Complete feed
No mitigation yet
No fix, workaround or mitigation extracted yet
Android app · Google Play
Take your CVE monitoring with you.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.
High [CVE-2026-64379] mask server-provided mode to 07777 in modefromsid
mask server-provided mode to 07777 in modefromsid. Red Hat rates this moderate (CVSS 7). Weakness: CWE-279.
High [CVE-2026-64525] move policy_bydst RCU sync from per-netns.exit to.pre_exit
move policy_bydst RCU sync from per-netns.exit to.pre_exit. Red Hat rates this moderate (CVSS 7). Weakness: CWE-821.
High [CVE-2026-64312] pcrypt - restore callback for non-parallel fallback
pcrypt - restore callback for non-parallel fallback. Red Hat rates this moderate (CVSS 7).
High [CVE-2026-64380] harden POSIX SID length parsing
harden POSIX SID length parsing. Red Hat rates this moderate (CVSS 7).
High [CVE-2026-64475] Release the VGA arbiter client on register_device failure
Release the VGA arbiter client on register_device() failure. Red Hat rates this moderate (CVSS 7).
High [CVE-2026-64434] Fix UAF in channel timeout by holding conn ref
Fix UAF in channel timeout by holding conn ref. Red Hat rates this important (CVSS 7). Weakness: CWE-364.
High [CVE-2026-64508] Support for hardening against JIT spraying
Support for hardening against JIT spraying. Red Hat rates this moderate (CVSS 7).
High [CVE-2026-64305] qat - protect service table iterations with service_lock
qat - protect service table iterations with service_lock. Red Hat rates this moderate (CVSS 7). Weakness: CWE-366.
High [CVE-2026-64422] bound TCP reordering sysctl writes and MTU probe sizes
bound TCP reordering sysctl writes and MTU probe sizes. Red Hat rates this moderate (CVSS 7).
High [CVE-2026-64306] drbg - Fix returning success on failure in CTR_DRBG
drbg - Fix returning success on failure in CTR_DRBG. Red Hat rates this moderate (CVSS 7).
High [CVE-2026-64410] IPIP tunnel hardware offload is not yet support
IPIP tunnel hardware offload is not yet support. Red Hat rates this moderate (CVSS 7). Weakness: CWE-166.
High [CVE-2026-64375] protect ptrace_may_access with exec_update_lock (FD links)
protect ptrace_may_access() with exec_update_lock (FD links). Red Hat rates this important (CVSS 7). Weakness: CWE-367.
High [CVE-2026-64320] fix pre-auth out-of-bounds heap read in Discovery Get Log Page
fix pre-auth out-of-bounds heap read in Discovery Get Log Page. Red Hat rates this moderate (CVSS 7). Weakness: CWE-125.
High [CVE-2026-64527] validate VMBus packet size in receive callback
validate VMBus packet size in receive callback. Red Hat rates this moderate (CVSS 7). Weakness: CWE-805.
High [CVE-2026-64267] avoid 32-bit prune notification count wrap
avoid 32-bit prune notification count wrap. Red Hat rates this moderate (CVSS 7). Weakness: CWE-190.
High [CVE-2026-64471] fix use-after-free on registration failure
fix use-after-free on registration failure. Red Hat rates this moderate (CVSS 7). Weakness: CWE-825.
High [CVE-2026-64473] Remove device debugfs before releasing devres
Remove device debugfs before releasing devres. Red Hat rates this moderate (CVSS 7). Weakness: CWE-911.
High [CVE-2026-64319] validate reply message payload bounds against transfer length
validate reply message payload bounds against transfer length. Red Hat rates this moderate (CVSS 7). Weakness: CWE-125.
High [CVE-2026-64266] re-lock request before returning from fuse_ref_folio
re-lock request before returning from fuse_ref_folio(). Red Hat rates this moderate (CVSS 7). Weakness: CWE-825.
High [CVE-2026-64414] handle unreadable frags
handle unreadable frags. Red Hat rates this moderate (CVSS 7). Weakness: CWE-390.