Skip to content
VulniPulse

Complete feed

Recently updated

Advisories the vendor has revised

Home overview

Android app · Google Play

Take your CVE monitoring with you.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

High7.0Vendor: MediumRed Hat

High [CVE-2026-64280] validate DMA mapping length in afu_dma_map_region

In the Linux kernel, the following vulnerability has been resolved: fpga: dfl-afu: validate DMA mapping length in afu_dma_map_region() afu_ioctl_dma_map() accepts a 64-bit length from userspace via DFL_FPGA_PORT_DMA_MAP ioctl without an upper bound check. The value is passed to afu_dma_pin_pages() where npages is derived as length >> PAGE_SHIFT and passed to pin_user_pages_fast() which takes int nr_pages, causing implicit truncation if length is very large. Validate map.length at the ioctl entry point before calling afu_dma_map_region(), rejecting values whose page count exceeds INT_MAX. A local user could exploit this vulnerability by providing an excessively large length value during Direct Memory Access (DMA) mapping operations. The system incorrectly truncates this value, leading to memory corruption. This could allow a local attacker to gain elevated privileges or execute arbitrary code on the system. Red Hat severity: Moderate — CVSS 7 (CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H). Weakness: CWE-190. Red Hat lists Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9 as not affected.

CVE-2026-64280
Unclassified
Jul 25, 2026
High7.0Vendor: MediumRed Hat

High [CVE-2026-64298] include MAY_WRITE in open permission mask for O_TRUNC

In the Linux kernel, the following vulnerability has been resolved: NFSv4: include MAY_WRITE in open permission mask for O_TRUNC POSIX requires write permission to truncate a file, so an open() that specifies O_TRUNC must be authorized for write access regardless of the O_ACCMODE access mode. nfs_open_permission_mask() builds the access mask passed to nfs_may_open(), which is the local authorization gate for OPENs the client serves itself from a cached write delegation via the can_open_delegated() path in nfs4_try_open_cached(). The mask is derived from O_ACCMODE alone, so an open(O_RDONLY | O_TRUNC) against a file the caller cannot write requests only MAY_READ and passes the local check. The OPEN is then satisfied locally and the truncation is issued to the server as a SETATTR(size=0) over the delegation stateid, which the server accepts under standard write-delegation semantics. A local user could exploit a vulnerability where opening a file with O_TRUNC (truncate) and O_RDONLY (read-only) flags would bypass the necessary write permission checks. This oversight allows an attacker to truncate a file without having explicit write access, leading to unauthorized data modification. Red Hat severity: Moderate — CVSS 7 (CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H). Weakness: CWE-358.

CVE-2026-64298
Linux Kernel
Jul 25, 2026
High7.0Vendor: MediumRed Hat

High [CVE-2026-64402] Fix OOB write in smb_sync_perf_buffer

In the Linux kernel, the following vulnerability has been resolved: coresight: ultrasoc-smb: Fix OOB write in smb_sync_perf_buffer() When the SMB sink is used as a perf AUX sink, smb_update_buffer() calls smb_sync_perf_buffer() to copy hardware trace data into the perf AUX ring buffer pages. It derives pg_idx = head >> PAGE_SHIFT from @head, which is handle->head, and indexes dst_pages[pg_idx]. The pg_idx %= nr_pages normalization is only applied after the first loop iteration. This leaves the initial page index underived from the buffer size, which can result in an out-of-bounds write past dst_pages[] when head exceeds the AUX buffer size. Normalize head modulo the AUX buffer size before deriving the page index and offset, mirroring tmc_etr_sync_perf_buffer(). This vulnerability involves an out-of-bounds write in the `smb_sync_perf_buffer()` function. An attacker could potentially exploit this by causing the system to write data beyond the intended memory buffer, which may lead to system instability or a denial of service (DoS). This occurs because a page index is calculated incorrectly before being properly normalized, allowing the system to access memory outside its allocated boundaries. Red Hat severity: Moderate — CVSS 7 (CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H). Weakness: CWE-787.

