folio\nin a not-uptodate, but dirty state with a netfs_folio struct hung off of\nfolio->private indicating the dirty range.  Subsequently truncating the\nfile such that the dirty data in the folio is removed, but the first part\nof the folio theoretically remains will cause the netfs_folio struct to be\ndiscarded... but will leave the dirty flag set.\n\nIf the folio is then read via mmap(), netfs_read_folio() will see that the\npage is dirty and jump to netfs_read_gaps() to fill in the missing bits.\nnetfs_read_gaps(), however, expects there to be a netfs_folio struct\npresent and can oops because truncate removed it.\n\nFix this by calling folio_cancel_dirty() in netfs_invalidate_folio() in the\nevent that all the dirty data in the folio is erased (as nfs does).\n\nAlso add some tracepoints to log modifications to a dirty page.\n\nThis can be reproduced with something like:\n\n    dd if=/dev/zero of=/xfstest.test/foo bs=1M count=1\n    umount /xfstest.test\n    mount /xfstest.test\n    xfs_io -c \"w 0xbbbf 0xf96c\" \\\n           -c \"truncate 0xbbbf\" \\\n           -c \"mmap -r 0xb000 0x11000\" \\\n           -c \"mr 0xb000 0x11000\" \\\n           /xfstest.test/foo\n\nwith fscaching disabled (otherwise streaming writes are suppressed) and a\nchange to netfs_perform_write() to disallow streaming writes if the fd is\nopen O_RDWR:\n\n\tif (//(file->f_mode & FMODE_READ) || <--- comment this out\n\t    netfs_is_cache_enabled(ctx)) {\n\nIt should be reproducible even without this change, but if prevents the\nabove trivial xfs_io command from reproducing it.\n\nNote that the initial dd is important: the file must start out sufficiently\nlarge that the zero-point logic doesn't just clear the gaps because it\nknows there's nothing in the file to read yet.  Unmounting and mounting is\nneeded to clear the pagecache (there are other ways to do that that may\nalso work).\n\nThis was initially reproduced with the generic/522 xfstest on some patches\nthat remove the FMODE_READ restriction."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["fs/netfs/misc.c","include/trace/events/netfs.h"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"9ebff83e648148b9ece97d4e4890dd84ca54d6ce","lessThan":"31ba145faceb378fa01afcb8349e15ea7d95e542","versionType":"git","status":"affected"},{"version":"9ebff83e648148b9ece97d4e4890dd84ca54d6ce","lessThan":"fb6ec883b48b8789e5e690dcd440d2db941e840c","versionType":"git","status":"affected"},{"version":"9ebff83e648148b9ece97d4e4890dd84ca54d6ce","lessThan":"65ae8717abf36202fef02260b64b781d2d44a9bf","versionType":"git","status":"affected"},{"version":"9ebff83e648148b9ece97d4e4890dd84ca54d6ce","lessThan":"156ac2ec2ee77c44c4eb7439d6d165247ba12247","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["fs/netfs/misc.c","include/trace/events/netfs.h"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.8","status":"affected"},{"version":"0","lessThan":"6.8","versionType":"semver","status":"unaffected"},{"version":"6.12.92","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.34","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.0.11","lessThanOrEqual":"7.0.*","versionType":"semver","status":"unaffected"},{"version":"7.1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/156ac2ec2ee77c44c4eb7439d6d165247ba12247","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/31ba145faceb378fa01afcb8349e15ea7d95e542","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/65ae8717abf36202fef02260b64b781d2d44a9bf","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/fb6ec883b48b8789e5e690dcd440d2db941e840c","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-64065","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-07-19T16:17:47.053","lastModified":"2026-07-19T16:17:47.053","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nnetfs: fix VM_BUG_ON_FOLIO() issue in netfs_write_begin() call\n\nThe multiple runs of generic/013 test-case is capable\nto reproduce a kernel BUG at mm/filemap.c:1504 with\nprobability of 30%.\n\nwhile true; do\n  sudo ./check generic/013\ndone\n\n[ 9849.452376] page: refcount:3 mapcount:0 mapping:00000000e58ff252 index:0x10781 pfn:0x1c322\n[ 9849.452412] memcg:ffff8881a1915800\n[ 9849.452417] aops:ceph_aops ino:1000058db9e dentry name(?):\"f9XXXXXX\"\n[ 9849.452432] flags: 0x17ffffc0000000(node=0|zone=2|lastcpupid=0x1fffff)\n[ 9849.452441] raw: 0017ffffc0000000 0000000000000000 dead000000000122 ffff88816110d248\n[ 9849.452445] raw: 0000000000010781 0000000000000000 00000003ffffffff ffff8881a1915800\n[ 9849.452447] page dumped because: VM_BUG_ON_FOLIO(!folio_test_locked(folio))\n[ 9849.452474] ------------[ cut here ]------------\n[ 9849.452476] kernel BUG at mm/filemap.c:1504!\n[ 9849.478635] Oops: invalid opcode: 0000 [#1] SMP KASAN NOPTI\n[ 9849.481772] CPU: 2 UID: 0 PID: 84223 Comm: fsstress Not tainted 7.0.0-rc1+ #18 PREEMPT(full)\n[ 9849.482881] Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS 1.17.0-9.fc43 06/1\n0/2025\n[ 9849.484539] RIP: 0010:folio_unlock+0x85/0xa0\n[ 9849.485076] Code: 89 df 31 f6 e8 1c f3 ff ff 48 8b 5d f8 c9 31 c0 31 d2 31 f6 31 ff c3 cc\ncc cc cc 48 c7 c6 80 6c d9 a7 48 89 df e8 4b b3 10 00 <0f> 0b 48 89 df e8 21 e6 2c 00 eb 9d 0f 1f 40 00 66 66 2e 0f 1f 84\n[ 9849.493818] RSP: 0018:ffff8881bb8076b0 EFLAGS: 00010246\n[ 9849.495740] RAX: 0000000000000000 RBX: ffffea00070c8980 RCX: 0000000000000000\n[ 9849.498678] RDX: 0000000000000000 RSI: 0000000000000000 RDI: 0000000000000000\n[ 9849.500559] RBP: ffff8881bb8076b8 R08: 0000000000000000 R09: 0000000000000000\n[ 9849.501097] R10: 0000000000000000 R11: 0000000000000000 R12: 0000000010782000\n[ 9849.502108] R13: ffff8881935de738 R14: ffff88816110d010 R15: 0000000000001000\n[ 9849.502516] FS:  00007e36cbe94740(0000) GS:ffff88824a899000(0000) knlGS:0000000000000000\n[ 9849.502996] CS:  0010 DS: 0000 ES: 0000 CR0: 0000000080050033\n[ 9849.503810] CR2: 000000c0002b0000 CR3: 000000011bbf6004 CR4: 0000000000772ef0\n[ 9849.504459] PKRU: 55555554\n[ 9849.504626] Call Trace:\n[ 9849.505242]  <TASK>\n[ 9849.505379]  netfs_write_begin+0x7c8/0x10a0\n[ 9849.505877]  ? __kasan_check_read+0x11/0x20\n[ 9849.506384]  ? __pfx_netfs_write_begin+0x10/0x10\n[ 9849.507178]  ceph_write_begin+0x8c/0x1c0\n[ 9849.507934]  generic_perform_write+0x391/0x8f0\n[ 9849.508503]  ? __pfx_generic_perform_write+0x10/0x10\n[ 9849.509062]  ? file_update_time_flags+0x19a/0x4b0\n[ 9849.509581]  ? ceph_get_caps+0x63/0xf0\n[ 9849.510259]  ? ceph_get_caps+0x63/0xf0\n[ 9849.510530]  ceph_write_iter+0xe79/0x1ae0\n[ 9849.511282]  ? __pfx_ceph_write_iter+0x10/0x10\n[ 9849.511839]  ? lock_acquire+0x1ad/0x310\n[ 9849.512334]  ? ksys_write+0xf9/0x230\n[ 9849.512582]  ? lock_is_held_type+0xaa/0x140\n[ 9849.513128]  vfs_write+0x512/0x1110\n[ 9849.513634]  ? __fget_files+0x33/0x350\n[ 9849.513893]  ? __pfx_vfs_write+0x10/0x10\n[ 9849.514143]  ? mutex_lock_nested+0x1b/0x30\n[ 9849.514394]  ksys_write+0xf9/0x230\n[ 9849.514621]  ? __pfx_ksys_write+0x10/0x10\n[ 9849.514887]  ? do_syscall_64+0x25e/0x1520\n[ 9849.515122]  ? __kasan_check_read+0x11/0x20\n[ 9849.515366]  ? trace_hardirqs_on_prepare+0x178/0x1c0\n[ 9849.515655]  __x64_sys_write+0x72/0xd0\n[ 9849.515885]  ? trace_hardirqs_on+0x24/0x1c0\n[ 9849.516130]  x64_sys_call+0x22f/0x2390\n[ 9849.516341]  do_syscall_64+0x12b/0x1520\n[ 9849.516545]  ? do_syscall_64+0x27c/0x1520\n[ 9849.516783]  ? do_syscall_64+0x27c/0x1520\n[ 9849.517003]  ? lock_release+0x318/0x480\n[ 9849.517220]  ? __x64_sys_io_getevents+0x143/0x2d0\n[ 9849.517479]  ? percpu_ref_put_many.constprop.0+0x8f/0x210\n[ 9849.517779]  ? entry_SYSCALL_64_after_hwframe+0x76/0x7e\n[ 9849.518073]  ? do_syscall_64+0x25e/0x1520\n[ 9849.518291]  ? __kasan_check_read+0x11/0x20\n[ 9849.518519]  ? trace_hardirqs_on_prepare+0x178/0x1c0\n[ 9849.518799]  ? do_syscall_64+0x27c/0x1520\n[ 9\n---truncated---"}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["fs/netfs/read_retry.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"ee4cdf7ba857a894ad1650d6ab77669cbbfa329e","lessThan":"51ffb788f074c0a61953086f49008028c1e7b645","versionType":"git","status":"affected"},{"version":"ee4cdf7ba857a894ad1650d6ab77669cbbfa329e","lessThan":"b63971238beb79cf701dac33c6cefc56c07c89fa","versionType":"git","status":"affected"},{"version":"ee4cdf7ba857a894ad1650d6ab77669cbbfa329e","lessThan":"5ad05b6f5df296ef046589f222bb2587495b991e","versionType":"git","status":"affected"},{"version":"ee4cdf7ba857a894ad1650d6ab77669cbbfa329e","lessThan":"dc7832d05deb4d632e8035e3299e31a3528fa0d0","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["fs/netfs/read_retry.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.12","status":"affected"},{"version":"0","lessThan":"6.12","versionType":"semver","status":"unaffected"},{"version":"6.12.92","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.34","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.0.11","lessThanOrEqual":"7.0.*","versionType":"semver","status":"unaffected"},{"version":"7.1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/51ffb788f074c0a61953086f49008028c1e7b645","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/5ad05b6f5df296ef046589f222bb2587495b991e","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/b63971238beb79cf701dac33c6cefc56c07c89fa","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/dc7832d05deb4d632e8035e3299e31a3528fa0d0","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-64070","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-07-19T16:17:47.583","lastModified":"2026-07-19T16:17:47.583","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\npowerpc/hv-gpci: fix preempt count leak in sysfs show paths\n\nFour sysfs show() callbacks in hv-gpci take get_cpu_var(hv_gpci_reqb)\n(which calls preempt_disable()) but only call the matching put_cpu_var()\non the error path under the 'out:' label. Every successful read leaks\none preempt_disable():\n\n  processor_bus_topology_show()\n  processor_config_show()\n  affinity_domain_via_virtual_processor_show()\n  affinity_domain_via_domain_show()\n\n(affinity_domain_via_partition_show() was already correct.)\n\nOn a CONFIG_PREEMPT=y kernel, repeated reads raise preempt_count and\neventually return to userspace with preemption still disabled. The\nnext user-mode page fault then hits faulthandler_disabled() == 1,\ngets forced to SIGSEGV, and the resulting coredump trips\n'BUG: scheduling while atomic' in call_usermodehelper_exec ->\nwait_for_completion_state -> schedule:\n\n  BUG: scheduling while atomic: <task>/<pid>/0x00000004\n  ...\n  __schedule_bug+0x6c/0x90\n  __schedule+0x58c/0x13a0\n  schedule+0x48/0x1a0\n  schedule_timeout+0x104/0x170\n  wait_for_completion_state+0x16c/0x330\n  call_usermodehelper_exec+0x254/0x2d0\n  vfs_coredump+0x1050/0x2590\n  get_signal+0xb9c/0xc80\n  do_notify_resume+0xf8/0x470\n\nAdd an out_success label that calls put_cpu_var() before returning\nthe byte count, mirroring affinity_domain_via_partition_show()."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["arch/powerpc/perf/hv-gpci.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"71f1c39647d8c9d4d54a861ec81f1ff17544bcb6","lessThan":"903409000a07ac8e31ffedeb8516f4f8d67150c8","versionType":"git","status":"affected"},{"version":"71f1c39647d8c9d4d54a861ec81f1ff17544bcb6","lessThan":"dbc30a57bd8e026995e9fa8e8c31cffd18542c01","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["arch/powerpc/perf/hv-gpci.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.6","status":"affected"},{"version":"0","lessThan":"6.6","versionType":"semver","status":"unaffected"},{"version":"7.0.11","lessThanOrEqual":"7.0.*","versionType":"semver","status":"unaffected"},{"version":"7.1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/903409000a07ac8e31ffedeb8516f4f8d67150c8","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/dbc30a57bd8e026995e9fa8e8c31cffd18542c01","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-64071","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-07-19T16:17:47.687","lastModified":"2026-07-19T16:17:47.687","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nnvme-pci: fix use-after-free in nvme_free_host_mem()\n\nnvme_free_host_mem() frees dev->hmb_sgt via dma_free_noncontiguous()\nbut never clears the pointer afterward.  This leads to a use-after-free\nif nvme_free_host_mem() is called twice in the same error path.\n\nThis can happen during nvme_probe() when nvme_setup_host_mem() succeeds\nin allocating the HMB (setting dev->hmb_sgt) but nvme_set_host_mem()\nfails with an I/O error:\n\n  nvme_setup_host_mem()\n    nvme_alloc_host_mem_single()   -> sets dev->hmb_sgt\n    nvme_set_host_mem()            -> fails with -EIO\n    nvme_free_host_mem()           -> frees hmb_sgt, but does NOT NULL it\n    return error\n\n  nvme_probe() error path:\n    nvme_free_host_mem()           -> dev->hmb_sgt is stale, use-after-free\n\nThe second call dereferences the freed sgt, causing a NULL pointer\ndereference in iommu_dma_free_noncontiguous() when it accesses\nsgt->sgl->dma_address (the backing memory has been freed and zeroed).\n\nThis is reproducible on Thunderbolt-attached NVMe devices (e.g., OWC\nEnvoy Express behind a Dell WD22TB4 dock) where the device intermittently\nreturns I/O errors during HMB setup due to PCIe link instability.\n\n BUG: kernel NULL pointer dereference, address: 0000000000000010\n RIP: 0010:iommu_dma_free_noncontiguous+0x22/0x80\n Call Trace:\n  <TASK>\n  dma_free_noncontiguous+0x3b/0x130\n  nvme_free_host_mem+0x30/0xf0 [nvme]\n  nvme_probe.cold+0xcc/0x275 [nvme]\n  local_pci_probe+0x43/0xa0\n  pci_device_probe+0xeea/0x290\n  really_probe+0xf9/0x3b0\n  __driver_probe_device+0x8b/0x170\n  driver_probe_device+0x24/0xd0\n  __driver_attach_async_helper+0x6b/0x110\n  async_run_entry_fn+0x37/0x170\n  process_one_work+0x1ac/0x3d0\n  worker_thread+0x1b8/0x360\n  kthread+0xf7/0x130\n  ret_from_fork+0x2d8/0x3a0\n  ret_from_fork_asm+0x1a/0x30\n  </TASK>\n\nFix this by setting dev->hmb_sgt to NULL after freeing it, so the\nsecond call takes the multi-descriptor path which safely handles the\nalready-cleaned-up state."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/nvme/host/pci.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"63a5c7a4b4c49ad86c362e9f555e6f343804ee1d","lessThan":"9525e3a6fbb1d126a22ab2ee86ddea25af581a7c","versionType":"git","status":"affected"},{"version":"63a5c7a4b4c49ad86c362e9f555e6f343804ee1d","lessThan":"7c89f474005d8377525d2991930b7432ee193a52","versionType":"git","status":"affected"},{"version":"63a5c7a4b4c49ad86c362e9f555e6f343804ee1d","lessThan":"b35a13036755c5803168a7cb93bc66035c3e65b8","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/nvme/host/pci.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.13","status":"affected"},{"version":"0","lessThan":"6.13","versionType":"semver","status":"unaffected"},{"version":"6.18.34","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.0.11","lessThanOrEqual":"7.0.*","versionType":"semver","status":"unaffected"},{"version":"7.1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/7c89f474005d8377525d2991930b7432ee193a52","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/9525e3a6fbb1d126a22ab2ee86ddea25af581a7c","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/b35a13036755c5803168a7cb93bc66035c3e65b8","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-64072","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-07-19T16:17:47.793","lastModified":"2026-07-19T16:17:47.793","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nnvme: fix bio leak on mapping failure\n\nThe local bio is always NULL, so we'd leak the bio if the integrity\nmapping failed. Just get it directly from the request."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/nvme/host/ioctl.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"d0d1d522316e91f2b935a78bbf962b8e529d8c4f","lessThan":"fea4b46f84c50caf93c6c0f2a54b1be2edfb4491","versionType":"git","status":"affected"},{"version":"d0d1d522316e91f2b935a78bbf962b8e529d8c4f","lessThan":"51ec7fc4e10c5e332bf4007bdb7e4c6bf03c14c9","versionType":"git","status":"affected"},{"version":"d0d1d522316e91f2b935a78bbf962b8e529d8c4f","lessThan":"2279cd9c61a330e5de4d6eb0bc422820dd6fdf36","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/nvme/host/ioctl.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.18","status":"affected"},{"version":"0","lessThan":"6.18","versionType":"semver","status":"unaffected"},{"version":"6.18.34","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.0.11","lessThanOrEqual":"7.0.*","versionType":"semver","status":"unaffected"},{"version":"7.1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/2279cd9c61a330e5de4d6eb0bc422820dd6fdf36","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/51ec7fc4e10c5e332bf4007bdb7e4c6bf03c14c9","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/fea4b46f84c50caf93c6c0f2a54b1be2edfb4491","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-64075","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-07-19T16:17:48.113","lastModified":"2026-07-19T16:17:48.113","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nfprobe: Fix unregister_fprobe() to wait for RCU grace period\n\nCommit 4346ba1604093 (\"fprobe: Rewrite fprobe on function-graph tracer\")\nchanged fprobe to register struct fprobe to an rcu-hlist, but it forgot\nto wait for RCU GP. Thus there can be use-after-free if the fprobe is\nreleased right after unregistering. This can be happened on fprobe\nevent and sample module code.\n\nTo fix this issue, add synchronize_rcu() in unregister_fprobe().\n\nNote that BPF is OK because fprobe is used as a part of\nbpf_kprobe_multi_link. This unregisters its fprobe in\nbpf_kprobe_multi_link_release() and it is deallocated via\nbpf_kprobe_multi_link_dealloc(), which is invoked from\nbpf_link_defer_dealloc_rcu_gp() RCU callback.\n\nFor BPF, this also introduced unregister_fprobe_async() which does\nNOT wait for RCU grace priod."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["include/linux/fprobe.h","kernel/trace/bpf_trace.c","kernel/trace/fprobe.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"4346ba1604093305a287e08eb465a9c15ba05b80","lessThan":"56b4cfcf1518245493c60fd39c56978f508f1816","versionType":"git","status":"affected"},{"version":"4346ba1604093305a287e08eb465a9c15ba05b80","lessThan":"a4f6a9005ed6cfd360ef2520430927f05f92ffb0","versionType":"git","status":"affected"},{"version":"4346ba1604093305a287e08eb465a9c15ba05b80","lessThan":"657b594b2084b39a4bc6d8493aa2140cb00cea49","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["include/linux/fprobe.h","kernel/trace/bpf_trace.c","kernel/trace/fprobe.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.14","status":"affected"},{"version":"0","lessThan":"6.14","versionType":"semver","status":"unaffected"},{"version":"6.18.34","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.0.11","lessThanOrEqual":"7.0.*","versionType":"semver","status":"unaffected"},{"version":"7.1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/56b4cfcf1518245493c60fd39c56978f508f1816","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/657b594b2084b39a4bc6d8493aa2140cb00cea49","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/a4f6a9005ed6cfd360ef2520430927f05f92ffb0","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-64079","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-07-19T16:17:48.503","lastModified":"2026-07-19T16:17:48.503","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nnetfilter: x_tables: allocate hook ops while under mutex\n\narp/ip(6)t_register_table() add the table to the per-netns list via\nxt_register_table() before allocating the per-netns hook ops copy\nvia kmemdup_array().  This leaves a window where the table is\nvisible in the list with ops=NULL.\n\nIf the pernet exit happens runs concurrently the pre_exit callback finds\nthe table via xt_find_table() and passes the NULL ops pointer to\nnf_unregister_net_hooks(), causing a NULL dereference:\n\n  general protection fault in nf_unregister_net_hooks+0xbc/0x150\n  RIP: nf_unregister_net_hooks (net/netfilter/core.c:613)\n  Call Trace:\n    ipt_unregister_table_pre_exit\n    iptable_mangle_net_pre_exit\n    ops_pre_exit_list\n    cleanup_net\n\nFix by moving the ops allocation into the xtables core so the table is\nnever in the list without valid ops.  Also ensure the table is no longer\nprocessing packets before its torn down on error unwind.\nnf_register_net_hooks might have published at least one hook; call\nsynchronize_rcu() if there was an error.\n\naudit log register message gets deferred until all operations have\npassed, this avoids need to emit another ureg message in case of\nerror unwinding.\n\nBased on earlier patch by Tristan Madani."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["include/linux/netfilter/x_tables.h","net/ipv4/netfilter/arp_tables.c","net/ipv4/netfilter/ip_tables.c","net/ipv6/netfilter/ip6_tables.c","net/netfilter/x_tables.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"ae689334225ff0e4ef112459ecd24aea932c2b00","lessThan":"2f92c5f923979f37ab1d5445381e4b8378a196cc","versionType":"git","status":"affected"},{"version":"ae689334225ff0e4ef112459ecd24aea932c2b00","lessThan":"b62eb8dcf2c47d4d676a434efbd57c4f776f7829","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["include/linux/netfilter/x_tables.h","net/ipv4/netfilter/arp_tables.c","net/ipv4/netfilter/ip_tables.c","net/ipv6/netfilter/ip6_tables.c","net/netfilter/x_tables.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"5.13","status":"affected"},{"version":"0","lessThan":"5.13","versionType":"semver","status":"unaffected"},{"version":"7.0.11","lessThanOrEqual":"7.0.*","versionType":"semver","status":"unaffected"},{"version":"7.1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/2f92c5f923979f37ab1d5445381e4b8378a196cc","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/b62eb8dcf2c47d4d676a434efbd57c4f776f7829","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-64083","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-07-19T16:17:48.910","lastModified":"2026-07-19T16:17:48.910","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nhwmon: (pmbus/adm1266) reject short block-read responses in the GPIO accessors\n\nadm1266_gpio_get() and adm1266_gpio_get_multiple() both compose the\npin-status word as\n\n\tpins_status = read_buf[0] + (read_buf[1] << 8);\n\nright after i2c_smbus_read_block_data(), guarding only against an\nerror return.  A well-behaved device returns 2 bytes for\nGPIO_STATUS/PDIO_STATUS, but the helper happily reports a 0- or\n1-byte response too.  If the device returns 0 bytes, both read_buf\nslots are uninitialized stack memory; if it returns 1 byte, read_buf[1]\nis.\n\nThe composed value then flows through set_bit() into the caller's\n*bits in adm1266_gpio_get_multiple(), or into the return value of\nadm1266_gpio_get(), and ends up in userspace via gpiolib (sysfs and\nthe char-dev ioctls).  That leaks a few bits of kernel stack per\nrequest on any device whose firmware glitch, bus error, or hostile\nslave produces a short block-read response.\n\nAdd the missing length check to both call sites and surface a short\nresponse as -EIO."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/hwmon/pmbus/adm1266.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"d98dfad35c38c037b37c4adc99df01da571031a5","lessThan":"fd9196aad9e5a3845cea17de3405ebc700382142","versionType":"git","status":"affected"},{"version":"d98dfad35c38c037b37c4adc99df01da571031a5","lessThan":"ee4799becf7d2af3778007e22c2e55c4009a49c7","versionType":"git","status":"affected"},{"version":"d98dfad35c38c037b37c4adc99df01da571031a5","lessThan":"c603b6c6840ac0c6285f5eefea0de6242710af21","versionType":"git","status":"affected"},{"version":"d98dfad35c38c037b37c4adc99df01da571031a5","lessThan":"a2d1c819348b36fccbbfcf37c5fa7a50a9b4528f","versionType":"git","status":"affected"},{"version":"d98dfad35c38c037b37c4adc99df01da571031a5","lessThan":"ae25cf2ea9ebd06d7ad416647dbdc7b5d0172946","versionType":"git","status":"affected"},{"version":"d98dfad35c38c037b37c4adc99df01da571031a5","lessThan":"eb3cd9bb590460c6127145cb245be925d23f5232","versionType":"git","status":"affected"},{"version":"d98dfad35c38c037b37c4adc99df01da571031a5","lessThan":"64fa9328948ddcc0f7f3c23ea1756c126d9dffac","versionType":"git","status":"affected"},{"version":"d98dfad35c38c037b37c4adc99df01da571031a5","lessThan":"a7232f68c43ca62f545049b7f5fbfc75137b843b","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/hwmon/pmbus/adm1266.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"5.10","status":"affected"},{"version":"0","lessThan":"5.10","versionType":"semver","status":"unaffected"},{"version":"5.10.258","lessThanOrEqual":"5.10.*","versionType":"semver","status":"unaffected"},{"version":"5.15.209","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.175","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.142","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.92","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.34","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.0.11","lessThanOrEqual":"7.0.*","versionType":"semver","status":"unaffected"},{"version":"7.1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/64fa9328948ddcc0f7f3c23ea1756c126d9dffac","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/a2d1c819348b36fccbbfcf37c5fa7a50a9b4528f","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/a7232f68c43ca62f545049b7f5fbfc75137b843b","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/ae25cf2ea9ebd06d7ad416647dbdc7b5d0172946","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/c603b6c6840ac0c6285f5eefea0de6242710af21","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/eb3cd9bb590460c6127145cb245be925d23f5232","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/ee4799becf7d2af3778007e22c2e55c4009a49c7","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/fd9196aad9e5a3845cea17de3405ebc700382142","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-64085","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-07-19T16:17:49.173","lastModified":"2026-07-19T16:17:49.173","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nhwmon: (pmbus/adm1266) bounce blackbox records through a protocol-sized buffer\n\nadm1266_pmbus_block_xfer() copies the device-supplied block payload\ninto the caller-provided buffer using the device-supplied length:\n\n\tmemcpy(data_r, &msgs[1].buf[1], msgs[1].buf[0]);\n\nThe helper does not know how large data_r is and trusts the device to\nreturn at most one record's worth of bytes.  adm1266_nvmem_read_blackbox()\nviolates that contract: it advances read_buff inside data->dev_mem in\nADM1266_BLACKBOX_SIZE (64-byte) strides while the helper is willing to\nwrite up to ADM1266_PMBUS_BLOCK_MAX (255) bytes.  A device that returns\nmore than 64 bytes on the trailing record (read_buff offset 1984 in\nthe 2048-byte dev_mem allocation) overflows dev_mem by up to 191 bytes\nbefore the post-call\n\n\tif (ret != ADM1266_BLACKBOX_SIZE)\n\t\treturn -EIO;\n\ncan reject the response.\n\nContain the fix in the caller without changing the helper signature:\nread each record into a 255-byte local bounce buffer that matches the\nhelper's maximum output, validate the returned length, and only then\ncopy exactly ADM1266_BLACKBOX_SIZE bytes into the dev_mem slot."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/hwmon/pmbus/adm1266.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"407dc802a9c0809ca6a48de4b4c63305eb84ef56","lessThan":"7896d87cbb05e097efc113243d4e38f9f8cea16c","versionType":"git","status":"affected"},{"version":"407dc802a9c0809ca6a48de4b4c63305eb84ef56","lessThan":"9d5309500b4607b7198e19f0a3fa13eb864cd5fb","versionType":"git","status":"affected"},{"version":"407dc802a9c0809ca6a48de4b4c63305eb84ef56","lessThan":"6098634cfa711f11a8d65368dc51ec8f7c8241ba","versionType":"git","status":"affected"},{"version":"407dc802a9c0809ca6a48de4b4c63305eb84ef56","lessThan":"60c4b9fe1a3dd012014b1f561a6928a0b5db1126","versionType":"git","status":"affected"},{"version":"407dc802a9c0809ca6a48de4b4c63305eb84ef56","lessThan":"83e039f0a43e0708515b0479cb7690fb93faaaa0","versionType":"git","status":"affected"},{"version":"407dc802a9c0809ca6a48de4b4c63305eb84ef56","lessThan":"97a9cf2a8217ca1cdaf48cb9ab26e471632c7e7f","versionType":"git","status":"affected"},{"version":"407dc802a9c0809ca6a48de4b4c63305eb84ef56","lessThan":"dd47b8c4a0a8ced442da3f008db28fbbd31feaf0","versionType":"git","status":"affected"},{"version":"407dc802a9c0809ca6a48de4b4c63305eb84ef56","lessThan":"43cae21424ff8e33894a0f86c6b80b840c049fd7","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/hwmon/pmbus/adm1266.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"5.10","status":"affected"},{"version":"0","lessThan":"5.10","versionType":"semver","status":"unaffected"},{"version":"5.10.258","lessThanOrEqual":"5.10.*","versionType":"semver","status":"unaffected"},{"version":"5.15.209","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.175","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.142","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.92","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.34","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.0.11","lessThanOrEqual":"7.0.*","versionType":"semver","status":"unaffected"},{"version":"7.1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/43cae21424ff8e33894a0f86c6b80b840c049fd7","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/6098634cfa711f11a8d65368dc51ec8f7c8241ba","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/60c4b9fe1a3dd012014b1f561a6928a0b5db1126","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/7896d87cbb05e097efc113243d4e38f9f8cea16c","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/83e039f0a43e0708515b0479cb7690fb93faaaa0","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/97a9cf2a8217ca1cdaf48cb9ab26e471632c7e7f","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/9d5309500b4607b7198e19f0a3fa13eb864cd5fb","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/dd47b8c4a0a8ced442da3f008db28fbbd31feaf0","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-64087","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-07-19T16:17:49.433","lastModified":"2026-07-19T16:17:49.433","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nhwmon: (pmbus/adm1266) reject implausible blackbox record_count\n\nadm1266_nvmem_read_blackbox() loops over a record_count that comes\nstraight from byte 3 of the BLACKBOX_INFO response.  The destination\nbuffer is data->dev_mem, sized for the nvmem cell's declared 2048\nbytes (ADM1266_BLACKBOX_MAX_RECORDS * ADM1266_BLACKBOX_SIZE = 32 * 64).\nA device that reports a record_count greater than 32 -- whether due\nto firmware bugs, bus corruption, or a non-responsive slave returning\n0xff -- would walk read_buff past the end of the dev_mem allocation\non the trailing iterations.\n\nCap record_count at ADM1266_BLACKBOX_MAX_RECORDS (introduced here)\nbefore entering the loop and return -EIO on any larger value, so a\nmalformed BLACKBOX_INFO response cannot drive the loop out of bounds."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/hwmon/pmbus/adm1266.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"15609d1893020436e1e8ccfd9ded774a96dd17a2","lessThan":"adcb163ad7cacca317872fc62bd8885e842e45e3","versionType":"git","status":"affected"},{"version":"15609d1893020436e1e8ccfd9ded774a96dd17a2","lessThan":"c2c56092710fe8a893b67b5a3d7e62808d02d84d","versionType":"git","status":"affected"},{"version":"15609d1893020436e1e8ccfd9ded774a96dd17a2","lessThan":"5469e1e7c411acc15fdd8262c99c3ebd9defd594","versionType":"git","status":"affected"},{"version":"15609d1893020436e1e8ccfd9ded774a96dd17a2","lessThan":"f85c81e93dbd6915970bd5f3bffcf62633c4c54c","versionType":"git","status":"affected"},{"version":"15609d1893020436e1e8ccfd9ded774a96dd17a2","lessThan":"0e791cd0140fb136083565aadfbe0f705aa260d0","versionType":"git","status":"affected"},{"version":"15609d1893020436e1e8ccfd9ded774a96dd17a2","lessThan":"75c862adf3d3caab4f49bb3530723c215376e37c","versionType":"git","status":"affected"},{"version":"15609d1893020436e1e8ccfd9ded774a96dd17a2","lessThan":"231db52a5b64d0a9769e298dadc148e1f79b26a6","versionType":"git","status":"affected"},{"version":"15609d1893020436e1e8ccfd9ded774a96dd17a2","lessThan":"4afca954622d672ea65ed961bed01cf91caa034e","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/hwmon/pmbus/adm1266.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"5.10","status":"affected"},{"version":"0","lessThan":"5.10","versionType":"semver","status":"unaffected"},{"version":"5.10.258","lessThanOrEqual":"5.10.*","versionType":"semver","status":"unaffected"},{"version":"5.15.209","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.175","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.142","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.92","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.34","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.0.11","lessThanOrEqual":"7.0.*","versionType":"semver","status":"unaffected"},{"version":"7.1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/0e791cd0140fb136083565aadfbe0f705aa260d0","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/231db52a5b64d0a9769e298dadc148e1f79b26a6","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/4afca954622d672ea65ed961bed01cf91caa034e","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/5469e1e7c411acc15fdd8262c99c3ebd9defd594","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/75c862adf3d3caab4f49bb3530723c215376e37c","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/adcb163ad7cacca317872fc62bd8885e842e45e3","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/c2c56092710fe8a893b67b5a3d7e62808d02d84d","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/f85c81e93dbd6915970bd5f3bffcf62633c4c54c","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-64090","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-07-19T16:17:49.837","lastModified":"2026-07-19T16:17:49.837","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nbatman-adv: tt: avoid empty VLAN responses\n\nThe commit 16116dac2339 (\"batman-adv: prevent TT request storms by not\nsending inconsistent TT TLVLs\") added checks to the local (direct) TT\nresponse code. But the response can also be done indirectly by another node\nusing the global TT state. To avoid such inconsistency states reported in\nthe original fix, also avoid sending empty VLANs for replies from the\nglobal TT state."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["net/batman-adv/translation-table.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"7ea7b4a142758deaf46c1af0ca9ceca6dd55138b","lessThan":"1f467d9a095211d3f77e8ff1bee90e73ffe01c64","versionType":"git","status":"affected"},{"version":"7ea7b4a142758deaf46c1af0ca9ceca6dd55138b","lessThan":"9a02c8fc963ddeecb5d8788be0740c1869fc54b7","versionType":"git","status":"affected"},{"version":"7ea7b4a142758deaf46c1af0ca9ceca6dd55138b","lessThan":"ea4f757641430bcc8322772e161453c4db5ecb64","versionType":"git","status":"affected"},{"version":"7ea7b4a142758deaf46c1af0ca9ceca6dd55138b","lessThan":"99f17d1cdb371cbd037975239b321f346d38f6d2","versionType":"git","status":"affected"},{"version":"7ea7b4a142758deaf46c1af0ca9ceca6dd55138b","lessThan":"cfb30645280a2131e46cbd1b9a38cfd3ff893f12","versionType":"git","status":"affected"},{"version":"7ea7b4a142758deaf46c1af0ca9ceca6dd55138b","lessThan":"b93ca6012712ecab2b551e120d7c95038d6a89e5","versionType":"git","status":"affected"},{"version":"7ea7b4a142758deaf46c1af0ca9ceca6dd55138b","lessThan":"ab26e346322648f5c39de017d9723c9256284fce","versionType":"git","status":"affected"},{"version":"7ea7b4a142758deaf46c1af0ca9ceca6dd55138b","lessThan":"fa1bd704940b5bcbc32c0b28db9167405c8ee5e0","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["net/batman-adv/translation-table.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"3.13","status":"affected"},{"version":"0","lessThan":"3.13","versionType":"semver","status":"unaffected"},{"version":"5.10.259","lessThanOrEqual":"5.10.*","versionType":"semver","status":"unaffected"},{"version":"5.15.210","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.176","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.143","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.93","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.34","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.0.11","lessThanOrEqual":"7.0.*","versionType":"semver","status":"unaffected"},{"version":"7.1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/1f467d9a095211d3f77e8ff1bee90e73ffe01c64","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/99f17d1cdb371cbd037975239b321f346d38f6d2","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/9a02c8fc963ddeecb5d8788be0740c1869fc54b7","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/ab26e346322648f5c39de017d9723c9256284fce","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/b93ca6012712ecab2b551e120d7c95038d6a89e5","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/cfb30645280a2131e46cbd1b9a38cfd3ff893f12","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/ea4f757641430bcc8322772e161453c4db5ecb64","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/fa1bd704940b5bcbc32c0b28db9167405c8ee5e0","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-64092","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-07-19T16:17:50.110","lastModified":"2026-07-19T16:17:50.110","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nbatman-adv: tp_meter: fix tp_vars reference leak in receiver shutdown\n\nThe receiver shutdown timer handler, batadv_tp_receiver_shutdown(), is\nresponsible for releasing the tp_vars reference it holds. However, the\nexisting logic for coordinating this release with batadv_tp_stop_all() was\nflawed.\n\ntimer_shutdown_sync() guarantees the timer will not fire again after it\nreturns, but it returns non-zero only when the timer was pending at the\ntime of the call. If the timer had already expired (and\nbatadv_tp_stop_all() would unsucessfully try to  rearm itself),\nbatadv_tp_stop_all() skips its batadv_tp_vars_put(), and\nbatadv_tp_receiver_shutdown() fails to put its own reference as well.\n\nFix this by introducing a new atomic variable receiving that is set to 1\nwhen the receiver is initialized and cleared atomically with atomic_xchg()\nby whichever side claims it first. Only the side that observes the\ntransition from 1 to 0 is responsible for releasing the tp_vars timer\nreference, eliminating the uncertainty."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["net/batman-adv/tp_meter.c","net/batman-adv/types.h"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"268078acae72daa12b17b2b299701cb9924e469a","lessThan":"7715c73f33260af724d734c41b794457e9be8dbc","versionType":"git","status":"affected"},{"version":"58943b7ea356294749dae3e75b96c0ee292c00be","lessThan":"297e1bc4a915b7cd3e65a79ed906b23fb3d7aaae","versionType":"git","status":"affected"},{"version":"79bc0eaeef2c5797317bf2da8e3159a74d62ec47","lessThan":"0b1bedf114ea93fef929b31f0d70a9eedcc601de","versionType":"git","status":"affected"},{"version":"26dfeee8db81354bfdade155f27f9e16510ad196","lessThan":"a9f0bfd624ee8a286d6fd2bf0f796e730efb49b0","versionType":"git","status":"affected"},{"version":"03660dab86f93319178a24667f6998526dc4355d","lessThan":"b285bc0a97f43823a4967fb6d286de4c7f53d541","versionType":"git","status":"affected"},{"version":"8634c1dbd73adb74d40533ebb7e914efb82e71fb","lessThan":"d078501dde9b57210f1808cdef4b59463d1f5fc8","versionType":"git","status":"affected"},{"version":"3d3cf6a7314aca4df0a6dde28ce784a2a30d0166","lessThan":"77098e4bea37af51d3962efa88a5af2ea5e1ac57","versionType":"git","status":"affected"},{"version":"5e7d0ac936354c36810e74ac3056b334ed1f4058","versionType":"git","status":"affected"},{"version":"5.10.259","lessThan":"5.11","versionType":"semver","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["net/batman-adv/tp_meter.c","net/batman-adv/types.h"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.6.140","lessThan":"6.6.142","versionType":"semver","status":"affected"},{"version":"6.12.90","lessThan":"6.12.92","versionType":"semver","status":"affected"},{"version":"6.18.32","lessThan":"6.18.34","versionType":"semver","status":"affected"},{"version":"7.0.9","lessThan":"7.0.11","versionType":"semver","status":"affected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/0b1bedf114ea93fef929b31f0d70a9eedcc601de","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/297e1bc4a915b7cd3e65a79ed906b23fb3d7aaae","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/77098e4bea37af51d3962efa88a5af2ea5e1ac57","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/7715c73f33260af724d734c41b794457e9be8dbc","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/a9f0bfd624ee8a286d6fd2bf0f796e730efb49b0","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/b285bc0a97f43823a4967fb6d286de4c7f53d541","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/d078501dde9b57210f1808cdef4b59463d1f5fc8","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-64094","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-07-19T16:17:50.353","lastModified":"2026-07-19T16:17:50.353","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nbatman-adv: bla: avoid NULL-ptr deref for claim via dropped interface\n\nWithout rtnl_lock held, a hardif might be retrieved as primary interface of\na meshif, but then (while operating on this interface) getting decoupled\nfrom the mesh interface. In this case, the meshif still exists but the\npointer from the primary hardif to the meshif is set to NULL.\n\nThe mesh_iface must be checked first to be non-NULL before continuing to\nsend an ARP request using meshif."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["net/batman-adv/bridge_loop_avoidance.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"23721387c409087fd3b97e274f34d3ddc0970b74","lessThan":"4f6266735a0ba6a568b6d4c9fa51c33a5a7f2d70","versionType":"git","status":"affected"},{"version":"23721387c409087fd3b97e274f34d3ddc0970b74","lessThan":"53cb3511f6eda37d3bd923545fdba6013b6d7bb7","versionType":"git","status":"affected"},{"version":"23721387c409087fd3b97e274f34d3ddc0970b74","lessThan":"efb62458c94db1fe3a287e7e89c31b0cfb03f938","versionType":"git","status":"affected"},{"version":"23721387c409087fd3b97e274f34d3ddc0970b74","lessThan":"2a8c9e86529156c62d9187b9ed9454c31665ad33","versionType":"git","status":"affected"},{"version":"23721387c409087fd3b97e274f34d3ddc0970b74","lessThan":"0f3ebd7bb417aabc44853cc7c2a184ebb0e05b45","versionType":"git","status":"affected"},{"version":"23721387c409087fd3b97e274f34d3ddc0970b74","lessThan":"6921a7683ae9ad0208d829e71f725a9e25ccff49","versionType":"git","status":"affected"},{"version":"23721387c409087fd3b97e274f34d3ddc0970b74","lessThan":"555b8d3f5c313d81d46274fd0976352dafc80124","versionType":"git","status":"affected"},{"version":"23721387c409087fd3b97e274f34d3ddc0970b74","lessThan":"f80d3d98d2ff78d9e2fe5d68b1f45948c4f7bd24","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["net/batman-adv/bridge_loop_avoidance.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"3.5","status":"affected"},{"version":"0","lessThan":"3.5","versionType":"semver","status":"unaffected"},{"version":"5.10.259","lessThanOrEqual":"5.10.*","versionType":"semver","status":"unaffected"},{"version":"5.15.210","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.176","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.143","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.93","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.34","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.0.11","lessThanOrEqual":"7.0.*","versionType":"semver","status":"unaffected"},{"version":"7.1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/0f3ebd7bb417aabc44853cc7c2a184ebb0e05b45","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/2a8c9e86529156c62d9187b9ed9454c31665ad33","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/4f6266735a0ba6a568b6d4c9fa51c33a5a7f2d70","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/53cb3511f6eda37d3bd923545fdba6013b6d7bb7","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/555b8d3f5c313d81d46274fd0976352dafc80124","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/6921a7683ae9ad0208d829e71f725a9e25ccff49","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/efb62458c94db1fe3a287e7e89c31b0cfb03f938","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/f80d3d98d2ff78d9e2fe5d68b1f45948c4f7bd24","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-64100","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-07-19T16:17:51.140","lastModified":"2026-07-19T16:17:51.140","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/msm: Fix shrinker deadlock\n\nWith PROVE_LOCKING on an Snapdragon X1 and VM reclaim pressure, we see:\n\n   ======================================================\n   WARNING: possible circular locking dependency detected\n   7.0.0-debug+ #43 Tainted: G        W\n   ------------------------------------------------------\n   kswapd0/82 is trying to acquire lock:\n   ffff800080ec3870 (reservation_ww_class_acquire){+.+.}-{0:0}, at: msm_gem_shrinker_scan+0x17c/0x400 [msm]\n\n   but task is already holding lock:\n   ffffc31709b263b8 (fs_reclaim){+.+.}-{0:0}, at: balance_pgdat+0x88/0x988\n\n   which lock already depends on the new lock.\n\n   the existing dependency chain (in reverse order) is:\n\n   -> #2 (fs_reclaim){+.+.}-{0:0}:\n          __lock_acquire+0x4d0/0xad0\n          lock_acquire.part.0+0xc4/0x248\n          lock_acquire+0x8c/0x248\n          fs_reclaim_acquire+0xd0/0xf0\n          dma_resv_lockdep+0x224/0x348\n          do_one_initcall+0x84/0x5d0\n          do_initcalls+0x194/0x1d8\n          kernel_init_freeable+0x128/0x180\n          kernel_init+0x2c/0x160\n          ret_from_fork+0x10/0x20\n\n   -> #1 (reservation_ww_class_mutex){+.+.}-{4:4}:\n          __lock_acquire+0x4d0/0xad0\n          lock_acquire.part.0+0xc4/0x248\n          lock_acquire+0x8c/0x248\n          dma_resv_lockdep+0x1a8/0x348\n          do_one_initcall+0x84/0x5d0\n          do_initcalls+0x194/0x1d8\n          kernel_init_freeable+0x128/0x180\n          kernel_init+0x2c/0x160\n          ret_from_fork+0x10/0x20\n\n   -> #0 (reservation_ww_class_acquire){+.+.