CVE-2026-64402
Unclassified
Jul 25, 2026
High7.0Red Hat

High [CVE-2026-64364] fix out-of-bounds bit access on mt_io_flags

In the Linux kernel, the following vulnerability has been resolved: HID: multitouch: fix out-of-bounds bit access on mt_io_flags mt_io_flags is a single unsigned long, but mt_process_slot(), mt_release_pending_palms() and mt_release_contacts() use it as a per-slot bitmap indexed by the slot number. That slot number is only bounded by td->maxcontacts, which is taken from the device's ContactCountMaximum feature report and can be up to 255, not by BITS_PER_LONG. As a result, a multitouch device that advertises a large contact count makes set_bit()/clear_bit() operate past the mt_io_flags word and corrupt the adjacent members of struct mt_device. The sticky-fingers release timer is the easiest way to reach this. mt_release_contacts() runs for (i = 0; i num_slots; i++) clear_bit(i, &td->mt_io_flags); with num_slots == maxcontacts. For maxcontacts around 250 the loop clears the bits that overlap td->applications.next, zeroing that list head, and the list_for_each_entry() that immediately follows then dereferences NULL. The kernel panics from timer (softirq) context. On a KASAN build this shows up as a general protection fault in mt_release_contacts() with a null-ptr-deref at offset 0x58, which is offsetof(struct mt_application, num_received). The state is reachable from an untrusted USB or Bluetooth HID multitouch device; no local privileges are required.

CVE-2026-64364
Unclassified
Jul 25, 2026
High7.0Red Hat

High [CVE-2026-64303] terminate the RX channel on TX prepare failure path

In the Linux kernel, the following vulnerability has been resolved: spi: fsl-lpspi: terminate the RX channel on TX prepare failure path When dmaengine_prep_slave_sg() fails for the TX channel, the error path terminates the TX DMA channel but leaves the RX channel running. Since the RX channel was already submitted and issued prior to preparing the TX descriptor, returning -EINVAL causes the SPI core to unmap the DMA buffers while the RX DMA engine continues writing to them, leading to potential memory corruption or use-after-free. This vulnerability occurs when the transmit (TX) Direct Memory Access (DMA) channel fails to prepare, but the receive (RX) DMA channel continues to operate. This can lead to memory corruption or a use-after-free condition, potentially allowing an attacker to compromise system integrity or execute unauthorized code. Red Hat severity: Important — CVSS 7 (CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H). Weakness: CWE-825. Affected Red Hat products: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9. Red Hat does not currently list a fixing RHSA for this CVE. Affected products named by the advisory: Red Hat package: kernel-rt.

CVE-2026-64303
Linux Kernel
Jul 25, 2026
High7.0Red Hat

High [CVE-2026-64271] touchwin - reset the packet index on every complete packet

In the Linux kernel, the following vulnerability has been resolved: Input: touchwin - reset the packet index on every complete packet tw_interrupt() accumulates each non-zero serial byte into a fixed three-byte buffer with a running index that is only reset once a full packet has been received *and* the device's two Y bytes agree: tw->data[tw->idx++] = data; if (tw->idx == TW_LENGTH && tw->data[1] == tw->data[2]) {... tw->idx = 0; } The reset is gated on tw->data[1] == tw->data[2], a value the device controls. A malicious, malfunctioning or counterfeit Touchwindow peripheral can stream non-zero bytes whose 2nd and 3rd bytes differ: the index reaches TW_LENGTH without the equality holding, is never reset, and keeps growing, so tw->data[tw->idx++] walks off the end of the three-byte array and the rest of the heap-allocated struct tw, one attacker-chosen byte at a time -- an unbounded, device-driven heap out-of-bounds write. Reset the index on every completed packet and report an event only when the two Y bytes match, like the other serio touchscreen drivers do. This prevents the packet index from resetting, allowing the peripheral to write arbitrary data beyond the intended buffer. This could lead to arbitrary code execution, enabling an attacker to take control of the affected system. Red Hat severity: Important — CVSS 7 (CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H).

CVE-2026-64271
Unclassified
Jul 25, 2026
High7.0Vendor: MediumRed Hat

High [CVE-2026-64283] Treat memslot binding offset+size as unsigned values

In the Linux kernel, the following vulnerability has been resolved: KVM: guest_memfd: Treat memslot binding offset+size as unsigned values When binding a memslot to a guest_memfd file, treat the offset and size as unsigned values to fix a bug where the sum of the two can result in a false negative when checking for overflow against the size of the file. Passing unsigned values also avoids relying on somewhat obscure checks in other flows for safety, and tracks the offset and size as they are intended to be tracked, as unsigned values. On 64-bit kernels, the number of pages a memslot contains and thus the size (and offset) of its guest_memfd binding are unsigned 64-bit values. Taking the offset+size as an loff_t instead of a uoff_t inadvertently converts the unsigned value to a signed value if the offset and/or size is massive. Locally storing the offset and size as signed values is benign in and of itself (though even that is *extremely* difficult to discern), but operating on their sum is not. For the offset, KVM explicitly checks against a negative value, which might seem like a bug as KVM could incorrectly reject a legitimate binding, but that's not actually the case as KVM_CREATE_GUEST_MEMFD takes a signed value for its size, i.e. a would-be-negative offset is also greater than the maximum possible size of any guest_memfd file.