}-{0:0}:\n          check_prev_add+0x114/0x790\n          validate_chain+0x594/0x6f0\n          __lock_acquire+0x4d0/0xad0\n          lock_acquire.part.0+0xc4/0x248\n          lock_acquire+0x8c/0x248\n          drm_gem_lru_scan+0x1ac/0x440\n          msm_gem_shrinker_scan+0x17c/0x400 [msm]\n          do_shrink_slab+0x150/0x4a0\n          shrink_slab+0x144/0x460\n          shrink_one+0x9c/0x1b0\n          shrink_many+0x27c/0x5c0\n          shrink_node+0x344/0x550\n          balance_pgdat+0x2c0/0x988\n          kswapd+0x11c/0x318\n          kthread+0x10c/0x128\n          ret_from_fork+0x10/0x20\n\n   other info that might help us debug this:\n   Chain exists of:\n     reservation_ww_class_acquire --> reservation_ww_class_mutex --> fs_reclaim\n    Possible unsafe locking scenario:\n          CPU0                    CPU1\n          ----                    ----\n     lock(fs_reclaim);\n                                  lock(reservation_ww_class_mutex);\n                                  lock(fs_reclaim);\n     lock(reservation_ww_class_acquire);\n\n    *** DEADLOCK ***\n   1 lock held by kswapd0/82:\n    #0: ffffc31709b263b8 (fs_reclaim){+.+.}-{0:0}, at: balance_pgdat+0x88/0x988\n\n   stack backtrace:\n   CPU: 4 UID: 0 PID: 82 Comm: kswapd0 Tainted: G        W           7.0.0-debug+ #43 PREEMPT(full)\n   Tainted: [W]=WARN\n   Hardware name: LENOVO 21BX0016US/21BX0016US, BIOS N3HET94W (1.66 ) 09/15/2025\n   Call trace:\n    show_stack+0x20/0x40 (C)\n    dump_stack_lvl+0x9c/0xd0\n    dump_stack+0x18/0x30\n    print_circular_bug+0x114/0x120\n    check_noncircular+0x178/0x198\n    check_prev_add+0x114/0x790\n    validate_chain+0x594/0x6f0\n    __lock_acquire+0x4d0/0xad0\n    lock_acquire.part.0+0xc4/0x248\n    lock_acquire+0x8c/0x248\n    drm_gem_lru_scan+0x1ac/0x440\n    msm_gem_shrinker_scan+0x17c/0x400 [msm]\n    do_shrink_slab+0x150/0x4a0\n    shrink_slab+0x144/0x460\n    shrink_one+0x9c/0x1b0\n    shrink_many+0x27c/0x5c0\n    shrink_node+0x344/0x550\n    balance_pgdat+0x2c0/0x988\n    kswapd+0x11c/0x318\n    kthread+0x10c/0x128\n    ret_from_fork+0x10/0x20\n\nkswapd0 holding fs_reclaim calls the MSM shrinker, which calls\ndma_resv_lock. This in turn acquires fs_reclaim.\n\nFix this deadlock by using dma_resv_trylock() instead, dropping the\nsubsequently unused passed wait-wound lock 'ticket'.\n\nPatchwork: https://patchwork.freedesktop.org/patch/723564/\n[rob: fixup compile errors, replace lockdep splat with somethin\n---truncated---"}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/gpu/drm/msm/msm_gem_shrinker.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"fe4952b5f27cca5d143d3de249562d4cc984c1d6","lessThan":"942968260e61d4a5d7552b20814b6277f9c553df","versionType":"git","status":"affected"},{"version":"fe4952b5f27cca5d143d3de249562d4cc984c1d6","lessThan":"928788566c79046f71a211fc32c115400be76402","versionType":"git","status":"affected"},{"version":"fe4952b5f27cca5d143d3de249562d4cc984c1d6","lessThan":"3392291fc509d8ad6e4ad90f15b0a193f721cbc9","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/gpu/drm/msm/msm_gem_shrinker.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.17","status":"affected"},{"version":"0","lessThan":"6.17","versionType":"semver","status":"unaffected"},{"version":"6.18.34","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.0.11","lessThanOrEqual":"7.0.*","versionType":"semver","status":"unaffected"},{"version":"7.1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/3392291fc509d8ad6e4ad90f15b0a193f721cbc9","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/928788566c79046f71a211fc32c115400be76402","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/942968260e61d4a5d7552b20814b6277f9c553df","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-64101","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-07-19T16:17:51.273","lastModified":"2026-07-19T16:17:51.273","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nfwctl: pds: Validate RPC input size before parsing\n\nThe fwctl core allocates the device-specific RPC input buffer with\nfwctl_rpc.in_len and passes that buffer to the driver callback.\n\npdsfc_fw_rpc() casts the buffer to struct fwctl_rpc_pds and then calls\npdsfc_validate_rpc(), which reads fields from that structure before\nchecking that the input buffer is large enough to contain it. A short\nin_len can make pds_fwctl read beyond the allocation.\n\nReject pds RPC buffers that are smaller than struct fwctl_rpc_pds before\nparsing any pds-specific fields."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/fwctl/pds/main.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"92c66ee829b99a860a90f62ef16df3e42f92edac","lessThan":"9e3f18883a98420a3b8873c6f894bc57e9b98e41","versionType":"git","status":"affected"},{"version":"92c66ee829b99a860a90f62ef16df3e42f92edac","lessThan":"0d470d36551058e3f728574308b815a80bca710f","versionType":"git","status":"affected"},{"version":"92c66ee829b99a860a90f62ef16df3e42f92edac","lessThan":"e7537735028c3ad4b0bfc02ff8fa2a1a28aa04fe","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/fwctl/pds/main.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.15","status":"affected"},{"version":"0","lessThan":"6.15","versionType":"semver","status":"unaffected"},{"version":"6.18.34","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.0.11","lessThanOrEqual":"7.0.*","versionType":"semver","status":"unaffected"},{"version":"7.1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/0d470d36551058e3f728574308b815a80bca710f","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/9e3f18883a98420a3b8873c6f894bc57e9b98e41","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/e7537735028c3ad4b0bfc02ff8fa2a1a28aa04fe","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-64103","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-07-19T16:17:51.533","lastModified":"2026-07-19T16:17:51.533","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nscsi: isci: Fix use-after-free in device removal path\n\nThe ISCI completion tasklet is initialized in isci_host_alloc()\n(drivers/scsi/isci/init.c:496) and scheduled from both MSI-X and legacy\ninterrupt handlers (drivers/scsi/isci/host.c:223,613).\n\nisci_host_deinit() stops the controller and waits for stop completion,\nbut it never kills completion_tasklet before teardown continues. A\ntop-of-function tasklet_kill() is not sufficient here: interrupts are\nonly disabled when isci_host_stop_complete() runs, so until\nwait_for_stop() returns the IRQ handlers can still requeue the\ntasklet. The tasklet callback also re-enables interrupts after draining\ncompletions, so killing the tasklet before the source is quiesced leaves\nthe same race open.\n\nOnce wait_for_stop() returns, no further IRQ-driven scheduling can\noccur. Kill completion_tasklet there so teardown cannot race a queued\ntasklet running on a dead ihost. On remove or unload, the stale callback\ncan otherwise dereference ihost and touch ihost->smu_registers after the\nhost lifetime ends.\n\nA UML + KASAN analogue reproduced the failure class both with no\ntasklet_kill() and with tasklet_kill() placed before source quiesce, and\nstayed clean once the kill happened after quiescing the scheduling\nsource.\n\nThis mirrors commit f6ab594672d4 (\"scsi: aic94xx: fix use-after-free in\ndevice removal path\"), but ISCI needs the kill after wait_for_stop()."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/scsi/isci/host.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6f231dda68080759f1aed3769896e94c73099f0f","lessThan":"1412995e10c74644b47f242aea6e4f3d4180e806","versionType":"git","status":"affected"},{"version":"6f231dda68080759f1aed3769896e94c73099f0f","lessThan":"a83d3e4daba40d49324cec1c51ed261e1ea48cf1","versionType":"git","status":"affected"},{"version":"6f231dda68080759f1aed3769896e94c73099f0f","lessThan":"ab2266601a875982f2d2033f41e070a6d5e615e2","versionType":"git","status":"affected"},{"version":"6f231dda68080759f1aed3769896e94c73099f0f","lessThan":"309c6058622d080fe8c2fab87c30da82d834d989","versionType":"git","status":"affected"},{"version":"6f231dda68080759f1aed3769896e94c73099f0f","lessThan":"cb9e72c50e6c81a5903f27e0b397ce8525d7539b","versionType":"git","status":"affected"},{"version":"6f231dda68080759f1aed3769896e94c73099f0f","lessThan":"b9ff8631006233ba246828ac70409d2cb2da38d3","versionType":"git","status":"affected"},{"version":"6f231dda68080759f1aed3769896e94c73099f0f","lessThan":"6d40f2f103bb30f52f3dbadbe2c3fdf274a9763c","versionType":"git","status":"affected"},{"version":"6f231dda68080759f1aed3769896e94c73099f0f","lessThan":"b52a8d52c3125ec9a93106ed816582368de34426","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/scsi/isci/host.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"3.0","status":"affected"},{"version":"0","lessThan":"3.0","versionType":"semver","status":"unaffected"},{"version":"5.10.258","lessThanOrEqual":"5.10.*","versionType":"semver","status":"unaffected"},{"version":"5.15.209","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.175","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.142","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.92","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.34","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.0.11","lessThanOrEqual":"7.0.*","versionType":"semver","status":"unaffected"},{"version":"7.1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/1412995e10c74644b47f242aea6e4f3d4180e806","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/309c6058622d080fe8c2fab87c30da82d834d989","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/6d40f2f103bb30f52f3dbadbe2c3fdf274a9763c","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/a83d3e4daba40d49324cec1c51ed261e1ea48cf1","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/ab2266601a875982f2d2033f41e070a6d5e615e2","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/b52a8d52c3125ec9a93106ed816582368de34426","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/b9ff8631006233ba246828ac70409d2cb2da38d3","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/cb9e72c50e6c81a5903f27e0b397ce8525d7539b","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-64105","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-07-19T16:17:51.780","lastModified":"2026-07-19T16:17:51.780","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nKVM: arm64: vgic: Free private_irqs when init fails after allocation\n\nCompanion to commit 250f25367b58 (\"KVM: arm64: Tear down vGIC on\nfailed vCPU creation\"), which added the missing kvm_vgic_vcpu_destroy()\ncall to the kvm_share_hyp() failure path in kvm_arch_vcpu_create(). The\nkvm_vgic_vcpu_init() failure path immediately above it has the same\nshape and still needs the same cleanup.\n\nCall kvm_vgic_vcpu_destroy() when kvm_vgic_vcpu_init() fails so private\nIRQs allocated before a redistributor iodev registration failure are\nreleased before the failed vCPU is freed."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["arch/arm64/kvm/arm.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"03b3d00a70b55857439511c1b558ca00a99f4126","lessThan":"173fb86e5519dbe7aabed1f5fa7456152a4a2e38","versionType":"git","status":"affected"},{"version":"03b3d00a70b55857439511c1b558ca00a99f4126","lessThan":"7023900b4988fb6f4a59d304d878003ff562e98d","versionType":"git","status":"affected"},{"version":"03b3d00a70b55857439511c1b558ca00a99f4126","lessThan":"e690caa54a6139d98495ac69626807623520babd","versionType":"git","status":"affected"},{"version":"03b3d00a70b55857439511c1b558ca00a99f4126","lessThan":"f19c354dbd457759dfcf1195ab4bdba2bb568323","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["arch/arm64/kvm/arm.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.10","status":"affected"},{"version":"0","lessThan":"6.10","versionType":"semver","status":"unaffected"},{"version":"6.12.92","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.34","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.0.11","lessThanOrEqual":"7.0.*","versionType":"semver","status":"unaffected"},{"version":"7.1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/173fb86e5519dbe7aabed1f5fa7456152a4a2e38","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/7023900b4988fb6f4a59d304d878003ff562e98d","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/e690caa54a6139d98495ac69626807623520babd","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/f19c354dbd457759dfcf1195ab4bdba2bb568323","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-64107","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-07-19T16:17:52.000","lastModified":"2026-07-19T16:17:52.000","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nASoC: codecs: pcm512x: fix null-ptr dereference in pcm512x_overclock_xxx_put()\n\nIn the pcm512x chipset driver, pcm512x_overclock_xxx_put() is defined as\na general mixer kcontrol instead of a DAPM kcontrol, so struct\nsnd_soc_dapm_context must not be accessed via\nsnd_soc_dapm_kcontrol_to_dapm().\n\nThis causes a NULL pointer dereference, so it must be modified to use\nsnd_soc_component_to_dapm()."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["sound/soc/codecs/pcm512x.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"02dbbb7e982a6873f81e69e4fef59a42decb7b1a","lessThan":"285159ca199cbbe424223d4b14db227b279b5767","versionType":"git","status":"affected"},{"version":"02dbbb7e982a6873f81e69e4fef59a42decb7b1a","lessThan":"09e8f9a9aa19aa8c1b0cc7a0ebc68f6ecf86a660","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["sound/soc/codecs/pcm512x.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.19","status":"affected"},{"version":"0","lessThan":"6.19","versionType":"semver","status":"unaffected"},{"version":"7.0.11","lessThanOrEqual":"7.0.*","versionType":"semver","status":"unaffected"},{"version":"7.1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/09e8f9a9aa19aa8c1b0cc7a0ebc68f6ecf86a660","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/285159ca199cbbe424223d4b14db227b279b5767","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-64110","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-07-19T16:17:52.370","lastModified":"2026-07-19T16:17:52.370","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nigc: fix potential skb leak in igc_fpe_xmit_smd_frame()\n\nWhen igc_fpe_init_tx_descriptor() fails, no one takes care of an\nallocated skb, leaking it. [1]\nUse dev_kfree_skb_any() on failure.\n\nTested on an I226 adapter with the following command, while injecting\nfaults in igc_fpe_init_tx_descriptor() to trigger the error path.\n # ethtool --set-mm $DEV verify-enabled on tx-enabled on pmac-enabled on\n\n[1]\nunreferenced object 0xffff888113c6cdc0 (size 224):\n...\n  backtrace (crc be3d3fda):\n    kmem_cache_alloc_node_noprof+0x3b1/0x410\n    __alloc_skb+0xde/0x830\n    igc_fpe_xmit_smd_frame.isra.0+0xad/0x1b0\n    igc_fpe_send_mpacket+0x37/0x90\n    ethtool_mmsv_verify_timer+0x15e/0x300"}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/net/ethernet/intel/igc/igc_tsn.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"5422570c0010bb968738f9256eb2bf83e79b4d63","lessThan":"f1bafd35f11b3aca1c7bb38da173b8787364a04c","versionType":"git","status":"affected"},{"version":"5422570c0010bb968738f9256eb2bf83e79b4d63","lessThan":"3ebf056556138e74c640e6dc2b3848abd398b460","versionType":"git","status":"affected"},{"version":"5422570c0010bb968738f9256eb2bf83e79b4d63","lessThan":"e935c37b8a94bb256fada6395a5d05e1c0c6bdaf","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/net/ethernet/intel/igc/igc_tsn.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.16","status":"affected"},{"version":"0","lessThan":"6.16","versionType":"semver","status":"unaffected"},{"version":"6.18.34","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.0.11","lessThanOrEqual":"7.0.*","versionType":"semver","status":"unaffected"},{"version":"7.1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/3ebf056556138e74c640e6dc2b3848abd398b460","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/e935c37b8a94bb256fada6395a5d05e1c0c6bdaf","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/f1bafd35f11b3aca1c7bb38da173b8787364a04c","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-64119","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-07-19T16:17:53.450","lastModified":"2026-07-19T16:17:53.450","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nl2tp: use list_del_rcu in l2tp_session_unhash\n\nAn unprivileged local user can pin a host CPU indefinitely in\nl2tp_session_get_by_ifname() by issuing L2TP_CMD_SESSION_GET on\nL2TP_ATTR_IFNAME concurrently with L2TP_CMD_SESSION_CREATE and\nL2TP_CMD_SESSION_DELETE on the same tunnel. All three commands take\nGENL_UNS_ADMIN_PERM, so CAP_NET_ADMIN in the netns user namespace\nsuffices; on any host that has l2tp_core loaded the trigger is\nreachable from a standard `unshare -Urn` sandbox.\n\nl2tp_session_unhash() removes a session from tunnel->session_list\nwith list_del_init(), but that list is walked by\nl2tp_session_get_by_ifname() with list_for_each_entry_rcu() under\nrcu_read_lock_bh(). list_del_init() leaves the deleted entry's\nnext/prev self-pointing; a reader that has loaded the entry and\nthen advances pos->list.next reads &session->list, container_of()s\nback to the same session, and list_for_each_entry_rcu() never\nreaches the list head. The CPU stays in strcmp() inside the\nwalker, with BH and preemption disabled, so RCU grace periods on\nthe host stall behind it and the wedged thread cannot be killed\n(SIGKILL is delivered on syscall return).\n\nUse list_del_rcu() to match the existing list_add_rcu() in\nl2tp_session_register(); the deleted session remains visible to\nin-flight walkers with consistent next/prev pointers until\nkfree_rcu() in l2tp_session_free() releases it. tunnel->session_list\nhas exactly one list_del_init() call site; the list_del_init\n(&session->clist) at l2tp_core.c:533 operates on the per-collision\nlist, which is not walked under RCU. list_empty(&session->list) is\nnot used anywhere in net/l2tp/ after the unhash point, so dropping\nthe post-delete self-init is safe; the fix has no userspace-visible\nbehavior change."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["net/l2tp/l2tp_core.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"89b768ec2dfefaeba5212de14fc71368e12d06ba","lessThan":"5e40919a40cb3e590ed45c2a54a4a2518aa88a99","versionType":"git","status":"affected"},{"version":"89b768ec2dfefaeba5212de14fc71368e12d06ba","lessThan":"e0c3dd7b30cc5ee42ab502da140cda93d794a20b","versionType":"git","status":"affected"},{"version":"89b768ec2dfefaeba5212de14fc71368e12d06ba","lessThan":"acab6314bb75be994f720ed13e9d9139cbf828a8","versionType":"git","status":"affected"},{"version":"89b768ec2dfefaeba5212de14fc71368e12d06ba","lessThan":"979c017803c40829b03acd9e5236e354b7622360","versionType":"git","status":"affected"},{"version":"b3dd82a879f25db9d096ae3053f657aa4260ecc6","versionType":"git","status":"affected"},{"version":"6.11.3","lessThan":"6.12","versionType":"semver","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["net/l2tp/l2tp_core.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.12","status":"affected"},{"version":"0","lessThan":"6.12","versionType":"semver","status":"unaffected"},{"version":"6.12.92","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.34","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.0.11","lessThanOrEqual":"7.0.*","versionType":"semver","status":"unaffected"},{"version":"7.1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/5e40919a40cb3e590ed45c2a54a4a2518aa88a99","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/979c017803c40829b03acd9e5236e354b7622360","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/acab6314bb75be994f720ed13e9d9139cbf828a8","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/e0c3dd7b30cc5ee42ab502da140cda93d794a20b","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-64120","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-07-19T16:17:53.563","lastModified":"2026-07-19T16:17:53.563","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nnet: ethtool: fix NULL pointer dereference in phy_reply_size\n\nIn phy_prepare_data(), several strings such as 'name', 'drvname',\n'upstream_sfp_name', and 'downstream_sfp_name' are allocated using\nkstrdup(). However, these allocations were not checked  for failure.\n\nIf kstrdup() fails for 'name', it returns NULL while the function\ncontinues. This leads to a kernel NULL pointer dereference and panic\nlater in phy_reply_size() when it unconditionally calls strlen() on\nthe NULL pointer.\n\nWhile other strings like 'upstream_sfp_name' might be checked before\naccess in certain code paths, failing to handle these allocations\nconsistently can lead to incomplete data reporting or hidden bugs.\n\nFix this by adding proper NULL checks for all kstrdup() calls in\nphy_prepare_data() and implement a centralized error handling path\nusing goto labels to ensure all previously allocated resources are\nfreed on failure."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["net/ethtool/phy.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"9dd2ad5e92b962d1349a7541d167e8e214e49f95","lessThan":"61f53c1e58d68723bc1db10912a53f1991f08719","versionType":"git","status":"affected"},{"version":"9dd2ad5e92b962d1349a7541d167e8e214e49f95","lessThan":"3dbe20a3809347bacda890822e7ca013bd85a18c","versionType":"git","status":"affected"},{"version":"9dd2ad5e92b962d1349a7541d167e8e214e49f95","lessThan":"4908f1395fb1b832ceec11584af649874a2732ea","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["net/ethtool/phy.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.16","status":"affected"},{"version":"0","lessThan":"6.16","versionType":"semver","status":"unaffected"},{"version":"6.18.34","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.0.11","lessThanOrEqual":"7.0.*","versionType":"semver","status":"unaffected"},{"version":"7.1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/3dbe20a3809347bacda890822e7ca013bd85a18c","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/4908f1395fb1b832ceec11584af649874a2732ea","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/61f53c1e58d68723bc1db10912a53f1991f08719","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-64121","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-07-19T16:17:53.663","lastModified":"2026-07-19T16:17:53.663","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nnet: ifb: report ethtool stats over num_tx_queues\n\nifb_dev_init() allocates dp->tx_private to dev->num_tx_queues\nentries via kzalloc_objs(*txp, dev->num_tx_queues). Both IFB\nper-queue RX and TX stats live in those entries: ifb_xmit() updates\ntxp->rx_stats using the skb queue mapping, ifb_ri_tasklet() updates\ntxp->tx_stats, and ifb_stats64() aggregates both over\ndev->num_tx_queues.\n\nThe ethtool stats callbacks instead size and walk the per-queue\nstats with dev->real_num_rx_queues and dev->real_num_tx_queues. With\nan asymmetric device where the RX queue count exceeds the TX queue\ncount, for example:\n\n    ip link add name ifb10 numtxqueues 1 numrxqueues 8 type ifb\n    ethtool -S ifb10\n\nifb_get_ethtool_stats() indexes past the tx_private allocation and\ncopies adjacent slab data through ETHTOOL_GSTATS.\n\nUse dev->num_tx_queues consistently for the stats strings, the\nstats count, and the stats data walks. This reports one RX stats\ngroup and one TX stats group for each backing ifb_q_private entry,\nwhich is the queue set IFB can actually populate.\n\nReproduced under UML+KASAN at v7.1-rc2:\n\n  BUG: KASAN: slab-out-of-bounds in ifb_fill_stats_data+0x3c/0xae\n  Read of size 8 at addr 0000000062dbd228 by task ethtool/36\n  ifb_fill_stats_data+0x3c/0xae\n  ifb_get_ethtool_stats+0xc0/0x129\n  __dev_ethtool+0x1ca5/0x363c\n  dev_ethtool+0x123/0x1b3\n  dev_ioctl+0x56c/0x744\n  sock_do_ioctl+0x15f/0x1b2\n  sock_ioctl+0x4d5/0x50a\n  sys_ioctl+0xd8b/0xde9\n\nWith the patch applied, the same UML+KASAN repro is silent and\nethtool -S ifb10 reports only the stats backed by the single\nallocated tx_private entry."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/net/ifb.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"a21ee5b2fcb8d6d3973446c5039e966c4cfe40d1","lessThan":"6afdb8113cb007f9332f59a9b7fd45731b8a9de5","versionType":"git","status":"affected"},{"version":"a21ee5b2fcb8d6d3973446c5039e966c4cfe40d1","lessThan":"16bd798cb6d8337d7c3eea1adc412f31b5181d5b","versionType":"git","status":"affected"},{"version":"a21ee5b2fcb8d6d3973446c5039e966c4cfe40d1","lessThan":"301a554e458e2f5ec47f2c336a7cb03b877f9fd6","versionType":"git","status":"affected"},{"version":"a21ee5b2fcb8d6d3973446c5039e966c4cfe40d1","lessThan":"f8a5a76b4a683043c6eff2a060bcaa17f9316ad5","versionType":"git","status":"affected"},{"version":"a21ee5b2fcb8d6d3973446c5039e966c4cfe40d1","lessThan":"2638e1773904d7aa8f24c6e7fda2ed7d69df6fa4","versionType":"git","status":"affected"},{"version":"a21ee5b2fcb8d6d3973446c5039e966c4cfe40d1","lessThan":"5db89c99566fc4728cc92e941d8e1975711e24b5","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/net/ifb.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"5.17","status":"affected"},{"version":"0","lessThan":"5.17","versionType":"semver","status":"unaffected"},{"version":"6.1.175","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.142","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.92","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.34","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.0.11","lessThanOrEqual":"7.0.*","versionType":"semver","status":"unaffected"},{"version":"7.1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/16bd798cb6d8337d7c3eea1adc412f31b5181d5b","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/2638e1773904d7aa8f24c6e7fda2ed7d69df6fa4","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/301a554e458e2f5ec47f2c336a7cb03b877f9fd6","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/5db89c99566fc4728cc92e941d8e1975711e24b5","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/6afdb8113cb007f9332f59a9b7fd45731b8a9de5","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/f8a5a76b4a683043c6eff2a060bcaa17f9316ad5","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-64127","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-07-19T16:17:54.387","lastModified":"2026-07-19T16:17:54.387","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nBluetooth: L2CAP: ecred_reconfigure: send packed pdu, not stack pointer\n\nCommit 1c08108f3014 (\"Bluetooth: L2CAP: Avoid -Wflex-array-member-not-at-end\nwarnings\") converted the on-stack request PDU in l2cap_ecred_reconfigure()\nfrom an explicit packed struct to DEFINE_RAW_FLEX(), but did not adjust the\nsize and source-pointer arguments to l2cap_send_cmd():\n\n  -    struct {\n  -            struct l2cap_ecred_reconf_req req;\n  -            __le16 scid;\n  -    } pdu;\n  +    DEFINE_RAW_FLEX(struct l2cap_ecred_reconf_req, pdu, scid, 1);\n       ...\n       l2cap_send_cmd(conn, chan->ident, L2CAP_ECRED_RECONF_REQ,\n                      sizeof(pdu), &pdu);\n\nAfter the conversion, DEFINE_RAW_FLEX() expands to declare an anonymous\nunion pdu_u plus a local pointer \"pdu\" pointing at it. Therefore:\n\n  - sizeof(pdu) is now sizeof(struct l2cap_ecred_reconf_req *) = 8 on\n    64-bit (4 on 32-bit), not the 6 bytes of (mtu, mps, scid[1]).\n  - &pdu is the address of the local pointer's stack storage, not the\n    address of the request payload.\n\nl2cap_send_cmd() forwards (data, count) to l2cap_build_cmd(), which calls\nskb_put_data(skb, data, count). The L2CAP_ECRED_RECONFIGURE_REQ packet\nbody therefore contains 8 bytes copied from the kernel stack starting at\n&pdu -- the 8 bytes overlap the pdu pointer's value, leaking a kernel\nstack address to the paired Bluetooth peer. The intended (mtu, mps, scid)\nfields are not transmitted at all, so the peer rejects the request as\nmalformed and the L2CAP_ECRED_RECONFIGURE feature itself has been broken\nfor the local-side initiator since the introducing commit landed.\n\nThe sibling site l2cap_ecred_conn_req() in the same commit was converted\ncorrectly (sizeof(*pdu) + len, pdu); only this site was missed.\n\nRestore the original semantics: pass the full flex-struct size via\nstruct_size(pdu, scid, 1) and the pdu pointer (the struct address) as\nthe source.\n\nValidated on a stock 7.0-based host kernel via the real call path:\nsetsockopt(SOL_BLUETOOTH, BT_RCVMTU, ...) on a BT_CONNECTED\nL2CAP_MODE_EXT_FLOWCTL socket emits an L2CAP_ECRED_RECONFIGURE_REQ\nwhose body is 8 bytes (the on-stack pdu local's value) rather than\nthe expected 6. Three captures from fresh socket / fresh hciemu peer\non the same host -- low bytes vary per call, high 0xffff confirms a\nkernel virtual address (KASLR-randomised stack slot, not a fixed\nstring):\n\n  RECONF_REQ body (ident=0x02 len=8): 42 fb 54 af 0e ca ff ff\n  RECONF_REQ body (ident=0x02 len=8): 52 3d 2e af 0e ca ff ff\n  RECONF_REQ body (ident=0x02 len=8): b2 fc 5b af 0e ca ff ff\n\nAfter this patch the body is 6 bytes carrying the expected\nlittle-endian (mtu, mps, scid)."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["net/bluetooth/l2cap_core.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"1c08108f3014881ad5f4c35a2abaf9c65475035d","lessThan":"ed5fcd2a26f0c16fc289c8cd6b03328a0582a687","versionType":"git","status":"affected"},{"version":"1c08108f3014881ad5f4c35a2abaf9c65475035d","lessThan":"051922ab709c0a6917eae765c22481dfc68379e5","versionType":"git","status":"affected"},{"version":"1c08108f3014881ad5f4c35a2abaf9c65475035d","lessThan":"356c9d1a1cbacd2a1640fff3c050e1c3472e924f","versionType":"git","status":"affected"},{"version":"1c08108f3014881ad5f4c35a2abaf9c65475035d","lessThan":"3374ef8cf99368a40f7efd51a2a375a4c5dc6f0d","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["net/bluetooth/l2cap_core.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.10","status":"affected"},{"version":"0","lessThan":"6.10","versionType":"semver","status":"unaffected"},{"version":"6.12.92","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.34","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.0.11","lessThanOrEqual":"7.0.*","versionType":"semver","status":"unaffected"},{"version":"7.1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/051922ab709c0a6917eae765c22481dfc68379e5","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/3374ef8cf99368a40f7efd51a2a375a4c5dc6f0d","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/356c9d1a1cbacd2a1640fff3c050e1c3472e924f","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/ed5fcd2a26f0c16fc289c8cd6b03328a0582a687","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-64128","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-07-19T16:17:54.510","lastModified":"2026-07-19T16:17:54.510","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nBluetooth: ISO: drop ISO_END frames received without prior ISO_START\n\nISO data PDUs carry a packet-boundary flag indicating START, CONT, END\nor SINGLE. The ISO_CONT branch of iso_recv() guards against a missing\nISO_START by checking conn->rx_len before touching conn->rx_skb, but\nISO_END does not.\n\nIf a peer sends an ISO_END as the first packet on a fresh ISO\nconnection, conn->rx_skb is still NULL and conn->rx_len is zero, so\nskb_put(conn->rx_skb, ...) dereferences NULL and oopses. For BIS,\nwhere receivers sync to a broadcaster without pairing, any broadcaster\non the air can trigger this.\n\nMirror the ISO_CONT check at the top of ISO_END so a stray end fragment\nis logged and dropped instead of crashing the host."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["net/bluetooth/iso.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"ccf74f2390d60a2f9a75ef496d2564abb478f46a","lessThan":"1c3d1e1696b72579b970e17999c503a14535205b","versionType":"git","status":"affected"},{"version":"ccf74f2390d60a2f9a75ef496d2564abb478f46a","lessThan":"3af41ee7ebecb0d5c8a504861f6cfad31345310f","versionType":"git","status":"affected"},{"version":"ccf74f2390d60a2f9a75ef496d2564abb478f46a","lessThan":"39f4a82e80c8f5ed2d6952d73fbafc895721a728","versionType":"git","status":"affected"},{"version":"ccf74f2390d60a2f9a75ef496d2564abb478f46a","lessThan":"61f2410a96dee808029e2ae4d6ef2dd635f3477f","versionType":"git","status":"affected"},{"version":"ccf74f2390d60a2f9a75ef496d2564abb478f46a","lessThan":"e3a799881c12d27596232636a607e2e3fa448d63","versionType":"git","status":"affected"},{"version":"ccf74f2390d60a2f9a75ef496d2564abb478f46a","lessThan":"84c24fb151fc1179355296d7ff29129ac7c42129","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["net/bluetooth/iso.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.0","status":"affected"},{"version":"0","lessThan":"6.0","versionType":"semver","status":"unaffected"},{"version":"6.1.175","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.142","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.92","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.34","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.0.11","lessThanOrEqual":"7.0.*","versionType":"semver","status":"unaffected"},{"version":"7.1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/1c3d1e1696b72579b970e17999c503a14535205b","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/39f4a82e80c8f5ed2d6952d73fbafc895721a728","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/3af41ee7ebecb0d5c8a504861f6cfad31345310f","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/61f2410a96dee808029e2ae4d6ef2dd635f3477f","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/84c24fb151fc1179355296d7ff29129ac7c42129","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/e3a799881c12d27596232636a607e2e3fa448d63","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-64129","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-07-19T16:17:54.627","lastModified":"2026-07-19T16:17:54.627","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nmm/migrate_device: fix spinlock leak in migrate_vma_insert_huge_pmd_page\n\nWhen check_stable_address_space() fails after the PMD spinlock has\nbeen acquired via pmd_lock(), the code jumps directly to the abort\nlabel, bypassing the spin_unlock() call in unlock_abort. This causes\nthe PMD spinlock to be permanently held, leading to a deadlock.\n\nChange the goto target from abort to unlock_abort to ensure the\nspinlock is always released on this error path."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["mm/migrate_device.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"a30b48bf1b244f11bf9b6d20cdccfe0c2264130c","lessThan":"c715f7ccf7a294c058667b678a4ba50fad933c62","versionType":"git","status":"affected"},{"version":"a30b48bf1b244f11bf9b6d20cdccfe0c2264130c","lessThan":"63451de16e0a08be40f9ab5e7c5c8f5c79676fb1","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["mm/migrate_device.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.19","status":"affected"},{"version":"0","lessThan":"6.19","versionType":"semver","status":"unaffected"},{"version":"7.0.11","lessThanOrEqual":"7.0.*","versionType":"semver","status":"unaffected"},{"version":"7.1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/63451de16e0a08be40f9ab5e7c5c8f5c79676fb1","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/c715f7ccf7a294c058667b678a4ba50fad933c62","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-64130","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-07-19T16:17:54.723","lastModified":"2026-07-19T16:17:54.723","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nmm/page_alloc: fix initialization of tags of the huge zero folio with init_on_free\n\n__GFP_ZEROTAGS semantics are currently a bit weird, but effectively this\nflag is only ever set alongside __GFP_ZERO and __GFP_SKIP_KASAN.\n\nIf we run with init_on_free, we will zero out pages during\n__free_pages_prepare(), to skip zeroing on the allocation path.\n\nHowever, when allocating with __GFP_ZEROTAG set, post_alloc_hook() will\nconsequently not only skip clearing page content, but also skip clearing\ntag memory.\n\nNot clearing tags through __GFP_ZEROTAGS is irrelevant for most pages that\nwill get mapped to user space through set_pte_at() later: set_pte_at() and\nfriends will detect that the tags have not been initialized yet\n(PG_mte_tagged not set), and initialize them.\n\nHowever, for the huge zero folio, which will be mapped through a PMD\nmarked as special, this initialization will not be performed, ending up\nexposing whatever tags were still set for the pages.\n\nThe docs (Documentation/arch/arm64/memory-tagging-extension.rst) state\nthat allocation tags are set to 0 when a page is first mapped to user\nspace.  That no longer holds with the huge zero folio when init_on_free is\nenabled.\n\nFix it by decoupling __GFP_ZEROTAGS from __GFP_ZERO, passing to\ntag_clear_highpages() whether we want to also clear page content.\n\nInvert the meaning of the tag_clear_highpages() return value to have\nclearer semantics.\n\nReproduced with the huge zero folio by modifying the check_buffer_fill\narm64/mte selftest to use a 2 MiB area, after making sure that pages have\na non-0 tag set when freeing (note that, during boot, we will not actually\ninitialize tags, but only set KASAN_TAG_KERNEL in the page flags).\n\n\t$ ./check_buffer_fill\n\t1..20\n\t...\n\tnot ok 17 Check initial tags with private mapping, sync error mode and mmap memory\n\tnot ok 18 Check initial tags with private mapping, sync error mode and mmap/mprotect memory\n\t...\n\nThis code needs more cleanups; we'll tackle that next, like\ndecoupling __GFP_ZEROTAGS from __GFP_SKIP_KASAN.\n\n[akpm@linux-foundation.org: s/__GPF_ZERO/__GFP_ZERO/, per David]"}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["arch/arm64/include/asm/page.h","arch/arm64/mm/fault.c","include/linux/gfp_types.h","include/linux/highmem.h","mm/page_alloc.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"adfb6609c6809e107ded9a1cd46f519c882e64ea","lessThan":"738d18f1da3513d17b6f7bf30146cc4ac2480ffd","versionType":"git","status":"affected"},{"version":"adfb6609c6809e107ded9a1cd46f519c882e64ea","lessThan":"2f2aec5120b93a8f8b52dc50cdc60dbb8aec72f6","versionType":"git","status":"affected"},{"version":"adfb6609c6809e107ded9a1cd46f519c882e64ea","lessThan":"6a288a4ddb4a994490505ab5f41c445f8e6b6467","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["arch/arm64/include/asm/page.h","arch/arm64/mm/fault.c","include/linux/gfp_types.h","include/linux/highmem.h","mm/page_alloc.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.18","status":"affected"},{"version":"0","lessThan":"6.18","versionType":"semver","status":"unaffected"},{"version":"6.18.34","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.0.11","lessThanOrEqual":"7.0.*","versionType":"semver","status":"unaffected"},{"version":"7.1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/2f2aec5120b93a8f8b52dc50cdc60dbb8aec72f6","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/6a288a4ddb4a994490505ab5f41c445f8e6b6467","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/738d18f1da3513d17b6f7bf30146cc4ac2480ffd","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-64131","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-07-19T16:17:54.853","lastModified":"2026-07-19T16:17:54.853","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nmm/memory: fix spurious warning when unmapping device-private/exclusive pages\n\nDevice private and exclusive entries are only supported for anonymous\nfolios.  This condition is tested in __migrate_device_pages() and\nmake_device_exclusive() using folio_test_anon().  However the unmap path\ntests this assumption using vma_is_anonymous().\n\nThis is wrong because whilst anonymous VMAs can only contain folios where\nfolio_test_anon() is true the opposite relation does not hold.  A folio\nfor which folio_test_anon() is true does not imply vma_is_anonymous() is\ntrue.  Such a condition can occur if for example a folio is part of a\nprivate filebacked mapping.\n\nIn this case vma_is_anonymous() is false as the mapping is filebacked, but\nfolio_test_anon() may be true, thus permitting devices to migrate the\nfolio to device private memory.  This can lead to the following spurious\nwarnings during process teardown:\n\n[  772.737706] ------------[ cut here ]------------\n[  772.739201] WARNING: mm/memory.c:1754 at unmap_page_range.cold+0x26/0x18a, CPU#17: hmm-tests/2041\n[  772.742050] Modules linked in: test_hmm nvidia_uvm(O) nvidia(O)\n[  772.743959] CPU: 17 UID: 0 PID: 2041 Comm: hmm-tests Tainted: G        W  O        7.0.0+ #387 PREEMPT(full)\n[  772.747104] Tainted: [W]=WARN, [O]=OOT_MODULE\n[  772.748509] Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS rel-1.17.0-0-gb52ca86e094d-prebuilt.qemu.org 04/01/2014\n[  772.752117] RIP: 0010:unmap_page_range.cold+0x26/0x18a\n[  772.753780] Code: 7e fe ff ff 48 89 4c 24 78 4c 89 44 24 38 e8 f2 ff b1 00 48 8b 4c 24 78 4c 8b 44 24 38 48 8b 44 24 18 48 83 78 48 00 74 04 90 <0f> 0b 90 48 89 ca b8 ff ff 37 00 48 c1 ea 03 48 c1 e0 2a 80 3c 02\n[  772.759602] RSP: 0018:ffff888112607550 EFLAGS: 00010286\n[  772.761310] RAX: ffff88811bbf4dc0 RBX: dffffc0000000000 RCX: ffffea03e9bfffd8\n[  772.763583] RDX: 1ffff1102377e9c1 RSI: 0000000000000008 RDI: ffff88811bbf4e08\n[  772.765914] RBP: 0000000000000006 R08: ffff8881059f7448 R09: ffffed10224c0e68\n[  772.768184] R10: ffff888112607347 R11: 0000000000000001 R12: 0000000000000001\n[  772.770461] R13: ffffea03e9bfffc0 R14: ffff888112607908 R15: ffffea03e9bfffc0\n[  772.772782] FS:  00007f327caa2780(0000) GS:ffff888427b7d000(0000) knlGS:0000000000000000\n[  772.775328] CS:  0010 DS: 0000 ES: 0000 CR0: 0000000080050033\n[  772.777187] CR2: 00007f327ca89000 CR3: 00000001994d5000 CR4: 00000000000006f0\n[  772.779135] Call Trace:\n[  772.779792]  <TASK>\n[  772.780317]  ? dmirror_interval_invalidate+0x1a3/0x290 [test_hmm]\n[  772.781873]  ? vm_normal_page_pud+0x2b0/0x2b0\n[  772.782992]  ? __rwlock_init+0x150/0x150\n[  772.784006]  ? lock_release+0x216/0x2b0\n[  772.785008]  ? __mmu_notifier_invalidate_range_start+0x505/0x6e0\n[  772.786522]  ? lock_release+0x216/0x2b0\n[  772.787498]  ? unmap_single_vma+0xb6/0x210\n[  772.788573]  unmap_vmas+0x27d/0x520\n[  772.789506]  ? unmap_single_vma+0x210/0x210\n[  772.790607]  ? mas_update_gap.part.0+0x620/0x620\n[  772.791834]  unmap_region+0x19e/0x350\n[  772.792769]  ? remove_vma+0x130/0x130\n[  772.793684]  ? mas_alloc_nodes+0x1f2/0x300\n[  772.794730]  vms_complete_munmap_vmas+0x8c1/0xe20\n[  772.795926]  ? unmap_region+0x350/0x350\n[  772.796917]  do_vmi_align_munmap+0x36a/0x4e0\n[  772.798018]  ? lock_release+0x216/0x2b0\n[  772.799024]  ? vma_shrink+0x620/0x620\n[  772.799983]  do_vmi_munmap+0x150/0x2c0\n[  772.800939]  __vm_munmap+0x161/0x2c0\n[  772.801872]  ? expand_downwards+0xd60/0xd60\n[  772.802948]  ? clockevents_program_event+0x1ef/0x540\n[  772.804217]  ? lock_release+0x216/0x2b0\n[  772.805158]  __x64_sys_munmap+0x59/0x80\n[  772.805776]  do_syscall_64+0xfc/0x670\n[  772.806336]  ? irqentry_exit+0xda/0x580\n[  772.806976]  entry_SYSCALL_64_after_hwframe+0x4b/0x53\n[  772.807772] RIP: 0033:0x7f327cbb2717\n[  772.808323] Code: 73 01 c3 48 8b 0d f9 76 0d 00 f7 d8 64 89 01 48 83 c8 ff c3 66 2e 0f 1f 84 00 00 00 00 00 0f 1f 44 00 00 b8 0b 00 00 00 0f 05 <48> 3d 01 f0 ff\n---truncated---"}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["mm/memory.c","tools/testing/selftests/mm/hmm-tests.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"999dad824c39ed14dee7c4412aae531ba9e74a90","lessThan":"e81446b559db4c98a6c2c5e039ac9cb23658432e","versionType":"git","status":"affected"},{"version":"999dad824c39ed14dee7c4412aae531ba9e74a90","lessThan":"e7af1b15c884ed12bb69da11aec095045d861ee8","versionType":"git","status":"affected"},{"version":"999dad824c39ed14dee7c4412aae531ba9e74a90","lessThan":"a825691b804b35141aaf4eac91003a70846e316d","versionType":"git","status":"affected"},{"version":"999dad824c39ed14dee7c4412aae531ba9e74a90","lessThan":"2fff0cdd942261497fb8922a194b4da3315ae864","versionType":"git","status":"affected"},{"version":"999dad824c39ed14dee7c4412aae531ba9e74a90","lessThan":"52f72b3f8f6fa64abb71b711962b97f1f6aced1c","versionType":"git","status":"affected"},{"version":"999dad824c39ed14dee7c4412aae531ba9e74a90","lessThan":"be3f38d05cc5a7c3f13e51994c5dd043ab604d28","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["mm/memory.c","tools/testing/selftests/mm/hmm-tests.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"5.19","status":"affected"},{"version":"0","lessThan":"5.19","versionType":"semver","status":"unaffected"},{"version":"6.1.176","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.143","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.93","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.34","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.0.11","lessThanOrEqual":"7.0.*","versionType":"semver","status":"unaffected"},{"version":"7.1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/2fff0cdd942261497fb8922a194b4da3315ae864","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/52f72b3f8f6fa64abb71b711962b97f1f6aced1c","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/a825691b804b35141aaf4eac91003a70846e316d","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/be3f38d05cc5a7c3f13e51994c5dd043ab604d28","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/e7af1b15c884ed12bb69da11aec095045d861ee8","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/e81446b559db4c98a6c2c5e039ac9cb23658432e","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-64135","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-07-19T16:17:55.333","lastModified":"2026-07-19T16:17:55.333","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nhwmon: (pmbus/adm1266) widen blackbox-info buffer to I2C_SMBUS_BLOCK_MAX\n\nadm1266_nvmem_read_blackbox() declares a 5-byte stack buffer and\npasses it to i2c_smbus_read_block_data() to retrieve the 4-byte\nBLACKBOX_INFO response.  i2c_smbus_read_block_data() does not honour\ncaller buffer sizes -- it memcpy()s data.block[0] bytes from the\nSMBus transaction (where data.block[0] is the length byte returned by\nthe slave device, up to I2C_SMBUS_BLOCK_MAX = 32):\n\n\tmemcpy(values, &data.block[1], data.block[0]);\n\nIf the device returns any block length above 5, the call overflows\nthe caller's 5-byte stack buffer before the post-call\n\n\tif (ret != 4)\n\t\treturn -EIO;\n\ncheck has a chance to reject the response.\n\nWiden the local buffer to I2C_SMBUS_BLOCK_MAX so the helper has room\nfor any well-formed SMBus block response, matching the convention used\nby the other i2c_smbus_read_block_data() callers in this driver."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/hwmon/pmbus/adm1266.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"15609d1893020436e1e8ccfd9ded774a96dd17a2","lessThan":"33251abb9c9dd62943be76f0427c5527ee39188f","versionType":"git","status":"affected"},{"version":"15609d1893020436e1e8ccfd9ded774a96dd17a2","lessThan":"ba09f4baa5bd96c5d26c942defa546a72dbbe5bf","versionType":"git","status":"affected"},{"version":"15609d1893020436e1e8ccfd9ded774a96dd17a2","lessThan":"6ed16a40b162e9d87d9ac8bed4d7f0e3e807700e","versionType":"git","status":"affected"},{"version":"15609d1893020436e1e8ccfd9ded774a96dd17a2","lessThan":"0dbf64c502443c08c2e28a77ecbfcc5479d93228","versionType":"git","status":"affected"},{"version":"15609d1893020436e1e8ccfd9ded774a96dd17a2","lessThan":"2b7a698d5093b548c464828d984f05ced5f3fd2a","versionType":"git","status":"affected"},{"version":"15609d1893020436e1e8ccfd9ded774a96dd17a2","lessThan":"ca560f7566df7e2826c2999e959e6b94eb938f76","versionType":"git","status":"affected"},{"version":"15609d1893020436e1e8ccfd9ded774a96dd17a2","lessThan":"7f705e581ef3e6bb308a121a89adf5237d968204","versionType":"git","status":"affected"},{"version":"15609d1893020436e1e8ccfd9ded774a96dd17a2","lessThan":"eee213daa1e1b402eb631bcd1b8c5aa340a6b081","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/hwmon/pmbus/adm1266.