CVE-2026-64283
Unclassified
Jul 25, 2026
High7.0Red Hat

High [CVE-2026-64439] krb5 - filter out async aead implementations at alloc

In the Linux kernel, the following vulnerability has been resolved: crypto: krb5 - filter out async aead implementations at alloc krb5_aead_encrypt(), krb5_aead_decrypt() in rfc3961_simplified.c and rfc8009_encrypt(), rfc8009_decrypt() in rfc8009_aes2.c set a NULL completion callback and treat any negative return from crypto_aead_{encrypt,decrypt}() as terminal, falling through to kfree_sensitive(buffer). When the encrypt_name resolves to an async AEAD instance the request returns -EINPROGRESS, the buffer is freed while the backend's worker still holds a pointer, and the worker dereferences the freed slab on completion. KASAN report under UML+SLUB with a synthetic async aead backend bound to krb5->encrypt_name: BUG: KASAN: slab-use-after-free in t5_stub_complete+0x7d/0xc7 The helpers were written synchronously, so filter the async instances out at allocation time instead of plumbing crypto_wait_req() through every call site. Reachable via net/rxrpc/rxgk.c, fs/afs/cm_security.c and net/ceph/crypto.c on systems with an async AEAD provider bound to the krb5 enctype name. A flaw was found in the Linux kernel's Kerberos 5 (krb5) cryptography module. This use-after-free vulnerability occurs when an asynchronous Authenticated Encryption with Associated Data (AEAD) instance is used.

CVE-2026-64439
Linux Kernel
Jul 25, 2026
High7.0Vendor: MediumRed Hat

High [CVE-2026-64516] Fix VCE 1 firmware size and offsets

In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu/vce1: Fix VCE 1 firmware size and offsets The VCPU BO contains the actual FW at an offset, but it was not calculated into the VCPU BO size. Subtract this from the FW size to make sure there is no out of bounds access. Make sure the stack and data offsets are aligned to the 32K TLB size. Check that the FW microcode actually fits in the space that is reserved for it. (cherry picked from commit c16fe59f622a080fc457a57b3e8f14c780699449) This issue could potentially allow a local attacker to cause system instability or a denial of service (DoS) by manipulating the firmware handling. Red Hat severity: Moderate — CVSS 7 (CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H). Weakness: CWE-125. Affected Red Hat products: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9. Red Hat does not currently list a fixing RHSA for this CVE. Affected products named by the advisory: Red Hat package: kernel-rt.

CVE-2026-64516
Linux Kernel
Jul 25, 2026
High7.0Vendor: MediumRed Hat

High [CVE-2026-64401] resolve SWN tcon from live registrations

In the Linux kernel, the following vulnerability has been resolved: smb: client: resolve SWN tcon from live registrations cifs_swn_notify() looks up a witness registration by id under cifs_swnreg_idr_mutex, drops the mutex, and then uses the registration's cached tcon pointer. That pointer is not a lifetime reference, and it is not a stable representative once cifs_get_swn_reg() lets multiple tcons for the same net/share name share one registration id. A same-share second mount can keep the cifs_swn_reg alive after the first tcon unregisters and is freed. The registration then still points at the freed first tcon, so taking tc_lock or incrementing tc_count through swnreg->tcon only moves the use-after-free earlier. Taking tc_lock while holding cifs_swnreg_idr_mutex also violates the documented CIFS lock order. Fix this by making the registration store only the stable witness identity: id, net name, share name, and notify flags. When a notify arrives, copy that identity under cifs_swnreg_idr_mutex, drop the mutex, then find and pin a live witness tcon that currently matches the net/share pair under the normal cifs_tcp_ses_lock -> tc_lock order. The notification path uses that pinned tcon directly and drops the reference when done. Registration and unregister messages now use the live tcon passed by the caller instead of a cached tcon in the registration.