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"5.10","status":"affected"},{"version":"0","lessThan":"5.10","versionType":"semver","status":"unaffected"},{"version":"5.10.258","lessThanOrEqual":"5.10.*","versionType":"semver","status":"unaffected"},{"version":"5.15.209","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.175","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.142","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.92","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.34","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.0.11","lessThanOrEqual":"7.0.*","versionType":"semver","status":"unaffected"},{"version":"7.1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/0dbf64c502443c08c2e28a77ecbfcc5479d93228","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/2b7a698d5093b548c464828d984f05ced5f3fd2a","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/33251abb9c9dd62943be76f0427c5527ee39188f","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/6ed16a40b162e9d87d9ac8bed4d7f0e3e807700e","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/7f705e581ef3e6bb308a121a89adf5237d968204","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/ba09f4baa5bd96c5d26c942defa546a72dbbe5bf","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/ca560f7566df7e2826c2999e959e6b94eb938f76","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/eee213daa1e1b402eb631bcd1b8c5aa340a6b081","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-64139","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-07-19T16:17:55.780","lastModified":"2026-07-19T16:17:55.780","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nksmbd: fix SID memory leak in set_posix_acl_entries_dacl() on overflow\n\nCommit 299f962c0b02 (\"ksmbd: use check_add_overflow() to prevent u16\nDACL size overflow\") added check_add_overflow() guards that break out\nof the ACE-building loops in set_posix_acl_entries_dacl() when the\naccumulated DACL size would wrap past 65535.\n\nHowever, each iteration allocates a struct smb_sid via kmalloc_obj()\nat the top of the loop and relies on the kfree(sid) call at the end\nof the loop body (the 'pass_same_sid' label in the first loop, and\nthe explicit kfree at the tail of the second loop) to release it.\nThe newly introduced 'break' statements bypass those kfree() calls,\nleaking the sid buffer every time an overflow is detected.\n\nA malicious or malformed file with enough POSIX ACL entries to trip\nthe overflow check will leak one or more struct smb_sid allocations\non every request that touches the file's DACL, providing a trivial\nkernel memory exhaustion vector.\n\nFree sid before breaking out of the loops to plug the leak."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["fs/smb/server/smbacl.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"8d5729350b236896f51379588d9a690b7fafb8db","lessThan":"9d378e17c864da08c3a4df41dae92cfa6468b00a","versionType":"git","status":"affected"},{"version":"e1955a94b6f17f4b058afa955a6f187eb3ed7615","lessThan":"519fb0a42ce5d7e46935577309fb282a5f2c6ea3","versionType":"git","status":"affected"},{"version":"5e7b8f3c539d69b2ed5f2408e2f75e68ce7eef43","lessThan":"0e198f09cb2a554c04de0fea4e790f1250a943ca","versionType":"git","status":"affected"},{"version":"ef7902be3f215b6bf7babe4dc9dd9a7d57dad7a7","lessThan":"eced48cb08f07393a5ea770fdd1026452883c3ad","versionType":"git","status":"affected"},{"version":"299f962c0b02d048fb45d248b4da493d03f3175d","lessThan":"af92ee994cc7f7e83a41c2025f32257a2f82a7ef","versionType":"git","status":"affected"},{"version":"41e53a773db6342ac9a689ee5ba635c31744c9f0","versionType":"git","status":"affected"},{"version":"6.1.175","lessThan":"6.2","versionType":"semver","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["fs/smb/server/smbacl.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.6.136","lessThan":"6.6.142","versionType":"semver","status":"affected"},{"version":"6.12.84","lessThan":"6.12.92","versionType":"semver","status":"affected"},{"version":"6.18.25","lessThan":"6.18.34","versionType":"semver","status":"affected"},{"version":"7.0.2","lessThan":"7.0.11","versionType":"semver","status":"affected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/0e198f09cb2a554c04de0fea4e790f1250a943ca","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/519fb0a42ce5d7e46935577309fb282a5f2c6ea3","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/9d378e17c864da08c3a4df41dae92cfa6468b00a","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/af92ee994cc7f7e83a41c2025f32257a2f82a7ef","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/eced48cb08f07393a5ea770fdd1026452883c3ad","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-64143","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-07-19T16:17:56.243","lastModified":"2026-07-19T16:17:56.243","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nplatform/x86: uniwill-laptop: Do not enable the charging limit even when forced\n\nIt seems that on some older models (~2020) the battery charging limit\ncan permanently damage the battery. Prevent users from enabling this\nfeature thru the \"force\" module parameter to avoid causing permanent\nhardware damage on such devices."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["Documentation/admin-guide/laptops/uniwill-laptop.rst","drivers/platform/x86/uniwill/uniwill-acpi.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"d050479693bb91da5a0e305ca9dd59f4c0b55dd3","lessThan":"c832a00c9b929b9ad26772833d425f520b2e09cd","versionType":"git","status":"affected"},{"version":"d050479693bb91da5a0e305ca9dd59f4c0b55dd3","lessThan":"26cbe119f99c86dcb4a0136d2bc73c0c716d80e4","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["Documentation/admin-guide/laptops/uniwill-laptop.rst","drivers/platform/x86/uniwill/uniwill-acpi.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.19","status":"affected"},{"version":"0","lessThan":"6.19","versionType":"semver","status":"unaffected"},{"version":"7.0.11","lessThanOrEqual":"7.0.*","versionType":"semver","status":"unaffected"},{"version":"7.1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/26cbe119f99c86dcb4a0136d2bc73c0c716d80e4","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/c832a00c9b929b9ad26772833d425f520b2e09cd","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-64144","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-07-19T16:17:56.347","lastModified":"2026-07-19T16:17:56.347","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nBluetooth: btmtk: fix urb->setup_packet leak in error paths\n\nThe setup_packet of control urb is not freed if usb_submit_urb fails or\nthe submitted urb is killed. Add free in these two paths."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/bluetooth/btmtk.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"a1c49c434e15050b5dafe3b6f5cc732d4f02d657","lessThan":"2a1905730e0c771b999906a7b509722f795563c6","versionType":"git","status":"affected"},{"version":"a1c49c434e15050b5dafe3b6f5cc732d4f02d657","lessThan":"68c027c2003b0a8a1439d0301c59c6fd1eb3b844","versionType":"git","status":"affected"},{"version":"a1c49c434e15050b5dafe3b6f5cc732d4f02d657","lessThan":"a0f5268c77eb73f84ba7c210ddfc54b1c73ff80c","versionType":"git","status":"affected"},{"version":"a1c49c434e15050b5dafe3b6f5cc732d4f02d657","lessThan":"0d2572bafea33c7cd1d77c6a25f25ff31a432482","versionType":"git","status":"affected"},{"version":"a1c49c434e15050b5dafe3b6f5cc732d4f02d657","lessThan":"dd1dda6b8d6e1f4376a5b3055a04f0ecbdb4d6bd","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/bluetooth/btmtk.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"5.3","status":"affected"},{"version":"0","lessThan":"5.3","versionType":"semver","status":"unaffected"},{"version":"6.6.142","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.92","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.34","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.0.11","lessThanOrEqual":"7.0.*","versionType":"semver","status":"unaffected"},{"version":"7.1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/0d2572bafea33c7cd1d77c6a25f25ff31a432482","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/2a1905730e0c771b999906a7b509722f795563c6","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/68c027c2003b0a8a1439d0301c59c6fd1eb3b844","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/a0f5268c77eb73f84ba7c210ddfc54b1c73ff80c","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/dd1dda6b8d6e1f4376a5b3055a04f0ecbdb4d6bd","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-64145","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-07-19T16:17:56.443","lastModified":"2026-07-19T16:17:56.443","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: wilc1000: fix dma_buffer leak on bus acquire failure\n\nwilc_wlan_firmware_download() allocates dma_buffer with kmalloc() at\nthe top of the function and uses a 'fail:' label to free it via\nkfree(dma_buffer) on error.\n\nAll later error paths correctly use 'goto fail' to route through this\ncleanup. However, the early failure path after the first acquire_bus()\ncall uses a bare 'return ret;', which leaks dma_buffer whenever the bus\nacquire fails.\n\nReplace the early return with goto fail so the existing cleanup path\nruns.\n\nFound via a custom Coccinelle semantic patch hunting for kmalloc'd\nlocals leaked on early-return error paths in driver firmware-download\ncode."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/net/wireless/microchip/wilc1000/wlan.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"1241c5650ff7a0236cebb89acca8aade48839fd6","lessThan":"95c82d498d74c4e587db30021ca1aec90e29b5a5","versionType":"git","status":"affected"},{"version":"1241c5650ff7a0236cebb89acca8aade48839fd6","lessThan":"32d7584441b9ecb279a03653b432612546e5efbe","versionType":"git","status":"affected"},{"version":"1241c5650ff7a0236cebb89acca8aade48839fd6","lessThan":"dd7b6a8671939708cc4b7a46786d8c11297e8f69","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/net/wireless/microchip/wilc1000/wlan.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.13","status":"affected"},{"version":"0","lessThan":"6.13","versionType":"semver","status":"unaffected"},{"version":"6.18.34","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.0.11","lessThanOrEqual":"7.0.*","versionType":"semver","status":"unaffected"},{"version":"7.1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/32d7584441b9ecb279a03653b432612546e5efbe","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/95c82d498d74c4e587db30021ca1aec90e29b5a5","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/dd7b6a8671939708cc4b7a46786d8c11297e8f69","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-64146","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-07-19T16:17:56.547","lastModified":"2026-07-19T16:17:56.547","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nerofs: fix metabuf leak in inode xattr initialization\n\ncommit bb88e8da0025 (\"erofs: use meta buffers for xattr operations\")\nconverted xattr operations to use on-stack erofs_buf instances.\nerofs_init_inode_xattrs() uses such a metabuf while reading the inline\nxattr header and shared xattr id array.\n\nSome error paths after erofs_read_metabuf() leave through out_unlock\nwithout dropping the metabuf, so the folio reference can leak.\n\nConsolidate the cleanup at out_unlock. erofs_put_metabuf() is a\nno-op if no folio has been acquired, and this keeps all paths after\ntaking EROFS_I_BL_XATTR_BIT covered by a single cleanup site."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["fs/erofs/xattr.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"bb88e8da00253bea0e7f0f4cdfd7910572d7799f","lessThan":"492c73b21fefa36f3869cb2b188ffb7fe37b3a9b","versionType":"git","status":"affected"},{"version":"bb88e8da00253bea0e7f0f4cdfd7910572d7799f","lessThan":"79b09c54c6563df9846ca3094bcfd72082c3e1d7","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["fs/erofs/xattr.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"5.17","status":"affected"},{"version":"0","lessThan":"5.17","versionType":"semver","status":"unaffected"},{"version":"7.0.11","lessThanOrEqual":"7.0.*","versionType":"semver","status":"unaffected"},{"version":"7.1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/492c73b21fefa36f3869cb2b188ffb7fe37b3a9b","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/79b09c54c6563df9846ca3094bcfd72082c3e1d7","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-64147","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-07-19T16:17:56.643","lastModified":"2026-07-19T16:17:56.643","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\npds_core: fix debugfs_lookup dentry leak and error handling\n\ndebugfs_lookup() returns a dentry with an elevated reference count that\nmust be released with dput(). The current code discards the returned\ndentry without calling dput(), causing a reference leak on every\nfirmware reset recovery.\n\nAdditionally, when CONFIG_DEBUG_FS is disabled, debugfs_lookup()\nreturns ERR_PTR(-ENODEV), not NULL. The current check passes for error\npointers and would call dput() on an invalid pointer, causing a crash."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/net/ethernet/amd/pds_core/debugfs.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"2bbf2b1c20f934a054172175ccbabcc01fe69ef6","lessThan":"60ef1675b652e912f3eb064767af4432393291fd","versionType":"git","status":"affected"},{"version":"bc90fbe0c3182157d2be100a2f6c2edbb1820677","lessThan":"26e19622c485e53c3fdb299e822068a0542ddf0c","versionType":"git","status":"affected"},{"version":"bc90fbe0c3182157d2be100a2f6c2edbb1820677","lessThan":"91d13e92b983e6c6d7631012c2e20ae8057de9f2","versionType":"git","status":"affected"},{"version":"bc90fbe0c3182157d2be100a2f6c2edbb1820677","lessThan":"d7f4dd4c8fb380898fef7a77d48fce7ccdb4fc32","versionType":"git","status":"affected"},{"version":"bc90fbe0c3182157d2be100a2f6c2edbb1820677","lessThan":"dc416e32baaeb620b9809e9e25fc7b30889686e9","versionType":"git","status":"affected"},{"version":"3ffe14c36985e3174933127c9efad82ac8f3fefb","versionType":"git","status":"affected"},{"version":"6.6.16","lessThan":"6.6.142","versionType":"semver","status":"affected"},{"version":"6.7.4","lessThan":"6.8","versionType":"semver","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/net/ethernet/amd/pds_core/debugfs.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.8","status":"affected"},{"version":"0","lessThan":"6.8","versionType":"semver","status":"unaffected"},{"version":"6.6.142","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.92","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.34","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.0.11","lessThanOrEqual":"7.0.*","versionType":"semver","status":"unaffected"},{"version":"7.1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/26e19622c485e53c3fdb299e822068a0542ddf0c","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/60ef1675b652e912f3eb064767af4432393291fd","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/91d13e92b983e6c6d7631012c2e20ae8057de9f2","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/d7f4dd4c8fb380898fef7a77d48fce7ccdb4fc32","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/dc416e32baaeb620b9809e9e25fc7b30889686e9","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-64149","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-07-19T16:17:56.860","lastModified":"2026-07-19T16:17:56.860","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\ndma-mapping: move dma_map_resource() sanity check into debug code\n\ndma_map_resource() uses pfn_valid() to ensure the range is not RAM.\nHowever, pfn_valid() only checks for availability of the memory map for\na PFN but it does not ensure that the PFN is actually backed by RAM. On\nARM64 with SPARSEMEM (128MB section granularity), MMIO addresses that\nshare a section with RAM will falsely trigger the WARN_ON_ONCE and cause\ndma_map_resource() to return DMA_MAPPING_ERROR.\n\nThis causes a WARNING on Raspberry Pi 4 during spi_bcm2835 probe because\nthe SPI FIFO register (0xfe204004) falls in the same sparsemem section\nas the end of RAM (0xf8000000-0xfbffffff), both in section 31\n(0xf8000000-0xffffffff).\n\nMove the sanity check from dma_map_resource() into debug_dma_map_phys()\nand replace the unreliable pfn_valid() with pfn_valid() &&\n!PageReserved(), which correctly identifies actual usable RAM without\nfalse positives for MMIO regions that happen to have struct pages.\n\nSince dma_map_resource() is dma_map_phys(DMA_ATTR_MMIO), the check\napplies equally to both APIs. Any non-reserved page represents kernel\nmemory to a sufficient degree that using DMA_ATTR_MMIO on it is almost\ncertainly wrong and risks breaking coherency on non-coherent platforms.\nZONE_DEVICE pages used for PCI P2P DMA (MEMORY_DEVICE_PCI_P2PDMA) have\nPageReserved set, so they will not trigger a false positive.\n\nThe check no longer blocks the mapping and uses err_printk() to\nintegrate with dma-debug filtering."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["kernel/dma/debug.c","kernel/dma/mapping.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"f7326196a781622b33bfbdabb00f5e72b5fb5679","lessThan":"181e67bc11c5ec5b87c6c512c2078752b23ca8d4","versionType":"git","status":"affected"},{"version":"f7326196a781622b33bfbdabb00f5e72b5fb5679","lessThan":"004a777879ff629f6e0ca3d09ad09fa3452bcc4d","versionType":"git","status":"affected"},{"version":"f7326196a781622b33bfbdabb00f5e72b5fb5679","lessThan":"af0c3f05866237f7592219bfe05387bc3bfc99b5","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["kernel/dma/debug.c","kernel/dma/mapping.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.18","status":"affected"},{"version":"0","lessThan":"6.18","versionType":"semver","status":"unaffected"},{"version":"6.18.34","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.0.11","lessThanOrEqual":"7.0.*","versionType":"semver","status":"unaffected"},{"version":"7.1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/004a777879ff629f6e0ca3d09ad09fa3452bcc4d","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/181e67bc11c5ec5b87c6c512c2078752b23ca8d4","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/af0c3f05866237f7592219bfe05387bc3bfc99b5","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-64154","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-07-19T16:17:57.390","lastModified":"2026-07-19T16:17:57.390","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/msm/adreno: Fix a reference leak in a6xx_gpu_init()\n\nIn a6xx_gpu_init(), node is obtained via of_parse_phandle().\nWhile there was a manual of_node_put() at the end of the\ncommon path, several early error returns would bypass this call,\nresulting in a reference leak.\nFix this by using the __free(device_node) cleanup handler to\nrelease the reference when the variable goes out of scope.\n\nPatchwork: https://patchwork.freedesktop.org/patch/700661/"}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/gpu/drm/msm/adreno/a6xx_gpu.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"5a903a44a98471cedf0021fac0a6a64bbe86943f","lessThan":"2be24c945e76cd538ce5dd2e50f5d3e7d848c175","versionType":"git","status":"affected"},{"version":"5a903a44a98471cedf0021fac0a6a64bbe86943f","lessThan":"e64bca63647db1d5518198d6c5ca2dbcc66b182b","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/gpu/drm/msm/adreno/a6xx_gpu.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.5","status":"affected"},{"version":"0","lessThan":"6.5","versionType":"semver","status":"unaffected"},{"version":"7.0.11","lessThanOrEqual":"7.0.*","versionType":"semver","status":"unaffected"},{"version":"7.1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/2be24c945e76cd538ce5dd2e50f5d3e7d848c175","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/e64bca63647db1d5518198d6c5ca2dbcc66b182b","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-64155","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-07-19T16:17:57.483","lastModified":"2026-07-19T16:17:57.483","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: ath11k: fix error path leaks in some WMI WOW calls\n\nFix two instances where we used to directly return the result of\nath11k_wmi_cmd_send(...). Because we did not check the return value, we\nalso did not free the skb in the error path."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/net/wireless/ath/ath11k/wmi.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"79802b13a492d0fdeb922e98628e5ff1a8b74026","lessThan":"d6c7b8d0dc22c0a8743435db8f42d98524b70df3","versionType":"git","status":"affected"},{"version":"79802b13a492d0fdeb922e98628e5ff1a8b74026","lessThan":"cd43d587dd333517c806cd24696e6e1a26b9951e","versionType":"git","status":"affected"},{"version":"79802b13a492d0fdeb922e98628e5ff1a8b74026","lessThan":"3d675896ea03aca631852a2a7e91e6cb8f664967","versionType":"git","status":"affected"},{"version":"79802b13a492d0fdeb922e98628e5ff1a8b74026","lessThan":"008955b1348452de25bc19d6e0f0f673d4cb9a3c","versionType":"git","status":"affected"},{"version":"79802b13a492d0fdeb922e98628e5ff1a8b74026","lessThan":"acde4692afcdaea6de3e2996ddfaeaa7ae6b0130","versionType":"git","status":"affected"},{"version":"79802b13a492d0fdeb922e98628e5ff1a8b74026","lessThan":"d618d322b95c80d5ad7091f35a7193e4050dcc27","versionType":"git","status":"affected"},{"version":"79802b13a492d0fdeb922e98628e5ff1a8b74026","lessThan":"55dda532bbc261aef495e403c8900c5e2ab5fa34","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/net/wireless/ath/ath11k/wmi.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"5.11","status":"affected"},{"version":"0","lessThan":"5.11","versionType":"semver","status":"unaffected"},{"version":"5.15.209","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.175","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.142","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.92","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.34","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.0.11","lessThanOrEqual":"7.0.*","versionType":"semver","status":"unaffected"},{"version":"7.1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/008955b1348452de25bc19d6e0f0f673d4cb9a3c","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/3d675896ea03aca631852a2a7e91e6cb8f664967","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/55dda532bbc261aef495e403c8900c5e2ab5fa34","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/acde4692afcdaea6de3e2996ddfaeaa7ae6b0130","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/cd43d587dd333517c806cd24696e6e1a26b9951e","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/d618d322b95c80d5ad7091f35a7193e4050dcc27","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/d6c7b8d0dc22c0a8743435db8f42d98524b70df3","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-64156","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-07-19T16:17:57.603","lastModified":"2026-07-19T16:17:57.603","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nnetfs, afs: Fix write skipping in dir/link writepages\n\nFix netfs_write_single() and afs_single_writepages() to better handle a\nwrite that would be skipped due to lock contention and WB_SYNC_NONE by\nreturning 1 from netfs_write_single() if it skipped and making\nafs_single_writepages() skip also.  If a skip occurs, the inode must be\nre-marked as the VFS may have cleared the mark.\n\nThis is really only theoretical for directories in netfs_write_single() as\nthe only path to that is through afs_single_writepages() that takes the\n->validate_lock around it, thereby serialising it."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["fs/afs/dir.c","fs/netfs/write_issue.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6dd80936618c4ff852d4db73aca400351d9bd9f0","lessThan":"77bb293049d61e04c12b24ebbffafaf5ab36af90","versionType":"git","status":"affected"},{"version":"6dd80936618c4ff852d4db73aca400351d9bd9f0","lessThan":"f91e10435c0dd37c48b1b25e6236284f656ddc0c","versionType":"git","status":"affected"},{"version":"6dd80936618c4ff852d4db73aca400351d9bd9f0","lessThan":"9871938f99cc6cb266a77265491660e2375271f5","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["fs/afs/dir.c","fs/netfs/write_issue.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.14","status":"affected"},{"version":"0","lessThan":"6.14","versionType":"semver","status":"unaffected"},{"version":"6.18.34","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.0.11","lessThanOrEqual":"7.0.*","versionType":"semver","status":"unaffected"},{"version":"7.1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/77bb293049d61e04c12b24ebbffafaf5ab36af90","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/9871938f99cc6cb266a77265491660e2375271f5","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/f91e10435c0dd37c48b1b25e6236284f656ddc0c","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-64157","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-07-19T16:17:57.703","lastModified":"2026-07-19T16:17:57.703","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nnetfs: Fix partial invalidation of streaming-write folio\n\nIn netfs_invalidate_folio(), if the region of a partial invalidation\noverlaps the front (but not all) of a dirty write cached in a streaming\nwrite page (dirty, but not uptodate, with the dirty region tracked by a\nnetfs_folio struct), the function modifies the dirty region - but\nincorrectly as it moves the region forward by setting the start to the\nstart, not the end, of the invalidation region.\n\nFix this by setting finfo->dirty_offset to the end of the invalidation\nregion (iend)."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["fs/netfs/misc.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"cce6bfa6ca0e30af9927b0074c97fe6a92f28092","lessThan":"f6b2569ae29b666fd15ff2848684c445ba442a39","versionType":"git","status":"affected"},{"version":"cce6bfa6ca0e30af9927b0074c97fe6a92f28092","lessThan":"3d9601c029b934b5b6a10f99791467b10eb6b211","versionType":"git","status":"affected"},{"version":"cce6bfa6ca0e30af9927b0074c97fe6a92f28092","lessThan":"6a3d27116be2c5fb9a03d5cf37c486ac517f3689","versionType":"git","status":"affected"},{"version":"cce6bfa6ca0e30af9927b0074c97fe6a92f28092","lessThan":"6d91acc7fb85d33ea58fca9b964a32a453937f4b","versionType":"git","status":"affected"},{"version":"e2814004138a541110d4b2dc254a8f619c2c4ce0","versionType":"git","status":"affected"},{"version":"6.10.8","lessThan":"6.11","versionType":"semver","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["fs/netfs/misc.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.11","status":"affected"},{"version":"0","lessThan":"6.11","versionType":"semver","status":"unaffected"},{"version":"6.12.92","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.34","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.0.11","lessThanOrEqual":"7.0.*","versionType":"semver","status":"unaffected"},{"version":"7.1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/3d9601c029b934b5b6a10f99791467b10eb6b211","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/6a3d27116be2c5fb9a03d5cf37c486ac517f3689","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/6d91acc7fb85d33ea58fca9b964a32a453937f4b","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/f6b2569ae29b666fd15ff2848684c445ba442a39","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-64159","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-07-19T16:17:57.913","lastModified":"2026-07-19T16:17:57.913","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nnetfs: Fix zeropoint update where i_size > remote_i_size\n\nFix the update of the zero point[*] by netfs_release_folio() when there is\nuncommitted data in the pagecache beyond the folio being released but the\non-server EOF is in this folio (ie. i_size > remote_i_size).  The update\nneeds to limit zero_point to remote_i_size, not i_size as i_size is a local\nphenomenon reflecting updates made locally to the pagecache, not stuff\nwritten to the server.  remote_i_size tracks the server's i_size.\n\n[*] The zero point is the file position from which we can assume that the\n    server will just return zeros, so we can avoid generating reads.\n\nNote that netfs_invalidate_folio() probably doesn't need fixing as\nzero_point should be updated by setattr after truncation or fallocate.\n\nFound with:\n\n    fsx -q -N 1000000 -p 10000 -o 128000 -l 600000 \\\n        /xfstest.test/junk --replay-ops=junk.fsxops\n\nusing the following as junk.fsxops:\n\n    truncate 0x0 0x1bbae 0x82864\n    write 0x3ef2e 0xf9c8 0x1bbae\n    write 0x67e05 0xcb5a 0x4e8f6\n    mapread 0x57781 0x85b6 0x7495f\n    copy_range 0x5d3d 0x10329 0x54fac 0x7495f\n    write 0x64710 0x1c2b 0x7495f\n    mapread 0x64000 0x1000 0x7495f\n\non cifs with the default cache option.\n\nIt shows read-gaps on folio 0x64 failing with a short read (ie. it hits\nEOF) if the FMODE_READ check is commented out in netfs_perform_write():\n\n                if (//(file->f_mode & FMODE_READ) ||\n                    netfs_is_cache_enabled(ctx)) {\n\nand no fscache.  This was initially found with the generic/522 xfstest."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["fs/netfs/misc.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"cce6bfa6ca0e30af9927b0074c97fe6a92f28092","lessThan":"5cd5207de519ef0c085f4f559adf5eefcb4c5202","versionType":"git","status":"affected"},{"version":"cce6bfa6ca0e30af9927b0074c97fe6a92f28092","lessThan":"4543a4d737944134a1394afe797622546fbcc98a","versionType":"git","status":"affected"},{"version":"e2814004138a541110d4b2dc254a8f619c2c4ce0","versionType":"git","status":"affected"},{"version":"6.10.8","lessThan":"6.11","versionType":"semver","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["fs/netfs/misc.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.11","status":"affected"},{"version":"0","lessThan":"6.11","versionType":"semver","status":"unaffected"},{"version":"7.0.11","lessThanOrEqual":"7.0.*","versionType":"semver","status":"unaffected"},{"version":"7.1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/4543a4d737944134a1394afe797622546fbcc98a","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/5cd5207de519ef0c085f4f559adf5eefcb4c5202","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-64161","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-07-19T16:17:58.113","lastModified":"2026-07-19T16:17:58.113","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nnet: ti: icssm-prueth: fix eth_ports_node leak in probe\n\nThe error path on of_property_read_u32() failure inside\nicssm_prueth_probe() returns without putting eth_ports_node,\nwhich was acquired before the for_each_child_of_node() loop.\n\nDrop it before returning."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/net/ethernet/ti/icssm/icssm_prueth.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"511f6c1ae093c7045742299d29eba71925709a71","lessThan":"994358adc0982d17731ffea7dfacd25afcc89773","versionType":"git","status":"affected"},{"version":"511f6c1ae093c7045742299d29eba71925709a71","lessThan":"ca029dde6ad732a5aba28d6b107d7a84ba5e302b","versionType":"git","status":"affected"},{"version":"511f6c1ae093c7045742299d29eba71925709a71","lessThan":"6635fa84403c3a59455b66007c019a7cc632db30","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/net/ethernet/ti/icssm/icssm_prueth.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.18","status":"affected"},{"version":"0","lessThan":"6.18","versionType":"semver","status":"unaffected"},{"version":"6.18.34","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.0.11","lessThanOrEqual":"7.0.*","versionType":"semver","status":"unaffected"},{"version":"7.1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/6635fa84403c3a59455b66007c019a7cc632db30","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/994358adc0982d17731ffea7dfacd25afcc89773","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/ca029dde6ad732a5aba28d6b107d7a84ba5e302b","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-64163","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-07-19T16:17:58.327","lastModified":"2026-07-19T16:17:58.327","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\ntest_kprobes: clear kprobes between test runs\n\nRunning the kprobes sanity tests twice makes all tests fail and\neventually crashes the kernel.\n\n[root@martin-riscv-1 ~]# echo 1 > /sys/kernel/debug/kunit/kprobes_test/run\n...\n   # Totals: pass:5 fail:0 skip:0 total:5\n   ok 1 kprobes_test\n[root@martin-riscv-1 ~]# echo 1 > /sys/kernel/debug/kunit/kprobes_test/run\n...\n  # test_kprobe: EXPECTATION FAILED at lib/tests/test_kprobes.c:64\n  Expected 0 == register_kprobe(&kp), but\n      register_kprobe(&kp) == -22 (0xffffffffffffffea)\n...\n  Unable to handle kernel paging request ...\n\nThe testsuite defines several kprobes and kretprobes as static variables\nthat are preserved across test runs.\n\nAfter register_kprobe and unregister_kprobe, a kprobe contains some\nleftover data that must be cleared before the kprobe can be registered\nagain. The tests are setting symbol_name to define the probe location.\nAddress and flags must be cleared.\n\nThe existing code clears some of the probes between subsequent tests, but\nnot between two test runs. The leftover data from a previous test run\nmakes the registrations fail in the next run.\n\nMove the cleanups for all kprobes into kprobes_test_init, this function\nis called before each single test (including the first test of a test\nrun)."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["lib/tests/test_kprobes.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"e44e81c5b90f698025eadceb7eef8661eda117d5","lessThan":"08d355936fcf70c81c94f9fe7310450b65c53399","versionType":"git","status":"affected"},{"version":"e44e81c5b90f698025eadceb7eef8661eda117d5","lessThan":"accc0004c501a9918313142282b094d408af06fb","versionType":"git","status":"affected"},{"version":"e44e81c5b90f698025eadceb7eef8661eda117d5","lessThan":"1c24cf1fd67f6702c719ab73499392cb7af956ae","versionType":"git","status":"affected"},{"version":"e44e81c5b90f698025eadceb7eef8661eda117d5","lessThan":"96515819d79f356f40da5540968d838ea570fab9","versionType":"git","status":"affected"},{"version":"e44e81c5b90f698025eadceb7eef8661eda117d5","lessThan":"ef5581bb30efb939cc2bf093475c6cc85258e5cd","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["lib/tests/test_kprobes.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"5.16","status":"affected"},{"version":"0","lessThan":"5.16","versionType":"semver","status":"unaffected"},{"version":"6.6.142","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.92","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.34","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.0.11","lessThanOrEqual":"7.0.*","versionType":"semver","status":"unaffected"},{"version":"7.1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/08d355936fcf70c81c94f9fe7310450b65c53399","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/1c24cf1fd67f6702c719ab73499392cb7af956ae","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/96515819d79f356f40da5540968d838ea570fab9","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/accc0004c501a9918313142282b094d408af06fb","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/ef5581bb30efb939cc2bf093475c6cc85258e5cd","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-64164","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-07-19T16:17:58.450","lastModified":"2026-07-19T16:17:58.450","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nbtrfs: tracepoints: fix sleep while in atomic context in btrfs_sync_file()\n\nThe trace event btrfs_sync_file() is called in an atomic context (all trace\nevents are) and its call to dput(), which is needed due to the call to\ndget_parent(), can sleep, triggering a kernel splat.\n\nThis can be reproduced by enabling the trace event and running btrfs/056\nfrom fstests for example. The splat shown in dmesg is the following:\n\n  [53.919] BUG: sleeping function called from invalid context at fs/dcache.c:970\n  [53.947] in_atomic(): 1, irqs_disabled(): 0, non_block: 0, pid: 32773, name: xfs_io\n  [53.988] preempt_count: 2, expected: 0\n  [53.967] RCU nest depth: 0, expected: 0\n  [53.943] Preemption disabled at:\n  [53.944] [<0000000000000000>] 0x0\n  [54.078] CPU: 0 UID: 0 PID: 32773 Comm: xfs_io Tainted: G        W           7.1.0-rc1-btrfs-next-232+ #1 PREEMPT(full)\n  [54.070] Tainted: [W]=WARN\n  [54.071] Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS rel-1.16.2-0-gea1b7a073390-prebuilt.qemu.org 04/01/2014\n  [54.072] Call Trace:\n  [54.074]  <TASK>\n  [54.076]  dump_stack_lvl+0x56/0x80\n  [54.079]  __might_resched.cold+0xd6/0x10f\n  [54.072]  dput.part.0+0x24/0x110\n  [54.078]  trace_event_raw_event_btrfs_sync_file+0x75/0x140 [btrfs]\n  [54.089]  btrfs_sync_file+0x1ed/0x530 [btrfs]\n  [54.087]  ? __handle_mm_fault+0x8ae/0xed0\n  [54.089]  btrfs_do_write_iter+0x172/0x210 [btrfs]\n  [54.091]  vfs_write+0x21f/0x450\n  [54.094]  __x64_sys_pwrite64+0x8d/0xc0\n  [54.096]  ? do_user_addr_fault+0x20c/0x670\n  [54.099]  do_syscall_64+0x60/0xf20\n  [54.092]  ? clear_bhb_loop+0x60/0xb0\n  [54.094]  entry_SYSCALL_64_after_hwframe+0x76/0x7e\n\nSo stop using dget_parent() and dput() and access the parent dentry\ndirectly as dentry->d_parent. This is also what ext4 is doing in\nits equivalent trace event ext4_sync_file_enter()."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["include/trace/events/btrfs.h"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"4a7bab35fad5251c8cb738161152578cd83b6b9c","lessThan":"d78b0a80eac36879ef5478707135c446920e134b","versionType":"git","status":"affected"},{"version":"520e8b4bcf872a534a7bf61ccf880047642df296","lessThan":"4361954f0e158af0530caa1e57f12b531be4658f","versionType":"git","status":"affected"},{"version":"e252db8ca2a01f82d472091f35d549b313278636","lessThan":"6279992c9ba2774901c9d4dd4a481162e2534714","versionType":"git","status":"affected"},{"version":"c09a7446aab5773f38d6abb25fce99b8e1dfbc97","lessThan":"26b2290baaf6da6add0f782a100766e686a33f4f","versionType":"git","status":"affected"},{"version":"32372781d664a9b03c40343e96c29d0a6139f97d","lessThan":"12a0487945c09760a5968d9333383014ea294117","versionType":"git","status":"affected"},{"version":"2e4adfaec97ee053ad1bdfb5036845e66f7e0d8a","lessThan":"c32a7e0e3c73c1c0768556a56bd78de9f7b83780","versionType":"git","status":"affected"},{"version":"a85b46db143fda5869e7d8df8f258ccef5fa1719","lessThan":"0a96d9a85cd2240481297156b9bb72e10b7a8036","versionType":"git","status":"affected"},{"version":"a85b46db143fda5869e7d8df8f258ccef5fa1719","lessThan":"c73370c677646e86fc4b1780fb07027bdf847375","versionType":"git","status":"affected"},{"version":"d110d7cdb045715c0b45b0dfd974525bb38f653d","versionType":"git","status":"affected"},{"version":"6.6.136","lessThan":"6.6.142","versionType":"semver","status":"affected"},{"version":"6.12.83","lessThan":"6.12.92","versionType":"semver","status":"affected"},{"version":"6.18.24","lessThan":"6.18.34","versionType":"semver","status":"affected"},{"version":"6.19.14","lessThan":"6.20","versionType":"semver","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["include/trace/events/btrfs.h"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"7.0","status":"affected"},{"version":"0","lessThan":"7.0","versionType":"semver","status":"unaffected"},{"version":"6.6.142","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.92","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.34","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.0.11","lessThanOrEqual":"7.0.*","versionType":"semver","status":"unaffected"},{"version":"7.1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/0a96d9a85cd2240481297156b9bb72e10b7a8036","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/12a0487945c09760a5968d9333383014ea294117","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/26b2290baaf6da6add0f782a100766e686a33f4f","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/4361954f0e158af0530caa1e57f12b531be4658f","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/6279992c9ba2774901c9d4dd4a481162e2534714","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/c32a7e0e3c73c1c0768556a56bd78de9f7b83780","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/c73370c677646e86fc4b1780fb07027bdf847375","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/d78b0a80eac36879ef5478707135c446920e134b","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-64165","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-07-19T16:17:58.587","lastModified":"2026-07-19T16:17:58.587","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nARM: integrator: Fix early initialization\n\nStarting with commit bdb249fce9ad4 (\"ARM: integrator: read counter using\nsyscon/regmap\"), intcp_init_early calls syscon_regmap_lookup_by_compatible\nwhich in turn calls of_syscon_register. This function allocates memory.\nSince the memory management code has not been initialized at that time,\nthe call always fails. It either returns -ENOMEM or crashes as follows.\n\nUnable to handle kernel NULL pointer dereference at virtual address 0000000c when read\n[0000000c] *pgd=00000000\nInternal error: Oops: 5 [#1] ARM\nModules linked in:\nCPU: 0 UID: 0 PID: 0 Comm: swapper Not tainted 6.15.0-rc5-00026-g5fcc9bf84ee5 #1 PREEMPT\nHardware name: ARM Integrator/CP (Device Tree)\nPC is at __kmalloc_cache_noprof+0xec/0x39c\nLR is at __kmalloc_cache_noprof+0x34/0x39c\n...\nCall trace:\n __kmalloc_cache_noprof from of_syscon_register+0x7c/0x310\n of_syscon_register from device_node_get_regmap+0xa4/0xb0\n device_node_get_regmap from intcp_init_early+0xc/0x40\n intcp_init_early from start_kernel+0x60/0x688\n start_kernel from 0x0\n\nThe crash is seen due to a dereferenced pointer which is not supposed to be\nNULL but is NULL if the memory management subsystem has not been\ninitialized. The crash is not seen with all versions of gcc. Some versions\nsuch as gcc 9.x apparently do not dereference the pointer, presumably if\ntracing is disabled. The problem has been reproduced with gcc 10.x, 11.x,\nand 13.x. Either case, if the crash is not seen, the call to\nsyscon_regmap_lookup_by_compatible returns -ENOMEM, and\nsched_clock_register is never called.\n\nFix the problem by moving the early initialization code into the standard\nmachine initialization code."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["arch/arm/mach-versatile/integrator_cp.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"bdb249fce9ad44aab340be3b7a77060114f7193b","lessThan":"22c738fb51f2d8b23ddff5cc0ccb2dd685bb39d3","versionType":"git","status":"affected"},{"version":"bdb249fce9ad44aab340be3b7a77060114f7193b","lessThan":"812103fb6da904bd03d62cf6a9826e537318ceed","versionType":"git","status":"affected"},{"version":"bdb249fce9ad44aab340be3b7a77060114f7193b","lessThan":"6624854554c4c2bdfed3559e5c11bb03b16e7bd1","versionType":"git","status":"affected"},{"version":"bdb249fce9ad44aab340be3b7a77060114f7193b","lessThan":"508b1193d63b5e073a3fe103eeb785fcba2d368c","versionType":"git","status":"affected"},{"version":"bdb249fce9ad44aab340be3b7a77060114f7193b","lessThan":"58a112b0973f6cd6bcb8c503d1ff88be411ed0f0","versionType":"git","status":"affected"},{"version":"bdb249fce9ad44aab340be3b7a77060114f7193b","lessThan":"e984dc22e2c24dc34d6728e338c82b1ce7862753","versionType":"git","status":"affected"},{"version":"bdb249fce9ad44aab340be3b7a77060114f7193b","lessThan":"33ad014abec90f37dade0e00560f28864187e21a","versionType":"git","status":"affected"},{"version":"bdb249fce9ad44aab340be3b7a77060114f7193b","lessThan":"90d77b30a666049ad24df463f52e5d529c44e8cd","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["arch/arm/mach-versatile/integrator_cp.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"4.9","status":"affected"},{"version":"0","lessThan":"4.9","versionType":"semver","status":"unaffected"},{"version":"5.10.258","lessThanOrEqual":"5.10.*","versionType":"semver","status":"unaffected"},{"version":"5.15.209","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.175","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.142","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.92","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.34","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.0.11","lessThanOrEqual":"7.0.*","versionType":"semver","status":"unaffected"},{"version":"7.1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/22c738fb51f2d8b23ddff5cc0ccb2dd685bb39d3","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/33ad014abec90f37dade0e00560f28864187e21a","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/508b1193d63b5e073a3fe103eeb785fcba2d368c","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/58a112b0973f6cd6bcb8c503d1ff88be411ed0f0","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/6624854554c4c2bdfed3559e5c11bb03b16e7bd1","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/812103fb6da904bd03d62cf6a9826e537318ceed","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/90d77b30a666049ad24df463f52e5d529c44e8cd","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/e984dc22e2c24dc34d6728e338c82b1ce7862753","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-64166","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-07-19T16:17:58.723","lastModified":"2026-07-19T16:17:58.723","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nfirmware: arm_ffa: Check for NULL FF-A ID table while driver registration\n\nThe bus match callback assumes that every FF-A driver provides an\nid_table and dereferences it unconditionally. Enforce that contract at\nregistration time so a buggy client driver cannot crash the bus during\nmatch."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/firmware/arm_ffa/bus.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"92743071464fca5acbbe812d9a0d88de3eaaad36","lessThan":"f98f131256beaddd51ad468e95d90d857fef12bf","versionType":"git","status":"affected"},{"version":"92743071464fca5acbbe812d9a0d88de3eaaad36","lessThan":"bc499d1acddbb75b5b4bce05f5296dd8ef9611fd","versionType":"git","status":"affected"},{"version":"92743071464fca5acbbe812d9a0d88de3eaaad36","lessThan":"adfff93d08a2e12ecf2a1eba272d18bc749f13c0","versionType":"git","status":"affected"},{"version":"92743071464fca5acbbe812d9a0d88de3eaaad36","lessThan":"34f59211984f66788390e7469f3e99d3796db4a8","versionType":"git","status":"affected"},{"version":"92743071464fca5acbbe812d9a0d88de3eaaad36","lessThan":"820245d86ce58898fb48b4fefc77d0cafc02801d","versionType":"git","status":"affected"},{"version":"92743071464fca5acbbe812d9a0d88de3eaaad36","lessThan":"198f6c86d508ed562f07dc00276cac6dbb5dd3bf","versionType":"git","status":"affected"},{"version":"92743071464fca5acbbe812d9a0d88de3eaaad36","lessThan":"0a5e695095c557d2380131b613dea4e8d90371be","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/firmware/arm_ffa/bus.