CVE-2026-64401
Unclassified
Jul 25, 2026
High7.0Vendor: MediumRed Hat

High [CVE-2026-64520] Bound PARTITION_INFO_GET_REGS copies

In the Linux kernel, the following vulnerability has been resolved: firmware: arm_ffa: Bound PARTITION_INFO_GET_REGS copies The register-based PARTITION_INFO_GET path trusted the firmware-provided indices when copying partition descriptors into the caller buffer. Reject inconsistent counts or index progressions so the copy loop cannot write past the allocated array. (fixed cur_idx when exactly one descriptor in the first fragment) A flaw was found in the Linux kernel's ARM Firmware Framework for ARM (FFA). The PARTITION_INFO_GET_REGS function, which handles copying partition descriptors, did not adequately validate the indices provided by the firmware. This oversight could allow the system to process inconsistent data, resulting in an out-of-bounds write. Such an issue can lead to memory corruption, potentially causing system instability or a denial of service. Red Hat severity: Moderate — CVSS 7 (CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H). Weakness: CWE-787. Red Hat lists Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9 as not affected.

CVE-2026-64520
Unclassified
Jul 25, 2026
High7.0Red Hat

High [CVE-2026-64366] fix slab-out-of-bounds write in wacom_wac_queue_insert

In the Linux kernel, the following vulnerability has been resolved: HID: wacom: fix slab-out-of-bounds write in wacom_wac_queue_insert wacom_wac_queue_insert() calls kfifo_skip() in a loop when the kfifo doesn't have enough space for the incoming report. If the kfifo is empty, kfifo_skip() reads stale data left in the kmalloc'd buffer via __kfifo_peek_n() and interprets it as a record length, advancing fifo->out by that garbage value. This corrupts the internal kfifo state, causing kfifo_unused() to return a value much larger than the actual buffer size, which bypasses __kfifo_in_r()'s guard: if (len + recsize > kfifo_unused(fifo)) return 0; kfifo_copy_in() then performs an out-of-bounds memcpy, writing up to 3842 bytes past the 256-byte buffer. Add a!kfifo_is_empty() condition to the while loop so kfifo_skip() is never called on an empty fifo, and check the return value of kfifo_in() to reject reports that are too large for the fifo. A flaw was found in the Linux kernel's Wacom Human Interface Device (HID) driver. This vulnerability occurs in the `wacom_wac_queue_insert` function when handling incoming reports. Improper management of the kernel's internal buffer (kfifo) can lead to a slab-out-of-bounds write, allowing an attacker to corrupt memory. This memory corruption could potentially result in a denial of service or, in some cases, arbitrary code execution.

CVE-2026-64366
Linux Kernel
Jul 25, 2026
High7.0Vendor: MediumRed Hat

High [CVE-2026-64323] validate VAT header length against the VAT inode size

validate VAT header length against the VAT inode size. Red Hat rates this moderate (CVSS 7). Weakness: CWE-125.

CVE-2026-64323
Unclassified
Jul 25, 2026
High7.0Red Hat

High [CVE-2026-64268] Remote out-of-bounds write in RDMA/siw

Remote out-of-bounds write in RDMA/siw. Red Hat rates this important (CVSS 7). Weakness: CWE-787.

CVE-2026-64268
Unclassified
Jul 25, 2026
High7.0Vendor: MediumRed Hat

High [CVE-2026-64341] fix use-after-free on disconnect race

fix use-after-free on disconnect race. Red Hat rates this moderate (CVSS 7). Weakness: CWE-825.

CVE-2026-64341
Unclassified
Jul 25, 2026
High7.0Red Hat

High [CVE-2026-64287] Bound used_lrs when flushing the pKVM hyp vCPU

Bound used_lrs when flushing the pKVM hyp vCPU. Red Hat rates this important (CVSS 7). Weakness: CWE-125.

CVE-2026-64287
Unclassified
Jul 25, 2026
High7.0Vendor: MediumRed Hat

High [CVE-2026-64340] fix use-after-free on disconnect race

fix use-after-free on disconnect race. Red Hat rates this moderate (CVSS 7). Weakness: CWE-364.

CVE-2026-64340
Unclassified
Jul 25, 2026
High7.0Red Hat

High [CVE-2026-64383] fix double-free in SMB2_flush replay

fix double-free in SMB2_flush() replay. Red Hat rates this important (CVSS 7).

CVE-2026-64383
Unclassified
Jul 25, 2026
High7.0Vendor: MediumRed Hat

High [CVE-2026-64379] mask server-provided mode to 07777 in modefromsid

mask server-provided mode to 07777 in modefromsid. Red Hat rates this moderate (CVSS 7). Weakness: CWE-279.

CVE-2026-64379
Unclassified
Jul 25, 2026
High7.0Vendor: MediumRed Hat

High [CVE-2026-64525] move policy_bydst RCU sync from per-netns.exit to.pre_exit

move policy_bydst RCU sync from per-netns.exit to.pre_exit. Red Hat rates this moderate (CVSS 7). Weakness: CWE-821.

CVE-2026-64525
Unclassified
Jul 25, 2026