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"5.14","status":"affected"},{"version":"0","lessThan":"5.14","versionType":"semver","status":"unaffected"},{"version":"5.15.209","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.175","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.142","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.92","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.34","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.0.11","lessThanOrEqual":"7.0.*","versionType":"semver","status":"unaffected"},{"version":"7.1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/0a5e695095c557d2380131b613dea4e8d90371be","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/198f6c86d508ed562f07dc00276cac6dbb5dd3bf","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/34f59211984f66788390e7469f3e99d3796db4a8","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/820245d86ce58898fb48b4fefc77d0cafc02801d","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/adfff93d08a2e12ecf2a1eba272d18bc749f13c0","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/bc499d1acddbb75b5b4bce05f5296dd8ef9611fd","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/f98f131256beaddd51ad468e95d90d857fef12bf","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-64167","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-07-19T16:17:58.833","lastModified":"2026-07-19T16:17:58.833","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nkho: skip KHO for crash kernel\n\nkho_fill_kimage() unconditionally populates the kimage with KHO\nmetadata for every kexec image type. When the image is a crash kernel,\nthis can be problematic as the crash kernel can run in a small reserved\nregion and the KHO scratch areas can sit outside it.\nThe crash kernel then faults during kho_memory_init() when it\ntries phys_to_virt() on the KHO FDT address:\n\n  Unable to handle kernel paging request at virtual address xxxxxxxx\n  ...\n    fdt_offset_ptr+...\n    fdt_check_node_offset_+...\n    fdt_first_property_offset+...\n    fdt_get_property_namelen_+...\n    fdt_getprop+...\n    kho_memory_init+...\n    mm_core_init+...\n    start_kernel+...\n\nkho_locate_mem_hole() already skips KHO logic for KEXEC_TYPE_CRASH\nimages, but kho_fill_kimage() was missing the same guard. As\nkho_fill_kimage() is the single point that populates image->kho.fdt\nand image->kho.scratch, fixing it here is sufficient for both arm64\nand x86 as the FDT and boot_params path are bailing out when these\nfields are unset."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["kernel/liveupdate/kexec_handover.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"d7255959b69a4e727c61eb04231d11390d4f391e","lessThan":"a6ac6721326a75ff2d14c68db05f93b576d8762f","versionType":"git","status":"affected"},{"version":"d7255959b69a4e727c61eb04231d11390d4f391e","lessThan":"a6715d7ec472a476db17787697a4abda62962284","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["kernel/liveupdate/kexec_handover.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.19","status":"affected"},{"version":"0","lessThan":"6.19","versionType":"semver","status":"unaffected"},{"version":"7.0.11","lessThanOrEqual":"7.0.*","versionType":"semver","status":"unaffected"},{"version":"7.1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/a6715d7ec472a476db17787697a4abda62962284","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/a6ac6721326a75ff2d14c68db05f93b576d8762f","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-64168","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-07-19T16:17:58.937","lastModified":"2026-07-19T16:17:58.937","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nspi: sprd: fix error pointer deref after DMA setup failure\n\nThe driver falls back to PIO mode if DMA setup fails during probe.\n\nMake sure to check the dma.enabled flag before trying to release the DMA\nchannels also on late probe errors to avoid dereferencing an error\npointer (or attempting to release a channel a second time).\n\nThis issue was flagged by Sashiko when reviewing a devres allocation\nconversion patch."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/spi/spi-sprd.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"386119bc7be9fa5114ced0274a22a943df890b4b","lessThan":"be74e276111f3c23b8e040c8c5e308f67a573add","versionType":"git","status":"affected"},{"version":"386119bc7be9fa5114ced0274a22a943df890b4b","lessThan":"a8f233fb0c7be29b97cd249f64120bf35ce72805","versionType":"git","status":"affected"},{"version":"386119bc7be9fa5114ced0274a22a943df890b4b","lessThan":"0cdea166c1a07c200caf9d0b722224fca43b23ae","versionType":"git","status":"affected"},{"version":"386119bc7be9fa5114ced0274a22a943df890b4b","lessThan":"450c319dd04d0eeff4184889768f7ada826a2e35","versionType":"git","status":"affected"},{"version":"386119bc7be9fa5114ced0274a22a943df890b4b","lessThan":"b6f1acf4e57ccf708cdc0cb70f5bb5b65162963b","versionType":"git","status":"affected"},{"version":"386119bc7be9fa5114ced0274a22a943df890b4b","lessThan":"be409d2bbe9ca7da7b05cc7dde7499bc481f0766","versionType":"git","status":"affected"},{"version":"386119bc7be9fa5114ced0274a22a943df890b4b","lessThan":"c33b4496e95d04722055446c0a31213639438536","versionType":"git","status":"affected"},{"version":"386119bc7be9fa5114ced0274a22a943df890b4b","lessThan":"3d67fffb74267772d461c02c67f1eff893ad547d","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/spi/spi-sprd.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"5.1","status":"affected"},{"version":"0","lessThan":"5.1","versionType":"semver","status":"unaffected"},{"version":"5.10.258","lessThanOrEqual":"5.10.*","versionType":"semver","status":"unaffected"},{"version":"5.15.209","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.175","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.142","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.92","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.34","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.0.11","lessThanOrEqual":"7.0.*","versionType":"semver","status":"unaffected"},{"version":"7.1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/0cdea166c1a07c200caf9d0b722224fca43b23ae","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/3d67fffb74267772d461c02c67f1eff893ad547d","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/450c319dd04d0eeff4184889768f7ada826a2e35","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/a8f233fb0c7be29b97cd249f64120bf35ce72805","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/b6f1acf4e57ccf708cdc0cb70f5bb5b65162963b","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/be409d2bbe9ca7da7b05cc7dde7499bc481f0766","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/be74e276111f3c23b8e040c8c5e308f67a573add","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/c33b4496e95d04722055446c0a31213639438536","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-64169","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-07-19T16:17:59.060","lastModified":"2026-07-19T16:17:59.060","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nspi: ep93xx: fix error pointer deref after DMA setup failure\n\nThe driver falls back to PIO mode if DMA setup fails during probe.\n\nMake sure to the clear the DMA channel pointers on setup failure to\navoid dereferencing an error pointer on later probe errors or driver\nunbind.\n\nThis issue was flagged by Sashiko when reviewing a devres allocation\nconversion patch."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/spi/spi-ep93xx.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"e79e7c2df6277ee1ad9364a231f6183da4492415","lessThan":"b6c0dabea07e25bd7db19a77ebfd0d02b9e2671a","versionType":"git","status":"affected"},{"version":"e79e7c2df6277ee1ad9364a231f6183da4492415","lessThan":"8e027db9fa310b1d5e7ad928510be800c4f004d9","versionType":"git","status":"affected"},{"version":"e79e7c2df6277ee1ad9364a231f6183da4492415","lessThan":"0e2189ab095e3657f37b8295f3f2bbcde0f27529","versionType":"git","status":"affected"},{"version":"e79e7c2df6277ee1ad9364a231f6183da4492415","lessThan":"5e121a81667a83e9a01d62b429e340f5a4a84abc","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/spi/spi-ep93xx.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.12","status":"affected"},{"version":"0","lessThan":"6.12","versionType":"semver","status":"unaffected"},{"version":"6.12.92","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.34","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.0.11","lessThanOrEqual":"7.0.*","versionType":"semver","status":"unaffected"},{"version":"7.1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/0e2189ab095e3657f37b8295f3f2bbcde0f27529","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/5e121a81667a83e9a01d62b429e340f5a4a84abc","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/8e027db9fa310b1d5e7ad928510be800c4f004d9","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/b6c0dabea07e25bd7db19a77ebfd0d02b9e2671a","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-64170","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-07-19T16:17:59.163","lastModified":"2026-07-19T16:17:59.163","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nspi: qup: fix error pointer deref after DMA setup failure\n\nThe driver falls back to PIO mode if DMA setup fails during probe.\n\nMake sure to the clear the DMA channel pointers on setup failure to\navoid dereferencing an error pointer (or attempting to release a channel\na second time) on later probe errors or driver unbind.\n\nThis issue was flagged by Sashiko when reviewing a devres allocation\nconversion patch."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/spi/spi-qup.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"612762e82ae6058d69b4ce734598491bf030afe7","lessThan":"0bb3bd442f0bdad3932739a61dd6c580c9c1955e","versionType":"git","status":"affected"},{"version":"612762e82ae6058d69b4ce734598491bf030afe7","lessThan":"d577c55d189e7ae150973058d13e299b6855633f","versionType":"git","status":"affected"},{"version":"612762e82ae6058d69b4ce734598491bf030afe7","lessThan":"9e673affb92c29d9ba879bf4ea81c5e840166b56","versionType":"git","status":"affected"},{"version":"612762e82ae6058d69b4ce734598491bf030afe7","lessThan":"45760b72e84c1a1498f1a8a9047184c85299da20","versionType":"git","status":"affected"},{"version":"612762e82ae6058d69b4ce734598491bf030afe7","lessThan":"8f9b61d255b1e989b8913b06c8ebe0aba5e1b238","versionType":"git","status":"affected"},{"version":"612762e82ae6058d69b4ce734598491bf030afe7","lessThan":"4bb4764f2c51f03f657a28029eb0595d8223aab5","versionType":"git","status":"affected"},{"version":"612762e82ae6058d69b4ce734598491bf030afe7","lessThan":"4f4051e9d644c371c50de4a042b85bba6727d5c3","versionType":"git","status":"affected"},{"version":"612762e82ae6058d69b4ce734598491bf030afe7","lessThan":"a7e8f3efd50a165ba0189f6dc57f7e51a7d149db","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/spi/spi-qup.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"4.1","status":"affected"},{"version":"0","lessThan":"4.1","versionType":"semver","status":"unaffected"},{"version":"5.10.259","lessThanOrEqual":"5.10.*","versionType":"semver","status":"unaffected"},{"version":"5.15.210","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.176","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.142","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.92","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.34","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.0.11","lessThanOrEqual":"7.0.*","versionType":"semver","status":"unaffected"},{"version":"7.1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/0bb3bd442f0bdad3932739a61dd6c580c9c1955e","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/45760b72e84c1a1498f1a8a9047184c85299da20","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/4bb4764f2c51f03f657a28029eb0595d8223aab5","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/4f4051e9d644c371c50de4a042b85bba6727d5c3","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/8f9b61d255b1e989b8913b06c8ebe0aba5e1b238","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/9e673affb92c29d9ba879bf4ea81c5e840166b56","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/a7e8f3efd50a165ba0189f6dc57f7e51a7d149db","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/d577c55d189e7ae150973058d13e299b6855633f","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-64171","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-07-19T16:17:59.283","lastModified":"2026-07-19T16:17:59.283","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\ni2c: tegra: fix pm_runtime leak on mutex_lock failure\n\nIf tegra_i2c_mutex_lock() fails, the function returns without calling\npm_runtime_put(), leaking the runtime PM reference acquired by the\npreceding pm_runtime_get_sync(). This prevents the device from ever\nentering runtime suspend.\n\nAdd the missing pm_runtime_put() before returning on lock failure."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/i2c/busses/i2c-tegra.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6077cfd716fbd4d1f2a3702e49ae8bf65c072685","lessThan":"8f7ed203b39004c02479a9156089d87d1ac2c1d8","versionType":"git","status":"affected"},{"version":"6077cfd716fbd4d1f2a3702e49ae8bf65c072685","lessThan":"57cf4e8d6a57dc2ef5810f4852a23ba4c71b74bb","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/i2c/busses/i2c-tegra.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"7.0","status":"affected"},{"version":"0","lessThan":"7.0","versionType":"semver","status":"unaffected"},{"version":"7.0.11","lessThanOrEqual":"7.0.*","versionType":"semver","status":"unaffected"},{"version":"7.1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/57cf4e8d6a57dc2ef5810f4852a23ba4c71b74bb","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/8f7ed203b39004c02479a9156089d87d1ac2c1d8","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-64173","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-07-19T16:17:59.493","lastModified":"2026-07-19T16:17:59.493","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\ntracing: Do not call map->ops->elt_free() if elt_alloc() fails\n\nIn paths where tracing_map_elt_alloc() failed to allocate objects,\nthe map->ops->elt_alloc() call was never successful. In this case,\nmap->ops->elt_free() should not be called."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["kernel/trace/tracing_map.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"2734b629525a9dae5bf217cbf0a9651da93d2108","lessThan":"49332e49ad5b20262cc719b03d4123b9362de701","versionType":"git","status":"affected"},{"version":"2734b629525a9dae5bf217cbf0a9651da93d2108","lessThan":"b559a218eece132de0c58d444877b5627cbee524","versionType":"git","status":"affected"},{"version":"2734b629525a9dae5bf217cbf0a9651da93d2108","lessThan":"b427e9f6d81c9341cba23ef92f860f99f830d91d","versionType":"git","status":"affected"},{"version":"2734b629525a9dae5bf217cbf0a9651da93d2108","lessThan":"f383cff9fb382139980bac1bcd3f3f5d59f68435","versionType":"git","status":"affected"},{"version":"2734b629525a9dae5bf217cbf0a9651da93d2108","lessThan":"1a150947f8480262a46c860f1acb9c6597ca7097","versionType":"git","status":"affected"},{"version":"2734b629525a9dae5bf217cbf0a9651da93d2108","lessThan":"798183376d9d3e278a270ea0e75a5769c8f145d9","versionType":"git","status":"affected"},{"version":"2734b629525a9dae5bf217cbf0a9651da93d2108","lessThan":"b6723339736320b2e1784258ad4490cec7aac11a","versionType":"git","status":"affected"},{"version":"2734b629525a9dae5bf217cbf0a9651da93d2108","lessThan":"8f0f5c4fb9df0e19a341e0c6ed8dc4fda9124f03","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["kernel/trace/tracing_map.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"4.17","status":"affected"},{"version":"0","lessThan":"4.17","versionType":"semver","status":"unaffected"},{"version":"5.10.258","lessThanOrEqual":"5.10.*","versionType":"semver","status":"unaffected"},{"version":"5.15.209","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.175","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.142","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.92","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.34","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.0.11","lessThanOrEqual":"7.0.*","versionType":"semver","status":"unaffected"},{"version":"7.1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/1a150947f8480262a46c860f1acb9c6597ca7097","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/49332e49ad5b20262cc719b03d4123b9362de701","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/798183376d9d3e278a270ea0e75a5769c8f145d9","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/8f0f5c4fb9df0e19a341e0c6ed8dc4fda9124f03","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/b427e9f6d81c9341cba23ef92f860f99f830d91d","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/b559a218eece132de0c58d444877b5627cbee524","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/b6723339736320b2e1784258ad4490cec7aac11a","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/f383cff9fb382139980bac1bcd3f3f5d59f68435","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-64174","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-07-19T16:17:59.617","lastModified":"2026-07-19T16:17:59.617","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: cfg80211: advance loop vars in cfg80211_merge_profile()\n\ncfg80211_merge_profile() reassembles a Multi-BSSID non-transmitted BSS\nprofile that has been split across multiple consecutive MBSSID elements.\nIts while-loop calls\n\n\tcfg80211_get_profile_continuation(ie, ielen, mbssid_elem, sub_elem)\n\nbut never advances mbssid_elem or sub_elem inside the body.  Each\niteration therefore searches for a continuation that follows the same\nfixed pair; the helper returns the same next_mbssid; and the same\nnext_sub bytes are memcpy()'d into merged_ie at a growing offset until\nthe buffer fills.\n\nAdvance both mbssid_elem and sub_elem to the just-consumed continuation\nso the next call to cfg80211_get_profile_continuation() searches for a\nfurther continuation beyond it (or returns NULL when none exists).\n\nA specially-crafted malicious beacon can take advantage of this bug\nto cause the kernel to spend an excessive amount of time in\ncfg80211_merge_profile (up to as much as 2ms per beacon received),\nwhich could theoretically be abused in some way."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["net/wireless/scan.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"fe806e4992c9047affd263bcc13b2c047029a726","lessThan":"5817e1e5205498a5df66eba2b34e817f4210fd0f","versionType":"git","status":"affected"},{"version":"fe806e4992c9047affd263bcc13b2c047029a726","lessThan":"cedbb608494ba1e7a5c6c56b7f1d3fd470094f28","versionType":"git","status":"affected"},{"version":"fe806e4992c9047affd263bcc13b2c047029a726","lessThan":"c0bc4c8bd556cbe036a5b9ed333c0aab9aadfcb8","versionType":"git","status":"affected"},{"version":"fe806e4992c9047affd263bcc13b2c047029a726","lessThan":"1ced0f5a851f9cae274545a42a06c459b7fd8881","versionType":"git","status":"affected"},{"version":"fe806e4992c9047affd263bcc13b2c047029a726","lessThan":"67915715fd3874057457363c87c63e18829527df","versionType":"git","status":"affected"},{"version":"fe806e4992c9047affd263bcc13b2c047029a726","lessThan":"6cfae4914439878b8acb35c7e3b40096eeb2ad9c","versionType":"git","status":"affected"},{"version":"fe806e4992c9047affd263bcc13b2c047029a726","lessThan":"1343a480f84b80c1249133a90ef87f8751d65cbb","versionType":"git","status":"affected"},{"version":"fe806e4992c9047affd263bcc13b2c047029a726","lessThan":"7666dbb1bacc4ba522b96740cba7283d243d16e1","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["net/wireless/scan.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"5.2","status":"affected"},{"version":"0","lessThan":"5.2","versionType":"semver","status":"unaffected"},{"version":"5.10.258","lessThanOrEqual":"5.10.*","versionType":"semver","status":"unaffected"},{"version":"5.15.209","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.175","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.142","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.92","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.34","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.0.11","lessThanOrEqual":"7.0.*","versionType":"semver","status":"unaffected"},{"version":"7.1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/1343a480f84b80c1249133a90ef87f8751d65cbb","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/1ced0f5a851f9cae274545a42a06c459b7fd8881","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/5817e1e5205498a5df66eba2b34e817f4210fd0f","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/67915715fd3874057457363c87c63e18829527df","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/6cfae4914439878b8acb35c7e3b40096eeb2ad9c","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/7666dbb1bacc4ba522b96740cba7283d243d16e1","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/c0bc4c8bd556cbe036a5b9ed333c0aab9aadfcb8","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/cedbb608494ba1e7a5c6c56b7f1d3fd470094f28","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-64177","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-07-19T16:17:59.977","lastModified":"2026-07-19T16:17:59.977","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nphonet/pep: disable BH around forwarded sk_receive_skb()\n\nThe networking receive path is usually run from softirq context, but\nprotocols that take the socket lock may have packets stored in the\nbacklog and processed later from process context. In that case\nrelease_sock() -> __release_sock() drops the slock with spin_unlock_bh()\nand then calls sk->sk_backlog_rcv() with bottom halves enabled.\n\nTypical sk_backlog_rcv handlers process the socket whose backlog is\nbeing drained, so the BH state at entry is irrelevant for the slocks\nthey touch. pep_do_rcv() is different: when the inbound skb targets an\nexisting PEP pipe, it forwards the skb to a different *child* socket\nvia sk_receive_skb(). That helper takes the child slock with\nbh_lock_sock_nested(), which is just spin_lock_nested() and assumes BH\nis already off. The same child slock therefore ends up acquired with\nBH on (process path) and with BH off (softirq path):\n\n  process context                   softirq context\n  ---------------                   ---------------\n  release_sock(listener)            __netif_receive_skb()\n   __release_sock()                  phonet_rcv()\n    spin_unlock_bh()                  __sk_receive_skb(listener)\n    [BH now ENABLED]                  [BH already disabled]\n    sk_backlog_rcv:                   sk_backlog_rcv:\n     pep_do_rcv()                      pep_do_rcv()\n      sk_receive_skb(child)             sk_receive_skb(child)\n       bh_lock_sock_nested(child)        bh_lock_sock_nested(child)\n       => SOFTIRQ-ON-W                   => IN-SOFTIRQ-W\n\nLockdep flags this as inconsistent lock state, and it can become a real\nself-deadlock if a softirq on the same CPU tries to receive to the same\nchild socket while its slock is held in the BH-enabled path:\n\n  WARNING: inconsistent lock state\n  inconsistent {SOFTIRQ-ON-W} -> {IN-SOFTIRQ-W} usage.\n   (slock-AF_PHONET/1){+.?.}-{3:3}, at: __sk_receive_skb+0x1cf/0x900\n    __sk_receive_skb              net/core/sock.c:563\n    sk_receive_skb                include/net/sock.h:2022 [inline]\n    pep_do_rcv                    net/phonet/pep.c:675\n    sk_backlog_rcv                include/net/sock.h:1190\n    __release_sock                net/core/sock.c:3216\n    release_sock                  net/core/sock.c:3815\n    pep_sock_accept               net/phonet/pep.c:879\n\nWrap the forwarded sk_receive_skb() in local_bh_disable() /\nlocal_bh_enable() so the child slock is always acquired with BH off.\nlocal_bh_disable() nests safely on the softirq path.\n\nDiscovered via in-house syzkaller fuzzing; the same root cause also\non the linux-6.1.y syzbot dashboard as extid 44f0626dd6284f02663c.\nReproduced under KASAN + LOCKDEP + PROVE_LOCKING, reproducer:\nhttps://pastebin.com/A3t8xzCR"}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["net/phonet/pep.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"9641458d3ec42def729fde64669abf07f3220cd5","lessThan":"f08c45076e4fd8b0adbc5eb186d6e6a3e7350d7b","versionType":"git","status":"affected"},{"version":"9641458d3ec42def729fde64669abf07f3220cd5","lessThan":"b2606c302d7f2b4ee48da05e32ed60aed1b0cd53","versionType":"git","status":"affected"},{"version":"9641458d3ec42def729fde64669abf07f3220cd5","lessThan":"02c04df84de709060f63e1d52ec67488c4f6f212","versionType":"git","status":"affected"},{"version":"9641458d3ec42def729fde64669abf07f3220cd5","lessThan":"8420aa4900417797323dd567ba9d1512280c2dc3","versionType":"git","status":"affected"},{"version":"9641458d3ec42def729fde64669abf07f3220cd5","lessThan":"bd795f106b3889fb0706c6e4831c4b27e2b5666b","versionType":"git","status":"affected"},{"version":"9641458d3ec42def729fde64669abf07f3220cd5","lessThan":"84bc87beb4cd77670939b446326788e4c9b3db37","versionType":"git","status":"affected"},{"version":"9641458d3ec42def729fde64669abf07f3220cd5","lessThan":"a3fc8f2dacd1c37325977fc1fbbf3d52141df99e","versionType":"git","status":"affected"},{"version":"9641458d3ec42def729fde64669abf07f3220cd5","lessThan":"dbc81608e3a653dea6cf403f20cae35468b8ab9c","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["net/phonet/pep.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"2.6.28","status":"affected"},{"version":"0","lessThan":"2.6.28","versionType":"semver","status":"unaffected"},{"version":"5.10.258","lessThanOrEqual":"5.10.*","versionType":"semver","status":"unaffected"},{"version":"5.15.209","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.175","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.142","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.92","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.34","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.0.11","lessThanOrEqual":"7.0.*","versionType":"semver","status":"unaffected"},{"version":"7.1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/02c04df84de709060f63e1d52ec67488c4f6f212","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/8420aa4900417797323dd567ba9d1512280c2dc3","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/84bc87beb4cd77670939b446326788e4c9b3db37","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/a3fc8f2dacd1c37325977fc1fbbf3d52141df99e","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/b2606c302d7f2b4ee48da05e32ed60aed1b0cd53","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/bd795f106b3889fb0706c6e4831c4b27e2b5666b","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/dbc81608e3a653dea6cf403f20cae35468b8ab9c","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/f08c45076e4fd8b0adbc5eb186d6e6a3e7350d7b","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-64179","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-07-19T16:18:00.277","lastModified":"2026-07-19T16:18:00.277","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nnet: wwan: iosm: fix potential memory leaks in ipc_imem_init()\n\nThe memory allocated in ipc_protocol_init() is not freed on the error\npaths that follow in ipc_imem_init(). Fix that by calling the\ncorresponding release function ipc_protocol_deinit() in the error path."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/net/wwan/iosm/iosm_ipc_imem.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"3670970dd8c661c10c10c300d726f59428eaad32","lessThan":"f1a4d57847813fae42fbb7eb35f2dd48b9cff8a9","versionType":"git","status":"affected"},{"version":"3670970dd8c661c10c10c300d726f59428eaad32","lessThan":"ba6d8643019c33428f7c0658863e80e0b04a70f4","versionType":"git","status":"affected"},{"version":"3670970dd8c661c10c10c300d726f59428eaad32","lessThan":"6f63a60580ebdd9a1f22f89a84814d1fefe16b1c","versionType":"git","status":"affected"},{"version":"3670970dd8c661c10c10c300d726f59428eaad32","lessThan":"583fd5a8fc797c8ecf2e1a7b923740c5e5734e85","versionType":"git","status":"affected"},{"version":"3670970dd8c661c10c10c300d726f59428eaad32","lessThan":"ffb6dbb49c96be82f07c7b112e3ebc3e6fdd8dd5","versionType":"git","status":"affected"},{"version":"3670970dd8c661c10c10c300d726f59428eaad32","lessThan":"8f764a7810a9f114313c439d25b11f4417c6e0dd","versionType":"git","status":"affected"},{"version":"3670970dd8c661c10c10c300d726f59428eaad32","lessThan":"c5d93b2c40355e999715262a824965aac025a427","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/net/wwan/iosm/iosm_ipc_imem.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"5.14","status":"affected"},{"version":"0","lessThan":"5.14","versionType":"semver","status":"unaffected"},{"version":"5.15.209","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.175","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.142","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.92","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.34","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.0.11","lessThanOrEqual":"7.0.*","versionType":"semver","status":"unaffected"},{"version":"7.1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/583fd5a8fc797c8ecf2e1a7b923740c5e5734e85","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/6f63a60580ebdd9a1f22f89a84814d1fefe16b1c","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/8f764a7810a9f114313c439d25b11f4417c6e0dd","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/ba6d8643019c33428f7c0658863e80e0b04a70f4","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/c5d93b2c40355e999715262a824965aac025a427","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/f1a4d57847813fae42fbb7eb35f2dd48b9cff8a9","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/ffb6dbb49c96be82f07c7b112e3ebc3e6fdd8dd5","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-64180","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-07-19T16:18:00.397","lastModified":"2026-07-19T16:18:00.397","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nmm/memory_hotplug: fix memory block reference leak on remove\n\nPatch series \"mm: Fix memory block leaks and locking\", v2.\n\nThis series fixes two memory block device reference leaks and one locking\nissue around the per-memory_block hwpoison counter.\n\n\nThis patch (of 2):\n\nremove_memory_blocks_and_altmaps() looks up each memory block with\nfind_memory_block(), which acquires a reference to the memory block\ndevice.\n\nThat reference is never dropped on this path, resulting in a leaked device\nreference when removing memory blocks and their altmaps.  Drop the\nreference after retrieving mem->altmap and clearing mem->altmap, before\nremoving the memory block device."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["mm/memory_hotplug.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6b8f0798b85aa529011570369db985a788f3003f","lessThan":"b8ab30c79fc00147125b9c39f928561d9dd13d06","versionType":"git","status":"affected"},{"version":"6b8f0798b85aa529011570369db985a788f3003f","lessThan":"09ce923071e7852ece60d7368e05249bf32c7967","versionType":"git","status":"affected"},{"version":"6b8f0798b85aa529011570369db985a788f3003f","lessThan":"df64c0d21c3f85f844b2f656333e43d97e6ffa74","versionType":"git","status":"affected"},{"version":"6b8f0798b85aa529011570369db985a788f3003f","lessThan":"93866f55f7e292fe3d47d36c9efe5ee10213a06b","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["mm/memory_hotplug.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.8","status":"affected"},{"version":"0","lessThan":"6.8","versionType":"semver","status":"unaffected"},{"version":"6.12.92","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.34","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.0.11","lessThanOrEqual":"7.0.*","versionType":"semver","status":"unaffected"},{"version":"7.1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/09ce923071e7852ece60d7368e05249bf32c7967","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/93866f55f7e292fe3d47d36c9efe5ee10213a06b","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/b8ab30c79fc00147125b9c39f928561d9dd13d06","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/df64c0d21c3f85f844b2f656333e43d97e6ffa74","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-64182","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-07-19T16:18:00.600","lastModified":"2026-07-19T16:18:00.600","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\ndrivers/base/memory: fix memory block reference leak in poison accounting\n\nmemblk_nr_poison_inc() and memblk_nr_poison_sub() look up a memory block\nvia find_memory_block_by_id(), which acquires a reference to the memory\nblock device.\n\nBoth helpers use the returned memory block without dropping that\nreference, leaking the device reference on each successful lookup.  Drop\nthe reference after updating nr_hwpoison."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/base/memory.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"5033091de814ab4b5623faed2755f3064e19e2d2","lessThan":"686b4283f82cd630fafd7ca9b03dfc080b3ec8fa","versionType":"git","status":"affected"},{"version":"5033091de814ab4b5623faed2755f3064e19e2d2","lessThan":"ce60d9452a0f2effa72fd20ea270c59ca691d455","versionType":"git","status":"affected"},{"version":"5033091de814ab4b5623faed2755f3064e19e2d2","lessThan":"24840b3139d7415144b81e4f9f4c44670d15bed9","versionType":"git","status":"affected"},{"version":"5033091de814ab4b5623faed2755f3064e19e2d2","lessThan":"8502e2c2d0633f99d94d22ae8dabc10caae1fc2a","versionType":"git","status":"affected"},{"version":"5033091de814ab4b5623faed2755f3064e19e2d2","lessThan":"03a2cc1756a0570f887d624cd6c535ea0cbd4951","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/base/memory.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.2","status":"affected"},{"version":"0","lessThan":"6.2","versionType":"semver","status":"unaffected"},{"version":"6.6.142","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.92","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.34","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.0.11","lessThanOrEqual":"7.0.*","versionType":"semver","status":"unaffected"},{"version":"7.1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/03a2cc1756a0570f887d624cd6c535ea0cbd4951","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/24840b3139d7415144b81e4f9f4c44670d15bed9","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/686b4283f82cd630fafd7ca9b03dfc080b3ec8fa","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/8502e2c2d0633f99d94d22ae8dabc10caae1fc2a","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/ce60d9452a0f2effa72fd20ea270c59ca691d455","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-64183","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-07-19T16:18:00.703","lastModified":"2026-07-19T16:18:00.703","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nefi: Allocate runtime workqueue before ACPI init\n\nSince commit\n\n  5894cf571e14 (\"acpi/prmt: Use EFI runtime sandbox to invoke PRM handlers\")\n\nACPI PRM calls are delegated to a workqueue which runs in a kernel\nthread, making it easier to detect and mitigate faulting memory accesses\nperformed by the firmware.\n\nRafael reports that such PRM accesses may occur before efisubsys_init()\nexecutes, which is where the workqueue is allocated, leading to NULL\npointer dereferences. Since acpi_init() [which triggers the early PRM\naccesses] executes as a subsys_initcall() as well, and has its own\ndependencies that may be sensitive to initcall ordering, deferring\nacpi_init() is not an option.\n\nSo instead, split off the workqueue allocation into its own postcore\ninitcall, as this is the only missing piece to allow EFI runtime calls\nto be made. This ensures that EFI runtime call (including PRM calls) are\naccessible to all code running at subsys_initcall() level."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/firmware/efi/efi.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"5894cf571e14fb393a4d0a82538de032127b9d8b","lessThan":"29cd94e678fcb3c4fd0f359deeac6d61334323fc","versionType":"git","status":"affected"},{"version":"5894cf571e14fb393a4d0a82538de032127b9d8b","lessThan":"6996e954ae830f5b793ba6cf449885ca519dbdd2","versionType":"git","status":"affected"},{"version":"5894cf571e14fb393a4d0a82538de032127b9d8b","lessThan":"c32a1fbe0f9a48453a552bb315cc4f1e7a74084e","versionType":"git","status":"affected"},{"version":"5894cf571e14fb393a4d0a82538de032127b9d8b","lessThan":"e871549f7894ad4114b3dd53f241aa25a268ba8b","versionType":"git","status":"affected"},{"version":"5894cf571e14fb393a4d0a82538de032127b9d8b","lessThan":"13c6da02e767152c9ac4330962247a5e47011035","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/firmware/efi/efi.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.6","status":"affected"},{"version":"0","lessThan":"6.6","versionType":"semver","status":"unaffected"},{"version":"6.6.142","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.92","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.34","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.0.11","lessThanOrEqual":"7.0.*","versionType":"semver","status":"unaffected"},{"version":"7.1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/13c6da02e767152c9ac4330962247a5e47011035","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/29cd94e678fcb3c4fd0f359deeac6d61334323fc","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/6996e954ae830f5b793ba6cf449885ca519dbdd2","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/c32a1fbe0f9a48453a552bb315cc4f1e7a74084e","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/e871549f7894ad4114b3dd53f241aa25a268ba8b","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-64184","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-07-19T16:18:00.817","lastModified":"2026-07-19T16:18:00.817","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nmm/damon/sysfs-schemes: call missing mem_cgroup_iter_break()\n\ndamon_sysfs_memcg_path_to_id() breaks mem_cgroup_iter() loop without\ncalling mem_cgroup_iter_break().  This leaks the cgroup reference.  Fix\nthe issue by calling mem_cgroup_iter_break() before the break.\n\nThe issue was discovered [1] by Sashiko."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["mm/damon/sysfs-schemes.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"29cbb9a13f05b20f0777c60db9603730b487a4e0","lessThan":"082351f9d40007414ad6af062b3a26fa02fd4b5f","versionType":"git","status":"affected"},{"version":"29cbb9a13f05b20f0777c60db9603730b487a4e0","lessThan":"30a361be33f3793b9ecbd10ab7be6d0564819b79","versionType":"git","status":"affected"},{"version":"29cbb9a13f05b20f0777c60db9603730b487a4e0","lessThan":"302e02f9ba49f81418ec2a749ae6f5cac1d424e9","versionType":"git","status":"affected"},{"version":"29cbb9a13f05b20f0777c60db9603730b487a4e0","lessThan":"1bd31386ec3b9ccec10c04429948a306ec5897c0","versionType":"git","status":"affected"},{"version":"29cbb9a13f05b20f0777c60db9603730b487a4e0","lessThan":"d4e7b5c4cc353f154d5ab8bb2e1ce7714d77a6e9","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["mm/damon/sysfs-schemes.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.3","status":"affected"},{"version":"0","lessThan":"6.3","versionType":"semver","status":"unaffected"},{"version":"6.6.142","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.92","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.34","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.0.11","lessThanOrEqual":"7.0.*","versionType":"semver","status":"unaffected"},{"version":"7.1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/082351f9d40007414ad6af062b3a26fa02fd4b5f","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/1bd31386ec3b9ccec10c04429948a306ec5897c0","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/302e02f9ba49f81418ec2a749ae6f5cac1d424e9","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/30a361be33f3793b9ecbd10ab7be6d0564819b79","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/d4e7b5c4cc353f154d5ab8bb2e1ce7714d77a6e9","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-64185","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-07-19T16:18:00.917","lastModified":"2026-07-19T16:18:00.917","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nsysfs: don't remove existing directory on update failure\n\nWhen sysfs_update_group() is called for a named group and create_files()\nfails (e.g. -ENOMEM), internal_create_group() calls kernfs_remove(kn) on\nthe group directory.  In the update path, kn was obtained via\nkernfs_find_and_get() and refers to a directory that already existed\nbefore this call.  Removing it silently destroys a sysfs group that the\ncaller did not create.\n\nOnly remove the directory if we created it ourselves.  On update failure\nthe directory remains as it is left empty by remove_files() inside\ncreate_files(), but can be repopulated by a retry."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["fs/sysfs/group.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"c855cf2759d27142f771173d9fd8e7fdf9cf5138","lessThan":"c5e125c828b701afaf7493b42a14aa89362ff36d","versionType":"git","status":"affected"},{"version":"c855cf2759d27142f771173d9fd8e7fdf9cf5138","lessThan":"ccadd32cc1263802a5969c9efe0e96225450428c","versionType":"git","status":"affected"},{"version":"c855cf2759d27142f771173d9fd8e7fdf9cf5138","lessThan":"14f2c14ae86c4af17a0a9f8ab46dacf2d5fd1d8a","versionType":"git","status":"affected"},{"version":"c855cf2759d27142f771173d9fd8e7fdf9cf5138","lessThan":"31527d80234caf83dc96ad478645e57df9de4472","versionType":"git","status":"affected"},{"version":"c855cf2759d27142f771173d9fd8e7fdf9cf5138","lessThan":"57b285e0368290aa55f79ba11419b96d0ebdb418","versionType":"git","status":"affected"},{"version":"c855cf2759d27142f771173d9fd8e7fdf9cf5138","lessThan":"48fa96538bd2868034d33429e4565fda384d0736","versionType":"git","status":"affected"},{"version":"c855cf2759d27142f771173d9fd8e7fdf9cf5138","lessThan":"708f6926f61f71e09b5e9fd668b9882ccd46e69f","versionType":"git","status":"affected"},{"version":"c855cf2759d27142f771173d9fd8e7fdf9cf5138","lessThan":"237557b8a81ab948e8332f7c0058e758f081c0a3","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["fs/sysfs/group.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"4.19","status":"affected"},{"version":"0","lessThan":"4.19","versionType":"semver","status":"unaffected"},{"version":"5.10.258","lessThanOrEqual":"5.10.*","versionType":"semver","status":"unaffected"},{"version":"5.15.209","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.175","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.142","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.92","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.34","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.0.11","lessThanOrEqual":"7.0.*","versionType":"semver","status":"unaffected"},{"version":"7.1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/14f2c14ae86c4af17a0a9f8ab46dacf2d5fd1d8a","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/237557b8a81ab948e8332f7c0058e758f081c0a3","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/31527d80234caf83dc96ad478645e57df9de4472","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/48fa96538bd2868034d33429e4565fda384d0736","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/57b285e0368290aa55f79ba11419b96d0ebdb418","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/708f6926f61f71e09b5e9fd668b9882ccd46e69f","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/c5e125c828b701afaf7493b42a14aa89362ff36d","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/ccadd32cc1263802a5969c9efe0e96225450428c","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-64186","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-07-19T16:18:01.037","lastModified":"2026-07-19T16:18:01.037","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\niommu/amd: Remove latent out-of-bounds access in IOMMU debugfs\n\nIn iommu_mmio_write() and iommu_capability_write(), the variables\ndbg_mmio_offset and dbg_cap_offset are declared as int. However, they\nare populated using kstrtou32_from_user(). If a user provides a\nsufficiently large value, it can become a negative integer.\n\nPrior to this patch, the AMD IOMMU debugfs implementation was already\nprotected by different mechanisms.\n\n1. #define OFS_IN_SZ 8 ensures the user string <= 8 bytes, so\n   e.g. 0xffffffff isn't a valid input.\n\n  if (cnt > OFS_IN_SZ)\n     return -EINVAL;\n\n2. Implicit type promotion in iommu_mmio_write(), dbg_mmio_offset is int\n   and iommu->mmio_phys_end is u64\n\n  if (dbg_mmio_offset > iommu->mmio_phys_end - sizeof(u64))\n      return -EINVAL;\n\n3. The show handlers would currently catch the negative number and\n   refuse to perform the read.\n\nReplace kstrtou32_from_user() with kstrtos32_from_user() to parse the\ninput, and check for negative values to explicitly prevent out-of-bounds\nmemory accesses directly in iommu_mmio_write() and\niommu_capability_write()."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/iommu/amd/debugfs.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"7a4ee419e8c144b747a8915856e91a034d7c8f34","lessThan":"488d2c76bd9f78433a70690d1054bfae3d39a407","versionType":"git","status":"affected"},{"version":"7a4ee419e8c144b747a8915856e91a034d7c8f34","lessThan":"62f9dfbf1aceae88b03c5ca08f7d36e943939dec","versionType":"git","status":"affected"},{"version":"7a4ee419e8c144b747a8915856e91a034d7c8f34","lessThan":"8dfd3d8d74435344ee8dc9237596959c8b2a6cbe","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/iommu/amd/debugfs.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.17","status":"affected"},{"version":"0","lessThan":"6.17","versionType":"semver","status":"unaffected"},{"version":"6.18.34","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.0.11","lessThanOrEqual":"7.0.*","versionType":"semver","status":"unaffected"},{"version":"7.1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/488d2c76bd9f78433a70690d1054bfae3d39a407","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/62f9dfbf1aceae88b03c5ca08f7d36e943939dec","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/8dfd3d8d74435344ee8dc9237596959c8b2a6cbe","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}}]}